Privacy policy
Here we explain which data CrowdFlow Live processes, why we need it and what rights you have.
Last updated: 14 September 2026 · Version 1.8
1. Controller
The controller for the CrowdFlow Live website, user accounts and plans, and our own administrative functions is:
Kern MedienOwner: Dennis-Michael Kern
Tschaikowskistraße 6
18069 Rostock
Germany
info@crowdflow.live
2. Responsibility at events
The event organiser is responsible for the event’s song requests, guest messages and feedback. They determine why the information is collected, how it is moderated and where it is displayed. CrowdFlow Live processes this information on the organiser’s behalf.
The name shown on the guest page identifies who receives the request or message. The organiser must also provide guests with a way to contact them and the privacy information applicable to the event, for example at the venue or in the event documents. For questions about a specific submission, contact the organiser first. Questions about CrowdFlow Live can be sent to info@crowdflow.live.
3. Availability and security
When you visit the website, we process necessary access data such as your IP address, time, requested page, browser and device information, and request status. We need this information to provide CrowdFlow Live, detect errors and prevent misuse.
Website access and error logs remain available for up to five weeks. Other operational logs are retained to a limited extent until new entries replace older ones.
For troubleshooting, we also store the error type, time, affected site section, and browser and device group. Errors during logged-in use may be linked to your account. Form contents, card details and access keys are not recorded in this error store. Entries are deleted during regular cleanup after 30 days without recurrence. Short-lived identifiers are used for up to ten minutes to prevent misuse and are then deleted regularly.
For temporary protection measures in guest forms, an identifier that changes daily may be generated from the IP address. The IP address is not stored permanently alongside the song request or message.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is secure, uninterrupted operation. The connection to CrowdFlow Live is encrypted.
4. User account, plan and billing details
During registration and account use, we process your username, display name, email address, login credentials, plan status, settings and any contact or billing details you choose to provide. These may include company, first and last name, street, postcode, town, country and billing email. Passwords are not stored in plain text.
We need these details to provide your account and subscribed plans (Article 6(1)(b) GDPR). Security measures also rely on our legitimate interest under Article 6(1)(f) GDPR. We process legally required billing data under Article 6(1)(c) GDPR.
If you change your email address, we may send confirmation and security notices to both the old and new addresses. Temporary confirmation data is deleted after the relevant link expires.
5. Payments with Stripe and PayPal
You can use Stripe or PayPal for paid plans. Your chosen payment provider processes the account, payment and transaction data needed for payment, security and fraud prevention. Full card details are not stored in CrowdFlow Live.
When an organiser enables requests with an extra contribution, Stripe processes the payment directly to the organiser’s connected merchant account. CrowdFlow Live stores only the transaction and amount data needed for matching, status, refunds and records; it does not receive card or wallet details. A payment does not guarantee that a song will be played and does not add an extra vote.
Processing serves contract performance and payment handling under Article 6(1)(b) GDPR and legal obligations under Article 6(1)(c) GDPR. Stripe and PayPal act as independent controllers for substantial parts of their payment processing.
- Stripe: Stripe privacy policy
- PayPal: PayPal privacy policy
6. Song requests, voting and events
For a song request, we process the entered name or pseudonym, artist, title, optional comment, time and handling status. The request is assigned to the relevant organiser and, where applicable, an event or archive folder. Music search information may add an album, genre, release year and cover image.
When voting is enabled, a guest can rate a visible song once and finally within an event context, positively or, if the organiser allows it, negatively. CrowdFlow Live processes a pseudonymous guest association, the song reference, vote and time. This ensures one vote per song and a limit of five accepted votes in five minutes and 30 votes per context. Votes cannot be changed or withdrawn; only the combined net score is shown publicly, without guest names.
The information is available to the organiser for preparing and running the event. The organiser determines the applicable legal basis according to their use. Please do not include confidential details or unnecessary information about others in comments.
A shared browser identifier links guest song requests, votes and messages during a session. It expires 16 hours after issue and is not extended by further use. This also applies to individual event links, whose validity is independent. The organiser may move requests to the live list or archive and retain them there until deletion. Aggregated vote scores may remain saved with an archive; the short-lived guest association is not needed for this.
