Privacy Policy
ConcertQueue is a Denver concert-discovery app operated by ConcertQueue LLC, a Colorado limited liability company. This document explains what data ConcertQueue collects, how we use it, and what controls you have over it.
Questions about this policy: support@concertqueue.com.
1. What we collect
1.1 Account data
- Email address: collected when you sign in (via Sign in with Apple, Sign in with Google, or magic-link). Used to identify your account, send you a magic-link if you choose that path, and notify you of important account changes. If you use Sign in with Apple's "Hide my email" relay, we store the relay address Apple gives us; we don't see your real email.
- Apple user identifier (
sub): if you sign in with Apple, we store the stable per-user identifier Apple provides so we can recognize you on subsequent sign-ins. - Apple refresh token: if you sign in with Apple, we store the refresh token Apple issues for one purpose only: revoking ConcertQueue's access to your Apple ID when you delete your account in the app, as Apple requires. It is never used to access any other Apple service or data, and it is deleted with your account.
- Google user identifier (
sub): if you sign in with Google, we store the stable per-user identifier Google provides so we can recognize you on subsequent sign-ins. - Username: the @handle you pick during onboarding (2–20 characters, starting with a lowercase letter, followed by lowercase letters, digits, or underscores). Visible to other users.
- Display name: captured from your sign-in provider (Apple or Google) when available. Stored privately for account records and support. Never shown to other users: everywhere in the app and on public pages, you appear as your @username only.
- Profile photo: if you upload one. Stored on Cloudflare R2. Pre-screened for inappropriate content via an automated check before upload.
- Sign-up source: which authentication path you used to create your account (Apple, Google, magic-link, or invite). Internal-only signal used to track which sign-in flows are popular.
- Inviter: if you signed up by tapping someone else's share link, we record which existing user invited you so we can auto-friend the two of you on the spot. Not currently exposed publicly.
- Public-schedule preference: a flag you control in the app's privacy settings, where you choose whether your concert list is shown publicly. When it is on, your upcoming Going shows are visible on your public profile page to anyone with your link. A separate control lets you choose whether your upcoming Interested shows are included too; when that is off, your Interested shows stay private. Default for sharing is off (only header counts visible).
1.2 Usage data
- Swipe decisions: for signed-in users, your Going / Interested / Pass choices on each show are stored with your account. Going and Interested are visible to your accepted friends; Pass is private to you. In guest mode, swipe decisions stay on your device unless you later sign up or sign in and choose to carry them into your account.
- Attendance confirmations: the morning after a show you marked Going, we may send a push notification asking whether you actually attended. Your answer (yes / no / unanswered) is stored alongside the original Going commitment. Used to distinguish "claimed Going" from "confirmed attended" for your friends and for aggregate analytics; the per-row answer is visible to your accepted friends in the same way the Going commitment was.
- Friendships: which other users you're friends with. Mutual-friend counts are visible to other users; the friend list itself is visible only to accepted friends.
- Ticket-link clicks: for signed-in users, when you tap "Buy Tickets," we record the click: the destination ticket link, our classification of which ticket provider it points to, how many of your friends were Going or Interested in that show at the time of the tap, and which screen in the app you tapped from. Used for analytics and to substantiate qualified-traffic value to potential ticketing partnerships. Guest ticket taps are not sent to our server.
- Listen-link taps: for signed-in users, when you tap a "Listen" button to open an artist on Apple Music or Spotify, we record which service you opened for aggregate analytics (how the feature is used and which platform people prefer). Guest taps are not sent to our server. We never receive anything back from Apple Music or Spotify about your account or your listening.
- Share opens: for signed-in users, when you tap "Share" on your profile, your schedule, or a show card, we record that you opened the share sheet (the surface, and the show ID for a card share) for aggregate analytics on how often and from where people share. We record the share intent only; we do not see whether, or to whom, you actually sent the link. Guest share taps are not sent to our server.
- Session pings: for signed-in users, when you open the app we record a lightweight "session" row used for aggregate DAU/WAU/MAU counts. We do not track per-session activity. Guests do not send session pings.
1.3 Device data
- APNs device token (iOS): required to send push notifications, which the app only enables after you explicitly agree in-app. Stored only while you have notifications enabled: turning notifications off, signing out, or deleting your account removes the token from our systems, and any queued, undelivered notification for that token is cancelled and its stored token copy scrubbed.
- FCM device token (Android): when you use the Android app and enable notifications there, we store a Firebase Cloud Messaging device token instead of an APNs token. It is handled under the same rules as the APNs token above.
- App version, OS version (iOS or Android), and device model: for signed-in users, included in session pings for support and analytics.
