Privacy Policy

Last Updated: November 25, 2025

Your privacy is critically important to us. This Privacy Policy explains how HitzDistro ("we", "us") collects, uses, and shares your personal information when you use our platform. We are committed to complying with applicable data protection laws, including GDPR and CCPA.

1. Data Controller

HitzDistro acts as the Data Controller for your account information and billing data. For the metadata associated with your music releases distributed to DSPs, we act as a Data Processor on your behalf.

2. Information We Collect

2.1 Information You Provide

  • Account Data: Name, email address, password, phone number.
  • Artist Data: Stage names, biography, social media links, photos.
  • Release Metadata: Song titles, lyrics, songwriter names, ISRC/UPC codes, contributor roles.
  • Financial Data: Bank account details, tax identification numbers (for royalty payouts).

2.2 Automatically Collected Data

  • Usage Data: Pages visited, features used, time spent on the platform.
  • Device Data: IP address, browser type, operating system.
  • Cookies: We use cookies to maintain your session and analyze platform performance.

3. Legal Basis for Processing (GDPR)

We process your data based on the following legal grounds:

  • Contractual Necessity: To fulfill our obligations to distribute your music and pay royalties.
  • Legal Obligation: To comply with tax laws and anti-money laundering regulations.
  • Legitimate Interests: To prevent fraud, improve our services, and ensure platform security.
  • Consent: For marketing communications (which you can withdraw at any time).

4. Sharing Your Information

Critical for Distribution: To provide our core service, we MUST share your Release Metadata and Artist Data with Digital Service Providers (DSPs) such as Spotify, Apple Music, Amazon Music, etc. By using HitzDistro, you explicitly authorize this transfer.

We may also share data with:

  • Payment Processors: Stripe, PayPal, or bank partners to process fees and payouts.
  • Fraud Prevention Partners: To detect artificial streaming and protect the ecosystem.
  • Legal Authorities: If required by a subpoena, court order, or other legal process.

5. International Data Transfers

HitzDistro operates globally. Your data may be transferred to and processed in servers located outside your country of residence (including the United States). We rely on Standard Contractual Clauses (SCCs) and adequacy decisions to ensure your data remains protected.

6. Your Rights

Depending on your location (e.g., EU, UK, California), you may have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Correct inaccurate or incomplete data.
  • Deletion ("Right to be Forgotten"): Request deletion of your account and data (subject to legal retention requirements for financial records).
  • Portability: Receive your data in a structured, machine-readable format.
  • Opt-Out: Opt-out of marketing emails or the sale of personal data (we do not sell your data).

To exercise these rights, email privacy@hitzdistro.com.

7. Data Retention

We retain your personal data for as long as your account is active. If you close your account, we may retain certain information (e.g., transaction history, tax forms) for up to 7 years to comply with legal and financial obligations.

8. Children's Privacy

HitzDistro is not intended for children under 13 (or 16 in certain jurisdictions). We do not knowingly collect data from children. If we discover such data, we will delete it immediately.

9. Contact Us

HitzDistro Privacy Officer

Email: privacy@hitzdistro.com