Privacy Policy
How Riddim & Vibez handles personal data when you visit the store, purchase a license, download music or use your Customer Library.
1. Who is responsible for your data?
Riddim & Vibez is responsible for the processing of personal data described in this policy.
2. What data do we process?
Website and first-party analytics
Riddim & Vibez measures use of the website with its own first-party analytics system. This may record an anonymous browser-session identifier, page or beat viewed, preview-play events, listening milestones, Free Download and purchase-related clicks, traffic source and a broad device category such as mobile or desktop.
The analytics event database does not store raw IP addresses, full browser user-agent strings, customer names or customer email addresses.
Orders and licenses
When you start or complete a purchase we may process your name, email address, selected beat, selected license, price, order status, Stripe Checkout identifiers, payment status, license agreement snapshot and download information.
Payment-card details are entered with the payment provider and are not stored by Riddim & Vibez.
Customer Library
If you use My Library, we process your email address, purchased products and temporary login-token information. Login links are one-time links and expire after 20 minutes.
Downloads and security
For paid downloads the system can record the order, download time and privacy-protective hashes used for security and abuse detection. For Free Downloads the website records download counts and anonymous analytics events.
We use your email address to send transactional messages such as purchase confirmations, secure Customer Library login links and information directly connected to your order or license.
3. Why do we process this data?
Depending on the situation, processing is necessary to perform a contract with you, comply with legal obligations, secure and operate the website, prevent abuse, provide downloads and licenses, and understand at an aggregated level how the store is used so we can improve it.
We do not use the V20 analytics system to build advertising profiles or follow visitors across unrelated websites.
4. How long do we keep data?
Analytics events: currently up to 180 days. Older analytics events are automatically eligible for deletion.
Temporary login links: they expire after 20 minutes. Technical token records may remain for a limited period for security and cleanup purposes.
Orders, invoices and financial administration: we retain information for as long as required to administer licenses, handle disputes and comply with applicable tax/accounting retention requirements. Dutch business records generally have a statutory retention period of 7 years; some situations can require a longer period.
License agreements: a purchased license snapshot may be kept together with the corresponding order so that both parties can establish which terms applied to the transaction.
5. Service providers
We use service providers where necessary to operate the store. These can include TransIP for hosting and email infrastructure and Stripe for payment processing. These providers process data according to their own roles, agreements and privacy terms.
If you follow an external link to a third-party platform such as Spotify, that third party's own privacy policy applies after you leave Riddim & Vibez.
6. Cookies and similar technologies
The site currently uses functional session technology and limited first-party analytics. It does not intentionally use advertising or cross-site tracking cookies.
For the detailed list and explanation, see our Cookie Policy.
7. Your privacy rights
Subject to the conditions of the GDPR, you can request access to your personal data, correction, deletion, restriction of processing, data portability or object to certain processing. You can also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
To exercise a privacy right, contact support@riddimandvibez.com. We may need enough information to verify that the request concerns your data.
8. Security
We use measures intended to protect customer and store data, including private file storage, controlled download routes, temporary login tokens, secure payment processing, access controls and HTTPS. No online system can guarantee absolute security.
9. Changes
We may update this policy when the store, legal requirements or service providers change. The latest version is always published on this page.