Privacy Policy

Effective date: July 31, 2026 · Last updated: July 31, 2026

This Privacy Policy explains how Shifted, LLC, a Rhode Island limited liability company doing business as CrateBridge ("CrateBridge," "we," "us," or "our"), collects, uses, discloses, and protects information about you when you use the CrateBridge website at cratebridge.app (the "Site"), the CrateBridge desktop application (the "Desktop App"), the CrateBridge web application (the "Web App"), and the CrateBridge Cloud storage and synchronization service (together, the "Service"). It also describes the rights and choices available to you. For the purposes of the EU and UK General Data Protection Regulation ("GDPR"), Shifted, LLC is the controller of the personal data described in this Policy.

This Policy is incorporated into and forms part of our Terms of Service. If you do not agree with this Policy, please do not use the Service.

1. Information We Collect

1.1 Information you provide

  • Account information. When you create an account we collect your name, email address, and a password. Passwords are stored only in salted, hashed form by our authentication provider; we never see or store your plaintext password.
  • Billing information. When you purchase a subscription, payment is processed by Stripe, Inc. Stripe collects your payment card details directly; we never receive or store your full card number. We receive from Stripe limited billing metadata such as the payment method type, the last four digits of your card, billing country, subscription status, and invoice history.
  • Your library ("User Content"). The core of the Service is storing and synchronizing your DJ library: audio files you upload, and library data such as playlists, crates, track metadata (titles, artists, tags), cue points, artwork, and analysis data (for example key, BPM, and file hashes used for duplicate detection).
  • Communications. If you contact us (for example at [email protected]), we collect the contents of your message and your contact details.

1.2 Information collected automatically

  • Device and sync information. To enforce plan device limits and show you which computers are connected, the Desktop App registers device identifiers and basic device information (such as computer name, platform, and app version), along with sync activity (for example timestamps of sync operations and storage usage).
  • Log and usage data. Our servers automatically record information sent by your browser or the apps, such as IP address, browser or app version, operating system, pages or endpoints accessed, timestamps, and error diagnostics. We use this for security, debugging, and capacity planning.
  • Local storage and cookies. The Site and Web App use cookies and browser storage (localStorage / sessionStorage) that are strictly necessary to operate the Service — chiefly to keep you signed in and to carry state through flows such as checkout and email verification. We do not use advertising cookies or third-party tracking pixels.

1.3 Information from third parties

We receive subscription and payment-status events from Stripe as described above. We do not purchase data about you from data brokers.

2. How We Use Information

We use the information we collect to:

  • provide, operate, and maintain the Service — including storing your library, synchronizing it across your devices, computing analysis data (key, BPM, duplicates), and enforcing storage quotas and device limits;
  • create and manage your account and authenticate you;
  • process subscriptions, payments, invoices, trials, and renewals;
  • communicate with you about the Service, including transactional emails (verification, receipts, subscription and security notices) and responses to support requests;
  • protect the Service and its users — detecting, preventing, and investigating fraud, abuse, security incidents, and violations of our Terms;
  • debug, analyze, and improve the performance and reliability of the Service;
  • comply with legal obligations and enforce our legal rights.

We do not sell your personal information, we do not share it for cross-context behavioral advertising, and we do not use the contents of your music library for advertising or marketing purposes. We do not use your User Content to train machine-learning models.

Where the GDPR applies, we process your personal data on the following legal bases:

  • Performance of a contract (Art. 6(1)(b)) — account creation, authentication, storing and syncing your library, billing, and support;
  • Legitimate interests (Art. 6(1)(f)) — securing the Service, preventing fraud and abuse, debugging and improving reliability, and defending legal claims, in each case balanced against your rights and expectations;
  • Legal obligation (Art. 6(1)(c)) — tax, accounting, and lawful requests from authorities;
  • Consent (Art. 6(1)(a)) — where we ask for it (for example optional marketing emails, if we ever send them). You may withdraw consent at any time without affecting prior processing.

4. How We Share Information

We share personal data only as described below, and we require service providers to process it solely on our instructions and to protect it appropriately:

RecipientRoleWhat they process
Supabase (Supabase, Inc.)Authentication, database, and transactional email deliveryAccount data, hashed credentials, library metadata, sync state
Cloudflare (Cloudflare, Inc.) — R2 storageObject storage for your uploaded audio files and artworkUser Content (audio files and related assets)
Stripe (Stripe, Inc.)Payment processing and subscription managementPayment card details (collected directly by Stripe), billing metadata
Railway (Railway Corp.)Application hosting for the Site and Web AppServer logs, including IP addresses and request metadata

We may also disclose information:

  • To comply with law — in response to a subpoena, court order, or other lawful request by public authorities, or where disclosure is required by applicable law;
  • To protect rights and safety — where reasonably necessary to enforce our Terms, protect the security or integrity of the Service, or protect the rights, property, or safety of CrateBridge, our users, or the public;
  • In a business transfer — in connection with a merger, acquisition, financing, reorganization, or sale of assets, in which case this Policy will continue to apply to your data and we will notify you of any material change of control or use;
  • With your direction or consent — for example if you ask us to share something with a third party.

