
Privacy Policy
Last updated: September 24, 2026
1. Who We Are
MUSIC INXITE PTE. LTD. ("Music Inxite," "we," "us," or "our") is a company registered in Singapore (UEN 201622344M), with its registered office at 180B Joo Chiat Place, Singapore 427894. We provide music curation and a business-to-business music platform for commercial venues.
The platform is used by curators, who choose and schedule music for venues, and by customers, the businesses that run venues such as hotels, restaurants, and stores. Music plays on players: devices we supply, or customers' own iPads, iPhones, and Macs running our app.
This policy covers the platform: our web app at app.musicinxite.com, our apps, our API, share links, and the players. It explains what personal data we collect, why, who can see or receive it, where it is stored, and how long we keep it.
Data Protection Officer. You can reach our Data Protection Officer at admin@musicinxite.com. Contact that address with any question about this policy or your personal data.
2. What Data We Collect
We collect what we need to run, support, and secure the platform. Here is what that includes, by category.
Account information
When an account is created for you, we store your email address, name, and a hashed password (we never store the password itself). We also record your role on the platform (curator, customer, or administrator), your role in your organization, which organization you belong to, which zones you may use, whether your email address is verified, and when you last signed in. We store your language and email-digest preferences.
Organization and venue information
For each organization, we store its name, type, status, contact email address, service settings, and, if the account is suspended, the reason. For each venue, we store its name, street address, country, timezone, business hours, venue type, and the music brief its curator works from (for example, the target audience and the atmosphere wanted).
Curators can create a profile with a bio, specialties, service areas, website and portfolio links, years of experience, and a photo. A profile is visible to the curator's own organization and, if the curator marks it public, to curators it already works with. There is no public directory of curators.
Music profiles
A curator can invite people at a venue, such as a manager, to answer a music-profile questionnaire. For each invitee we store their name, email address, job title, whether they make music decisions for the venue, and their answers. We send the invitation email, with the curator's email address as the reply-to address. When someone opens a questionnaire link, we record a one-way hash of their IP address (a scrambled code made from it; we do not store the address itself), a one-way hash of their browser type, and a country code where one is available.
Players
Every player. When a player is paired to a zone, we collect:
- A device fingerprint: a one-way SHA-256 hash of an identifier from the device. On an iPad or iPhone this is the identifier the device gives our app. On a Mac it is the Mac's hardware ID, which stays the same if the app is reinstalled. On a player we supply it is derived from the system's unique machine ID.
- The device name, model, and operating system version. A device name is whatever the device's owner has named it, so it often contains a personal name, for example "Sam's iPad."
- The app or player software version.
- The device's local (LAN) IP address and its public IP address.
- A country code looked up from the public IP address in a database held on our own servers, for licensing and geo-compliance checks. We do not send IP addresses to an outside service for this, and we do not collect GPS location.
- The audio outputs connected to the player.
- Connection type (Wi-Fi or wired) and timezone.
- About every 30 seconds while the player is online, a status report: what is playing, volume, sync status, and device health (CPU, memory, disk, and battery where applicable).
Your own iPad, iPhone, or Mac. We also store the device's battery and storage levels and a push notification token (see section 4, Apple).
Player devices we supply. These run our software on Ubuntu Linux, and we look after them remotely, as our Terms of Service describe. For these players we also collect:
- The Wi-Fi network name, signal strength, and connection speed, and the Wi-Fi chip's model ID.
- The device's hostname and its address on our secure management connection (a VPN), which we keep open so that we can maintain the player.
- The serial numbers of USB audio devices connected to it.
- The speakers the player finds on your local network, such as Sonos speakers, with their IDs and local IP addresses, so that it can play through them.
- System logs. We can read the player's system logs remotely, and to investigate a fault we collect diagnostic bundles containing its system and kernel logs and lists of its audio and USB devices.
- A unique key that identifies the player on our management connection.
Customer listening devices
Customers can register their own phones and Macs to listen through the service. For each one we store a device fingerprint, the device name (which often contains a personal name), model, platform, operating system version, approval status, and when it was last seen.
Curator-uploaded content
Curators upload audio files to the platform. Each file is encrypted on the curator's own device before it is uploaded, so what we receive and store is encrypted audio, not playable audio.
