bandvan Privacy Policy
Your data is yours, not ours. This policy says what we collect, why we collect it, who else sees it, how we protect it, and what you can ask us to do with it. We do not sell your data. We never have and we will not.
1. What this policy covers
1.1 This policy covers bandvan: the web app, the iOS app, the calendar feeds, the promoter forms, the emails we send, and our website. bandvan is run by Band Van Inc.
1.2 It covers information about our customers and their users: the people who hold bandvan accounts.
1.3 It also describes, in section 4, how we handle information you enter about other people. That information is different in one important way: you decide what goes in and why, so you are the controller of it and we are your processor. Our obligations for that information are set out in section 4 and in your agreement with us.
1.4 If a promoter or a venue sent you here after filling in one of our forms, go to section 5.
2. What we collect, and why
We collect what we need to run the product and nothing we cannot justify.
2.1 Account identity. Your name and email address, so you can sign in and so we can send you the things the product has to send you. Sign-in is handled by our own identity server. Passwords, passkeys, and two-factor secrets are stored there and nowhere else in the product; the rest of bandvan only ever sees your name, your email address, and an internal identifier.
2.2 Your Team. The name of your Team, its logo if you upload one, who is a member, and what role each member has.
2.3 Tour data. Everything you put in: tours, shows, venues, dates, schedules, hotels, production requirements, deal terms, notes. This is the product. We keep it as long as your account is active.
2.4 Files you upload. Riders, contracts, stage plots, and anything else. They are stored in cloud object storage and served through short-lived private links.
2.5 Contracts sent for signature. If you use e-signature, the document, the signers' names, and the signers' email addresses go to our e-signature provider. See section 6.
2.6 Email we send for you. When you send an advance or an invitation, we pass the recipient's address and the message to our mail provider. Advance emails currently include the contents of the advance itself, so anything in the advance travels with the mail.
2.7 Product events. We record what happens in the product: an advance was sent, a show was created, a sign-in succeeded or failed. This is first-party only, stored on our own systems, and used to understand whether the product works. We use no third-party analytics, no advertising trackers, and no ad networks. There are no advertising cookies in bandvan.
2.8 Operational logs. Our servers record requests they handle, for security, debugging, and abuse prevention. Before those logs leave the server, private links, email addresses, and IP addresses are automatically replaced with placeholders.
2.9 Push notifications. Only if you turn them on. If you do, your browser or device gives us a subscription identifier so we can send you a notification. Turn them off and it is deleted.
2.10 Cookies and local storage. We use browser storage to keep you signed in, remember your preferences, and let the app work offline. That includes the token that keeps you signed in. Signing out clears it. We do not use cookies to track you across other websites.
2.11 Support correspondence. If you email us, we keep the thread so we have the history next time.
2.12 Billing. Payments, when enabled, are processed by Stripe. Card numbers never touch our servers. We will keep a record of the transaction, the last four digits, and your billing address.
