version 2.3

Privacy Policy

Version 2.3 · Published 16 August 2026 · Effective 16 August 2026

1. About this policy

1.1 This Privacy Policy explains how we collect, use, disclose, store and protect your personal information, and how you can request access or correction or make a complaint.

1.2 Wristband is a live-music service operated by the partnership D.C Cartagena Nunez & M.C Myers, ABN 19 312 123 906, under its registered business name Wristband, whose principal place of business is in Western Australia. In this policy, "Wristband", "we", "us" and "our" refer to that partnership.

1.3 This policy has been prepared with reference to the Australian Privacy Principles in the Privacy Act 1988 (Cth). Whether or not the Privacy Act applies to us at a particular time, we will handle personal information as described in this policy.

1.4 Contact us at hello@trywristband.com if you have questions about this policy.

2. What personal information means

2.1 "Personal information" is information or an opinion about an identified individual, or an individual who is reasonably identifiable. Information that has been aggregated or de-identified so that a person can no longer reasonably be identified is not personal information.

3. Personal information we collect

3.1 Depending on how you use Wristband, we may collect the information described in this section.

When you create and manage an account

3.2 We collect:

(a) your email address, display name and year of birth;

(b) your declaration that you are at least 16 years old;

(c) authentication credentials handled by our authentication provider, noting that Wristband does not receive or store your password in readable form;

(d) a short history of display-name changes for impersonation and abuse prevention;

(e) the Terms version, privacy collection-notice version and age confirmation recorded when you created the account;

(f) account settings, account status and leaderboard choices; and

(g) internal access, moderation and contribution records, including account role, trust status and contribution counts.

3.3 Your year of birth and age declaration are self-declared information, not identity verification. Existing members who have not provided a year of birth may be asked to provide it once when they next sign in. Wristband does not ask for or infer your country of residence as part of your member profile in the current Service.

When you use Wristband

3.4 We collect:

(a) festivals, concerts and artists added to your archive;

(b) show dates, attendance choices, ratings, pinned shows and lineup selections;

(c) companion tags created by you or by another signed-in member involving you; and

(d) feedback, contact and support messages, including any name, email address, subject or message you provide.

When you attach photos to a show

3.5 We collect:

(a) the image itself, and the show it is attached to;

(b) the date the photo was uploaded, its file size and format, and the storage reference needed to retrieve it; and

(c) any personal information visible in the image, including people who appear in it.

3.6 Before a photo leaves your device, the Service removes embedded camera metadata, including any GPS location recorded by your camera. We do not receive or store the location where a photo was taken.

3.7 Photos are private to your account — see section 8. Only attach photos you have the rights to use. Terms section 8 sets out the content rules that apply.

If you take part in the venue partnership programme

3.8 We collect:

(a) the name of the venue, promoter or organisation you represent;

(b) your name, role, business email address and business contact details;

(c) the event, schedule, lineup and venue information you supply; and

(d) material you upload for a partner page, and records of what was submitted and when.

3.9 We handle that business-contact information for the purpose of operating the partnership. Participation is governed by the separate Venue Partnership Terms.

When you contribute catalogue information

3.10 We collect:

(a) festivals, concerts, artists, lineups and corrections you submit;

(b) supporting links, context and other information included with a submission;

(c) the status and moderation outcome of each submission; and

(d) contributor recognition and leaderboard choices.

Automatically, for security and operation

3.11 We collect:

(a) IP addresses, endpoint identifiers, request counts and timestamps used for rate limiting and abuse prevention;

(b) bot-detection results from Cloudflare Turnstile;

(c) essential session cookies and authentication identifiers;

(d) email delivery, bounce and unsubscribe events; and

(e) security and administrative audit records.

Sensitive information

3.12 We do not ask you to provide sensitive information such as health information, political opinions, religious beliefs or biometric information. Please do not include sensitive information in your archive, contributions, photos or support messages. If we receive sensitive information unintentionally, we will handle it consistently with this policy and delete it when it is not reasonably necessary.

4. How we collect information

4.1 We collect personal information:

(a) directly from you when you create an account, use your archive, attach a photo, submit catalogue information or contact us;

(b) automatically when you use the Service;

(c) from another signed-in member when they tag you as a companion;

(d) from service providers when they return authentication, security or email-delivery events; and

(e) from contributors and lawful public or open-data sources when building the catalogue.

4.2 Catalogue information ordinarily concerns public events and the professional activities of performers. Public availability does not necessarily mean information is no longer personal information. Where catalogue information identifies an individual, we handle it consistently with this policy.

