Privacy Policy
Last updated: April 2026
1. Who we are
GameSetDrop (“we”, “us”, “our”) is a community platform for discovering DJ sets and live mixes, operated by Yash Purohit. Our website is gamesetdrop.yashpurohit.me.
Contact: privacy@gamesetdrop.com
2. What data we collect and why
Account data
- Phone number - required for SMS OTP authentication. Legal basis: performance of a contract (to provide you with an account).
- Email address - optional. If provided, used for transactional communications and, if consented, marketing. Legal basis: consent.
- Username and display name - chosen by you, displayed publicly. Legal basis: performance of a contract.
Usage and preference data
- Genre preferences and theme - to personalise your feed. Legal basis: legitimate interests (providing a personalised service).
- Listening history and progress - votes, play counts, timestamps, and playlist data. Legal basis: legitimate interests (improving recommendations).
- Artist and user follows - to show relevant content. Legal basis: performance of a contract.
- Comments and submissions - content you create publicly. Legal basis: performance of a contract.
- Marketing consent flag - recorded when you opt in during onboarding. Legal basis: consent.
Technical data
- Browser local storage - used to store your theme preference, listening progress, and recently played sets. This data stays on your device and is not transmitted to our servers unless you are logged in.
- Analytics - we use Vercel Analytics which collects anonymised, aggregate traffic data (page views, referrers). No personal identifiers are collected. No advertising cookies are used.
3. SMS and telephone communications (TCPA)
By entering your phone number and clicking “Get my code”, you expressly consent to receive a one-time verification SMS from us for login purposes. This is a transactional message, not marketing.
- We do not send marketing text messages.
- Message and data rates may apply depending on your carrier.
- Reply STOP to any message to opt out. Reply HELP for assistance.
- Consent to receive SMS is not a condition of purchase or use.
4. Marketing communications
We only send marketing emails if you explicitly ticked “I'm happy to receive occasional emails” during onboarding. You can withdraw this consent at any time by:
- Clicking the unsubscribe link in any marketing email, or
- Emailing privacy@gamesetdrop.com
5. Data storage, security and international transfers
Your data is stored in Supabase (PostgreSQL), hosted on Amazon Web Services (AWS) infrastructure. Supabase applies row-level security so users can only access their own private data.
If you are in the EEA or UK, your data may be transferred to and processed in the United States (where AWS infrastructure is located). These transfers are made under Standard Contractual Clauses (SCCs) as provided by Supabase's Data Processing Agreement.
We do not sell, rent, or trade your personal data to third parties.
6. Data retention
- Account data - retained for as long as your account is active. Deleted within 30 days of an account deletion request.
- Listening history and progress - retained while your account is active. Deleted with your account.
- Comments and submissions - may remain publicly visible after deletion in anonymised form (username replaced), unless you request full removal.
- Backup data - may persist in encrypted backups for up to 90 days after deletion.
7. Your rights
Under GDPR (EEA and UK users)
- Access - request a copy of the personal data we hold about you.
- Rectification - ask us to correct inaccurate or incomplete data.
- Erasure - request deletion of your account and associated personal data.
- Restriction - ask us to restrict processing of your data in certain circumstances.
- Portability - receive your data in a machine-readable format.
- Object - object to processing based on legitimate interests.
- Withdraw consent - at any time, for processing based on consent (marketing, optional email).
- Lodge a complaint - with your local data protection authority. In the UK: the ICO (ico.org.uk).
Under CCPA (California residents)
- Know - what personal information we collect and how we use it (this policy).
- Delete - request deletion of your personal information.
- Non-discrimination - we will not discriminate against you for exercising your rights.
- Opt out of sale - we do not sell your personal information to third parties.
To exercise any of these rights, email privacy@gamesetdrop.com. We will respond within 30 days.
8. Children's privacy (COPPA)
GameSetDrop is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal data, please contact us and we will delete it promptly.
9. Third-party content and DMCA
GameSetDrop links to and embeds content hosted on third-party platforms including YouTube, SoundCloud, and Mixcloud. We do not host, store, or distribute audio or video files.
If you believe a submission on GameSetDrop infringes your copyright, please send a DMCA notice to privacy@gamesetdrop.com including:
- Identification of the copyrighted work you claim has been infringed.
- The URL of the allegedly infringing submission on GameSetDrop.
- Your contact information.
- A statement that you have a good-faith belief the use is not authorised.
- A statement that the information in the notice is accurate and, under penalty of perjury, that you are authorised to act on behalf of the copyright owner.
We will respond promptly and remove infringing content where appropriate.
10. Changes to this policy
We may update this policy from time to time. We will notify registered users of material changes via email (if provided) or by posting a notice on the platform. Continued use after changes constitutes acceptance.
11. Contact
For all privacy requests, data deletion requests, and DMCA notices:
Email: privacy@gamesetdrop.com