2.13 The same list, in one view.
| What we collect | Where it comes from | Why | Who else sees it | How long we keep it |
|---|---|---|---|---|
| Account identity: your name and email address | You, when you create an account | So you can sign in, and so we can send you what the product has to send you | Our own identity server, which is not a third party, holds passwords, passkeys and two-factor secrets; our mail provider carries the email we send you | While your account is active. When you close it, ask us and we delete your Team's content by hand within 30 days |
| Your Team: its name, its logo, who is a member, what role each member has | You and the people you invite | To run the product for your Team | Our hosting provider, which stores it encrypted at rest | While your account is active |
| Tour data: tours, shows, venues, dates, schedules, hotels, production requirements, deal terms, notes | You and your users | This is the product | Our hosting provider, encrypted at rest; venue lookups are answered by our own venue-search server, so the terms you type do not leave our systems | As long as your account is active |
| Files you upload: riders, contracts, stage plots, anything else | You and your users | So the product can hold them for you | Our hosting provider, which stores them in cloud object storage and serves them through short-lived private links | While your account is active |
| Contracts sent for signature: the document, the signers' names, the signers' email addresses | You, when you use e-signature | So the document can be signed | BoldSign | While your account is active |
| Email we send for you: the recipient's address and the message, including the contents of the advance | You, when you send an advance or an invitation | So the message reaches the person you are doing business with | Our mail provider | The advance stays in your account while it is active |
| Product events: an advance was sent, a show was created, a sign-in succeeded or failed | The product, as you use it | To understand whether the product works | Nobody. No third-party analytics, no advertising trackers, no ad networks | Until we ship a retention schedule, which we expect during 2027. They are deleted with your account |
| Operational logs: the requests our servers handle | Our servers, as they handle requests | Security, debugging, and abuse prevention | Nobody. Logs stay on infrastructure we run ourselves, with private links, email addresses and IP addresses redacted before they leave the server | 90 days |
| Push notifications: a subscription identifier | Your browser or device, only if you turn notifications on | So we can send you a notification | Nobody in the table in section 6 | Deleted when you turn notifications off |
| Cookies and local storage, including the token that keeps you signed in and the offline cache of your advances | Your browser or device | To keep you signed in, remember your preferences, and let the app work offline | Nobody. We do not use cookies to track you across other websites | Until you sign out, which clears both |
| Support correspondence | You, when you email us | So we have the history next time | Our mail provider | As long as it is useful for supporting you |
| Billing: the transaction, the last four digits of the card, your billing address | You and Stripe, when payments are enabled | To take payment. Card numbers never touch our servers | Stripe | As long as tax and accounting law requires |
3. What we do not do
3.1 We have not sold personal information, or shared it for cross-context behavioural advertising, in the preceding 12 months. We do not do so today and we have no plans to.
3.2 We do not use your content, or the contact details in your account, to train machine learning models.
3.3 We do not read your content. The only exceptions are in section 7.
3.4 We do not use third-party advertising or analytics services.
4. Information you enter about other people
4.1 bandvan is a tour management tool, so most of what you enter is about other people: promoters, venue staff, production crew, hotel contacts, and clients.
4.2 You control that information. You decide who goes in the system, what is recorded about them, and how long it stays. We process it on your instructions, only to run the Service for you. In privacy law terms you are the controller and we are the processor.
4.3 That means it is your responsibility to have the right to enter that information, and to give whatever notice the law where those people live requires. Our terms of service say this too.
4.4 We will not market to the people in your address book, sell their details, or use them for anything other than running bandvan for you.
4.5 If someone whose details you entered writes to us with a request, we will tell them to contact you and let you know they asked. If you ask us to correct or delete something you entered, we will do it.
5. If you are a promoter or a venue filling in a form
5.1 A tour manager sent you a private link to an advance form. You do not have a bandvan account and you do not need one.
5.2 What you type into that form, and any file you attach, goes to the act's bandvan account. The act, not bandvan, decides what happens with it. If you want it corrected or removed, contact whoever sent you the link. You can also write to us at hello@bandvan.app and we will pass it on and help.
5.3 We record that the form was opened and submitted, and we store what you submitted, so the act can see it.
5.4 The link is private, works for one show, and can be switched off by the act at any time. Do not forward it to anyone who should not fill in the form.
6. Who else sees your data
We use a small number of service providers. Each of them sees only what they need to do their job.
