Privacy Policy

This Privacy Policy explains how Rezone Group Sp. z o.o. ("we", "us", or "our"), as the controller of personal data, processes personal data when you use Crosspad.

Crosspad consists of the website, native mobile applications for Android and iOS, and connected services (together, the "Service").

πŸ“– View all legal documents

1. Personal Data We Process

1.1 Account and Authentication Data

When you register or use an account, we process:

  • Username and account identifier
  • Email address
  • Password hash; we do not store your password in plain text
  • Account status, creation date, settings, rights, and security information
  • Authentication tokens, verification codes, and information about enabled two-factor authentication

If you choose Google sign-in, Google provides us with information you authorize it to share, such as your Google account identifier, name, email address, and profile picture. The source of this data is Google and your Google account.

1.2 User Content and Profile Data

We process content and metadata that you upload, create, or publish, including:

  • Audio samples and sound files
  • Kit configurations, names, descriptions, categories, and publication status
  • Profile avatar and social-profile information you choose to provide
  • Ownership and activity records needed to manage kits, samples, and groups

Published content, your public username, and your avatar may be visible to other users and visitors according to the Service's visibility settings.

1.3 Website Usage and Analytics Data

With analytics consent, we use Google Analytics 4 to process information such as:

  • Pages viewed, navigation paths, and interactions
  • Approximate session duration and frequency
  • Browser, device category, screen resolution, and referring URL
  • Approximate country or region derived by Google from network information

We do not send your Crosspad account identifier, email address, or username to Google Analytics.

The website uses Google Consent Mode in its basic implementation. Before analytics consent, the Google Analytics tag is blocked: no Analytics cookies are read or written and no Analytics measurement request is sent to Google. If you consent, the tag loads with analytics storage enabled. Advertising storage, advertising user data, and advertising personalization remain controlled separately and are not used for Crosspad Analytics measurement.

With analytics consent, opening or playing a kit may also increment a first-party aggregate popularity counter. We store the counter by kit and source, not by account or device.

1.4 Technical, Security, and Network Data

When any device connects to the Service, our infrastructure provider, Cloudflare, processes technical data needed to deliver and secure the request, including:

  • IP address and connection timestamps
  • Request URL, method, headers, and response information
  • Browser or application user agent
  • Security signals used for rate limiting, bot detection, abuse prevention, and incident investigation

This processing applies to website and mobile requests, including sign-in, account actions, downloads, uploads, and kit-counter requests. Security information is kept separate from aggregate kit counters to the extent reasonably possible.

1.5 Mobile Application Data and Permissions

The mobile applications do not contain third-party advertising, crash-reporting, or general-purpose analytics SDKs. They store the following information locally on your device:

  • Authentication token used to keep you signed in
  • App settings and preferences, such as language, interface, and sound choices
  • Privacy and analytics choices
  • Downloaded kits and audio samples for offline playback

The applications communicate with our servers when you request an online feature, for example when you sign in, browse or download online kits, or upload account information. Those requests involve the account, content, and technical data necessary for the requested feature.

Optional kit popularity counters. When "Analytics (Kit Popularity & Play Counts)" is enabled in the mobile privacy settings, opening or playing a kit sends an increment request with an X-Analytics-Consent signal. The application does not include an account, email, advertising ID, or persistent device identifier in the counter payload. The resulting count is stored only in aggregate for the kit. The network request is still processed with the technical data described in section 1.4. When the setting is disabled, the application does not send the counter increment.

The mobile applications may request these device permissions for the stated purposes:

  • Notifications β€” showing kit-download status and important service messages
  • Vibration β€” providing haptic feedback when pads are played
  • MIDI / USB device access β€” connecting external MIDI controllers or pad hardware
  • Bluetooth β€” discovering and connecting Bluetooth Low Energy MIDI controllers or musical hardware
  • Foreground Service Data Sync (Android) β€” continuing kit-audio and preset downloads for offline playback while the application is not in the foreground
  • Selected photo access β€” accessing only the image you choose when uploading an avatar

We do not request general access to your microphone, contacts, or location for these features. Permissions can be managed in your device settings, although disabling one may prevent the related feature from working.

1.6 Contact and Communication Data

When you contact us, make a complaint, report content, or request account deletion, we process the information you provide, which may include:

  • Email address and account identifier
  • Subject, message, report, and attachments or content identifiers
  • Deletion or verification code where required to confirm identity
  • Correspondence history and the status of the request

Contact-form messages are transmitted through MailerSend and delivered to our support mailbox. They are not stored in a separate Crosspad contact-message database.

