TAPE IN
Русский

Global Privacy Notice

Version: GLOBAL-006 · Effective: 2026-09-17

1. Who Controls Your Personal Information

Tape In is operated by sole proprietor Andrey Viktorovich Shabaev-Markin (ИП Андрей Викторович Шабаев-Маркин), OGRNIP 314774605600902, INN 027815065929, registered on 25 February 2014 by Interdistrict Inspectorate of the Federal Tax Service No. 46 for Moscow, Russian Federation.

Privacy contact: privacy@tapein.ru
Legal contact: legal@tapein.ru
Support: support@tapein.ru

2. Scope

This Notice describes the unified Tape In account and Tape In Setlist in the current free, 18+ launch. Browser Studio, Music Notebook, Music Assist, Google Cloud and OpenAI processing are outside this launch scope.

3. Information We Process

Typical account/service data: email, password hash, internal user/account/workspace IDs, account status, registration/verification/login timestamps, hashed session/verification/reset/CSRF tokens, account settings, product data associated with the account, security events and user-requested support data.

Service content: Setlist titles, songs, dates, notes, blocks/chains, layouts and share state; information you choose to include about another person in User Content.

Public Share data: content you expressly choose to make available by a public link; technical share identifiers needed to operate/revoke the share.

Security and diagnostics
Depending on the current server logging configuration, Tape In infrastructure may process request time, route, method, status, request identifiers, IP address, User-Agent and, after authentication, internal account/workspace identifiers for security, incident response and debugging.

Support/legal/privacy requests
If you contact Tape In, we process the sender address, message content, attachments and mail metadata needed to handle the request.

4. Purposes And Processing Basis

We process information for purposes including:
- creating and securing accounts;
- authenticating users and maintaining sessions;
- providing Setlist and requested account functions;
- storing/synchronising user projects where server storage is part of the active product;
- operating user-requested Public Share;
- responding to support, legal and privacy requests;
- detecting abuse and protecting the security/reliability of the service;
- complying with applicable legal obligations and establishing or defending legal claims.

Core account/service processing is not treated as if it were based on a universal “consent to this Privacy Notice”. Where a specific operation legally requires consent, the consent should be separate, specific and optional where appropriate.

5. Cookie / Local Storage / Device Storage

Strictly necessary storage may be used for requested service, authentication, CSRF/security state, reliability/recovery and user preferences where genuinely necessary.

Non-essential analytics must remain separate from Terms and marketing. For the conservative launch profile, optional analytics on public/signup surfaces remains OFF until a separate affirmative choice is implemented and validated. Rejecting optional analytics must not block core service use.

No third-party behavioral advertising, sale of profiles or cross-site ad tracking is authorized in this launch package.

6. Where Information Is Processed

Current production controller and primary storage/processing geography for the launch scope: Russian Federation, Selectel infrastructure. Current launch-scope transactional/verification email path is Russian.

7. Service Providers And Recipients

Selectel provides the Russian hosting/cloud infrastructure used in the current launch scope. The Service Providers / Processing Recipients Register identifies actual provider roles and geography.

Google Drive and Notion are used for internal development/project/legal evidence and are not intended to be operational storage for raw user production content merely because they are project tools.

Tape In does not currently sell personal information, sell user lists or operate a third-party targeted-advertising data business.

8. Public Share

Public Share is enabled only by an affirmative user action. Account email and internal authentication identifiers should not be placed in a public share payload merely because a public link exists.

If you create a public link, the information included in that share can be accessed by anyone who receives the link. You are responsible for ensuring you have the right to disclose the material you place there. A share may be revoked through product controls or restricted in response to valid legal/security/IP complaints.

9. Retention And Deletion

Tape In keeps personal information only for as long as reasonably needed for the relevant purpose, contract, security need or legal obligation, subject to the actual technical lifecycle of each data store.

Technical/account-linked IP and related security metadata is retained only for as long as reasonably necessary for security, abuse/fraud investigation, dispute handling or applicable legal obligations, subject to the actually implemented lifecycle of the relevant data store. Where a fixed maximum retention period has not been operationally verified, Tape In does not state a fixed number of days. Backup decay follows the actual technical backup lifecycle.