Alongside the audio we store the information needed to catalog it:
- Track title, artist, and album.
- The original filename of the uploaded file, so curators can recognize their own material and so we can warn them about accidental duplicate uploads.
- Technical audio measurements: duration, loudness (LUFS), true peak, loudness range, and, where analysis succeeds, tempo (BPM).
- A content hash of the file, used only to detect exact duplicates.
Uploaded audio is delivered only where the curator directs: to the zones and customer apps the curator authorizes, and to share links the curator creates. It is also relayed live, without being recorded, during Listen Live sessions (below). We do not sell it, license it to anyone except as the curator directs, or use it to train any AI or machine-learning model.
Playback history
Each time a track plays, we record which track and playlist played, in which zone and organization, when, for how long, and the event type (scheduled play, manual play, skip, crossfade, and so on). We also record the public IP address the play was reported from, which is the venue's address for a player or the listener's address for a web browser, and a country code looked up from it. This data powers the dashboards that curators and customers see, and our reports to music-rights organizations.
Live zone audio monitoring (Listen Live)
A zone's curator can open a short, time-limited "Listen Live" session to hear what that zone is playing right now, for example to confirm that a schedule change took effect, or to diagnose a report that the music sounds wrong.
What is streamed is the app's own audio output: the decoded music the zone is already playing, captured from inside the player itself. It is not a microphone feed. It does not pick up room noise, conversation, or any other ambient sound in the venue.
The audio is relayed live through a server we run ourselves, and it is not recorded. We do not store it, and no copy of it remains once the session ends. A Listen Live session can only be opened by the curator organization responsible for that zone, or by a Music Inxite administrator. Listen Live can be turned off for an individual zone; contact us to do so.
We keep a record that a session happened: which curator opened it, for which zone, when it started and ended, and the IP address and browser type it was opened from. Opening and closing a session is also written to our audit log.
Feedback, comments, and requests
Signed-in users can rate tracks and playlists and add comments and messages. We store each of these with the user who left it, the zone and playlist it concerns, and any comment text, together with any note the curator adds. We work out a simple positive-or-negative score from the words in a comment, on our own servers. A rating given on a venue kiosk by someone who is not signed in is not linked to any person.
Share links
A curator can create a share link so that a current or prospective client can preview music in a web browser without an account. When someone opens a share link, we record page loads, plays, and completed plays, with the track played, a one-way hash of the listener's IP address combined with the link, a one-way hash of their browser type, and a country code where one is available.
API keys and connected tools
Curators can create API keys to connect software, including AI assistants they choose, to the service. We store a hash of each key (not the key itself), its name, what it is allowed to do, and when it was last used, and we log every request made with a key: which part of the service it called, the type of request, the result, the request details with sensitive values removed, and the software used. Requests made with an agent token (a credential for automated tools) are logged with the IP address they came from.
Depending on what the curator allows a key to do, a connected tool can read a customer's venue, zone, schedule, and playback information, and feedback, including the name and email address of the person who left it. Keys cannot reach organization or user-management functions. The tool, and any AI provider behind it, is chosen and run by the curator, not by us. The platform itself does not send your data to any AI service.
Emails we send
We send service emails: email verification and password resets, invitations (including music-profile questionnaires and reminders), security notices about your keys, alerts, and the digests you choose to receive. These contain names, email addresses, and venue and zone names. The platform does not send marketing email.
Error reports
When our software hits an error or crashes, it sends an error report so that we can fix it. What a report contains depends on where it comes from:
- The iOS and macOS apps (release versions) report to Sentry: device model, operating system version, app version, the error and where in the code it happened, and the zone's ID and name. From a Mac, reports also carry the device fingerprint, and when a curator is signed in to the Mac app, the curator's email address and organization name. The apps also report app sessions so that we can measure crash rates, and send performance timings for a small sample of sessions. When a request to our servers fails with a server error, the report includes the address that was requested. Sentry may also record the IP address a report was sent from. The apps do not send screenshots.
- Our servers, the web app, the players we supply, and test versions of the apps report to an error tracker we run ourselves (GlitchTip). Server reports can include the signed-in user's ID and email address, their IP address and browser type, and the page or API address requested. Web-app reports can include the user's ID, email address, role, and organization ID. Reports from players we supply include the zone ID, hostname, and software version, with the error text redacted.
