Privacy Policy – YourSongBox
Last Updated: 14 December 2025
CVPK Digital Studio LLC ("Company", "we", "our", or "us") operates www.yoursongbox.com and provides the YourSongBox platform ("Service").
This Privacy Policy explains how we collect, use, store, and protect personal data when you use our Service.
If you do not agree with this Policy, please do not use our Service.
1. Information We Collect
We collect only the data necessary to operate and deliver your personalized song.
1.1 Contact Information
- Email address (to send your song and updates)
1.2 Song Personalization Data
- Names of sender and recipient (optional)
- Personal messages and stories you submit
- Occasion type and preferences
- AI-generated lyrics and audio files
1.3 Payment Information
- Payment details (processed securely by Stripe)
- We do not store full credit card numbers or financial data on our servers.
1.4 Technical Information
- IP address, browser type, device type, and usage timestamps
- Anonymous logs for debugging and performance improvement
1.5 Communications
- Emails or messages sent to us via support or feedback channels
2. How We Use Information
We use your data to:
- Generate and deliver your personalized song via email or download
- Improve our AI models and song generation quality
- Process payments and fulfill purchases
- Provide customer support and respond to inquiries
- Ensure compliance with applicable laws and our Terms of Service
We do not use your personal messages for marketing or resale.
3. Legal Basis for Processing (GDPR)
If you are located in the EU or EEA, we process your data under the following lawful bases:
- Contractual necessity – to deliver your personalized song.
- Legitimate interest – to improve the Service, ensure security, and prevent misuse.
- Consent – when you submit your information for song creation.
- Legal obligation – for accounting and regulatory compliance.
You may withdraw consent at any time by contacting legal@cvpkdigitalstudio.com.
4. Sharing of Information
We share data only with trusted third-party providers required to operate the Service:
| Purpose | Provider | Location | Notes |
|---|---|---|---|
| Hosting & Data Storage | Supabase / EU Server (Sweden) | EU | GDPR compliant storage and database |
| Payment Processing | Stripe Payments Europe, Ltd. | EU | PCI-DSS certified payment processor |
| AI Processing | OpenAI / Anthropic / Suno APIs | US | Processed under Standard Contractual Clauses |
| Email Delivery | Resend | US/EU | Transactional email delivery |
We do not sell or rent personal data to advertisers or third parties.
5. Data Retention
- Song personalization data and audio files are stored for up to 90 days after delivery for troubleshooting and quality assurance.
- Payment data is retained for up to 7 years for legal and accounting obligations.
- AI-generated content may be anonymized for service improvement.
You can request early deletion at any time by emailing legal@cvpkdigitalstudio.com.
6. Data Location and Transfers
All data is stored and primarily processed in Sweden (EU).
Some processing (AI model inference or email delivery) may occur in the United States.
For transfers outside the EU/EEA, we rely on EU Standard Contractual Clauses (SCCs) to ensure adequate protection.
7. Security
We implement appropriate technical and organizational measures to protect your data, including:
- Encrypted data transmission (HTTPS / TLS 1.3)
- Secure database access controls
- Periodic security audits
- Principle of least privilege for all internal access
No system is 100% secure, but we continuously review and update our protections.
8. Your Rights (GDPR / CCPA)
Depending on your jurisdiction, you have the right to:
- Access the personal data we hold about you
- Request correction or deletion of your data
- Withdraw consent for processing
- Object to certain processing (e.g., marketing)
- Request a copy of your data in portable format (data portability)
- File a complaint with your local supervisory authority
Requests can be sent to legal@cvpkdigitalstudio.com.
We will respond within 30 days.
9. Cookies and Tracking
YourSongBox uses minimal, privacy-friendly analytics and essential session cookies only.
We do not use advertising or tracking cookies.
10. Children's Privacy
YourSongBox is not directed at individuals under 18 years of age.
We do not knowingly collect data from minors.
11. Changes to this Policy
We may update this Privacy Policy periodically.
Material changes will be communicated via email or on our website, with an updated "Last Updated" date.
12. Contact Information
Data Controller:
CVPK Digital Studio LLC
3164 21st St #1098, Astoria, NY 11106, United States
Email: legal@cvpkdigitalstudio.com
Data Storage Location: Sweden (EU)
