Listeners Artists Smashify Token How It Works About Blog Help Center Contact
Legal

Privacy Policy.

Your data. Your rights. Our job is to protect both. This policy explains exactly what we collect, why we collect it, and how you stay in control.

Effective Date: April 21, 2026 · Last Updated: April 21, 2026

Plain English summary: We collect the minimum data needed to run Smashify. We never sell it to third parties. You can request, download, or delete your data anytime. Blockchain data (things already written on-chain) is permanent by nature and can't be erased, but we keep off-chain data deletable and under your control.

1. Who We Are

Smashify Technologies Private Limited ("Smashify", "we", "us", or "our") is a company registered in Pune, Maharashtra, India, operating the Smashify music streaming platform and the Smashify Token (SMFY) ecosystem.

We are the data controller for the personal information processed through the Platform. Contact our Data Protection Officer at support@smashify.app.

2. Information We Collect

Information you give us directly:

  • Account data: Name, email, username, password (encrypted), profile photo, country
  • Artist data: Legal name, rights ownership documentation, payout wallet address, tax information where required
  • Payment data: Wallet addresses (on-chain public keys only, never private keys)
  • Communication data: Support tickets, emails, survey responses, feedback submissions

Information we collect automatically:

  • Usage data: Songs played, session duration, skip rates, playlist activity, search history
  • Device data: Device type, operating system, app version, language, timezone
  • Technical data: IP address, crash logs, performance metrics
  • Cookies & analytics: Standard web analytics data (anonymized where possible)

Information from third parties:

  • Single sign-on providers (Google, Apple) when you use their login
  • Artist rights databases and distributor partners for verification
  • Fraud-prevention partners to protect against bots and fake accounts

3. How We Use Your Data

We use your data only for specific purposes:

  • To provide, maintain, and improve the Smashify Platform
  • To personalize music recommendations and discover new artists you might love
  • To calculate, verify, and deliver Smashify Token (SMFY) rewards fairly
  • To prevent fraud, abuse, and unauthorized access
  • To communicate important updates, respond to support tickets, and send occasional product news (only if you opt in)
  • To comply with legal obligations like tax reporting and regulatory compliance
  • To conduct anonymized research that helps us build better products

We do NOT use your data to train external AI models, sell profiles to advertisers, or target political content at you.

4. Legal Basis for Processing

Under GDPR and equivalent laws, we process your data on one or more of the following legal bases:

  • Contract: To provide the services you signed up for
  • Consent: For optional features like marketing emails and analytics cookies
  • Legitimate interest: To operate, secure, and improve the Platform
  • Legal obligation: To comply with applicable law and court orders

5. Blockchain & On-Chain Data

Important: Public blockchain data is permanent. Smashify Token (SMFY) transactions, wallet addresses, and on-chain reward distributions are recorded on public blockchain networks (currently BNB Smart Chain) and cannot be erased, modified, or removed, even if you delete your Smashify account.

On-chain data is pseudonymous (tied to wallet addresses, not directly to your name) but permanent. We never write personally identifying information to the blockchain. If you wish to minimize on-chain exposure, you may use a separate wallet or privacy-preserving tools of your choice.

Your off-chain data, including name, email, app preferences, and listening history, remains under our control and is deletable per your request.

6. How We Share Data

We do NOT sell your personal data to anyone, ever.

We share data only in these limited circumstances:

  • Service providers: Trusted vendors who process data on our behalf (hosting, analytics, fraud prevention), bound by strict contractual obligations
  • Artists and labels: Aggregated, anonymized play data so artists can see how their music performs (never individual listener identities)
  • Legal compliance: When required by law, court order, or to protect rights, property, or safety
  • Business transfers: In the event of a merger, acquisition, or bankruptcy, data may transfer to the successor entity (with notice to you)
  • With your consent: Any other sharing happens only with your explicit permission

7. Data Retention

We keep your data only as long as needed for the purposes outlined above or as required by law.

  • Account data: For the lifetime of your account, plus up to 90 days after deletion for backup and recovery
  • Listening history: Up to 24 months for recommendation accuracy, then anonymized
  • Transaction records: As required by tax and financial regulations (typically 7 to 10 years)
  • Support tickets: Up to 3 years after resolution

8. Your Rights

Depending on your location, you have some or all of the following rights under applicable law (GDPR, CCPA, DPDP Act, and others):

  • Access: Request a copy of the data we hold about you
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your personal data (subject to blockchain immutability caveats above)
  • Restriction: Limit how we process your data in certain situations
  • Portability: Receive your data in a machine-readable format
  • Objection: Object to processing based on legitimate interest
  • Withdraw consent: Revoke any consent you previously gave
  • Complaint: Lodge a complaint with your local data protection authority

To exercise any of these rights, email support@smashify.app. We respond within 30 days.

9. Security

We implement industry-standard security measures including:

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Zero-knowledge architecture for sensitive fields wherever feasible
  • Regular penetration testing and third-party security audits
  • Role-based access controls for our team
  • 24/7 monitoring for unauthorized access attempts

No system is perfectly secure, however, and we cannot guarantee absolute protection. If a breach occurs, we will notify affected users and relevant authorities within 72 hours, as required by law.

10. International Data Transfers

We operate globally, which means your data may be transferred to and processed in countries outside your own, including India, Singapore, the United States, and the European Union. When we transfer data across borders, we use legally approved mechanisms such as Standard Contractual Clauses (SCCs) to ensure adequate protection.

11. Children's Privacy

Smashify is not intended for children under 13 (or the minimum digital consent age in your country, whichever is higher). We do not knowingly collect data from children under that age.

If you believe we have inadvertently collected data from a minor, please contact support@smashify.app and we will delete it immediately.

12. Cookies & Tracking

We use cookies and similar technologies to keep you logged in, remember your preferences, and analyze Platform usage. You can manage cookie preferences through your browser settings or in-app privacy controls.

We do NOT use third-party advertising cookies or cross-site tracking pixels.

13. Changes to This Policy

We may update this Privacy Policy to reflect product changes, new legal requirements, or operational improvements. Material changes will be communicated via email or in-app notification at least 30 days before they take effect. The current version is always available at smashify.app/info/privacy-policy.


Questions, concerns, or requests? Reach our Data Protection Officer at support@smashify.app. We take every message seriously and respond personally.