- Calendar access (opt-in): if you turn on Calendar export in Settings, ConcertQueue asks your device for permission to write to its Calendar. There are two independent toggles: shows you mark Going are added to your device Calendar when "Auto-add Going shows" is on, and shows you mark Interested are added when "Auto-add Interested shows" is on. Either is removed if you change your mind. We only write events you create by marking Going or Interested; we do not read, store, or transmit your existing calendar events, and ConcertQueue itself never sends your calendar data to ConcertQueue LLC or any third party. Note that the events ConcertQueue writes into your device Calendar may be synced by your operating system to any Google, Outlook, or other calendar account you have connected in your device settings, exactly as your own manually-created events are; that syncing is governed by your device's calendar settings, not by ConcertQueue. The integration is off by default and you can revoke Calendar access at any time in your device settings (iOS Settings, or the equivalent on Android when available).
1.4 Moderation data
- Content reports: if you report another user, we record the report with your user ID, the target user ID, the reason, and any details you provide. Used to action the report.
- User blocks: if you block another user, we record the block so we can hide them from your discovery surfaces. A new block also creates an internal moderation report record so the developer can review abuse patterns. They are not notified that you blocked them.
- Show corrections: if you flag a wrong genre / date / venue / etc. on a show, we record the correction so an admin can review and apply it. If you are signed in, the correction is tied to your user ID; if you are browsing as a guest, the correction is stored without a reporter user ID.
2. What we do NOT collect
- Location data: we do not request or use any location permission. Denver-area shows are a global setting, not based on your phone's location.
- Contacts: we do not access your phone's contacts.
- Photos: beyond the single profile photo you optionally upload, we do not access your photo library.
- Existing calendar events: the opt-in Calendar export only writes the shows you mark Going or Interested. We never read, store, or transmit the events already in your calendar.
- Microphone, camera, motion data: we don't request these permissions.
- Browsing history or activity in other apps: we have no third-party SDKs that track you across other apps or websites.
- Financial information: we don't process payments. Ticket purchases happen on the ticketing provider's site, not ours.
3. How we use your data
| Data | Used for |
|---|---|
| Authentication, account-related notifications | |
Apple sub | Recognizing you across Apple Sign In sessions |
Google sub | Recognizing you across Sign in with Google sessions |
| Username, avatar | Showing you to other users in friend search, profile views, and friend lists |
| Display name | Account records and support. Never displayed to other users |
| Swipe decisions | Building your personalized calendar; computing social signal ("3 friends going to this show") |
| Attendance confirmations | Distinguishing "claimed Going" from "confirmed attended" for friends and aggregate analytics |
| Friendships | Routing friend-aware features (mutual counts, friend activity in feeds, push notifications about friend activity) |
| Sign-up source / Inviter | Aggregate attribution analytics; auto-friending the inviter when you signed up via their share link |
| Public-schedule preference | Controlling whether your upcoming shows render on your /@username share page |
| Ticket clicks | Aggregate analytics for ticketing partnership pitches |
| Listen-link taps | Aggregate analytics on Listen usage and platform preference |
| Share opens | Aggregate analytics on how often and from where users share |
| Session pings | Aggregate DAU/WAU/MAU for product health |
| APNs / FCM device token | Sending push notifications you've opted into |
| Reports, blocks, corrections | Moderating the catalog and the user base |
We do not use any of this data for cross-app advertising, behavioral targeting, or sale to third parties.
4. Third-party services
| Service | Purpose | Data sent |
|---|---|---|
| Apple | Sign in with Apple, Push Notifications (iOS) | Identity token (for verification), device token (for push) |
| Firebase Cloud Messaging (Google) | Push notifications on Android | Device token (for push), notification content in transit |
| Sign in with Google | OIDC ID token (for verification). When you tap "Sign in with Google," Google sees that you're signing in to ConcertQueue and returns your email, name, and a stable identifier to us. Google does not receive any of your in-app activity. | |
| Cloudflare R2 | Profile-photo hosting | Your uploaded photo, processed to WebP at 256×256 |
| Resend | Transactional email: magic-link sign-in, admin sign-in links and codes, and operational summary emails to the operator | Recipient email address and the content of the email being sent |
| Railway | Application and database hosting | All account, usage, device, and moderation data described above, stored in our Postgres database |
| Anthropic Claude | Genre classification of public show metadata + automated avatar pre-screening | Show titles + artist names (public concert data) + your uploaded avatar bytes (one-off NSFW screening; not retained by Anthropic) |
| Ticketmaster | Public show metadata (when applicable) | None of your personal data. Outbound public catalog reads only. |
| Operator notification tools | Routing content reports and system alerts to the operator for review | The report or alert being routed |
These services are bound by their own privacy policies and are required, by contract or by their published policies, to protect your data to a standard consistent with this policy. None of them are used for tracking you across other apps.
A note on the Sign in with Google SDK: Google's iOS Sign-In SDK ships a privacy manifest declaring that it may collect Phone Number, Coarse Location, and usage data. Apple aggregates every bundled SDK's manifest into the app's App Store privacy label, so those data types appear on ConcertQueue's label. ConcertQueue requests only your email and basic profile from Google and never requests, receives, or stores your phone number or your location.
IP address: When you sign in, load a public share-link preview page, or submit a show correction as a guest, we briefly process your device's IP address to rate-limit those requests and prevent abuse. We do not store your IP address or link it to your account.