Error reports do not contain audio.
Audit and request logs
We keep audit logs of significant actions on the platform, such as playback overrides, schedule changes, player updates, and key management operations. They record the action; the name, email address, and role at the time of whoever took it; the affected zone or organization, the IP address, and the browser or app used.
Our servers also log every request they receive, including the IP address, browser type, the address and query requested, and the signed-in user and organization.
Microphone, camera, and location
The iOS and macOS apps declare a microphone permission because the audio software we use for Listen Live is designed around a microphone. We set that software up so that it never turns on the microphone: Listen Live sends only the music the app is playing, and we do not record sound in the venue.
Camera access is used for one thing: scanning a pairing QR code on an iPad or iPhone. The app shows the camera view on screen and reads only QR codes from it. It never takes or saves a photo or video, and no image is sent to us. You can also pair by typing the code, so camera access is optional. The Mac app does not use the camera.
The apps do not use the device's location services.
What we do not collect
We do not collect precise location (GPS coordinates), contact lists, photos, or calendar data. We do not collect payment card numbers: billing is handled by invoice, outside the platform. We do not use advertising identifiers, and our apps include no advertising or analytics software from other companies. The one exception is Sentry's error reporting, described above; our playback analytics are our own.
3. Why We Collect It
We use the data listed above for the following purposes:
- Account management: to authenticate users, manage permissions, and give access to the right playlists and zones.
- Delivering and protecting music: device fingerprints and encryption keys limit decryption of protected audio to paired players, authorized apps and browsers, and the curator's own tools (section 6 explains the limits).
- Running and supporting players: status, network, and diagnostic data, the management connection, and system logs let us and your curator install, update, monitor, diagnose, and repair players, and let a player play through speakers on your network.
- Playback analytics: play history and status reports let curators and customers see what is playing, identify popular tracks, and monitor zone health.
- Live zone monitoring: Listen Live lets a zone's curator hear the music that zone is playing, so they can verify a schedule or diagnose an audio fault without traveling to the venue. The session records described above exist so that this access is accountable and reviewable.
- Content ingestion: audio a curator uploads, with its title, artist, and technical measurements, is used to build the playlists delivered to that curator's zones and to keep loudness consistent between tracks.
- Programming your venue: venue details, music profiles, and feedback help your curator choose and adjust your music.
- Reporting to music-rights organizations: as our licenses require, we report the music played to the organizations that license it, for example the venue and play reports we file with Music Rights (Singapore) Public Limited ("MRSS").
- Notifications and email: push notifications wake the Apple apps when a schedule changes and deliver device-approval alerts; emails handle verification, password resets, invitations, and alerts.
- Geo-compliance: country codes looked up from IP addresses help us flag zones operating in unexpected countries.
- Security and abuse prevention: IP addresses, browser types, audit logs, and request logs let us investigate unauthorized access, detect account compromise, and meet legal obligations.
- Fixing errors: error reports let us diagnose and fix software faults without waiting for someone to report them.
- Legal obligations: keeping records the law requires, such as tax records, and responding to lawful requests.
We do not use your data for advertising or profiling, and we do not sell or rent it.
4. Who Can See or Receive Your Data
Within the platform
- Your organization's users see what their role allows.
- Your curator. If you are a customer, your curator (us, or an independent curator working on the service) can:
- list, add, and remove your organization's users, set a user's password, change a user's email address, and choose which zones each user can use;
- see your zones' player and network details, including the Wi-Fi network name, hostname, and local IP address;
- see and export your play history;
- see feedback with the name and email address of the person who left it, and the names on comments;
- see the names and email addresses of music-profile invitees;
- see its own organization's audit log, including the email address of the person who took each action;
- listen to your zones with Listen Live; and
- see the device name, and the name and email address of the user, on each request to approve a customer listening device.
A curator may invite other curators to help serve you, with the access the curator chooses.
- Tools your curator connects with an API key see what that key allows (section 2, API keys and connected tools).
- Music Inxite administrators can access the data above to operate, support, and secure the service.
