Privacy Policy
Last updated 3 August 2026
1. Who we are
Partando is operated by Sombrero Holding AS, a company registered in Norway (organisation number 935 338 646, registered address Holmenveien 51E, 0376 Oslo, Norway). We are the data controller for the personal data described here.
For anything in this policy, including to exercise your rights, contact privacy@partando.com.
2. What we collect
Everything below is data our own systems hold. We have tried to make this an exhaustive list rather than a representative one.
Your account
| Data | Notes |
|---|---|
| Email address | From Spotify sign-in or entered directly. Guests who never claim an account get an internal placeholder address instead of a real one. |
| Display name and emoji | Chosen by you; shown to everyone in a party. |
| Avatar image | Optional. Stored in Cloudflare R2 at a public, unguessable URL. |
| Password | Only if you set one. Stored hashed, never in plain text. |
| Account status | Whether you have claimed the account, feature grants on your account, and any moderation state. |
Sessions and technical data
| Data | Notes |
|---|---|
| Session tokens and expiry | So you stay signed in. |
| IP address and browser/device user agent | Recorded against each session, for security and abuse prevention. |
| Operational logs | Errors and performance traces, which can include your user id and the request path. |
What you do in a party
| Data | Notes |
|---|---|
| Rooms you host or join | Room name, join time, and — for hosts — the name and type of the playback device you selected, plus an optional event image. |
| Tracks you add | The track, when you added it, any note you attached, and whether it came from you or the auto-radio. |
| Hypes, skip votes, emoji reactions | Attributed to you, and visible to others in the room. |
| Vibe-check ratings | Your 1–5 ratings. Shown to the room only in aggregate, but stored against your account. |
| Party photos | See section 9. |
A party is a shared space. Your name, emoji, avatar, the songs you add and the reactions you send are visible to everyone else in that room, and can appear on a TV screen in the room. Treat anything you do in a party as visible to the people at that party.
3. Why we use it, and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Running the service — accounts, rooms, the shared queue, controlling playback, recaps | Performance of a contract, Art. 6(1)(b) |
| Connecting your Spotify account, and the camera for party photos | Consent, Art. 6(1)(a) — you grant these explicitly and can withdraw them |
| Security, abuse prevention, debugging, keeping the service working | Legitimate interests, Art. 6(1)(f) |
| Service emails — verifying your address, account and security notices | Contract, Art. 6(1)(b) |
We do not sell your personal data. We do not use it for advertising, we do not run ad networks or trackers in the app, and we do not build advertising profiles.
4. Spotify
Partando plays music through your own Spotify account — we are not a music service and we never receive or store audio. Hosting a party requires Spotify Premium.
When you link Spotify, you grant permissions that let us:
- read your Spotify profile, including your email address and display name;
- read your saved songs, top tracks and playlists, to power search and the taste-seeded auto-radio;
- see your available playback devices and what is currently playing, and — for hosts — start, pause and change playback on the device you pick;
- save a track to your Liked Songs when you tap the like button;
- create a private playlist when you save a party recap.
We store the access and refresh tokens Spotify issues, and the list of permissions you granted. We do not have, and never ask for, your Spotify password.
You can disconnect at any time from your Spotify account settings, or by contacting us. What Spotify itself does with your data is governed by Spotify's own privacy policy, not this one.
5. Who else sees it
We use the following providers. They process data on our instructions, under contract, and only to provide their service to us.
| Provider | What for |
|---|---|
| Cloudflare | Hosting, database, file storage and email delivery. Effectively all of the data above rests here. |
| Spotify AB | The music integration described above. |
| Pydantic Logfire | Error and performance monitoring, which can include your user id. |
| Reccobeats, Last.fm, LRCLib | Track information used for beat-synced visuals, the auto-radio and, for a small number of accounts, lyrics. We send track details only — never anything identifying you. |
Beyond these, we share personal data only where the law requires it, or to establish or defend legal claims. If the business is ever sold or reorganised, data may transfer with it; we will tell you first.
6. How long we keep it
We should be straightforward about this: Partando does not currently delete data automatically. There is no scheduled clean-up job. Party history, queue entries, reactions and account records persist until something or someone removes them.
What you can remove today:
- A room — a host can delete a party outright, which removes the room and everything attached to it: membership, queue, votes, reactions, vibe checks and photos.
- A photo — you can delete a photo you took, and the host can remove any photo in their room.
- Your account — email privacy@partando.com and we will erase it and the personal data attached to it. We act on these within 30 days.
Session records and their IP addresses expire on their own schedule. Operational logs are retained by our monitoring provider on a rolling basis.
7. Your rights
Under the GDPR you have the right to:
- ask what personal data we hold about you, and get a copy;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to how we use it, including anything we do on the basis of legitimate interests;
- receive your data in a portable, machine-readable form;
- withdraw consent at any time, without affecting what we did before you withdrew it.
Email privacy@partando.com to exercise any of these. We will respond within one month. There is no charge.
If you think we have handled your data badly, you can complain to the Norwegian Data Protection Authority (Datatilsynet), or to the supervisory authority where you live. We would rather you told us first so we can fix it.
8. Guests and temporary profiles
You can join a party with just a room code — no account, no Spotify, no email. We still create a profile for you behind the scenes so your name, emoji and the songs you add can be attributed in the room, and so your history carries across parties with the same host.
That profile is real personal data and everything in this policy applies to it. If you later claim the account, the guest profile is merged into it. If you never claim it, it stays until you ask us to delete it.
9. Party photos
If a host enables photos, guests can take pictures that appear in the room and on the party's TV view. We store the image, who took it, which room it belongs to, and which song was playing at the time.
- Hosts can turn photos off entirely, require approval before a photo reaches the TV, and stop photos from carrying into the recap.
- You can delete your own photo at any time; the host can delete any photo in their room.
- Images are stored at public but unguessable URLs. Anyone given the link can open it, so a deleted photo may persist in someone's cache or camera roll — we can only control our own copy.
Photograph other people at a party only if they are happy to be photographed.
10. Children
Partando is not intended for children under 13, and we do not knowingly collect their data. Hosting also requires a Spotify account, which carries Spotify's own age requirements. If you believe a child has given us personal data, contact us and we will delete it.
11. International transfers
Our providers operate globally, so your data may be processed outside the EU/EEA. Where that happens, transfers are covered by the European Commission's Standard Contractual Clauses or another safeguard permitted under Chapter V of the GDPR. Ask us if you want the detail for a specific provider.
12. Changes
If we change this policy we will update the date at the top, and for anything significant we will tell you in the app or by email before it takes effect.