Privacy Policy

Last updated: 3 August 2026

Who we are

Loyal League is operated by Loyal League Ltd (company no. 17197430), registered office 20 Wenlock Road, London, N1 7GU, England. Loyal League is a fan-data CRM for independent record labels.

For personal data about fans, the label using Loyal League is the data controller and Loyal League Ltd is the data processor. For personal data about our own customers and website visitors (label account holders, waitlist sign-ups), Loyal League Ltd is the controller. Contact: support@loyalleague.app.

What we process, why, and on what lawful basis

DataPurposeLawful basis (UK GDPR)
Label account data (name, email, password hash, workspace settings)Creating and running your account, authentication, supportContract (Art. 6(1)(b))
Billing data (Stripe customer ID, plan, invoices)Taking subscription payments and meeting accounting dutiesContract; legal obligation (Art. 6(1)(b),(c))
Fan records (email, optional phone, city, page of origin, consent flags)Providing the CRM to the label — we act only on the label's instructionsProcessor acting for the label; label relies on consent or legitimate interests
Engagement events (page visits, opens, clicks, purchases, streams, superfan score)Analytics and superfan scoring inside the label's workspaceProcessor acting for the label
Purchase and membership dataFulfilling drop purchases and memberships, delivering download linksContract (with the fan, via the label)
Waitlist sign-ups (email, label name, optional survey answers)Contacting you about early accessConsent (Art. 6(1)(a))
Email delivery logs (recipient, template, status, error)Making sure email actually arrives and debugging failuresLegitimate interests (Art. 6(1)(f))
Security and abuse logs (IP-derived rate-limit keys, error reports)Protecting the service from abuse and fraudLegitimate interests (Art. 6(1)(f))

We do not use fan data for advertising, we never sell it, and we never use it to train AI models.

Retention

  • Fan records and events: kept for as long as the label's workspace is active. Deleted within 60 days of account cancellation, or sooner on request.
  • Label account data: deleted within 60 days of cancellation.
  • Billing and invoice records: retained for 6 years to meet UK accounting and tax obligations.
  • Email delivery logs: 12 months.
  • Security, rate-limit and error logs: 90 days.
  • Waitlist entries: until you ask to be removed, or 24 months of inactivity.
  • Backups: purged on a rolling schedule of up to 30 days after deletion from live systems.

Sub-processors

We use a small number of vetted providers. Each is bound by a data processing agreement.

ProviderPurposeLocation
SupabaseDatabase, authentication, file storage and hostingAWS eu-west-1 (Ireland), EU
ResendTransactional and broadcast email deliveryUS / EU
StripeSubscription billing and fan payments (Stripe Connect)EU / US

We give notice of new sub-processors before they start processing. See our Data Processing Agreement.

International transfers

Fan and account data is stored in the EU (AWS eu-west-1, Ireland). Some sub-processors (Resend, Stripe) may process limited data outside the UK/EEA. Where they do, transfers are covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or an adequacy decision, together with appropriate technical safeguards.

Your rights

Under UK GDPR you have the right to access, rectify, erase, restrict, and object to processing of your personal data, the right to data portability, and the right to withdraw consent at any time.

Fans: the label that captured you is the controller — contact them first. If you reach us instead, we will forward your request to the relevant label and assist them in fulfilling it. Label customers: email support@loyalleague.app and we will respond within one month.

Complaints

You can complain to the UK Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF — ico.org.uk/make-a-complaint or 0303 123 1113. We'd appreciate the chance to resolve it with you first.

Security

Encryption in transit and at rest, row-level database isolation per label, private storage buckets with short-lived signed URLs, and least-privilege access. Details and how to report a vulnerability: Security.

Changes

We may update this policy. Material changes are notified by email or in-app before they take effect.