Privacy Policy
Effective date: August 25, 2026 · Last updated: August 25, 2026
This Privacy Policy explains how Shifted, LLC, a Rhode Island limited liability company doing business as CrateBridge ("CrateBridge," "we," "us," or "our"), collects, uses, discloses, and protects information about you when you use the CrateBridge website at cratebridge.app (the "Site"), the CrateBridge desktop application (the "Desktop App"), the CrateBridge web application (the "Web App"), and the CrateBridge Cloud storage and synchronization service (together, the "Service"). It also describes the rights and choices available to you. For the purposes of the EU and UK General Data Protection Regulation ("GDPR"), Shifted, LLC is the controller of the personal data described in this Policy.
This Policy is incorporated into and forms part of our Terms of Service. If you do not agree with this Policy, please do not use the Service.
1. Information We Collect
1.1 Information you provide
- Account information. When you create an account we collect your name, email address, and a password. Passwords are stored only in salted, hashed form by our authentication provider; we never see or store your plaintext password.
- Billing information. When you purchase a subscription, payment is processed by Stripe, Inc. Stripe collects your payment card details directly; we never receive or store your full card number. We receive from Stripe limited billing metadata such as the payment method type, the last four digits of your card, billing country, subscription status, and invoice history.
- Your library ("User Content"). The core of the Service is storing and synchronizing your DJ library: audio files you upload, and library data such as playlists, crates, track metadata (titles, artists, tags), cue points, artwork, and analysis data (for example key, BPM, and file hashes used for duplicate detection).
- Communications. If you contact us (for example at [email protected]), we collect the contents of your message and your contact details.
1.2 Information collected automatically
- Device and sync information. To enforce plan device limits and show you which computers are connected, the Desktop App registers device identifiers and basic device information (such as computer name, platform, and app version), along with sync activity (for example timestamps of sync operations and storage usage).
- Log and usage data. Our servers automatically record information sent by your browser or the apps, such as IP address, browser or app version, operating system, pages or endpoints accessed, timestamps, and error diagnostics. We use this for security, debugging, and capacity planning.
- Local storage and cookies. The Site and Web App use cookies and browser storage (localStorage / sessionStorage) that are strictly necessary to operate the Service — chiefly to keep you signed in and to carry state through flows such as checkout and email verification. In addition, the marketing pages of the Site use the Meta Pixel, an advertising measurement tool, as described in Section 5 ("Advertising and Analytics"). The Meta Pixel is not used inside the Desktop App, and you can opt out at any time on our Privacy choices page.
1.3 Information from third parties
We receive subscription and payment-status events from Stripe as described above. We do not purchase data about you from data brokers.
2. How We Use Information
We use the information we collect to:
- provide, operate, and maintain the Service — including storing your library, synchronizing it across your devices, computing analysis data (key, BPM, duplicates), and enforcing storage quotas and device limits;
- create and manage your account and authenticate you;
- process subscriptions, payments, invoices, trials, and renewals;
- communicate with you about the Service, including transactional emails (verification, receipts, subscription and security notices) and responses to support requests;
- protect the Service and its users — detecting, preventing, and investigating fraud, abuse, security incidents, and violations of our Terms;
- debug, analyze, and improve the performance and reliability of the Service;
- measure the performance of our advertising and reach people who may be interested in CrateBridge, as described in Section 5 ("Advertising and Analytics");
- comply with legal obligations and enforce our legal rights.
We do not sell your personal information for money, and we do not use the contents of your music library for advertising or marketing purposes. We do share limited identifiers and event data with Meta for advertising measurement as described in Section 5, which some laws treat as "sharing" for cross-context behavioral advertising — you can opt out on our Privacy choices page. We do not use your User Content to train machine-learning models.
3. Legal Bases for Processing (EEA/UK)
Where the GDPR applies, we process your personal data on the following legal bases:
- Performance of a contract (Art. 6(1)(b)) — account creation, authentication, storing and syncing your library, billing, and support;
- Legitimate interests (Art. 6(1)(f)) — securing the Service, preventing fraud and abuse, debugging and improving reliability, and defending legal claims, in each case balanced against your rights and expectations;
- Legal obligation (Art. 6(1)(c)) — tax, accounting, and lawful requests from authorities;
- Consent (Art. 6(1)(a)) — the advertising tools described in Section 5 (for visitors in the EEA and UK, none of those tools run until you consent) and any other processing where we ask for it (for example optional marketing emails, if we ever send them). You may withdraw consent at any time without affecting prior processing.