3. Infrastructure, Recipients, and Retention

3.1 Infrastructure and Service Providers

We use selected providers that receive data only as needed for their role:

  • Cloudflare β€” Workers compute, D1 database, R2 object storage, KV storage, content delivery, network security, rate limiting, and aggregate infrastructure analytics
  • Google β€” optional Google sign-in, Google Analytics, and delivery of correspondence to our support mailbox; Google's role depends on the relevant service and contract
  • MailerSend β€” delivery of transactional messages and contact-form correspondence on our behalf
  • Professional advisers and authorities β€” only where reasonably necessary for legal claims, compliance, or a binding legal request

We do not sell personal data.

3.2 Data Retention

We retain your data for as long as your account is active and as needed to provide the Service. If you request account deletion:

Step 1: Anonymization (Automatic)

When you click Delete in your profile settings:

  • Your account enters a 24-day grace period with status "anonymization pending"
  • After 24 days, your account is automatically anonymized:
    • Username becomes "User"
    • Avatar is removed
    • Login credentials are deleted
    • Your public kits and sounds remain visible
  • You can undo anonymization within the 24-day grace period by using the method in the confirmation email or contacting support

Step 2: Complete Deletion (Requires Contact Form)

For full deletion that removes all kits, sounds, and account data:

  1. Click Delete in profile settings to receive a verification code by email
  2. Visit our Contact Form, select "Account Deletion Request," and provide the requested account email and code
  3. Confirm the deletion request in the form
  4. We process a verified request without undue delay and normally within 30 days

The contact workflow is a method of confirming identity and is not the only way to exercise the GDPR right to erasure. You may also contact us at k.nowak@rezone-group.com. We may ask only for additional information reasonably necessary to confirm identity. The right to erasure is subject to legal exceptions, including data needed for legal obligations or the establishment, exercise, or defense of claims.

Anonymized data is retained only if it has been irreversibly changed so that no person is identifiable by reasonably available means. Such data is no longer personal data under the GDPR.

3.3 Data Stored on Your Device

Mobile local data remains until you use Reset All Data, clear application data, or uninstall the application. Website cookies and browser storage remain for the periods described in the Cookie Policy or until you delete them. Clearing local data does not itself delete your Crosspad account or uploaded content.

3.4 Retention Schedule

Data CategoryRetention Period or Criterion
Unverified registration dataNormally deleted after 24 hours if the email address is not verified
Active account and User ContentFor the life of the account or until the data or content is deleted; active-system deletion normally completes within 30 days
Authentication and security dataFor the life of the account and then only as long as needed to secure the Service, investigate an incident, or meet a legal obligation
Contact, complaint, and report correspondenceUp to 12 months after the last communication, unless a longer period is necessary for an unresolved dispute, legal obligation, or legal claim
Google Analytics user-level and event-level dataFor the retention period configured for our standard GA4 property, not exceeding 14 months; aggregate reports may no longer identify an individual browser
Cookie and analytics choicesUp to 1 year or until you change or clear the choice; an outdated policy version is no longer treated as active consent
Aggregate kit countersFor as long as the relevant kit or popularity feature exists; the stored counters do not identify a user or device
Provider security logs and backupsLimited according to provider settings and our need to detect abuse, resolve incidents, ensure continuity, and meet legal obligations; access is restricted and retention is periodically reviewed

4. Analytics Details

4.1 Google Analytics on the Website

Google Analytics 4 is provided by Google. Before analytics consent, the Analytics tag is not loaded and no Analytics request is sent. If you consent, Analytics may set _ga and _ga_[CONTAINER_ID] cookies and process pseudonymous browser identifiers and usage events. This data is pseudonymous, not necessarily anonymous.

You can withhold or withdraw analytics consent through the cookie settings control. Withdrawal prevents future consent-based measurement and removes accessible Google Analytics cookies set for Crosspad; it does not affect processing that occurred lawfully before withdrawal.

4.2 Cloudflare Analytics and Security

Cloudflare provides aggregate information about traffic, performance, and security threats and processes request-level technical data to deliver and protect the Service. This processing does not depend on Google Analytics consent where it is strictly necessary for network delivery or security.

4.3 Mobile Kit Counters

The mobile applications do not use Google Analytics or advertising SDKs. They send only the optional first-party kit-counter signal described in section 1.5 when the mobile analytics setting is enabled.

5. Data Security

We use technical and organizational measures appropriate to the risk, including:

  • Password hashing and protected authentication tokens
  • HTTPS encryption in transit
  • Access controls for administrative and infrastructure systems
  • Rate limiting, bot management, and DDoS protection
  • Separation of aggregate kit counters from account records
  • Procedures for deletion, incident handling, and restoration

No system is completely secure. If a personal-data breach creates a risk requiring notice under applicable law, we will notify the competent authority and affected individuals as required.