Your library is private per-user storage. We do not make your User Content available to other users or to the public, and our personnel access it only when necessary to operate the Service, resolve a support request you make, investigate abuse, or comply with law.

5. Data Retention

  • Account data is retained for as long as your account exists and for a short administrative period after deletion.
  • User Content is retained while your account is active and entitled to storage. Following account deletion, or 90 days after a subscription ends without renewal, User Content may be permanently deleted from production systems, with residual copies purged from backups in the ordinary course (typically within a further 35 days).
  • Billing records are retained as required by tax and accounting law (generally up to 7 years).
  • Server logs are retained for a limited period (generally no more than 90 days) unless needed longer for an ongoing security investigation or legal matter.

Where deletion is requested or scheduled, we delete or irreversibly anonymize the data unless we are legally required or permitted to retain it (for example billing records, or data subject to a legal hold).

6. Security

We use technical and organizational measures designed to protect your data, including encryption in transit (TLS) for all connections to the Service, encryption at rest on our storage providers, salted password hashing, access controls and least-privilege access for our systems, and scoped, expiring credentials (such as time-limited signed URLs) for file access. No method of transmission or storage is completely secure; we cannot guarantee absolute security. If we become aware of a personal data breach affecting you, we will notify you and the relevant authorities where and as required by applicable law.

7. International Data Transfers

We are based in the United States, and the providers listed in Section 4 store and process data in the United States and other countries. If you access the Service from outside the United States, your personal data will be transferred to and processed in countries that may not provide the same level of data protection as your home jurisdiction. Where the GDPR or UK GDPR applies to such transfers, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum or International Data Transfer Agreement), and, where applicable, our providers' certification under the EU–U.S. Data Privacy Framework. You may contact us for more information about the safeguards applied.

8. Your Rights and Choices

8.1 All users

  • Access and update. You can view and update your account information from your account page.
  • Export. Your library remains on your own computers in standard formats; you can also download your stored files from the Service at any time while your account is active.
  • Deletion. You can delete individual content at any time from within the apps, and you can request deletion of your account entirely by emailing [email protected] (or via any self-serve deletion option we make available in the product).
  • Email preferences. Transactional emails (receipts, security and subscription notices) are part of the Service and cannot be opted out of while you hold an account; any marketing email we send will include an unsubscribe link.

8.2 EEA, UK, and Swiss residents (GDPR)

You have the right to request access to, rectification of, erasure of, or a portable copy of your personal data; to restrict or object to processing (including processing based on legitimate interests); and to withdraw consent where processing is based on consent. To exercise these rights, email [email protected]. We will respond within one month (extendable as permitted by law). You also have the right to lodge a complaint with your local supervisory authority, though we would appreciate the chance to address your concerns first.

8.3 California residents (CCPA/CPRA)

California law grants you the right to know what personal information we collect, use, and disclose (as described in this Policy); to access and receive a copy of it; to correct inaccuracies; to delete it (subject to exceptions); and to not be discriminated against for exercising these rights. The categories of personal information we collect are: identifiers (name, email, IP address, device identifiers), commercial information (subscription and transaction history), internet activity (log and usage data), and user-provided content (your library). We do not sell personal information and we do not share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months; accordingly there is no need for a "Do Not Sell or Share" opt out. We do not use or disclose sensitive personal information for purposes requiring a right to limit. To exercise your rights, email [email protected]; we will verify your request using the email address associated with your account. You may use an authorized agent, in which case we may require proof of authorization and verification of your identity.

8.4 Other jurisdictions

Residents of other U.S. states and other countries with comprehensive privacy laws may have similar rights of access, correction, deletion, and portability. We honor such requests as required by the law applicable to you, via the same contact address. If we deny a request, you may appeal by replying to our decision, and we will re-review it.

9. Do Not Track and Global Privacy Control

Because we do not track users across third-party websites or sell or share personal information for advertising, the Service does not respond differently to "Do Not Track" or Global Privacy Control signals — there is no tracking to disable.

10. Children's Privacy

The Service is not directed to children and may not be used by anyone under 16 years of age. We do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, contact [email protected] and we will delete it.

The Site links to third-party websites and services (for example our social media pages and Stripe's checkout). Those third parties have their own privacy practices, which this Policy does not cover. We encourage you to review the privacy policies of any third-party service you use, including Stripe, Supabase, and Cloudflare.

12. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will notify you before they take effect — by email to the address on your account, by in-product notice, or by prominent notice on the Site — and update the "Last updated" date above. We will not use previously collected personal data in materially new ways without providing notice and, where required by law, obtaining your consent. Your continued use of the Service after a change takes effect constitutes acceptance of the revised Policy.

13. Contact Us

For privacy questions, requests, or complaints, contact us at [email protected]. We will respond as soon as reasonably possible and within any timeframe required by applicable law.