Legal
Privacy Policy
Last updated: 19 August 2026
Playing Next (“we”, “us”) operates a platform that lets guests at an event pay to request a song from a DJ. This policy explains what personal data we collect from guests and DJs, why, and what your rights are.
Data controller: Elliot Sanfilippo, trading as Playing Next. Contact us at info@playingnextapp.com for anything in this policy, including exercising any of the rights below.
1. Information we collect
If you’re a guest making a request, you don’t create an account with us. We store:
- The song title and artist you request
- An optional message, if you choose “Song + Message”. Whatever you type is stored as-is, so please don’t include personal details you don’t want kept
- If you report a request as not played, an optional note explaining why, stored as-is and visible to us when reviewing the report
Your browser also stores a list of your own request IDs in localStorage on your device, scoped to the DJ you requested from, so the “My Requests” page can show you your own history. This never leaves your device and isn’t something we can see.
When you pay, you’re taken to Stripe’s own checkout page. Stripe collects your email address and cardholder name, and processes your card details directly. We never see or store your card details ourselves.
If you’re a DJ, you create an account, which involves more data:
- Email and password, held by our authentication provider (Supabase)
- Your DJ name, slug, bio, genres, profile photo, and prices (all self-entered and, by design, publicly visible on your profile page)
- When you connect payouts, Stripe collects your legal identity details directly (full name, date of birth, address, and bank account details) as part of their own onboarding flow. We never see or store this; we only hold a reference ID to your Stripe account.
2. Why we use it, and on what basis
- To operate the service: taking and routing requests, processing payments, showing DJs their queue. This is necessary to perform our contract with you.
- To keep the platform secure: for example, we use IP addresses transiently, in memory only, to rate-limit abusive request volume. This is a legitimate interest in preventing abuse.
- To fix bugs: our error-monitoring tool (Sentry) may capture technical details about an error, including IP address and browser information, when something breaks.
We don’t use your data for advertising, and we don’t sell it.
3. Who we share it with
We use a small number of third-party processors to run the service. Each only receives what it needs to do its job:
- Supabase: hosts our database, DJ authentication, and profile images
- Stripe: processes guest payments and DJ payouts (Stripe Connect); collects guest email/payment details and DJ identity/bank details directly
- Spotify: receives the song/artist text you search for, so we can show matching tracks; we use app-level credentials, not your personal Spotify account, so no identifying information about you is sent
- Sentry: receives technical error reports to help us fix bugs
- Vercel: hosts the website and its server functions, and by nature of running the servers, logs request traffic including IP addresses
4. How long we keep it
Honestly: we don’t yet have an automated retention or deletion schedule. Request records (including guest messages) are currently kept indefinitely. A DJ hiding a request from their own dashboard view doesn’t delete the underlying record.
We’re aware this needs to change before we can consider our retention practice fully compliant, and it’s on our roadmap. Until an automatic process exists, you can contact us directly to ask for your data to be deleted and we’ll do it manually.
5. Cookies
We don’t set any cookies ourselves. Our login sessions are stored in your browser’s localStorage, not cookies. When you pay, you’re taken to Stripe’s own checkout page, which sets its own cookies under Stripe’s control. That’s covered by Stripe’s own privacy policy, not this one.
6. Your rights
Under UK GDPR, you have the right to access, correct, delete, or export the personal data we hold about you, and to object to or restrict certain processing. Since we don’t yet have self-service tools for most of this, contact us at info@playingnextapp.com and we’ll action it manually. You also have the right to complain to the Information Commissioner’s Office (ICO) if you think we’ve mishandled your data.
Asking for a copy of your data. Email info@playingnextapp.com. Because guests don’t have accounts, we need to confirm the records are yours before we send anything: a payment shown in Stripe under the address you write from, a My Requests link, or the wording of a message you sent. We’ll then send you a PDF and a machine-readable JSON file covering the records we were able to verify as yours. UK GDPR gives us one month to respond.
Playing Next does not maintain a guest account or store a guest email address or dedicated guest name field. Information entered into a request, such as a message, may still contain personal information.
Playing Next does not receive or store your email address, cardholder name or payment details. Stripe collects those directly, and Stripe also holds the payment and refund transaction records, so those must be requested from Stripe.
7. Age requirements
You must be at least 16 years old to submit a paid request or create a DJ account. DJ accounts additionally require being 18 or older, since Stripe Connect payouts require the account holder to be a legal adult.
8. Changes to this policy
If we make material changes to this policy, we’ll update the date at the top of this page.