5. Why we use personal information

5.1 We use personal information to:

(a) create, authenticate, secure and administer your account;

(b) apply the minimum-age requirement;

(c) understand the age composition of the Wristband community using aggregated or de-identified age ranges;

(d) build and display your private live-music archive, including ratings and selected artists;

(e) store, resize, process and display photos you attach to a show, and review them where reasonably necessary for moderation, safety or legal compliance;

(f) operate the venue partnership programme and communicate with venue partners about their events and partner pages;

(g) use individual attendance choices and ratings to provide private archive statistics and calculate aggregate attendance counts, ratings and trends where members are not reasonably identifiable;

(h) retain, verify, correct, combine and use lawful factual catalogue information entered through missing-show, event, artist, lineup and correction flows to develop the shared catalogue, whether or not the information is approved or published immediately;

(i) provide archive statistics and account preferences;

(j) let members tag companions and let a tagged member view or remove their own tag;

(k) receive, review and publish catalogue contributions;

(l) send verification, security, account, submission and other essential service emails;

(m) provide support and respond to access, correction, deletion and privacy requests;

(n) prevent fraud, spam, abuse, impersonation and unauthorised access;

(o) diagnose technical problems, maintain reliability and improve features using operational records and feedback; and

(p) comply with legal obligations and protect the rights and safety of users, the operators and the Service.

5.2 We do not publish your exact year of birth, use it for advertising or include it in individual user reports.

5.3 We do not use third-party advertising analytics or cross-site tracking. We only collect personal information that is reasonably necessary for operating Wristband and use it for the purpose for which it was collected, a related purpose you would reasonably expect, a purpose you consent to, or another purpose permitted by law.

6. Cookies and browser storage

6.1 Wristband uses essential cookies and limited browser storage to authenticate you, keep your session secure and support the operation of the Service.

6.2 These technologies are required for account and security functions. Blocking essential cookies may prevent you from signing in or using authenticated features.

6.3 We do not use advertising cookies, cross-site tracking or third-party advertising analytics. Cloudflare Turnstile may process limited browser, device and network signals on protected forms to identify automated abuse.

7. Automated checks and decisions

7.1 Wristband uses automated systems for limited operational and security purposes. These systems may:

(a) detect automated form submissions;

(b) apply request and submission limits;

(c) require an additional security check;

(d) temporarily prevent repeated requests; and

(e) identify activity for review by an operator.

7.2 Catalogue contributions are approved or rejected by a human moderator. Automated systems may enforce technical limits, but they do not determine whether contributed catalogue information is accurate or should be published.

7.3 Wristband does not currently arrange for a computer program to make decisions using personal information that could reasonably be expected to significantly affect a person's legal or contractual rights, or their access to an essential or significant service.

7.4 If that changes, we will update this policy to explain the kinds of personal information used and the kinds of automated decisions made.

8. Information visible to other people

8.1 Your archive and account profile are private. They require your authenticated session.

8.2 Your individual attendance choices and ratings are private. We do not display them to other members. We may publish an aggregate attendance count, rating or trend only where the result does not reasonably identify a member.

8.3 Your photos are private. Photos you attach to a show are visible only to you through your authenticated session. We do not display them to other members, publish them in the shared catalogue, or use them to promote Wristband. Authorised operators may access a photo where reasonably necessary for moderation, a safety or legal issue, or a support request you have made.

8.4 Your display name has limited visibility. Other signed-in members may find it when searching for someone to tag as a companion.

8.5 Companion tags share limited information. The owner of a logged show and members tagged on that show may see the companion list and limited show details. A tagged member may remove their own tag. People who are not involved in the tag cannot use this feature to view the logged show.

8.6 Leaderboard participation is optional. If you opt in, your display name, rank and contributor tier may be publicly visible. You can opt out in account settings.

8.7 Published catalogue facts are public. Approved information about events, artists and lineups becomes part of the shared catalogue. Your private archive and the identity attached to your submission are not published as part of those facts.

8.8 Authorised operators have limited administrative access. The partners and authorised administrators may access account, contribution, support and audit information where reasonably necessary to operate, secure, moderate or support the Service.

8.9 Wristband does not currently provide public member profiles or public sharing of a member's personal archive.

9. Information about artists and performers

9.1 The Wristband catalogue contains information about public events and the professional activities of artists and performers. This information may come from contributors, public sources and open-data services.

9.2 We aim to keep catalogue information accurate, relevant and limited to professional or publicly documented activities. We do not intend to publish private contact information or unrelated personal details about performers.

9.3 If you are an artist, performer or authorised representative and believe catalogue information is inaccurate, improperly attributed or raises a privacy concern, contact hello@trywristband.com. We will review the request and may ask for information reasonably necessary to verify your connection to the subject.

