Privacy Policy
This Privacy Policy explains how Rezone Group Sp. z o.o. ("we", "us", or "our"), as the controller of personal data, processes personal data when you use Crosspad.
Crosspad consists of the website, native mobile applications for Android and iOS, and connected services (together, the "Service").
1. Personal Data We Process
1.1 Account and Authentication Data
When you register or use an account, we process:
- Username and account identifier
- Email address
- Password hash; we do not store your password in plain text
- Account status, creation date, settings, rights, and security information
- Authentication tokens, verification codes, and information about enabled two-factor authentication
If you choose Google sign-in, Google provides us with information you authorize it to share, such as your Google account identifier, name, email address, and profile picture. The source of this data is Google and your Google account.
1.2 User Content and Profile Data
We process content and metadata that you upload, create, or publish, including:
- Audio samples and sound files
- Kit configurations, names, descriptions, categories, and publication status
- Profile avatar and social-profile information you choose to provide
- Ownership and activity records needed to manage kits, samples, and groups
Published content, your public username, and your avatar may be visible to other users and visitors according to the Service's visibility settings.
1.3 Website Usage and Analytics Data
With analytics consent, we use Google Analytics 4 to process information such as:
- Pages viewed, navigation paths, and interactions
- Approximate session duration and frequency
- Browser, device category, screen resolution, and referring URL
- Approximate country or region derived by Google from network information
We do not send your Crosspad account identifier, email address, or username to Google Analytics.
The website uses Google Consent Mode in its basic implementation. Before analytics consent, the Google Analytics tag is blocked: no Analytics cookies are read or written and no Analytics measurement request is sent to Google. If you consent, the tag loads with analytics storage enabled. Advertising storage, advertising user data, and advertising personalization remain controlled separately and are not used for Crosspad Analytics measurement.
With analytics consent, opening or playing a kit may also increment a first-party aggregate popularity counter. We store the counter by kit and source, not by account or device.
1.4 Technical, Security, and Network Data
When any device connects to the Service, our infrastructure provider, Cloudflare, processes technical data needed to deliver and secure the request, including:
- IP address and connection timestamps
- Request URL, method, headers, and response information
- Browser or application user agent
- Security signals used for rate limiting, bot detection, abuse prevention, and incident investigation
This processing applies to website and mobile requests, including sign-in, account actions, downloads, uploads, and kit-counter requests. Security information is kept separate from aggregate kit counters to the extent reasonably possible.
1.5 Mobile Application Data and Permissions
The mobile applications do not contain third-party advertising, crash-reporting, or general-purpose analytics SDKs. They store the following information locally on your device:
- Authentication token used to keep you signed in
- App settings and preferences, such as language, interface, and sound choices
- Privacy and analytics choices
- Downloaded kits and audio samples for offline playback
The applications communicate with our servers when you request an online feature, for example when you sign in, browse or download online kits, or upload account information. Those requests involve the account, content, and technical data necessary for the requested feature.
Optional kit popularity counters. When "Analytics (Kit Popularity & Play Counts)" is enabled in the mobile privacy settings, opening or playing a kit sends an increment request with an X-Analytics-Consent signal. The application does not include an account, email, advertising ID, or persistent device identifier in the counter payload. The resulting count is stored only in aggregate for the kit. The network request is still processed with the technical data described in section 1.4. When the setting is disabled, the application does not send the counter increment.
The mobile applications may request these device permissions for the stated purposes:
- Notifications β showing kit-download status and important service messages
- Vibration β providing haptic feedback when pads are played
- MIDI / USB device access β connecting external MIDI controllers or pad hardware
- Bluetooth β discovering and connecting Bluetooth Low Energy MIDI controllers or musical hardware
- Foreground Service Data Sync (Android) β continuing kit-audio and preset downloads for offline playback while the application is not in the foreground
- Selected photo access β accessing only the image you choose when uploading an avatar
We do not request general access to your microphone, contacts, or location for these features. Permissions can be managed in your device settings, although disabling one may prevent the related feature from working.
1.6 Contact and Communication Data
When you contact us, make a complaint, report content, or request account deletion, we process the information you provide, which may include:
- Email address and account identifier
- Subject, message, report, and attachments or content identifiers
- Deletion or verification code where required to confirm identity
- Correspondence history and the status of the request
Contact-form messages are transmitted through MailerSend and delivered to our support mailbox. They are not stored in a separate Crosspad contact-message database.
