1. Introduction
wf.band ("we," "our," or "us") is operated by WaterFall and provides a music streaming platform at https://wf.band (the "Service"). This Privacy Policy explains how we collect, use, store, and protect your personal information.
By using wf.band, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Account Information
When you register for an account, we collect:
- Email address (required for registration, login, and account-related communications)
- Username (publicly displayed on your comments)
- Password (encrypted using bcrypt hashing and never stored in plain text)
2.2 User-Generated Content
- Comments you post on songs (visible to all members, tied to your username)
- Comment history and timestamps
2.3 Listening Data
We collect data about your music listening activity, including:
- Which songs you play
- When you listen
- Listening duration and completion rates
- Playlist interactions
2.4 Automatically Collected Information
- Login timestamps (for security and account management)
- IP addresses (for security, fraud prevention, and geographic analytics)
- Session data (temporary, for maintaining your logged-in state)
- Browser and device information (for compatibility and security)
2.5 Cookies and Tracking Technologies
- Session cookies (required for login functionality)
- Cloudflare security cookies (for DDoS protection and bot detection)
- Future: We may add analytics cookies (Google Analytics or similar) - we will update this policy and notify you if we do
3. How We Use Your Information
We use your information for the following purposes:
3.1 To Provide the Service
- Authenticate your login
- Display your comments to other members
- Maintain your account and preferences
- Enable music streaming functionality
3.2 Communications
- Required emails:
- Email confirmation (verify your account)
- Password reset requests
- Critical account security notifications
- Important service updates (e.g., Terms of Service changes)
- Optional emails (you can opt out):
- New post notifications (new music from WaterFall)
- Feed updates and activity
You can manage email preferences in your account settings.
3.3 Analytics and Improvement
- Analyze listening patterns to improve WaterFall's music
- Understand which songs resonate with audiences
- Improve Service performance and user experience
- Detect and prevent fraud or abuse
3.4 Legal Compliance
- Comply with legal obligations
- Enforce our Terms of Service
- Protect our rights and the rights of other users
4. Information Sharing and Disclosure
4.1 What Other Members See
- Your username (on comments you post)
- Your comments (visible to all members)
Members CANNOT see:
- Your email address
- Your login activity
- Your listening history
- Your IP address
4.2 What Administrators See
WaterFall administrators have access to:
- All account information (email, username, registration date)
- Login history and IP addresses
- All comments and activity
- Listening analytics (aggregated and individual)
This access is necessary to operate the Service, provide support, and prevent abuse.
4.3 Third-Party Service Providers
We share limited information with trusted third-party service providers who help us operate the Service:
Cloudflare (CDN, Security, DDoS Protection)- What they see: All web traffic, IP addresses, browser information
- Purpose: Content delivery, SSL/HTTPS encryption, security protection
- Privacy Policy: https://www.cloudflare.com/privacypolicy/
- What they store: All Service data (hosted in Dallas, TX, USA)
- Purpose: Infrastructure hosting
- Privacy Policy: https://www.linode.com/legal-privacy/
- What they process: Emails we send you (confirmations, notifications)
- Purpose: Transactional email delivery
- Privacy Policy: https://www.migadu.com/privacy/
These providers are contractually obligated to protect your data and cannot use it for their own purposes.
4.4 Law Enforcement and Legal Requests
We may disclose your information if required by law or in response to:
- Valid legal processes (subpoenas, court orders)
- Government requests
- Investigations of illegal activity
- Protection of our rights, property, or safety
4.5 Business Transfers
If WaterFall is acquired, merged, or sells assets, your information may be transferred to the new entity. We will notify you of any such change.
4.6 What We Do NOT Do
- ❌ Sell your data to advertisers or data brokers
- ❌ Share your email with other members
- ❌ Use listening data for advertising
- ❌ Share your data with social media platforms
- ❌ Track you across other websites
5. Data Retention
5.1 Active Accounts
We retain your account data for as long as your account is active.
5.2 Deleted Accounts
When you delete your account:
- Within 30 days: We permanently delete:
- Your email address
- Your password hash
- Your login history
- Your preferences and settings
- Comments: Your comments remain visible but are anonymized (username changes to "Deleted User"). We do this to preserve conversation context for other members.
