Privacy Policy
Last updated: June 11, 2026 · Version 1.0
What we collect
When you create an account: username, email address, password (hashed with bcrypt, never stored in plain text), and an optional display name.
When you use the Service: sheets you upload (PDF/images and the metadata you provide — title, composer, key, category, tags), setlists you create, basic usage logs (IP address, timestamp, page visited — kept up to 30 days for abuse prevention).
We do NOT collect: location, contacts, device identifiers, advertising IDs, or anything else not listed above. We do NOT use cookies or trackers from advertising networks.
How we use it
To run the Service for you: store and serve your sheets, log you in, send transactional email (verification, password reset, important account notices).
To prevent abuse: detect spam signups, rate-limit suspicious activity.
To improve the Service: aggregate, anonymous usage statistics. We do not analyze the content of your sheets.
What we share
Nothing, unless: (a) you explicitly share content with a bandmate via the Service's sharing features, (b) we are required by lawful court order or subpoena, (c) we sell or transfer the Service (we'd notify you with a chance to export and delete first).
We do NOT sell your data to advertisers, data brokers, or anyone else.
Security
Passwords are bcrypt-hashed. Uploaded files are stored above the web server's document root and served only through an authentication-checking PHP script — direct URL access is blocked by Apache config. All traffic is encrypted via HTTPS (TLS).
That said: no online service is 100% secure. See Terms § 8 (limitation of liability).
Your rights
Export your data: email apps@ratzonorchestra.com — we'll send you a zip of your sheets + metadata within 30 days.
Delete your account: email apps@ratzonorchestra.com from the address on your account — we'll delete within 30 days (some backup copies may persist up to 90 days).
Correct your info: edit it in your account settings, or email us.
EU/UK users have additional GDPR rights (access, portability, restriction, objection); CA users have CCPA rights. Email apps@ratzonorchestra.com to exercise them.
Children
The Service is not for children under 13. We do not knowingly collect personal information from anyone under 13. If you believe a child has signed up, email apps@ratzonorchestra.com and we'll delete the account.
Changes
We'll update the "Last updated" date and notify you by email of material changes. Continued use after changes means you accept the new Policy.