1. Data Controller
The controller of your personal data is the individual operating under
Individuali veikla (Individual Activity) Registration No. 1498242,
EVRK: 621090, registered in the Republic of Lithuania (hereinafter — "we", "us",
"Provider").
Contact: support@greengomusic.com
2. Overview
GreenGo is a desktop browser application and companion online account platform for DJs and
producers. Access to GreenGo is provided on a subscription basis, managed
through a GreenGo account. This policy explains what personal data we process when you create
an account, subscribe (including during the free trial), and use the application and website.
We are committed to data minimisation: the substantive work GreenGo performs —
browsing, capturing, downloading and converting audio, BPM/key/energy analysis, stem
separation and the SoundMap — runs locally on your device. Your audio files,
browsing history, in-app cookies and analysis results are not uploaded to us.
3. What Data We Collect
We collect and process the minimum amount of personal data necessary to operate your account and
subscription:
3.1. Data You Provide
- Email address — used to create and identify your account, verify ownership,
deliver account and billing communications, and provide support.
- Password — stored only as a salted cryptographic hash (scrypt). We never
store or have access to your password in plain text.
- Support correspondence — any information you include when you contact us.
3.2. Subscription & Payment Data
- Payments are processed by Stripe. Your full card number and payment
credentials are entered on Stripe's systems and are handled directly by Stripe — we do
not receive or store your full card details.
- Subscription records — we store the Stripe customer and subscription
identifiers, your selected plan (Monthly, 3 Months or Yearly), subscription status
(e.g. trialing, active, past due, canceled), the current billing period end date, whether a
cancellation is scheduled, and whether your one free trial has been used.
- Invoice records — invoice identifiers, amounts, currency and billing
period, retained for accounting and tax purposes.
3.3. Data Collected Automatically
- Account session & security data — when you sign in we create a session
associated with your account and record the IP address, browser user-agent string and
timestamps for security and abuse prevention. Email verification and password-reset codes
are stored only as short-lived hashes.
- Device information and telemetry — when you launch the GreenGo application,
we process your IP address and basic device information for the purposes of license /
entitlement validation, security and abuse prevention.
- Basic server logs — IP address, request type and timestamps when you use
our services. These are retained for security purposes and routinely deleted.
- Website analytics — our marketing website uses Cloudflare Web Analytics, a
privacy-friendly, cookieless analytics service that does not track individuals across sites
or build advertising profiles.
3.4. Data Processed Locally (Not Collected by Us)
- Your browsing history, in-app site cookies and logins within the GreenGo
browser stay on your device.
- Your audio files, downloads, converted files, analysis results (BPM, key, energy,
mood), stem separations and SoundMap library are created and stored locally and are
not transmitted to us.
- We do not collect names, physical addresses, phone numbers, or government
IDs.
4. Legal Basis for Processing
We process your personal data under the following legal bases as defined by the
General Data Protection Regulation (GDPR, Regulation (EU) 2016/679):
- Contract performance (Art. 6(1)(b) GDPR) — processing your email, account,
subscription and payment data is necessary to provide the subscription service you signed
up for.
- Legal obligation (Art. 6(1)(c) GDPR) — retaining invoice and transaction
records to comply with tax and accounting law.
- Legitimate interest (Art. 6(1)(f) GDPR) — processing session data, device
telemetry and server logs for security, license validation and fraud prevention.
5. How We Use Your Data
- To create your account and verify ownership of your email address.
- To start, bill, renew, manage and cancel your subscription (including the free trial).
- To validate your subscription/entitlement so the application unlocks for you.
- To send essential service communications (verification codes, password resets, billing and
account notices).
- To respond to support inquiries you initiate.
- To maintain security and prevent abuse and fraud.
6. Data Sharing
We do not sell, rent, or share your personal data with third parties for
marketing purposes.
Your data is processed by the following third-party service providers (processors), solely for
the purposes described above:
- Stripe — payment processing and subscription billing.
- Brevo — sending transactional emails (verification codes, password resets
and account notices).
- Cloudflare — content delivery, network security and privacy-friendly
website analytics.
- Hosting / database provider — hosting our servers and account database.
7. Data Retention
- Account and subscription data — retained for as long as your account
exists, plus a limited period afterwards for legal compliance and support.
- Invoice and payment records — retained for 10 years as required by
Lithuanian tax and accounting legislation.
- Login sessions — expire automatically (by default after 30 days) and are
removed on sign-out.
- Email verification / password-reset codes — expire within 10 minutes.
- Server logs — retained only for a short period for security.
8. Your Rights Under GDPR
As a data subject, you have the following rights under the GDPR:
- Right of access (Art. 15) — request a copy of the personal data we hold
about you.
- Right to rectification (Art. 16) — request correction of inaccurate
data.
- Right to erasure (Art. 17) — request deletion of your data ("right to be
forgotten"), subject to legal retention obligations.
- Right to restriction of processing (Art. 18) — request that we limit
processing of your data.
- Right to data portability (Art. 20) — receive your data in a structured,
machine-readable format.
- Right to object (Art. 21) — object to processing based on legitimate
interest.
To exercise any of these rights, contact us at
support@greengomusic.com. We will respond within
30 days.
9. Cookies
Our account platform uses a single strictly necessary, httpOnly session cookie
(named gg_session) to keep you signed in. It is essential for the service to
function and is not used for advertising or cross-site tracking.
We do not use:
- Advertising or tracking cookies
- Third-party marketing cookies
- Cookie-based analytics (our website analytics are cookieless)
Separately, when you browse websites inside the GreenGo browser application, those sites
may set their own cookies; these are stored locally on your device to keep you logged in to those
sites and are not transmitted to us. GreenGo also includes an ad blocker that reduces third-party
advertising and tracking as you browse.
10. International Data Transfers
Some of our processors (such as Stripe, Brevo and Cloudflare) may process personal data outside
the European Economic Area (EEA). Where this occurs, such transfers are governed by appropriate
safeguards in accordance with Chapter V of the GDPR, such as the European Commission's Standard
Contractual Clauses.
11. Data Security
We implement appropriate technical and organizational measures to protect your personal data
against unauthorized access, alteration, disclosure, or destruction, including:
- HTTPS encryption for all website traffic.
- Access controls and authentication for administrative systems.
- Regular security reviews.
12. Children's Privacy
Our Service is not directed at children under 16 years of age. We do not knowingly collect
personal data from children. If you believe a child has provided us with personal data, please
contact us immediately.
13. Supervisory Authority
If you believe your data protection rights have been violated, you have the right to lodge a
complaint with the Lithuanian supervisory authority:
Valstybinė duomenų apsaugos inspekcija (VDAI)
State Data Protection Inspectorate
L. Sapiegos g. 17, 10312 Vilnius
Website: vdai.lrv.lt
Email: ada@ada.lt
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this
page with an updated revision date. We encourage you to review this page periodically.
15. Contact
Activity registration: Individuali veikla Nr. 1498242, EVRK: 621090