This Privacy Policy explains how personal data is collected, used, stored, and protected when you use Catalog Manager ("the Service"). Catalog Manager is a standalone music catalog management platform for record labels, artists, managers, and rights holders. The Service is offered globally and may be accessed by users worldwide.
This policy complies with the GDPR (EU), CCPA/CPRA (California), LGPD (Brazil), PIPEDA (Canada), and other applicable privacy laws. Where you act as Data Controller, you are responsible for compliance with applicable data protection laws in your jurisdiction.
Catalog Manager is operated by Catalog Manager (company registration pending), based in Rome, Italy. Privacy inquiries: legal@catalogmanager.app.
Catalog Manager acts as a Data Processor. We provide the technology platform and infrastructure. We process personal data only on your instructions, and as necessary to provide, maintain, and secure the Service. We do not decide what data to collect or how to use it — you do.
When you create an account and upload data to Catalog Manager, you are the Data Controller:
If you are an independent artist managing your own catalog, you are both the Data Subject and Data Controller of your own data.
For this data, Catalog Manager is the Data Controller. Lawful basis: contractual necessity (GDPR Art. 6(1)(b)).
| Data Category | Examples | Purpose |
|---|---|---|
| Account Data | Email, name, password hash, org name | Auth, account mgmt, service delivery |
| Catalog Data | Releases, tracks, ISRCs, UPCs, artist names, genres | Core service — catalog management |
| Financial Data | Royalty statements, earnings, recoupment, PDFs | Storing financial records you upload |
| Rights Holder Splits | Rights holder names, split %, roles | Recording splits as you define them |
| Connected Tokens | Spotify/Gmail OAuth tokens | Optional integrations you connect |
| Usage Data | Login times, features used, browser | Security and improvement |
| Documents | Statement PDFs, artwork | Storage for your catalog |
What we do NOT collect: Payment card data, biometric data, racial/ethnic origin, political opinions, religious beliefs, health data, or any GDPR Art. 9 special categories.
You determine the lawful basis for data you upload. We process it solely on your instructions as Processor, governed by the DPA.
We do not sell, rent, or share your personal data with any third party.
Sub-processors:
gmail.readonly scope to detect and parse music distributor royalty statement emails. See section 6.1 below for the full Limited Use disclosure.OAuth tokens (e.g., from Spotify and Google) are stored securely (AES-256-GCM encryption at rest) and used only to enable the integrations you request. Tokens are deleted when you disconnect an integration or close your account.
Each sub-processor is bound by data processing agreements. We will notify users of material sub-processor changes via email or in-app notification. We may disclose data if required by law.
Catalog Manager's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When you connect Gmail, Catalog Manager requests the gmail.readonly scope solely to detect and parse royalty statement emails sent by music distributors (e.g., DistroKid, TuneCore, CD Baby, Believe, Symphonic, AWAL). Specifically:
We rely on third-party infrastructure providers (such as Supabase) that implement industry-standard security measures, including encryption at rest and in transit. We also implement application-level controls:
Depending on your jurisdiction, you may have rights under applicable data protection laws, including the right to access, correct, delete, restrict, port, and object to the processing of your personal data.
GDPR/CCPA/LGPD/PIPEDA and equivalent local laws: access, rectify, erase, restrict, port, object. Contact us and we will respond within 30 days.
You control it. Edit, export, delete anytime. Third-party requests redirected to you; we assist.
We do not sell or share personal data as defined under applicable US privacy laws, including the CCPA/CPRA.
Personal data may be transferred and processed outside your country of residence. Where required, appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms are implemented in accordance with applicable law.
We use only essential cookies necessary for the operation of the Service (authentication, session management). We do not use advertising or tracking cookies.
Not for under-16s. No knowing collection from children.
Material changes: email/in-app notice, updated date/version, renewed consent where required.
Authority notified within 72 hours. Users notified if high risk. All applicable laws followed.
Garante per la protezione dei dati personali
Piazza Venezia 11, 00187 Roma — www.garanteprivacy.it
This Privacy Policy shall be governed by and construed in accordance with the laws of Italy, without regard to conflict of law principles. Nothing in this policy limits any rights you may have under mandatory local law in your jurisdiction.
Catalog Manager
Rome, Italy
Email: legal@catalogmanager.app