Users may request access/correction and other applicable rights through privacy@tapein.ru. Account deletion and export behavior must match the actual production implementation; public copy must not promise a self-service control that does not exist.

Deletion must cover the unified identity/account and the account-linked product data within the approved lifecycle, including defined backup decay. Immutable legal-acceptance evidence may be retained only where necessary to prove the contract/compliance history and must not be reused as general product data.

10. Your Choices And Rights

You may contact privacy@tapein.ru to ask about personal information Tape In holds about you, request correction, raise a complaint or exercise another right available under applicable law.

Where applicable law gives you rights to access, correction, deletion, restriction, objection, portability, withdrawal of consent or regulator complaint, Tape In will handle the request under the applicable legal regime. The existence and scope of a particular right depends on the law that applies to the processing.

Withdrawing an optional consent does not invalidate processing that was lawful before withdrawal and does not stop processing that rests on another lawful basis.

11. Regional Provisions

US REGIONAL MODULE
Tape In may officially support the United States under the free 18+ launch profile, subject to a maintained state-law applicability matrix based on real scale and activity. No sale of personal information, no targeted advertising and no third-party behavioral advertising is authorized by this launch package. A neutral 18+ gate is used; full date of birth is not collected solely to prove acceptance unless a later legal requirement establishes the need. State-specific rights must be enabled only where applicable and must not be falsely claimed where thresholds/scope are not met.

AUSTRALIA REGIONAL MODULE
Tape In may officially support Australia under the free 18+ launch profile. The Australian privacy applicability position must be kept current against actual turnover and statutory small-business exceptions. The service must preserve mandatory Australian Consumer Law rights. If the Privacy Act applies, APP transparency, access/correction, security, complaints, NDB and overseas-disclosure handling must be implemented. Russian controller/storage geography must be disclosed.

NEW ZEALAND REGIONAL MODULE
Tape In may officially support New Zealand under the free 18+ launch profile. Privacy contact/accountability, access/correction, complaints, serious privacy breach handling and overseas-disclosure classification must be operational. Russian controller/storage geography and actual service providers must be disclosed.

EU/EEA UNSUPPORTED REGISTRATION MODULE
EU/EEA is not a supported registration region in this release. The current signup flow does not create accounts for EU/EEA. Any later launch requires a separate privacy/legal and technical activation review.

UK UNSUPPORTED REGISTRATION MODULE
The United Kingdom is not a supported registration region in this release. The current signup flow does not create accounts for the UK. Any later launch requires a separate privacy/legal and technical activation review.

12. Age Requirement

International account registration is 18+.

13. Marketing Consent

Marketing is optional and separate from Terms, Privacy Notice and transactional mail.
The marketing checkbox must be unchecked by default and refusal must not block core service access.
Evidence must store exact consent text/version, timestamp, user/account ID, surface/build/locale and withdrawal/unsubscribe state. Withdrawal stops future marketing but does not disable verification, security, password-reset or other transactional service messages.

14. Security

Tape In uses organizational and technical safeguards appropriate to the service and current risk profile. Confirmed controls include HTTPS/TLS, password hashing, hashed auth/session/reset/verification tokens on the server, session/CSRF controls, workspace/tenant isolation, minimized Public Share payloads and backup/checkpoint mechanisms.

Public privacy materials intentionally do not disclose credentials, keys or technical details that would materially increase security risk.

15. Incidents And Complaints

Report suspected privacy issues to privacy@tapein.ru and security/support issues to support@tapein.ru.

Tape In maintains incident-response obligations under Russian law and will apply additional notification/complaint duties where another applicable law requires them. If the Australian Privacy Act applies, the final operating package must include the applicable APP complaint process and Notifiable Data Breaches response.

16. Changes To This Notice

Tape In will update this Notice when material information-handling practices, products, providers, storage locations, retention rules or legal requirements change. Each public version must have a stable version/date identifier. Replaced public versions should remain available through a policy archive or equivalent version-history mechanism so the document applicable at a particular time can be identified.

A material privacy change is not treated as if it were automatically accepted merely because Terms of Service are changed. Where a new processing activity requires consent or another specific legal step, Tape In will implement that step separately.