5. Your controls
- Delete your account: Settings → Danger Zone → Delete account. Type-to-confirm required. This permanently deletes your user row and cascades to your swipe decisions, friendships, device tokens, queued notification records, and blocks. Reports and show corrections you filed are kept only as moderation or catalog audit records with your user ID removed and your free-text notes scrubbed.
- Reset your swipes: Settings → Danger Zone → Reset my schedule. Wipes your Going / Interested / Pass decisions without deleting your account.
- Block another user: User profile → menu → Block. They will not see you in search and you will not see them in any discovery surface.
- Report content: User profile → menu → Report, or any show → menu → Report a problem. Reports go to an admin for review; we aim to review promptly, typically within a few days.
- Manage push notifications: Settings → Notifications, plus your phone's system Settings → ConcertQueue.
- Remove your profile photo: Settings → Profile photo → Remove. The image is dereferenced from your account immediately, and the stored copy is cleaned up from our image hosting shortly after on a best-effort basis.
- Sign out: Settings → Sign out. Clears your authentication token from this device.
- Change your username: Settings → Username. You can change your handle at any time; a handle you release may then be taken by someone else.
- Show or hide your concert list publicly: in the app's privacy settings you can choose whether your concert list is shown publicly. Turning it off reverts your /@username public page to header counts only. Turning it on exposes your upcoming Going shows to anyone with your link; a separate control lets you choose whether your upcoming Interested shows are included as well. Your @handle, profile photo, and aggregate show counts remain visible on your public profile page even when the list itself is hidden. Past shows never appear publicly. Default is off.
- Answer or skip attendance prompts: the morning-after "Did you go?" sheet is optional. You can dismiss it anytime; unanswered rows just stay unanswered. You can disable all push notifications via the controls above to stop the prompt push.
5.1 What people see on your public profile page
Your /@username page is a public web page at app.concertqueue.com/@yourhandle. It always shows: your @username, your profile photo (if you have one), and aggregate counts of your Going + Interested shows. Your display name is never shown. When you choose to show your concert list publicly in the app's privacy settings, the page additionally renders your upcoming Going shows, plus your upcoming Interested shows if you also choose to include them.
A small image preview (1200×630 PNG) is generated server-side at /@username/og.png and referenced via Open Graph meta tags. This image renders the same data the page shows: avatar, name, top three upcoming Going shows (only when public-schedule is ON). iMessage / Twitter / Slack request this image when someone shares your link. Public pages and preview images may be cached briefly by browsers and messaging apps, and a preview image already fetched by a third-party app may persist as a copy that ConcertQueue cannot recall.
Profile pages for users with the hidden-from-search flag (typically: admin or internal accounts) return 404 to deny direct access. Toggling public-schedule OFF does not hide the page itself, only the list of shows.
6. Data retention
- Active accounts: we retain your account data for as long as you have an account.
- Deleted accounts: when you delete your account, your account data is purged. Some derived analytics and audit records, such as anonymized ticket-click counts, anonymized Listen-link taps, and de-identified moderation or catalog records, may be retained without your user identifier.
- Magic-link tokens: expire after 10 minutes.
- Session pings: retained, with a scheduled purge on a 365-day window being introduced.
7. Children's privacy
ConcertQueue is rated 17+ on the App Store. Concert metadata may reference alcohol, late hours, and similar themes appropriate for a mature (17+) audience. We do not knowingly accept signups from users under 13. If you believe a minor has created an account, email support@concertqueue.com and we will delete it.
8. Security
- All data in transit is encrypted via HTTPS / TLS.
- Authentication uses JWTs signed with a server-side secret. Apple Sign In tokens are verified against Apple's published public keys before any account is created or read.
- We do not store passwords (we don't support password authentication).
- Profile photos are pre-screened by an automated content classifier before upload, then EXIF-stripped and resized to 256×256.
9. Changes to this policy
If we make material changes to this policy, we'll update the "Last updated" date at the top of this page.
10. Your rights under California and Colorado law
If you reside in California or Colorado, state privacy law gives you the right to:
- Know what personal information ConcertQueue has about you.
- Request deletion of your personal information.
- Request correction of inaccurate personal information.
- Opt out of any sale or sharing of your personal information for cross-context behavioral advertising.
ConcertQueue does not sell your personal information. We do not share it for behavioral advertising or build advertising profiles.
To exercise any of these rights, email support@concertqueue.com. We aim to respond promptly, typically within a few days, and always within the timeframe state law requires. We may ask you to verify your identity before fulfilling a request, to make sure we don't release your data to someone impersonating you.
11. Contact
Email: support@concertqueue.com
Operator: ConcertQueue LLC
Mailing address: 1500 N Grant St Ste N, Denver, CO 80203
In-app deletion (Settings → Danger Zone → Delete account) takes effect immediately; best-effort cleanup of copies stored with external hosting services (such as a profile photo) completes shortly after. If you instead email a deletion request, we process it promptly, typically within a few days. For formal rights requests under state privacy law, we respond within the timeframe the law requires.