2. Purposes and Legal Bases
Where the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") applies, we rely on these legal bases:
- Performance of a contract or steps requested before a contract (Art. 6(1)(b)) β registering and authenticating accounts, providing requested website and mobile functions, storing and serving User Content, enabling offline playback, and administering account settings
- Consent (Art. 6(1)(a)) β enabling Google Analytics cookies and full analytics measurement, optional kit popularity counters, and optional storage or access that requires consent; consent may be withdrawn at any time without affecting earlier lawful processing
- Legitimate interests (Art. 6(1)(f)) β securing the Service, preventing abuse and fraud, enforcing rules, responding to inquiries and reports, maintaining service reliability, and handling potential legal claims; we assess necessity and balance these interests against users' rights
- Legal obligation (Art. 6(1)(c)) β retaining or disclosing information where applicable law requires it and responding to binding requests from competent authorities
If we need personal data for a new incompatible purpose, we will provide the required information before that processing and obtain consent where required.
3. Infrastructure, Recipients, and Retention
3.1 Infrastructure and Service Providers
We use selected providers that receive data only as needed for their role:
- Cloudflare β Workers compute, D1 database, R2 object storage, KV storage, content delivery, network security, rate limiting, and aggregate infrastructure analytics
- Google β optional Google sign-in, Google Analytics, and delivery of correspondence to our support mailbox; Google's role depends on the relevant service and contract
- MailerSend β delivery of transactional messages and contact-form correspondence on our behalf
- Professional advisers and authorities β only where reasonably necessary for legal claims, compliance, or a binding legal request
We do not sell personal data.
3.2 Data Retention
We retain your data for as long as your account is active and as needed to provide the Service. If you request account deletion:
Step 1: Anonymization (Automatic)
When you click Delete in your profile settings:
- Your account enters a 24-day grace period with status "anonymization pending"
- After 24 days, your account is automatically anonymized:
- Username becomes "User"
- Avatar is removed
- Login credentials are deleted
- Your public kits and sounds remain visible
- You can undo anonymization within the 24-day grace period by using the method in the confirmation email or contacting support
Step 2: Complete Deletion (Requires Contact Form)
For full deletion that removes all kits, sounds, and account data:
- Click Delete in profile settings to receive a verification code by email
- Visit our Contact Form, select "Account Deletion Request," and provide the requested account email and code
- Confirm the deletion request in the form
- We process a verified request without undue delay and normally within 30 days
The contact workflow is a method of confirming identity and is not the only way to exercise the GDPR right to erasure. You may also contact us at k.nowak@rezone-group.com. We may ask only for additional information reasonably necessary to confirm identity. The right to erasure is subject to legal exceptions, including data needed for legal obligations or the establishment, exercise, or defense of claims.
Anonymized data is retained only if it has been irreversibly changed so that no person is identifiable by reasonably available means. Such data is no longer personal data under the GDPR.
3.3 Data Stored on Your Device
Mobile local data remains until you use Reset All Data, clear application data, or uninstall the application. Website cookies and browser storage remain for the periods described in the Cookie Policy or until you delete them. Clearing local data does not itself delete your Crosspad account or uploaded content.
3.4 Retention Schedule
| Data Category | Retention Period or Criterion |
|---|---|
| Unverified registration data | Normally deleted after 24 hours if the email address is not verified |
| Active account and User Content | For the life of the account or until the data or content is deleted; active-system deletion normally completes within 30 days |
| Authentication and security data | For the life of the account and then only as long as needed to secure the Service, investigate an incident, or meet a legal obligation |
| Contact, complaint, and report correspondence | Up to 12 months after the last communication, unless a longer period is necessary for an unresolved dispute, legal obligation, or legal claim |
| Google Analytics user-level and event-level data | For the retention period configured for our standard GA4 property, not exceeding 14 months; aggregate reports may no longer identify an individual browser |
| Cookie and analytics choices | Up to 1 year or until you change or clear the choice; an outdated policy version is no longer treated as active consent |
| Aggregate kit counters | For as long as the relevant kit or popularity feature exists; the stored counters do not identify a user or device |
| Provider security logs and backups | Limited according to provider settings and our need to detect abuse, resolve incidents, ensure continuity, and meet legal obligations; access is restricted and retention is periodically reviewed |
4. Analytics Details
4.1 Google Analytics on the Website
Google Analytics 4 is provided by Google. Before analytics consent, the Analytics tag is not loaded and no Analytics request is sent. If you consent, Analytics may set _ga and _ga_[CONTAINER_ID] cookies and process pseudonymous browser identifiers and usage events. This data is pseudonymous, not necessarily anonymous.
You can withhold or withdraw analytics consent through the cookie settings control. Withdrawal prevents future consent-based measurement and removes accessible Google Analytics cookies set for Crosspad; it does not affect processing that occurred lawfully before withdrawal.
4.2 Cloudflare Analytics and Security
Cloudflare provides aggregate information about traffic, performance, and security threats and processes request-level technical data to deliver and protect the Service. This processing does not depend on Google Analytics consent where it is strictly necessary for network delivery or security.
4.3 Mobile Kit Counters
The mobile applications do not use Google Analytics or advertising SDKs. They send only the optional first-party kit-counter signal described in section 1.5 when the mobile analytics setting is enabled.