4. How We Share Information
We share personal data only as described below, and we require service providers to process it solely on our instructions and to protect it appropriately:
| Recipient | Role | What they process |
|---|---|---|
| Supabase (Supabase, Inc.) | Authentication and database | Account data, hashed credentials, library metadata, sync state |
| Resend (Resend, Inc.) | Transactional email delivery | Email address, name, and the contents of the emails we send you |
| Cloudflare (Cloudflare, Inc.) — R2 storage | Object storage for your uploaded audio files and artwork | User Content (audio files and related assets) |
| Stripe (Stripe, Inc.) | Payment processing and subscription management | Payment card details (collected directly by Stripe), billing metadata |
| Railway (Railway Corp.) | Application hosting for the Site and Web App | Server logs, including IP addresses and request metadata |
| Meta (Meta Platforms, Inc.) | Advertising measurement and audiences (see Section 5) | Hashed identifiers, browser identifiers, and ad event data |
We may also disclose information:
- To comply with law — in response to a subpoena, court order, or other lawful request by public authorities, or where disclosure is required by applicable law;
- To protect rights and safety — where reasonably necessary to enforce our Terms, protect the security or integrity of the Service, or protect the rights, property, or safety of CrateBridge, our users, or the public;
- In a business transfer — in connection with a merger, acquisition, financing, reorganization, or sale of assets, in which case this Policy will continue to apply to your data and we will notify you of any material change of control or use;
- With your direction or consent — for example if you ask us to share something with a third party.
Your library is private per-user storage. We do not make your User Content available to other users or to the public, and our personnel access it only when necessary to operate the Service, resolve a support request you make, investigate abuse, or comply with law.
5. Advertising and Analytics
We advertise CrateBridge, and we use tools from Meta Platforms, Inc. ("Meta") to understand whether that advertising works. Specifically, the marketing pages of the Site — including our quiz and offer funnels — use the Meta Pixel, and our servers send corresponding events to Meta through the Conversions API. These tools are used only on the marketing site and its funnels; they are not embedded in the Desktop App, and they have no access to your music library.
What is shared with Meta:
- Event data — which pages you visit and which funnel steps you complete (for example viewing the pricing page, starting a quiz, or beginning a trial), along with event names and timestamps.
- Advanced matching identifiers. If you enter your email address or first name in one of our funnels, the pixel hashes them in your browser, before anything is sent; Meta receives only the hashed values, which it uses to match events to Meta accounts for attribution.
- Server-side (Conversions API) events — the event name, the same hashed identifiers, and browser identifiers such as Meta's
_fbpand_fbccookies, sent from our servers to Meta so measurement works even when the browser pixel is blocked.
We use this data to measure the performance of our ad campaigns and to build advertising audiences (for example, reaching people similar to those who signed up). Meta processes this data under its own privacy policy.
Your choices. You can opt out of this sharing at any time on our Privacy choices page, and we honor the Global Privacy Control (GPC) browser signal as an opt-out of sharing (see Section 10). Visitors in the EU and UK are asked for consent before any of these tools run — until you consent, no pixel loads and no data is sent to Meta.
6. Data Retention
- Account data is retained for as long as your account exists and for a short administrative period after deletion.
- User Content is retained while your account is active and entitled to storage. Following account deletion, or 90 days after a subscription ends without renewal, User Content may be permanently deleted from production systems, with residual copies purged from backups in the ordinary course (typically within a further 35 days).
- Billing records are retained as required by tax and accounting law (generally up to 7 years).
- Server logs are retained for a limited period (generally no more than 90 days) unless needed longer for an ongoing security investigation or legal matter.
Where deletion is requested or scheduled, we delete or irreversibly anonymize the data unless we are legally required or permitted to retain it (for example billing records, or data subject to a legal hold).
7. Security
We use technical and organizational measures designed to protect your data, including encryption in transit (TLS) for all connections to the Service, encryption at rest on our storage providers, salted password hashing, access controls and least-privilege access for our systems, and scoped, expiring credentials (such as time-limited signed URLs) for file access. No method of transmission or storage is completely secure; we cannot guarantee absolute security. If we become aware of a personal data breach affecting you, we will notify you and the relevant authorities where and as required by applicable law.