10. Service providers and other disclosures

10.1 We do not sell, rent or trade personal information.

10.2 We use service providers to operate, secure and support Wristband. They receive only the information reasonably necessary for the relevant service.

ProviderPurposeLikely processing locations
SupabaseDatabase, authentication, and file storage including photos you attach to a showOur primary project data, including stored photos, is held and processed in Sydney, Australia. Provider account, support and authorised subprocessor operations may involve the United States and other locations described by Supabase.
VercelApplication hosting, content delivery and operational request processingUnited States and global infrastructure locations
ResendSending account and service emails and handling delivery eventsUnited States
CloudflareTurnstile bot and abuse preventionUnited States and global network locations

10.3 A provider may use authorised subprocessors. Where a provider independently determines how it uses limited account, service-generated or security information, its own privacy notice also applies. For example, Cloudflare processes limited Turnstile signals both to protect Wristband forms and to improve its bot-detection capabilities.

10.4 We may also disclose personal information:

(a) when you direct or authorise the disclosure, including through the companion features described in section 8;

(b) to the authorised operators and administrators described in section 8;

(c) when required or authorised by Australian law or a court or tribunal order;

(d) where reasonably necessary to investigate unlawful activity, protect the security of the Service or protect the rights, safety or property of a person; or

(e) in connection with a transfer or restructure of the Service, subject to appropriate confidentiality arrangements and reasonable notice where practicable.

10.5 We may use or publish aggregated or de-identified information, such as catalogue-level statistics, only where individuals are no longer reasonably identifiable.

11. Overseas processing and disclosure

11.1 Some personal information is processed outside Australia.

11.2 Our primary Supabase database is hosted in Sydney, Australia. Our likely overseas recipients currently include providers and authorised subprocessors in the United States. Vercel and Cloudflare operate global infrastructure, so technical routing or edge processing may occur in other countries. This does not mean that Wristband intentionally discloses every category of personal information to every country in those networks. Because edge and authorised subprocessor locations may change, it is not practicable to list every possible infrastructure location. We will update this policy if another country becomes a likely recipient of Wristband personal information.

11.3 Before disclosing personal information to an overseas recipient, we take reasonable steps appropriate to the circumstances to protect that information. Those steps may include:

(a) reviewing the provider's data-processing terms, security measures and subprocessors;

(b) limiting the information disclosed and the purposes for which it may be used;

(c) applying access controls and contractual data-protection obligations; and

(d) reviewing material changes to providers and processing locations.

11.4 We do not rely on your consent to exclude APP 8.1. Where applicable, Wristband remains accountable for overseas disclosures as required by Australian privacy law.

12. Direct marketing and service communications

12.1 Wristband does not currently send direct-marketing communications.

12.2 We currently send account and service communications reasonably necessary to operate or support the Service. These may include:

(a) email verification, authentication, security and account notices;

(b) requested data-export and account-deletion communications;

(c) acknowledgements of contact or privacy requests;

(d) catalogue-submission and moderation outcomes; and

(e) material legal, privacy or service-change notices.

12.3 If we introduce direct marketing in the future, we will first implement an appropriate consent and opt-out process. We will:

(a) send marketing only with express consent or where otherwise permitted by law;

(b) keep evidence of when and how consent was obtained;

(c) accurately identify Wristband and its operators and provide current contact details;

(d) provide a clear, functional and free method to unsubscribe without requiring an account, login or additional personal information; and

(e) action unsubscribe requests within five working days.

12.4 You will be able to opt out using the link in the message or by contacting hello@trywristband.com. We will retain only the limited opt-out record reasonably necessary to honour the request and comply with the law.

12.5 Opting out of marketing will not prevent essential account, security or requested service communications. Essential service messages will not be used to conceal promotional content.

13. How we protect personal information

13.1 We take reasonable technical and organisational steps appropriate to the nature, volume and sensitivity of the personal information we hold. These steps are designed to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.

13.2 Our measures include:

(a) managed authentication and password hashing, encrypted network connections and secure session controls;

(b) row-level database permissions, private service credentials and access limited to the operators, administrators and service providers who need it for an authorised purpose;

(c) private file storage for photos, served only through short-lived links to the account that owns them;

(d) bot protection, request limits and verification of supported provider webhooks;

(e) security and administrative logging, software maintenance, testing, backups and recovery procedures; and

(f) retention controls intended to delete or de-identify personal information when it is no longer reasonably needed.

13.3 No online service can guarantee absolute security. If you believe your account or personal information may have been compromised, contact hello@trywristband.com. We will investigate suspected data breaches, take reasonable containment and remedial steps and make notifications required by the Privacy Act 1988 (Cth), including under the Notifiable Data Breaches scheme where it applies.