- Listening data: Aggregated listening data may be retained for analytics, but is no longer tied to your identity.
5.3 Legal Retention
We may retain certain data longer if required by law or to resolve disputes.
6. Your Rights and Choices
6.1 Access Your Data
You can view your account information anytime in your Settings.
6.2 Correct Your Data
You can update your username and password in Settings.
6.3 Delete Your Account
You can delete your account at any time:
- Go to Settings → Delete Account
- Confirm deletion (this cannot be undone)
- Your data will be deleted within 30 days
6.4 Export Your Data
Contact us at admin@wf.band to request an export of your data (comments, listening history).
6.5 Opt Out of Emails
You can disable optional emails (new post notifications) in Settings. You cannot opt out of critical account emails (password resets, Terms updates).
6.6 Additional Rights for EU Residents (GDPR)
If you are in the European Union, you have additional rights:
- Right to access: Request a copy of your personal data
- Right to rectification: Correct inaccurate data
- Right to erasure: Request deletion of your data ("right to be forgotten")
- Right to restrict processing: Limit how we use your data
- Right to data portability: Receive your data in a portable format
- Right to object: Object to certain processing activities
- Right to withdraw consent: Withdraw consent at any time
To exercise these rights, contact us at admin@wf.band.
Legal basis for processing (GDPR):- Contractual necessity: To provide the Service you signed up for
- Legitimate interests: Security, fraud prevention, service improvement
- Consent: For optional features (email notifications)
6.7 Additional Rights for California Residents (CCPA)
If you are a California resident, you have the right to:
- Know: What personal information we collect, use, and share
- Delete: Request deletion of your personal information
- Opt-out: Opt out of sale of personal information (we do NOT sell your data)
- Non-discrimination: We will not discriminate against you for exercising your rights
To exercise these rights, contact us at admin@wf.band.
7. Security
We take reasonable measures to protect your information:
- HTTPS encryption: All connections are encrypted via SSL/TLS (provided by Cloudflare)
- Password hashing: Passwords are hashed using bcrypt and never stored in plain text
- Secure hosting: Data stored on secure servers (Linode, Dallas, TX)
- Access controls: Limited administrator access to sensitive data
- Regular updates: Security patches and software updates
8. International Users
Our servers are located in the United States (Dallas, TX). If you access wf.band from outside the US, your information will be transferred to and processed in the United States.
By using the Service, you consent to the transfer of your information to the US, which may have different data protection laws than your country.
9. Children's Privacy (COPPA Compliance)
wf.band is intended for users 13 years of age or older. We do not knowingly collect personal information from children under 13.
If you are under 13, do not use this Service or provide any personal information.
If we discover we have collected information from a child under 13, we will delete it immediately. If you believe we have collected information from a child under 13, contact us at admin@wf.band.
10. Future Changes to the Service
10.1 Planned Features
We plan to add the following features in the future:
- Paid subscriptions (premium tiers with additional features)
- Donations (support WaterFall directly)
- Merchandise sales (band merch)
- Song release sales (purchase individual songs or albums)
- Offline listening (encrypted local storage for premium users)
- Analytics tools (Google Analytics or similar)
We will update this Privacy Policy before implementing features that materially change how we collect or use your data.
10.2 Notification of Changes
If we make significant changes to this Privacy Policy, we will:
- Update the "Last Updated" date at the top
- Notify you via email (to your registered email address)
- Post a notice on the Service
Your continued use of the Service after changes indicates acceptance of the updated Privacy Policy.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us:
- Email: admin@wf.band
- Website: https://wf.band
12. Governing Law
This Privacy Policy is governed by the laws of the United States (server location) and the State of Texas (data center location).
Future: Once WaterFall is registered in Switzerland, this may be updated to Swiss law.---
Summary (Plain English):- We collect your email, username, and listening data
- We use it to run the site and improve music
- We don't sell your data
- You can delete your account anytime
- Comments get anonymized when you leave
- We use Cloudflare, Linode, and Migadu to operate
- You have rights under GDPR (EU) and CCPA (California)
- Email us with questions