Privacy Policy
Last updated: March 17, 2026
1. Overview
Jazzy ("we", "us") is a service that sends periodic jazz album recommendations via email. We take the protection of your personal data seriously and process it in accordance with the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP/DSG).
2. Data We Collect
When you create an account, we collect and store:
- Email address — for authentication and sending recommendations
- Name — for personalizing emails
- Password — stored as a secure hash, never in plain text
- Newsletter frequency preference — your chosen delivery interval
- Recommendation history — which albums were sent to you, to avoid duplicates
We also process:
- Session cookies — strictly necessary for authentication (no tracking)
- IP address — processed by our hosting provider for delivering the website
3. Purpose and Legal Basis
- Contract performance (Art. 6(1)(b) GDPR) — processing your data to provide the recommendation service you signed up for
- Consent (Art. 6(1)(a) GDPR) — sending recommendation emails based on your explicit consent at registration
- Legitimate interest (Art. 6(1)(f) GDPR) — session cookies necessary for website functionality
4. Third-Party Services
We use the following third-party services to operate Jazzy:
- Supabase(database & authentication) — stores your account data and recommendation history. Servers located in the EU/US. Supabase Privacy Policy
- Resend(email delivery) — receives your email address and name to deliver recommendation emails. Servers located in the US. Resend Privacy Policy
- Vercel(website hosting) — processes your IP address and session cookies when you visit the website. Servers located in the US. Vercel Privacy Policy
For data transfers to the US, we rely on the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCCs) as applicable.
5. Data Retention
We retain your personal data for as long as your account is active. When you delete your account, all your data (account information, preferences, and recommendation history) is permanently and immediately deleted from our database. We do not retain backups of deleted accounts.
6. Cookies
Jazzy only uses strictly necessary session cookies for authentication. We do not use tracking cookies, analytics cookies, or advertising cookies. These essential cookies do not require consent under the GDPR ePrivacy exemption.
7. Your Rights
Under the GDPR and Swiss DSG, you have the following rights:
- Right of access — request a copy of your personal data (available via "Export My Data" in Settings)
- Right to rectification — update your information in your account settings
- Right to erasure — delete your account and all data via "Delete Account" in Settings
- Right to object — unsubscribe from emails using the link in any recommendation email, or change your frequency in Settings
- Right to data portability — export your data in JSON format via Settings
- Right to withdraw consent — you can unsubscribe or delete your account at any time
To exercise any of these rights, use the self-service options in your account settings or contact us at the address below.
8. Contact
If you have questions about this privacy policy or wish to exercise your rights, please contact us via the details on our Imprint page.
9. Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated revision date. We encourage you to review this page periodically.