8. International Data Transfers
We are based in the United States, and the providers listed in Section 4 store and process data in the United States and other countries. If you access the Service from outside the United States, your personal data will be transferred to and processed in countries that may not provide the same level of data protection as your home jurisdiction. Where the GDPR or UK GDPR applies to such transfers, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum or International Data Transfer Agreement), and, where applicable, our providers' certification under the EU–U.S. Data Privacy Framework. You may contact us for more information about the safeguards applied.
9. Your Rights and Choices
9.1 All users
- Access and update. You can view and update your account information from your account page.
- Export. Your library remains on your own computers in standard formats; you can also download your stored files from the Service at any time while your account is active.
- Deletion. You can delete individual content at any time from within the apps, and you can request deletion of your account entirely by emailing [email protected] (or via any self-serve deletion option we make available in the product).
- Email preferences. Transactional emails (receipts, security and subscription notices) are part of the Service and cannot be opted out of while you hold an account; any marketing email we send will include an unsubscribe link.
9.2 EEA, UK, and Swiss residents (GDPR)
You have the right to request access to, rectification of, erasure of, or a portable copy of your personal data; to restrict or object to processing (including processing based on legitimate interests); and to withdraw consent where processing is based on consent. To exercise these rights, email [email protected]. We will respond within one month (extendable as permitted by law). You also have the right to lodge a complaint with your local supervisory authority, though we would appreciate the chance to address your concerns first.
9.3 California residents (CCPA/CPRA)
California law grants you the right to know what personal information we collect, use, and disclose (as described in this Policy); to access and receive a copy of it; to correct inaccuracies; to delete it (subject to exceptions); and to not be discriminated against for exercising these rights. The categories of personal information we collect are: identifiers (name, email, IP address, device identifiers), commercial information (subscription and transaction history), internet activity (log and usage data), and user-provided content (your library). We do not sell personal information for money. However, our use of the Meta advertising tools described in Section 5 may constitute "sharing" personal information (identifiers and internet activity) for cross-context behavioral advertising under the CCPA/CPRA. You can opt out of this sharing at any time on our Privacy choices page, or by browsing with the Global Privacy Control signal enabled, which we honor as an opt-out of sharing. We do not use or disclose sensitive personal information for purposes requiring a right to limit, and we do not knowingly sell or share the personal information of anyone under 16. To exercise your rights, email [email protected]; we will verify your request using the email address associated with your account. You may use an authorized agent, in which case we may require proof of authorization and verification of your identity.
9.4 Other jurisdictions
Residents of other U.S. states and other countries with comprehensive privacy laws may have similar rights of access, correction, deletion, and portability. We honor such requests as required by the law applicable to you, via the same contact address. If we deny a request, you may appeal by replying to our decision, and we will re-review it.
10. Do Not Track and Global Privacy Control
We honor the Global Privacy Control (GPC) signal. If your browser sends GPC, we treat it as a valid opt-out of the sharing described in Section 5: the Meta advertising tools do not run for your browser, without any further action on your part. You can also opt out (or opt back in) manually on our Privacy choices page. Because "Do Not Track" never became a settled standard, we do not respond to DNT signals specifically, but GPC and the Privacy choices page give you the same result.
11. Children's Privacy
The Service is not directed to children and may not be used by anyone under 16 years of age. We do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, contact [email protected] and we will delete it.
12. Third-Party Sites and Services
The Site links to third-party websites and services (for example our social media pages and Stripe's checkout). Those third parties have their own privacy practices, which this Policy does not cover. We encourage you to review the privacy policies of any third-party service you use, including Stripe, Supabase, and Cloudflare.
13. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will notify you before they take effect — by email to the address on your account, by in-product notice, or by prominent notice on the Site — and update the "Last updated" date above. We will not use previously collected personal data in materially new ways without providing notice and, where required by law, obtaining your consent. Your continued use of the Service after a change takes effect constitutes acceptance of the revised Policy.
14. Contact Us
For privacy questions, requests, or complaints, contact us at [email protected]. We will respond as soon as reasonably possible and within any timeframe required by applicable law.
Change History
Aug 25, 2026 — disclosed the Meta advertising tools (Pixel and Conversions API) used on the marketing site, added Meta and Resend to the service-provider table, added the Privacy choices opt-out and Global Privacy Control support, and added EU consumer withdrawal terms to the Terms of Service.