| Provider | What it does | What it sees | Where |
|---|---|---|---|
| Amazon Web Services | Hosting, database, file storage, content delivery | Everything, encrypted at rest | Data hosted in Canada, with a global content delivery network; vendor headquartered in the United States |
| BoldSign | Electronic signatures | Contract documents, signer names and email addresses | Data hosted in Canada; vendor headquartered in the United States |
| Amazon Web Services (Simple Email Service) | Sending transactional email | Recipient addresses and message contents | Data hosted in Canada and the United States; vendor headquartered in the United States |
| Stripe | Payments, when enabled | Billing details. Card data never reaches us | United States |
| Our own venue-search server | Venue name and address lookup, from OpenStreetMap data | The venue search terms you type. No personal information, and nothing leaves our systems | Data hosted in Canada, alongside our other systems |
| GitHub | Source code and automated checks | Our code. No customer data | United States |
| 1Password | Storage of our own credentials | Our credentials only. No customer data | Not applicable |
6.1 Our own identity server is run by us on our own infrastructure. It is not a third party.
6.2 We will publish changes to this list here. If we add a provider that handles customer data in a materially different way, we will tell account owners by email.
7. When we access or disclose your information
7.1 To help you. If we need to look at your account to fix a support issue, we will ask you first.
7.2 To fix something broken. If an automated process fails part-way, we get an alert. Where we can fix it without looking at your content, we do. In rare cases we have to look, and when that happens we fix the underlying cause so it does not happen again.
7.3 To keep bandvan safe. We look at logs and metadata to investigate abuse, fraud, and attacks.
7.4 When the law requires it. We will only hand over data if we are compelled by a valid legal order. Where we are legally allowed to, we will tell you before we do.
7.5 If the business changes hands. If bandvan is acquired or merges, we will tell you before your information becomes subject to a different privacy policy.
7.6 Aggregated data. We may use anonymized, aggregated statistics for any purpose. It never identifies you or anyone in your account.
8. How we protect your data
This is a plain description of what we actually do today, not a wish list.
8.1 In transit. Connections between you and bandvan use TLS 1.2 or better, with HTTP Strict Transport Security. Our database requires encrypted connections, and mail leaves us over an encrypted connection. One hop is not yet encrypted: between our content delivery edge and our application server, traffic travels over our hosting provider's private network, which never touches the public internet. Encrypting that hop as well is planned.
8.2 At rest. The database, the servers' disks, and the file storage are all encrypted with AES-256 using keys managed by our hosting provider. We do not encrypt individual fields separately.
8.3 Access control. Every operation in bandvan is checked against a single permissions model that binds each action to a minimum role on a team or a resource, enforced in one layer and tested automatically. If you do not have access to something, the product cannot tell you whether it exists.
8.4 Infrastructure access. There is no remote shell access to our production servers. Administrative access goes through our hosting provider's audited session manager. The database sits on a private network reachable only by the application, using accounts limited to exactly what each part of the system needs.
8.5 Private links. The links we generate for promoters and calendar feeds are cryptographically signed, compared in constant time, and use separate secrets for each purpose so one cannot be used in place of another. Promoter links are per-show and can be switched off individually. Calendar feed links cannot yet be switched off one at a time. If someone leaves your team, tell us and we will rotate them.
8.6 Secrets. Credentials are stored in a password manager, delivered to servers encrypted, written with restrictive permissions, and never committed to our source code. The application refuses to start in production with a default credential.
8.7 Logging. Operational logs are centralized on infrastructure we run ourselves and kept for 90 days. Private links, email addresses, and IP addresses are redacted before logs leave the server.
8.8 Keeping it that way. Every release is blocked unless it passes an automated scan for known vulnerabilities in our code's dependencies, an audit of front-end packages, and a scan for leaked credentials. Dependency updates arrive weekly. The same checks run publicly on every code change. We run whole-codebase security reviews and fix high-severity findings before shipping.
8.9 Backups. The database is backed up automatically every day with point-in-time recovery, and file storage keeps previous versions of files. We have not yet run a full restore drill, and we do not yet keep a copy in a second region. Both are planned. Please keep your own copies of documents you cannot afford to lose.
8.10 What we do not claim. No service is unbreakable. We do not promise that bandvan cannot be breached. We promise to keep our protections reasonable and current, and to tell you quickly if something goes wrong.
