BandInSync
ENPTES
Back to BandInSync

Your data, in plain language

Privacy Policy

This policy explains what BandInSync collects, why we need it, the services that help us operate, and the choices you have about your information.

Effective July 20, 2026Last updated July 20, 2026
On this page
1. Scope and who is responsible2. Information we collect3. How we use information4. Legal bases and your choices5. When we share information6. Private Telegram operator alerts7. Google sign-in data8. International data transfers9. Retention and deletion10. Cookies and local storage11. Security12. Your privacy rights13. Children and youth participants14. Changes and contact

On this page

1. Scope and who is responsible2. Information we collect3. How we use information4. Legal bases and your choices5. When we share information6. Private Telegram operator alerts7. Google sign-in data8. International data transfers9. Retention and deletion10. Cookies and local storage11. Security12. Your privacy rights13. Children and youth participants14. Changes and contact

1. Scope and who is responsible

BandInSync (“BandInSync,” “we,” “us,” or “our”) operates bandinsync.com and the BandInSync web application. This policy applies when you visit the public website, create an account, join a church workspace, use the service, contact us, or submit feedback.

A church or ministry may add and manage information about its teams and members. In that situation, the church may also be responsible for how it collects and uses that information. Contact your church administrator first if your question concerns information they added to a workspace.

2. Information we collect

We collect information you provide, information created while you use BandInSync, and limited technical information needed to operate and secure the service.

  • Account and profile information, including name, email address, profile image, authentication identifiers, and language preferences.
  • Church and team information, including church name, team names, roles, membership, invitations, availability, and service assignments.
  • Content you create, including songs, lyrics, chords, set lists, arrangement notes, annotations, performance-session activity, and imported material.
  • Support and feedback information, including bug reports, suggestions, questions, replies, and any details you include with them.
  • Billing information, including plan, subscription status, coupon redemptions, billing customer identifiers, and transaction metadata. Stripe processes payment-card details; BandInSync does not store complete card numbers.
  • Technical and usage information, including IP address, browser and device details, pages or features used, timestamps, diagnostic events, error reports, and security logs.

3. How we use information

We use personal information only for legitimate service and business purposes, including to:

  • Create and secure accounts, authenticate users, and maintain church and team access controls.
  • Provide songs, set lists, invitations, collaboration, live performance synchronization, AI-assisted features, billing, and customer support.
  • Send service messages and notify the BandInSync operator about signups, new churches, and feedback so we can respond and monitor the service.
  • Diagnose errors, prevent abuse, protect users, understand feature performance, and improve BandInSync.
  • Comply with law, enforce our Terms of Service, and establish or defend legal claims.

4. Legal bases and your choices

Where a law such as Brazil’s LGPD requires a legal basis, we process information as needed to perform our agreement with you, comply with legal obligations, protect legitimate interests such as service security and improvement, or with consent when required. You may withdraw consent for future processing when consent is the applicable basis.

You can choose not to provide optional information. Some account, church, and team information is necessary to deliver the service, so BandInSync may not work without it.

5. When we share information

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share only what is reasonably necessary with service providers, workspace participants, or authorities in the circumstances below.

  • Clerk and connected sign-in providers, such as Google, for authentication and account management.
  • Convex for application hosting, databases, realtime synchronization, and backend processing.
  • Stripe for checkout, subscriptions, invoices, fraud prevention, and billing support.
  • Sentry for error monitoring and diagnostics.
  • Google Analytics, only after you consent, to measure visits and feature usage so we can understand and improve BandInSync.
  • OpenAI when you intentionally use an AI-assisted import or set-list feature. Only the content and context needed to fulfill that request is sent.
  • Telegram for the limited private operator alerts described below.
  • Infrastructure, email, security, and professional-service providers that help us operate BandInSync under appropriate confidentiality obligations.
  • Other members and administrators of your church workspace, according to their role and the collaboration features you use.
  • Government authorities or other parties when required by law, necessary to protect rights and safety, or involved in a merger, financing, acquisition, or sale of assets subject to appropriate protections.

6. Private Telegram operator alerts

BandInSync sends limited alerts to a private Telegram account controlled by the BandInSync operator. A new-user alert may include the user’s name and email. A new-church alert may include the church name and creator details. A feedback alert may include the feedback type, subject, message, name, email, and church context.

These alerts are used only to monitor adoption and respond to support, bug, and product-feedback requests. They are not sent to other BandInSync users and are not used for advertising. Because Telegram is a separate service, this processing is also subject to Telegram’s privacy and security practices.

7. Google sign-in data

If you sign in with Google, we receive the basic account information authorized during sign-in, such as your name, email address, profile image, and an account identifier. We use it to authenticate you, create and maintain your BandInSync profile, communicate about the service, and protect your account.

We do not sell Google user data, use it for targeted advertising, or use it to train general-purpose AI models. We disclose it only as described in this policy and only as needed to provide or secure BandInSync.

8. International data transfers

BandInSync and its providers may process information in the United States and other countries. Those countries may have privacy laws different from the laws where you live. When required, we rely on contractual safeguards or other lawful transfer mechanisms and apply the protections described in this policy.

9. Retention and deletion

We keep information while your account or church workspace is active and as reasonably necessary to provide the service, resolve disputes, maintain security, comply with legal and accounting duties, and enforce agreements. Retention periods vary by data type. Backup copies and security logs may remain for a limited period after deletion.

You may request account or personal-data deletion by emailing support@bandinsync.com. A church administrator may also remove workspace membership or workspace content. We may need to verify your identity and may retain information when law permits or requires it. Removing an account may not remove content owned or shared by a church workspace when the church has a valid reason to retain it.

10. Cookies and local storage

BandInSync uses cookies and browser storage for authentication, security, language, theme, app preferences, offline functionality, and session continuity. These technologies are necessary for core app behavior.

With your permission, Google Analytics uses analytics cookies and related technical information to help us understand visits and feature usage. The Google Analytics tag does not load until you allow analytics. You can decline it or change your choice at any time through Cookie settings.

11. Security

We use reasonable administrative and technical safeguards designed to protect personal information, including HTTPS in transit, provider access controls, role-based application permissions, restricted production credentials, and error monitoring. No online service can guarantee absolute security. Protect your login credentials and tell us promptly if you suspect unauthorized access.

12. Your privacy rights

Depending on where you live, you may have rights to confirm processing, access, correct, delete, restrict, object to, or obtain a portable copy of personal information; learn about sharing; withdraw consent; or appeal a decision. Brazilian users may exercise the rights provided by the LGPD, including information about the entities with which data is shared.

Email support@bandinsync.com to make a request. We will verify the request and respond within the period required by applicable law. You may also complain to your local privacy regulator, including Brazil’s Autoridade Nacional de Proteção de Dados (ANPD). We will not discriminate against you for exercising a privacy right.

13. Children and youth participants

BandInSync is not directed to children under 13. Church administrators must have any authorization required before adding or inviting a minor and should limit the information entered about youth participants. If you believe a child’s information was provided without appropriate authorization, contact support@bandinsync.com.

14. Changes and contact

We may update this policy as BandInSync changes. We will update the date above and provide additional notice when a change is material or law requires it.

For privacy questions or requests, email support@bandinsync.com. Please do not include passwords, payment-card numbers, or other highly sensitive information in your message.

support@bandinsync.com
Privacy PolicyTerms of Service