tmo — Privacy Policy

Last updated: 29 June 2026

tmo ("tmo", "we", "us") is a gig-discovery service for Melbourne's inner north. It is operated as a personal project by Nick Woods, based in Victoria, Australia. This policy explains what personal information the tmo website, email digest, and mobile apps (Android and iOS) collect, how it is used, and the choices you have. It is written to meet the requirements of the Australian Privacy Act 1988 (including the Australian Privacy Principles) and the EU/UK General Data Protection Regulation (GDPR) for any international subscribers.

If you have any questions, or want to access or delete your data, contact us at n.m.woods1@gmail.com.

1. What we collect

DataWhen & whyWhere it's stored
Email address When you subscribe or create an account, so we can send the weekly digest and identify your account. Turso database; email-list copy in Brevo.
Display name Supplied by you or by your Spotify, Google, or Apple profile when you sign in, used to personalise the app. Turso database.
Sign-in identifiers If you sign in with Spotify, Google, or Apple, we store the provider's account identifier to recognise you on return visits. We do not receive or store your provider password. Turso database.
Password (if you choose email sign-up) Stored only as a salted, one-way PBKDF2-HMAC-SHA256 hash. We never store or can recover the plaintext password. Turso database.
Shortlist The gigs you save, so your shortlist syncs across devices and can be shared via a link you generate. Turso database; also cached on your device.
Approximate / precise location Only if you grant the location permission, and only to sort or filter gigs by distance from you. Your location is used on-device and is not stored on our servers or shared. On your device only.
Session token A random token issued after sign-in to keep you logged in (up to 90 days). Stored on your device and as a session record on our side. Device storage; Turso database.
Usage analytics Aggregate, product-improvement analytics about how pages and features are used. PostHog and Microsoft Clarity (see §3).
Ticket-link clicks When you tap through to a ticketing site, we record which gig and venue, the time, which of our apps you came from, and a random device identifier — so we can tell venues how much interest we send them. If you are signed in, these clicks are linked to your account. We do not know whether you completed a purchase; the ticketing site does not tell us. We add a utm_source=deepnorth tag to the link so the venue can see the referral in their own ticketing dashboard. Turso database.

2. How we use it

We do not sell your personal information, and we do not use it for third-party advertising or cross-app tracking.

3. Third-party services

We rely on a small number of processors to run the service:

Each processor handles data under its own terms and may store it outside Australia (for example, in the United States or the EU). We share only what each service needs to perform its function.

4. Device permissions (mobile apps)

You can change or revoke these permissions any time in your device settings.

5. Data retention

We keep account data while your account is active. Sign-in sessions expire after at most 90 days. Email/magic-link verification tokens expire within 24 hours. If you ask us to delete your account, we remove your account record, identities, shortlist, sessions, and the link between your account and your ticket-link clicks, and unsubscribe your email from the list. Ticket-link click records are kept for at most 24 months and are deleted or anonymised after that. Aggregate analytics that cannot be tied back to you may be retained.

6. Your rights

You can request access to, correction of, or deletion of your personal information, and you can unsubscribe from emails at any time using the link in any digest or by emailing us. Where the GDPR applies, you also have rights to data portability and to object to or restrict certain processing, and you may lodge a complaint with your local supervisory authority. In Australia you may complain to the Office of the Australian Information Commissioner (OAIC).

To exercise any of these rights, email n.m.woods1@gmail.com. We aim to respond within 30 days. To delete your account specifically, see Delete Your Account for the in-app self-service option and the email fallback.

7. Children

tmo is intended for adults attending live music. It is not directed at children under 13 (or under 16 where local law sets a higher age), and we do not knowingly collect their data.

8. Security

All traffic uses HTTPS. Passwords are stored only as salted one-way hashes. Access to the production database and backend is restricted. No method of transmission or storage is perfectly secure, but we take reasonable steps to protect your information.

9. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, announced in the digest.

10. Trademarks

Venue, artist, and platform names and logos shown in tmo are the property of their respective owners and are used only to identify the gigs and venues they refer to. tmo is an independent project and is not affiliated with, endorsed by, or sponsored by any venue, artist, or ticketing platform featured in the app.

11. Contact

tmo — Nick Woods, Victoria, Australia.
n.m.woods1@gmail.com

← Back to tmo