tmo — Privacy Policy
tmo ("tmo", "we", "us") is a gig-discovery service for Melbourne's inner north. It is operated as a personal project by Nick Woods, based in Victoria, Australia. This policy explains what personal information the tmo website, email digest, and mobile apps (Android and iOS) collect, how it is used, and the choices you have. It is written to meet the requirements of the Australian Privacy Act 1988 (including the Australian Privacy Principles) and the EU/UK General Data Protection Regulation (GDPR) for any international subscribers.
If you have any questions, or want to access or delete your data, contact us at n.m.woods1@gmail.com.
1. What we collect
| Data | When & why | Where it's stored |
|---|---|---|
| Email address | When you subscribe or create an account, so we can send the weekly digest and identify your account. | Turso database; email-list copy in Brevo. |
| Display name | Supplied by you or by your Spotify, Google, or Apple profile when you sign in, used to personalise the app. | Turso database. |
| Sign-in identifiers | If you sign in with Spotify, Google, or Apple, we store the provider's account identifier to recognise you on return visits. We do not receive or store your provider password. | Turso database. |
| Password (if you choose email sign-up) | Stored only as a salted, one-way PBKDF2-HMAC-SHA256 hash. We never store or can recover the plaintext password. | Turso database. |
| Shortlist | The gigs you save, so your shortlist syncs across devices and can be shared via a link you generate. | Turso database; also cached on your device. |
| Approximate / precise location | Only if you grant the location permission, and only to sort or filter gigs by distance from you. Your location is used on-device and is not stored on our servers or shared. | On your device only. |
| Session token | A random token issued after sign-in to keep you logged in (up to 90 days). Stored on your device and as a session record on our side. | Device storage; Turso database. |
| Usage analytics | Aggregate, product-improvement analytics about how pages and features are used. | PostHog and Microsoft Clarity (see §3). |
| Ticket-link clicks | When you tap through to a ticketing site, we record which gig and
venue, the time, which of our apps you came from, and a random
device identifier — so we can tell venues how much interest we
send them. If you are signed in, these clicks are linked
to your account. We do not know whether you completed a
purchase; the ticketing site does not tell us. We add a
utm_source=deepnorth tag to the link so the venue can
see the referral in their own ticketing dashboard. |
Turso database. |
2. How we use it
- To send you the weekly gig digest and run your account.
- To show, sort, and filter gigs — including by distance if you opt in to location.
- To sync and share your shortlist across your devices.
- To keep you signed in securely.
- To understand, in aggregate, which features are used so we can improve the product.
We do not sell your personal information, and we do not use it for third-party advertising or cross-app tracking.
3. Third-party services
We rely on a small number of processors to run the service:
- Brevo — email delivery and the subscriber list.
- Turso (libSQL) — the database holding accounts and shortlists.
- Cloudflare — hosting and the application/API backend (Workers).
- GitHub Pages — hosting the public web gig guide and this page.
- Spotify, Google, and Apple — optional sign-in providers. We request only the scopes needed to identify you and (for Spotify, if you connect it) read your profile and your followed/top artists. Sign in with Apple supports Apple's private-relay email.
- PostHog and Microsoft Clarity — privacy-conscious product analytics on the web experience.
- Firebase Cloud Messaging (mobile apps) — to deliver the optional weekly push notification.
Each processor handles data under its own terms and may store it outside Australia (for example, in the United States or the EU). We share only what each service needs to perform its function.
4. Device permissions (mobile apps)
- Location — optional; used to sort/filter gigs by distance. Denying it leaves all other features working.
- Notifications — optional; used for the weekly digest reminder.
- Network — required to load gig data.
You can change or revoke these permissions any time in your device settings.
5. Data retention
We keep account data while your account is active. Sign-in sessions expire after at most 90 days. Email/magic-link verification tokens expire within 24 hours. If you ask us to delete your account, we remove your account record, identities, shortlist, sessions, and the link between your account and your ticket-link clicks, and unsubscribe your email from the list. Ticket-link click records are kept for at most 24 months and are deleted or anonymised after that. Aggregate analytics that cannot be tied back to you may be retained.
6. Your rights
You can request access to, correction of, or deletion of your personal information, and you can unsubscribe from emails at any time using the link in any digest or by emailing us. Where the GDPR applies, you also have rights to data portability and to object to or restrict certain processing, and you may lodge a complaint with your local supervisory authority. In Australia you may complain to the Office of the Australian Information Commissioner (OAIC).
To exercise any of these rights, email n.m.woods1@gmail.com. We aim to respond within 30 days. To delete your account specifically, see Delete Your Account for the in-app self-service option and the email fallback.
7. Children
tmo is intended for adults attending live music. It is not directed at children under 13 (or under 16 where local law sets a higher age), and we do not knowingly collect their data.
8. Security
All traffic uses HTTPS. Passwords are stored only as salted one-way hashes. Access to the production database and backend is restricted. No method of transmission or storage is perfectly secure, but we take reasonable steps to protect your information.
9. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, announced in the digest.
10. Trademarks
Venue, artist, and platform names and logos shown in tmo are the property of their respective owners and are used only to identify the gigs and venues they refer to. tmo is an independent project and is not affiliated with, endorsed by, or sponsored by any venue, artist, or ticketing platform featured in the app.
11. Contact
tmo — Nick Woods, Victoria, Australia.
n.m.woods1@gmail.com