5. Data Security
We use technical and organizational measures appropriate to the risk, including:
- Password hashing and protected authentication tokens
- HTTPS encryption in transit
- Access controls for administrative and infrastructure systems
- Rate limiting, bot management, and DDoS protection
- Separation of aggregate kit counters from account records
- Procedures for deletion, incident handling, and restoration
No system is completely secure. If a personal-data breach creates a risk requiring notice under applicable law, we will notify the competent authority and affected individuals as required.
6. International Data Transfers
Cloudflare, Google, and MailerSend operate internationally, and personal data may be processed outside the European Economic Area, including in the United States.
For transfers to a U.S. recipient with an active certification under the EU-U.S. Data Privacy Framework, we may rely on the European Commission's adequacy decision, Commission Implementing Decision (EU) 2023/1795. Certification can be checked in the U.S. Department of Commerce Data Privacy Framework participant list.
Where an adequacy decision does not apply, we use an applicable transfer mechanism such as the European Commission's Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, together with supplementary measures where required. You may contact us for information about the applicable safeguards and how to obtain a copy, subject to protection of confidential information.
7. Your Data-Protection Rights
Subject to the conditions and exceptions in applicable law, you may have the right to:
- Access your personal data and receive information about its processing
- Correct inaccurate or incomplete personal data
- Request erasure of personal data
- Restrict processing
- Receive data you provided in a structured, commonly used, machine-readable format and transmit it to another controller where portability applies
- Object, on grounds relating to your situation, to processing based on legitimate interests
- Withdraw consent at any time through the relevant settings or by contacting us
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects
- Lodge a complaint with a supervisory authority
We do not currently use solely automated decision-making that produces legal or similarly significant effects.
Requests are generally free of charge. We will provide information about action taken without undue delay and within one month. That period may be extended by up to two additional months where necessary because of complexity or the number of requests; if so, we will explain the extension within the first month.
To exercise a right, use the Contact Form or email k.nowak@rezone-group.com. We may need to verify your identity. If we do not act on a request, we will explain why and provide information about complaint and judicial remedies.
7.1 Supervisory Authority
You may complain to the authority for your habitual residence, place of work, or the place of an alleged infringement. In Poland, the competent authority is:
- Authority: President of the Personal Data Protection Office (Prezes UrzΔdu Ochrony Danych Osobowych, UODO)
- Address: ul. StanisΕawa Moniuszki 1A, 00-014 Warsaw, Poland
- Website: https://uodo.gov.pl
- Telephone: +48 22 531 03 00
8. Children's Privacy
The Service is not intended for users under 16, and users under 16 may not create an account. We do not knowingly collect personal data from such users. If we learn that a user under 16 provided personal data, we will take reasonable steps to delete it, unless retention is legally required. A parent or guardian may contact us about a child's data.
The age threshold in GDPR Article 8 concerns consent-based processing for information-society services and does not replace national rules governing a minor's capacity to enter into a contract.
9. Required and Optional Data
Providing an email address, username, authentication credential, and required security information is necessary to create and maintain an account. Without it, we cannot provide account features. Information marked optional, such as an avatar, social links, personalization choices, analytics consent, or a reason for account deletion, is not required for basic account access.
Where we need information to handle a complaint, rights request, or illegal-content notice, failure to provide enough information to identify the request, content, or account may prevent us from investigating or fulfilling it. We will not require information that is unnecessary for the purpose.
10. Contact-Form Retention
Contact-form submissions are sent through MailerSend to our support mailbox. We retain the resulting correspondence for up to 12 months after the last communication so that we can answer follow-up questions, track a request, handle reports and complaints, and maintain appropriate records. We may retain a specific thread longer where necessary for an unresolved dispute, a legal obligation, or a legal claim.
Depending on the request, processing is necessary to perform the account contract, take requested pre-contract steps, comply with a legal obligation, or pursue our legitimate interests in handling communications and legal claims. The form's privacy acknowledgment confirms that you have received this information; it is not the legal basis for necessary support processing.
You may request earlier deletion, subject to applicable retention exceptions. MailerSend and the support mailbox provider process message and delivery data as described in section 3.1.
11. Changes to This Policy
We may update this Policy to reflect changes in the Service, providers, or law. We will state the new update date and give clear advance notice of material changes where required. If a change introduces processing that requires consent, we will request consent before that processing begins rather than treating continued use as consent.
12. Controller and Contact
The controller of personal data is:
- Company: Rezone Group Sp. z o.o.
- KRS: 0001174687
- NIP: 9492276473
- REGON: 541807867
- Share capital: PLN 5,000
- Registered address: ul. Ε»elazna 51/53, 00-841 Warsaw, Poland
- General contact: xazu.work@gmail.com or the Contact Form
- Data-protection contact: k.nowak@rezone-group.com
The data-protection contact is the channel for privacy matters. The address does not imply that a Data Protection Officer has been formally designated unless we separately state that appointment.