Service providers
These providers receive or store personal data so that we can run the service. We give each provider personal data only so that it can provide its service to us. Each handles it under its own standard terms.
| Provider | What it does for us | What it receives | Location |
|---|---|---|---|
| DigitalOcean | Hosts our servers, database, backups, object storage, and the management connection to players we supply; its content delivery network delivers audio files | All platform data. Audio files are encrypted | Singapore. One management-connection server, used by some players we supply, is in Frankfurt, Germany. Encrypted audio files may be cached at delivery locations worldwide |
| Zoho | Sends our service emails and hosts our email inboxes | Recipients' names and email addresses and the content of each email we send, and every email you send us | United States |
| Sentry | Error reports from the release iOS and macOS apps | As described in section 2, Error reports | United States |
| Apple | Delivers push notifications to the iOS and macOS apps | Each device's push token; the zone ID; for device-approval alerts, the device name and platform | Apple's servers |
| Cloudflare | Runs our domain name system, and carries error reports to our own error tracker | Error reports in transit (section 2). If a curator runs a Cloud Daemon (our software that a curator can run on its own server), we publish that server's hostname and IP address as a public DNS record through Cloudflare | Global network |
| GitHub | Hosts our code; receives automatic internal fault reports | Technical details such as zone and organization IDs | United States |
We also run some software ourselves. HashiCorp Vault, for encryption-key management, and LiveKit, to relay Listen Live audio (audio passes through and is not recorded), run on our DigitalOcean servers in Singapore. GlitchTip, which collects error reports, and the Cloud Daemon that holds the key for the music we curate ourselves, run on our own hardware in Singapore.
Music-rights organizations
Where our license requires it, we report the music played to the organization that licensed it. In Singapore, we report to MRSS: your business's name and brand, the venue's name, address, and country, the zone's name, and each track's details, with how often and how long it was played. We prepare and file these reports ourselves. They describe venues, not individuals.
Destinations you choose
If you or your curator set up alerts to Slack or a webhook, we send alert details there. A curator's own Cloud Daemon server holds that curator's key and handles its audio (section 6), and any AI tool a curator connects receives what its API key allows (section 2). The curator chooses where both run.
Our staff, contractors, and advisers
Our staff and contractors who need personal data to run and support the service, and our professional advisers such as lawyers and accountants, can see it, and are bound to keep it confidential.
A successor business
If our business is transferred to a successor, personal data may pass to that successor with it, and we will tell you.
Legal requests
We may disclose data when the law requires it or in response to a valid legal process, such as a court order or a regulator's request. Where the law allows, we will tell the affected customer.
5. Data Retention
| Data | How long we keep it |
|---|---|
| Account details (name, email address, role) | While the account exists. Removing a user deactivates the account and keeps the name and email address; ask us to erase them (section 7). |
| Organization, venue, and curator-profile details | While the organization exists. Ending or suspending the service does not delete it automatically; we delete it when you ask, once its zones have been removed. Deleting a customer organization also deletes its venues, user accounts, notifications, and feedback. A curator organization can be deleted only after its users and playlists have been removed. |
| Uploaded audio and track details | No automatic deletion. Kept until the curator deletes a track, or asks us to. Deleting a track also deletes its encrypted file from our storage and its play history. Uploads that fail are deleted automatically after a day. |
| Playlists and schedules | No automatic deletion. Kept until the curator deletes them, or asks us to. A zone's schedules are deleted with the zone. |
| Play history, including the IP address and country recorded with each play | 400 days by default. An organization may have a different period, never less than 180 days. Deleted earlier if its zone or track is deleted. |
| Reports to music-rights organizations | No fixed end date: they are records of our license reporting. |
| Player status reports | 30 days |
| Player network health | 7 days |
| Player health snapshots and playback-quality records | 90 days |
| Player error records | 180 days |
| Player diagnostic log bundles, command history, and network tests | No automatic deletion. Deleted with their zone. |
| A player's latest network details (Wi-Fi network name, public IP address) | While the zone exists. Unpairing does not clear them. |
| A paired device's fingerprint, name, model, push token, and management address | Cleared when the device is unpaired. |
| Customer listening devices | Deleted in a monthly cleanup once a device has been revoked for 7 days, has waited 7 days without approval, or has gone 90 days without use. |
| Listen Live session records | No automatic deletion. The IP address and browser type are removed after 30 days. |
| Action audit logs | 180 days. The IP address and browser type are removed after 30 days. |
