Privacy policy

Last updated 27 August 2026. This policy replaces the privacy policy dated 15 January 2017.

WARM ApS · CVR 38280570 · Rentemestervej 80, 2400 Copenhagen NV, Denmark · support@warmmusic.net

Who we are and what this covers

WARM ApS (“WARM”, “we”, “us”) operates the World Airplay Radio Monitor: a service that listens to radio stations worldwide and tells you when your music is played. This policy covers the WARM web dashboard at dashboard.warmmusic.net, the WARM iOS app, our websites, and the APIs behind them.

We are the data controller for the personal data described here. If you have any question about this policy, or want to exercise any of the rights in the “Your rights” section below, write to support@warmmusic.net.

What we collect, and why

Your account

When you sign up we collect your name, your email address, and an account identifier. If you sign in with Google, Facebook or Apple, we receive your name and email address from that provider — we never receive or store your password for it. We also store the role you select (for example artist, label or manager), and your language preference.

We need this to give you an account, to sign you in, and to contact you about the service. Legal basis: performance of our contract with you.

The music you ask us to monitor

For each song you add, we store the title, the artist name, the ISRC and related release metadata, plus the cover art we retrieve from public music catalogues. If you upload an audio file so that we can fingerprint your release, we store that file and its acoustic fingerprint.

Detections themselves — which station played which song, when, in which country, and the station's audience figure — are about radio broadcasts rather than about you, but they are linked to your account so we can show them to you. Legal basis: performance of our contract with you.

Billing

Subscriptions are handled by Recurly. Card details are entered directly into fields hosted by Recurly and are never sent to, seen by, or stored on WARM's servers. What we store is your subscription state, your plan, your invoices, and your billing address and country.

Legal basis: performance of our contract with you, and our legal obligation to keep accounting records.

How you use the service

We record which pages and features you use, and events such as adding a song or starting a trial, together with your IP address, approximate country, device type and browser. We use this to understand where the product is confusing, to fix faults, and to decide what to build next.

Legal basis: our legitimate interest in operating and improving the service. Where this involves non-essential cookies or similar technologies, we ask for your consent first — see “Cookies, tracking and advertising”.

Support conversations

If you contact us by email or through the in-app chat, we keep the conversation and anything you choose to include in it, so we can answer you and refer back to the history. Legal basis: performance of our contract with you and our legitimate interest in supporting our customers.

Notifications

If you turn on notifications on a device, we store a device token so we can deliver them. You can switch notifications off at any time in the app or in your device settings, and the token is removed when you sign out. Legal basis: your consent.

Cookies, tracking and advertising

Strictly necessary cookies keep you signed in and remember your preferences. These cannot be switched off, because the service does not work without them.

Analytics and advertising technologies are only loaded if you accept them. That includes Google Tag Manager and the Meta (Facebook) advertising pixel, which we use to measure whether our advertising reaches people who find WARM useful. If you decline, they are not loaded.

On iOS, the app asks separately — through Apple's App Tracking Transparency prompt — for permission to use your data to measure advertising performance. If you say no, we do not use your data for that purpose. You can change your answer at any time in iOS Settings under Privacy & Security → Tracking, and you can change your cookie choice at any time from the privacy settings in the app.

We do not sell your personal data, and we do not share it with data brokers.

Who processes your data on our behalf

We use a small number of established providers. Each one only receives what it needs to do its job, and each is bound by a data processing agreement.

  • Auth0 (Okta) — sign-in and account security
  • MongoDB Atlas — the database holding your account, songs and detections
  • Render — hosting for our applications and APIs
  • Recurly — subscriptions, invoicing and card processing
  • PostHog — product analytics
  • Google (Tag Manager) and Meta — advertising measurement, only with your consent
  • Brevo and SendGrid (Twilio) — service and account emails
  • Tidio — in-app support chat
  • Google Firebase — delivery of push notifications, if you enable them
  • ACRCloud — audio fingerprinting that detects your music on air
  • We may also disclose personal data where we are legally required to, or to establish or defend legal claims.

    Where your data is held

    We are based in Denmark and prefer European hosting, but some of the providers above process data in the United States. Where data leaves the European Economic Area, the transfer is covered by the European Commission's Standard Contractual Clauses or by an adequacy decision such as the EU–US Data Privacy Framework.

    How long we keep it

    We keep your account and the airplay history attached to it for as long as your account is open, because that history is the product you are paying for and it loses its value if we discard it. Invoices and accounting records are kept for five years, as Danish bookkeeping law requires. Analytics data is kept in a reduced form after 12 months. Support conversations are kept for three years.

    If you close your account, we delete or anonymise your personal data within 90 days, apart from anything we are legally required to keep.

    Your rights

    Under the GDPR you can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use of it, object to processing we carry out on the basis of legitimate interest, and ask for your data in a portable form. Where we rely on your consent, you can withdraw it at any time, and that does not affect anything we did before you withdrew it.

    Write to support@warmmusic.net and we will answer within one month. If you are not satisfied with our answer you can complain to the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk), or to the supervisory authority in the country where you live.

    Children

    WARM is a business tool and is not directed at children. You must be 18 or older to hold an account, or 13 or older with your parent or guardian's consent. If you believe a child has given us personal data, contact us and we will remove it.

    Security

    Data is encrypted in transit and at rest. Access to production systems is limited to the people who need it. Payment card details never reach our servers. No system is perfectly secure, so if a breach ever affects your personal data we will notify you and the authorities as the law requires.

    Changes to this policy

    If we make a material change we will update the date at the top of this page and, where the change matters to you, tell you in the app or by email. The previous policy, dated 15 January 2017, remains available within our terms and conditions for reference.

    Contact

    WARM ApS, Rentemestervej 80, 2400 Copenhagen NV, Denmark. CVR 38280570. support@warmmusic.net.