Back to Mitch Stephen Music

Privacy Policy

Last Updated: December 17, 2025

GDPR Notice: This policy complies with EU GDPR. See "Your Rights" section below.

1. Data Controller

Mitch Stephen Music, San Antonio, Texas, USA
Email: mitch@mitchstephenmusic.com

2. Information We Collect

You Provide: Name, email, phone, payment info (via Stripe), messages
Automatically: IP address, browser, device, usage data, cookies

3. Legal Basis (GDPR Article 6)

We process data based on: consent, contract performance, legal obligations, and legitimate interests.

4. How We Use Data

To provide services, process payments, send Music Monday SMS (with consent), marketing (with consent), analytics, security, and legal compliance.

5. Cookies

Essential: Required (no consent needed)
Analytics/Marketing/Functional: Require your consent.

6. Music Monday SMS

Weekly messages with your consent. Reply STOP to unsubscribe. Your number is never sold.

7. Data Sharing

We never sell your data. We share with: Stripe (payments), Twilio (SMS), and when legally required.

8. International Transfers

Data may transfer to the US. We use Standard Contractual Clauses for EU data protection.

9. Security

SSL encryption, secure passwords, limited access, PCI-compliant payments.

10. Data Retention

Account: duration + 3 years. Transactions: 7 years. Marketing: until withdrawn. Analytics: 26 months.

11. Your Rights (GDPR)

Access, rectify, erase, restrict, portability, object, withdraw consent, lodge complaint. Email: mitch@mitchstephenmusic.com

12. California Rights (CCPA)

Right to know, delete, opt-out. We do not sell personal information.

13. Children

Not intended for under 16. We delete such data if discovered.

14. Changes

We notify users of material changes via email.