Privacy Policy
Last updated: [Effective Date]
This Privacy Policy explains how [Company Legal Name] (“TRAX,” “we,” “us”) collects, uses, and protects information in connection with the TRAX Catalog application and website at traxmusiclabs.com (the “Service”). TRAX is a catalog-management tool for music labels: it stores the tracks, splits, credits, agreements, and related files that account holders enter or upload.
1. Information we collect
Information you provide
- Account information — your email address, a hashed (bcrypt) password, and your assigned role. Accounts are created by invitation from an existing administrator.
- Catalog content — the data you enter about recordings and releases: titles, artist and party names, ISRCs/UPCs, genres, labels, release dates, master and publishing split percentages, credits, and agreement details.
- Files you upload — cover art, audio (stems and masters), agreement documents, and credit documents. For every file we also record an audit entry: the file name, who uploaded it, and when.
- Files you import from Google Drive — see Section 4.
- Support correspondence — messages you send us.
Information collected automatically
- Authentication and security data — a session cookie, a CSRF token, and, when multi-factor authentication is enabled, one-time codes sent to your email and short-lived password-reset tokens.
- Server logs — standard request metadata such as IP address, timestamp, requested URL, and user agent, used to operate and secure the Service.
We do not use advertising or third-party analytics/tracking cookies. The only cookies we set are the ones required for you to stay signed in and to protect against cross-site request forgery.
2. How we use information
- To provide, maintain, and improve the Service;
- To authenticate you and secure your account (including MFA and password resets);
- To send transactional email — invitations, password-reset links, and MFA codes;
- To keep the upload audit log described above, for record-keeping and security;
- To detect, investigate, and prevent abuse or security incidents;
- To comply with legal obligations and enforce our Terms of Service.
We do not sell personal information, and we do not use your catalog content or uploaded files for advertising or to train machine-learning models.
3. Google Drive access & Limited Use
If you choose to add a file from Google Drive, we use Google’s file picker and request the
https://www.googleapis.com/auth/drive.file scope. This scope only
grants access to the specific files you select in the picker — not your whole Drive.
When you select files, your browser receives a short-lived Google access token and sends it to our server together with the file identifiers. We use the token once to download a copy of each selected file, then discard the token — we do not store Google tokens or your Google credentials. The downloaded copy is stored and treated exactly like a file you upload directly, including the audit entry described above.
TRAX’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
4. AI-assisted features
TRAX offers an optional feature that suggests a catalog genre for free-text you enter. When you use it, the text you provide is sent to Google’s Generative AI API to return a suggested match. We do not send your account details or uploaded files to this API, and it is used only to produce the suggestion you requested.
5. Service providers
We share information with vendors that process it on our behalf, under contract, only to provide the Service:
- Google Cloud Platform — application hosting, file storage (Cloud Storage), secret management, and the Google Drive and Generative AI APIs described above;
- Resend — delivery of transactional email;
- [Hosting / VPS provider] — server infrastructure for the development environment.
We may also disclose information if required by law, to enforce our agreements, or to protect the rights, safety, and security of TRAX, our users, or the public. If we are involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction.
6. Public share links
The Service lets an account holder generate a link that gives anyone who has the link temporary access to a specific file, without signing in. Only share these links with people you intend to give access. Links can be revoked, and they expire automatically.
7. Data retention
We retain account and catalog data for as long as your account is active or as needed to provide the Service. The file-upload audit log is append-only: removing a document from a list does not delete its audit entry, and the stored file may be retained for record-keeping and security. We retain server logs for a limited period. We will delete or anonymize information when it is no longer needed, subject to legal retention requirements.
8. Security
We protect information with measures including encryption in transit (HTTPS), hashed password storage (bcrypt), optional multi-factor authentication, role-based access within an account, and restricted access to production systems. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your rights and choices
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, or to object to or restrict certain processing. To make a request, contact us at [Contact Email]. You can also ask your account administrator to update or remove account data. We will respond as required by applicable law.
Because accounts are administrator-managed, some data (such as catalog records you created) may be retained by the account even after your individual access is removed.
10. International data transfers
We operate the Service from the United States. If you access it from outside the United States, your information will be transferred to and processed in the United States and other countries where we or our service providers operate.
11. Children
The Service is intended for business use and is not directed to children. We do not knowingly collect personal information from anyone under 16.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, provide additional notice.
13. Contact us
[Company Legal Name]
[Company Address]
[Contact Email]