14. How long we keep personal information

14.1 We keep personal information only for as long as it is reasonably needed for the purposes described in this policy, to protect the Service and its members, to resolve a dispute or incident, or to comply with a legal obligation. We then delete or de-identify it unless an Australian law or a court or tribunal order requires it to be kept.

14.2 Our ordinary retention periods are:

InformationOrdinary retention period
Active account, profile, birth year, private archive including individual attendance and ratings, companion tags and personal submission recordsWhile the account remains open. After account closure, a restricted recovery snapshot may be held for up to 30 days and is then deleted or de-identified.
Lawful factual catalogue inputsMay be retained internally, verified, corrected, combined or later published to develop the shared catalogue, whether or not immediately approved. After the recovery period, the member's account link and personal submission context are deleted or de-identified. Material rejected for privacy, rights, safety or legal reasons is not retained under this rule.
Published catalogue factsMay remain in the shared catalogue because they describe public events and performers. The deleted member's private archive, personal submission record and account identity are not retained as part of those facts.
Properly de-identified aggregate attendance and rating statisticsMay remain for as long as they support the Service and no individual is reasonably identifiable.
Display-name history used for impersonation and abuse prevention90 days after the name changes.
IP addresses and request records used only for rate limiting30 days.
General security and administrative audit records24 months. A record connected to a specific incident, investigation, dispute or legal hold may be retained for longer while reasonably necessary.
Resolved contact, support, access, correction, deletion and privacy requests24 months after resolution, unless an active dispute or legal requirement requires longer.
Data-export fileThe download link expires 24 hours after creation. The underlying file is removed by the next scheduled daily cleanup run. Export-request status and minimal delivery metadata are kept for 90 days.
Photos attached to a showWhile the account remains open, unless you delete the photo earlier. Deleting a photo removes it from the live Service. After account closure, photos follow the account-deletion lifecycle in section 16 and the restricted 30-day recovery period.
Photos removed for a breach of the TermsRemoved from the Service promptly. A minimal record of the removal is kept for 24 months for moderation and appeal purposes. Material we are legally required to preserve and report is handled separately as required by law.
Venue partner business-contact and submission recordsWhile the partnership is current and for two years after it ends, unless a longer period is required by law or by an active dispute.
Minimal evidence of Terms acceptance, privacy collection notice and the 16+ declarationWhile the account is open and for six years after closure. We limit this record to the applicable version, timestamp and the minimum pseudonymous account reference reasonably necessary.

14.3 The six-year period for acceptance evidence in the table above is the period in which a claim about the agreement could ordinarily be brought under Australian limitation legislation. The record exists so that we can show which version applied to you, and we do not use it for any other purpose.

14.4 Provider backups and operational records may persist for a limited technical cycle after information is removed from the live Service. During that period they remain restricted from ordinary use and are deleted or overwritten according to the provider's configured backup and retention schedule.

14.5 Financial, taxation or employment records, if Wristband becomes legally required to keep them, are maintained separately for the applicable statutory period. Those requirements do not extend the retention of unrelated account content or general product telemetry.

15. Accessing and correcting your personal information

15.1 You may request access to the personal information Wristband holds about you. Signed-in members can request a data export from Account → Manage your data. We verify an export request through the signed-in account and a time-limited email step before making the export available. You may also request access by emailing hello@trywristband.com.

15.2 We will take reasonable steps to verify that a request is made by you or by a person authorised to act for you. We will not ask for more identity information than is reasonably necessary for that verification.

15.3 We aim to respond within a reasonable period, ordinarily within 30 calendar days. We do not charge you for making an access request and do not currently charge for providing access.

15.4 In limited circumstances, we may be permitted or required to refuse access to some information, including where providing it would unreasonably affect another person's privacy or would be unlawful. Where practicable, we will first consider whether access can be provided by redacting another person's information, providing a summary, or using another suitable format. If we refuse access or cannot provide it in the requested form, we will give you written reasons where reasonable and explain how you may complain.

15.5 You can update your display name and email address through account settings. To correct other personal information, including your year of birth, email hello@trywristband.com. We will take reasonable steps to ensure the information is accurate, up to date, complete, relevant and not misleading for the purpose for which we hold it.

15.6 If we correct information that we previously disclosed to another entity, you may ask us to take reasonable steps to notify that entity, unless doing so would be impracticable or unlawful. If we refuse a correction request, we will provide written reasons where reasonable, explain the available complaint mechanisms and, if you ask, take reasonable steps to associate a statement with the record noting that you consider it incorrect. We do not charge for correction requests, corrections, or associating such a statement.