| Key-management audit logs | 90 days in our database, then moved to a private archive in our object storage, where they are kept with no automatic deletion. They are not deleted when a zone or organization is deleted, or when you ask us to erase your data (section 7). The IP address and browser type are removed after 30 days, before a record is archived. |
| Player update records, which include the email address of whoever started an update | 730 days |
| Other change records (speaker groups, audio settings, update rollouts, maintenance-access grants), which include the email address of whoever made the change | No automatic deletion. |
| Automated-agent activity logs, which include IP addresses | 180 days |
| API key usage logs | No automatic deletion. |
| Notifications, alert-delivery records, and integration events | 90 days |
| Feedback, comments, and requests | No automatic deletion. Feedback is deleted with its organization. |
| Music-profile invitees and answers | No automatic deletion. |
| Share-link listen records | No automatic deletion. |
| Detailed playback event logs, only if your organization turns them on: each play, skip, or stop, with its reason, and the IP address it came from | No automatic deletion. IP addresses are removed after 30 days. |
| Records that keep you signed in | No automatic deletion. |
| Error reports in our own error tracker | 90 days |
| Error reports in Sentry | Up to 90 days, as Sentry keeps them |
| Server request logs | Web server access logs: about 15 days. Application logs are overwritten by newer logs once they reach a size limit, so how long they last depends on activity, not on a fixed number of days. |
| Database backups | Daily backups for 7 days and weekly backups for 4 weeks, on our server in Singapore. Data deleted from the platform stays in backups until they expire. |
Where the table says "no automatic deletion," we have no scheduled job that deletes the data. It is deleted when the zone or organization it belongs to is deleted, or when you ask us to delete it, except records we must keep for music-rights reporting, tax, or other legal purposes. Deactivating a user does not delete these records; ask us to erase them (section 7).
6. How We Protect Your Data
- Audio is stored and delivered encrypted. The servers that run the platform and store the audio do not hold any track's decryption key in readable form. A paired player or an authorized browser unlocks each track for playback.
- Players decrypt only the tracks they are about to play, keeping the decrypted audio in memory or in a memory-backed temporary area, which a device that uses swap space may write to its disk. Web browsers decrypt in memory.
- Decoded audio can still be reached in some ways, and we state them plainly. Listen Live relays decoded audio through our server while a session is open, without recording it. A player we supply sends decoded audio to network speakers on your local network, such as Sonos, without encryption. Our curator app briefly writes a decrypted copy of a track to the curator's device's temporary storage to read its tempo and tags, and deletes it immediately. Each curator's tracks can be unlocked with that curator's own key; for the music we curate ourselves, that key is held by a Cloud Daemon on our own hardware. A curator's Cloud Daemon server can decrypt tracks to prepare them for web playback, and we can connect to that server with administrator rights to install and maintain the daemon. Anyone with administrator access to a player, including our staff who maintain the players we supply, can reach the audio that player has decrypted and its key files.
- Passwords are stored only as hashes. Encryption keys are managed in a key vault we run ourselves, and a copy of our database alone does not expose them.
- Breaches. If we become aware of a breach affecting personal data in your account, we will tell you without undue delay, and we will notify Singapore's Personal Data Protection Commission where the law requires.
7. Your Rights
Singapore (PDPA)
Singapore's Personal Data Protection Act 2012 applies to us. Under it, you may:
- ask for access to the personal data we hold about you, and how we have used or disclosed it in the past year;
- ask us to correct personal data that is wrong or incomplete; and
- withdraw your consent to our collecting, using, or disclosing your personal data. We will tell you what withdrawing means for you. Because most of this data is needed to run the service, withdrawing may mean we can no longer provide it to you.
If you are not satisfied with our response, you can contact Singapore's Personal Data Protection Commission.
Copies and deletion
You can change your name, password, and language yourself in the web app's settings. For anything else, email us.
You can ask for a copy of your account data and play history, in a common format such as CSV, while we still hold it.
You can ask us to erase your personal data. We do this by anonymizing it. We replace your name and email address with placeholders in your account, our main audit log, player-update records, and music profiles. We remove the text of comments you left with ratings; the ratings stay, no longer linked to you. We also remove the IP addresses and browser types stored with your audit-log entries and Listen Live sessions. IP addresses held in play history, server logs, and error reports are deleted on the schedule in section 5. Some other records of changes you made keep your email address. We keep records we must keep for music-rights reporting, tax, or other legal purposes. Erased data stays in backups until they expire (section 5).