9. Multi-factor authentication
We offer time-based one-time codes and passkeys, and we prompt you to set one up when you sign in. We do not currently require it. We recommend that every account owner and admin turn it on.
10. If there is a breach
10.1 If we discover that personal information in bandvan has been lost, stolen, or accessed by someone who should not have it, and there is a real risk of significant harm, we will:
(a) tell the affected account owners without unreasonable delay;
(b) report it to the Office of the Privacy Commissioner of Canada, and to any other regulator we are required to report it to;
(c) keep a record of the incident for at least 24 months, as Canadian law requires. We keep a record of every breach of our security safeguards, including ones we are not required to report; and
(d) give you what you need to notify the people whose information you entered, since for that information you are the one who has to notify them.
10.2 We notify you. You notify the people in your address book. We will help.
10.3 We hold ourselves to the strictest notification deadline that applies to any of our customers, rather than tracking each one separately. Our internal target is 72 hours, measured from the point we confirm a reportable breach.
11. Where your data lives
11.1 bandvan runs in Canada. Your account data, tour data, and uploaded files are stored there.
11.2 Some of our providers are outside Canada, as shown in the table in section 6. When your data goes to them, it is subject to the laws of the country they operate in, including lawful access by that country's authorities. Where we can, we place providers under contracts requiring them to protect it. Our hosting provider is under such a contract; we are in the process of putting one in place with our e-signature provider.
12. How long we keep things
12.1 Your content stays as long as your account is active.
12.2 When you close your account, ask us and we will delete your Team's content. We do not yet have a self-serve delete button in the app, so today this is a request to hello@bandvan.app and we do it by hand within 30 days. A self-serve deletion path is planned, and this section will be updated when it ships.
12.3 Operational logs are kept for 90 days, with private links, email addresses, and IP addresses already redacted.
12.4 Product event records are kept until we ship a retention schedule, which we expect during 2027. They are tied to your account and are deleted with it.
12.5 Support email is kept as long as it is useful for supporting you.
12.6 Billing records are kept for as long as tax and accounting law requires.
12.7 On your device. The app caches your advances on your device so it works without a signal. That cache is cleared when you sign out. Sign out on any device you no longer control.
13. Your rights
Wherever you live, we give every customer the same rights.
13.1 To know what we collect and why. That is this document.
13.2 To access the personal information we hold about you.
13.3 To correct anything that is wrong.
13.4 To delete your information, subject to what we have to keep by law.
13.5 To take it with you. Ask and we will give you your Team's data in a machine-readable form.
13.6 To withdraw consent to optional things, like push notifications or product emails that are not essential to the Service.
13.7 To complain. If you are unhappy with how we have handled your information, tell us first at hello@bandvan.app. If we do not resolve it, you may complain to the Office of the Privacy Commissioner of Canada, or to the privacy regulator where you live.
13.8 Not to be treated differently for exercising any of these rights. We will not charge you more or give you worse support. Some requests, such as deleting your account, will end your ability to use the Service, because there will be nothing left to use.
13.9 To make any of these requests, email hello@bandvan.app. We may need to verify who you are before we act, usually by confirming you control the account's email address. We will respond within 30 days.
14. Automated decisions
We do not make decisions about you by automated means that have legal or similarly significant effects.
15. Children
bandvan is a business tool and is not intended for anyone under 16. We do not knowingly collect information from children. If you believe a child has given us information, email hello@bandvan.app and we will delete it.
16. Changes to this policy
We will update this policy as the product changes and as the law requires. Every version is numbered. When we make a significant change, we will change the date at the top, tell account owners by email, and ask you to accept the new version in the app.
17. Contact
Questions, requests, or complaints about your privacy: hello@bandvan.app. That address reaches the person accountable for privacy at bandvan. We will tell you that person's name if you ask.
18. Attribution
Portions of this policy are adapted from the Basecamp open-source policies / CC BY 4.0. 37signals does not endorse bandvan or this policy.