6. International Data Transfers

Cloudflare, Google, and MailerSend operate internationally, and personal data may be processed outside the European Economic Area, including in the United States.

For transfers to a U.S. recipient with an active certification under the EU-U.S. Data Privacy Framework, we may rely on the European Commission's adequacy decision, Commission Implementing Decision (EU) 2023/1795. Certification can be checked in the U.S. Department of Commerce Data Privacy Framework participant list.

Where an adequacy decision does not apply, we use an applicable transfer mechanism such as the European Commission's Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, together with supplementary measures where required. You may contact us for information about the applicable safeguards and how to obtain a copy, subject to protection of confidential information.

7. Your Data-Protection Rights

Subject to the conditions and exceptions in applicable law, you may have the right to:

  • Access your personal data and receive information about its processing
  • Correct inaccurate or incomplete personal data
  • Request erasure of personal data
  • Restrict processing
  • Receive data you provided in a structured, commonly used, machine-readable format and transmit it to another controller where portability applies
  • Object, on grounds relating to your situation, to processing based on legitimate interests
  • Withdraw consent at any time through the relevant settings or by contacting us
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects
  • Lodge a complaint with a supervisory authority

We do not currently use solely automated decision-making that produces legal or similarly significant effects.

Requests are generally free of charge. We will provide information about action taken without undue delay and within one month. That period may be extended by up to two additional months where necessary because of complexity or the number of requests; if so, we will explain the extension within the first month.

To exercise a right, use the Contact Form or email k.nowak@rezone-group.com. We may need to verify your identity. If we do not act on a request, we will explain why and provide information about complaint and judicial remedies.

7.1 Supervisory Authority

You may complain to the authority for your habitual residence, place of work, or the place of an alleged infringement. In Poland, the competent authority is:

  • Authority: President of the Personal Data Protection Office (Prezes UrzΔ™du Ochrony Danych Osobowych, UODO)
  • Address: ul. StanisΕ‚awa Moniuszki 1A, 00-014 Warsaw, Poland
  • Website: https://uodo.gov.pl
  • Telephone: +48 22 531 03 00

8. Children's Privacy

The Service is not intended for users under 16, and users under 16 may not create an account. We do not knowingly collect personal data from such users. If we learn that a user under 16 provided personal data, we will take reasonable steps to delete it, unless retention is legally required. A parent or guardian may contact us about a child's data.

The age threshold in GDPR Article 8 concerns consent-based processing for information-society services and does not replace national rules governing a minor's capacity to enter into a contract.

9. Required and Optional Data

Providing an email address, username, authentication credential, and required security information is necessary to create and maintain an account. Without it, we cannot provide account features. Information marked optional, such as an avatar, social links, personalization choices, analytics consent, or a reason for account deletion, is not required for basic account access.

Where we need information to handle a complaint, rights request, or illegal-content notice, failure to provide enough information to identify the request, content, or account may prevent us from investigating or fulfilling it. We will not require information that is unnecessary for the purpose.

10. Contact-Form Retention

Contact-form submissions are sent through MailerSend to our support mailbox. We retain the resulting correspondence for up to 12 months after the last communication so that we can answer follow-up questions, track a request, handle reports and complaints, and maintain appropriate records. We may retain a specific thread longer where necessary for an unresolved dispute, a legal obligation, or a legal claim.

Depending on the request, processing is necessary to perform the account contract, take requested pre-contract steps, comply with a legal obligation, or pursue our legitimate interests in handling communications and legal claims. The form's privacy acknowledgment confirms that you have received this information; it is not the legal basis for necessary support processing.

You may request earlier deletion, subject to applicable retention exceptions. MailerSend and the support mailbox provider process message and delivery data as described in section 3.1.

11. Changes to This Policy

We may update this Policy to reflect changes in the Service, providers, or law. We will state the new update date and give clear advance notice of material changes where required. If a change introduces processing that requires consent, we will request consent before that processing begins rather than treating continued use as consent.

12. Controller and Contact

The controller of personal data is:

  • Company: Rezone Group Sp. z o.o.
  • KRS: 0001174687
  • NIP: 9492276473
  • REGON: 541807867
  • Share capital: PLN 5,000
  • Registered address: ul. Ε»elazna 51/53, 00-841 Warsaw, Poland
  • General contact: xazu.work@gmail.com or the Contact Form
  • Data-protection contact: k.nowak@rezone-group.com

The data-protection contact is the channel for privacy matters. The address does not imply that a Data Protection Officer has been formally designated unless we separately state that appointment.

πŸ“– Back to all legal documents