How to make a request
Email our Data Protection Officer at admin@musicinxite.com. We may need to confirm your identity first.
Because Music Inxite is a business-to-business platform, most users use it as staff of a subscribing organization. That organization, as the account holder, may also decide how your data in its account is used, and we may ask it to confirm a request. If your organization or curator gave us your details, for example to invite you to a music profile, it is responsible for telling you and for obtaining any consent the law requires.
GDPR (European Economic Area and UK)
If you are in the EEA or the UK, you also have the right to data portability (receiving your data in a structured, machine-readable format), the right to restrict processing, and the right to object to processing based on legitimate interests. You can complain to your national data protection authority.
Our lawful bases for processing are:
- Contract: processing needed to deliver the service you or your organization subscribed to.
- Legitimate interests: security, fraud prevention, service reliability, and the reporting our music licenses require, where our interests do not override your rights.
- Legal obligation: where the law requires us to keep records.
If a data-protection law that applies to your organization requires terms between us for personal data we process for you, or for its transfer, ask us and we will agree them with you.
California
If you are a California resident, you have the right to know what personal information we collect about you, the right to delete it, and the right to opt out of its sale. We do not sell personal information. To exercise your rights, contact admin@musicinxite.com.
8. Cookies and Browser Storage
Everything the web app stores in your browser is our own. We do not use advertising cookies, cross-site tracking, or analytics services, and our fonts are served from our own servers.
| Name or kind | What it does | How long it lasts |
|---|---|---|
| Sign-in session cookie | Keeps you signed in | Stays in your browser for up to 30 days. Unless you choose "remember me", it stops signing you in after 24 hours |
locale cookie | Remembers your language | 1 year |
audio_session and csrf_token cookies | Protect audio playback and form submissions | 2 hours |
| Local storage | Your display preferences, recent searches, whether you have seen update notices, and a random ID for this browser | Until you clear it |
IndexedDB (mi-mpd-keys) | Your browser's playback key pair, protected by your password; a copy tied to this browser that lets it play without your password for up to 30 days after you last use it; and this browser's random ID | Until you clear it. The browser-tied copy expires after 30 days unused |
| Session storage | Technical IDs for the current tab | Until you close the tab |
These are needed for the service to work, so they cannot be turned off while you use the web app.
9. Where Your Data Is Stored
Our platform, database, key vault, Listen Live relay, player management connection (VPN), backups, and object storage are hosted by DigitalOcean in Singapore. Some data leaves Singapore:
- Encrypted audio files may be cached at DigitalOcean delivery locations outside Singapore.
- Some players we supply use a management-connection server hosted by DigitalOcean in Frankfurt, Germany.
- Error reports from the release iOS and macOS apps go to Sentry in the United States.
- Error reports from everything else go to our own error tracker on our own hardware in Singapore, carried over Cloudflare's global network. The Cloud Daemon that holds the key for the music we curate ourselves runs on the same hardware.
- Our service emails and email inboxes are hosted by Zoho in the United States.
- Push notifications go through Apple's push notification service.
- Automatic internal fault reports, which carry technical IDs, go to GitHub in the United States.
- Tools and servers that a curator chooses, such as an AI assistant or the curator's own Cloud Daemon server, may be anywhere.
Section 7 explains how to ask for terms covering these transfers.
10. Children's Data
Music Inxite is a platform for businesses and their staff. It is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe we have collected such data, contact us at admin@musicinxite.com and we will promptly erase it, as described in section 7.
11. Changes to This Policy
We may update this policy to reflect changes to the platform or the law. When we make a material change, we will email the primary contact of each account and update the "Last updated" date.
This policy describes how we handle personal data. It is not part of our Terms of Service, but section 9 of those terms refers to the retention periods in section 5 of this policy. Changes to the Terms of Service follow section 11 of those terms.
12. Contact
For privacy questions, access, correction, copy, or erasure requests, or to withdraw consent:
Data Protection Officer: admin@musicinxite.com
Post: MUSIC INXITE PTE. LTD., 180B Joo Chiat Place, Singapore 427894
We aim to respond to all requests within 30 days.