16. Deleting your account

16.1 You can request account deletion from Account → Manage your data. We recommend requesting an export first if you want to keep a copy of your private archive.

16.2 When you delete your account:

(a) sign-in access and active sessions are disabled promptly;

(b) identifying account details are anonymised, public leaderboard participation is disabled and your private archive is no longer available through the account;

(c) your photos stop being served and are scheduled for deletion with the account;

(d) a restricted recovery snapshot may be held for up to 30 days; and

(e) after that period, the account, private archive, photos, companion relationships and unpublished personal submission records are permanently deleted or de-identified.

16.3 If you contact hello@trywristband.com within the 30-day period, we will verify the request and may be able to restore the account where technically possible. Restoration is not guaranteed and may require you to verify or replace your sign-in email address.

16.4 Lawful factual catalogue inputs, including event and artist names, dates, venues, locations and lineups, may remain in internal catalogue-development records or in the shared catalogue whether or not they were published before account deletion. They may be verified, corrected, combined, published or removed through catalogue moderation, but they will not retain an identifiable link to your deleted account, personal submission record or private archive after the recovery period.

16.5 Photos are not catalogue information and are deleted with your account under the lifecycle above. Properly de-identified aggregate attendance and rating statistics may remain where no member is reasonably identifiable. Your individual attendance, rating, notes and other private archive content are deleted or de-identified under the account-deletion lifecycle.

16.6 You keep any rights you may have in a Contribution, and the separate contribution licence in the Terms survives account deletion. We also retain the minimal legal evidence and any specific incident, dispute, legal-hold or statutory record described in section 14. Provider backups age out under the restricted technical cycle described in that section.

17. Data breaches

17.1 We respond promptly to suspected or actual loss, unauthorised access, disclosure or misuse of personal information. Our response may include containing the incident, investigating what occurred, reducing the risk of harm, preserving appropriate evidence and reviewing the safeguards that failed.

17.2 Where the Notifiable Data Breaches scheme applies to Wristband and we have reasonable grounds to believe that an eligible data breach has occurred, we will notify the Office of the Australian Information Commissioner and affected individuals as soon as practicable, as required by law.

17.3 Even where that scheme does not legally apply, we will notify affected individuals when we consider notification reasonably necessary to help them reduce a material risk of harm. A notification may describe what occurred, the kinds of information involved, the steps we have taken and actions the affected person can take.

17.4 If you believe your Wristband account or personal information may have been affected by a security incident, contact hello@trywristband.com.

18. Age requirement

18.1 You must be at least 16 years old to create or use a Wristband account.

18.2 Your year of birth is self-declared. We use it to apply the age requirement and to understand the age ranges of our members in aggregated or de-identified form. We do not currently use it as identity verification and we do not ask you to provide an identity document to prove your age.

18.3 If we learn that an account belongs to a person under 16, we may disable the account and delete or de-identify the associated personal information in accordance with sections 14 and 16.

19. Privacy complaints

19.1 If you believe Wristband has mishandled your personal information, email hello@trywristband.com and identify the message as a privacy complaint. Please describe what happened, when it occurred, the information involved and the outcome you are seeking.

19.2 We will acknowledge the complaint promptly and aim to provide a substantive response within 30 calendar days. If we need more time, we will explain why and provide an expected response date. We may ask for information reasonably necessary to verify your identity or investigate the complaint.

19.3 If you are not satisfied with our response, or we have not responded within 30 days, you may seek information from the Office of the Australian Information Commissioner (OAIC). Where the Privacy Act applies to Wristband, you may also be entitled to make a complaint to the OAIC at oaic.gov.au or on 1300 363 992.

20. Changes to this policy

20.1 We may update this Privacy Policy when Wristband, our information-handling practices, our service providers or applicable legal requirements change.

20.2 Each version will identify its publication date and version number. Previous versions will remain available through Wristband's legal archive.

20.3 Where a change materially affects how we collect, use or disclose personal information, we will provide reasonable notice by email, through the Service or both. Where consent is legally required for a new practice, we will obtain that consent before applying the practice to your personal information.

20.4 An urgent change required for security, fraud prevention or legal compliance may take effect immediately. Where practicable, we will notify affected members as soon as possible.

21. Contact

21.1 Wristband is a registered business name of D.C Cartagena Nunez & M.C Myers, ABN 19 312 123 906, Western Australia, Australia. Email: hello@trywristband.com.

21.2 You may use that address for privacy questions, access or correction requests, account-deletion assistance, complaints and suspected security incidents. If you need this policy in another accessible format, contact us and we will take reasonable steps to provide it.

© 2026 Wristband