The DJ can send short messages about a song request. Explicitly public DJ messages appear in the request list; private DJ messages and guest replies are visible only to that guest and authorised account managers. We store the message, time, request reference, visibility and read status. In My song requests, guests can view their requests and messages during the valid 16-hour session, even after archiving. Archived conversations cannot continue. Messages remain linked to the saved request and are deleted with it or the associated account.
7. Chatwall, guest photos and public display
For Chatwall, we process the message, time, moderation status, account association and a pseudonymous visitor identifier. This identifier helps prevent duplicate submissions, supports moderation and enables temporary blocks in cases of misuse.
If the organiser enables guest photos, we also process the selected images (up to six per post), one shared optional caption, moderation status and technical file information. CrowdFlow Live initially stores uploads privately, removes embedded metadata and prepares images for display. The organiser chooses whether posts appear automatically after upload or only after manual approval. Photos submitted together are displayed and moderated as one group. The organiser may reject posts or temporarily block the sender. Image content is not assessed automatically, and photos are not sent to external image-review services. CrowdFlow Live does not use guest photos for facial recognition, advertising or model training.
Approved messages and photos may appear on the event display. They are visible to people present and anyone given access to the display address. Share only content that may be shown at the event, without confidential or sensitive information. For photos, you must hold the necessary rights and have the consent of recognisable people pictured.
Guest messages and related blocking information are automatically deleted after 16 hours by default. Rejected photos are deleted immediately; all other guest photos and versions created from them become inaccessible 16 hours after upload and are then automatically deleted. The legal basis depends on the event; legitimate interests may include running the event, moderation and preventing misuse (Article 6(1)(f) GDPR).
8. Feedback and analytics
Guests can submit star ratings or their mood. Until an analysis period closes, we store the rating, time, account association and visitor identifier. These may then be used to produce aggregated values such as counts and averages. The organiser can rename or delete saved periods.
For the account overview, CrowdFlow Live counts song requests and guest messages by account and period. These counts contain no request or message texts.
9. Music data from Spotify, Apple, Deezer and Last.fm
To search for a song or add album, genre, release year or cover information, artist and title details and the associated song or album identifiers may be sent to Spotify, Apple (iTunes), Deezer and Last.fm. Guest names and comments are not part of these requests. Searches and additions run through CrowdFlow Live; the guest’s IP address is not sent directly from their browser to these providers.
Music data and covers found may be saved for later searches and analyses. The providers’ privacy notices apply to their processing:
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is convenient song searches and meaningful analytics for the account holder.
10. Browser notifications
Account holders can enable browser notifications for new song requests. We store the data needed for delivery, along with status and error information. Depending on the device, notifications are delivered through the browser or operating system provider’s push service, such as Apple, Google or Mozilla.
The legal basis is your consent under Article 6(1)(a) GDPR. You can withdraw permission in your browser and in CrowdFlow Live. Successfully processed delivery events are deleted after seven days; undelivered events after 30 days.
11. Protecting login and registration
Login, registration and password recovery must be protected against automated attacks. We use Google reCAPTCHA for this. When a protected page is opened, the service processes data including the IP address, interactions, browser, device and connection information to detect abusive requests.
Processing is based on Article 6(1)(f) GDPR. Our legitimate interest is protecting accounts, forms and our service. Google processes this data as our processor. Google’s retention period depends on the data type and security purpose; Google does not specify one fixed period for all reCAPTCHA data. Further information: Google reCAPTCHA.
11a. Contact form
When you use the contact form, we process your name, email address, subject, message and receipt and delivery status. We need these details to process and answer your enquiry and track its receipt. Depending on the enquiry, the legal basis is Article 6(1)(b) GDPR for pre-contractual or contractual matters, or Article 6(1)(f) GDPR for general enquiries. Our legitimate interest is reliable communication.
The enquiry is sent to info@crowdflow.live and also stored in CrowdFlow Live’s protected administration area. Contact enquiries are automatically deleted after 365 days. You may request earlier deletion unless legal obligations or overriding grounds prevent it.
Google reCAPTCHA may also be used on the contact page to protect against automated enquiries. It evaluates connection and usage data. The information about Google reCAPTCHA in section 11 applies accordingly.
12. Media uploads
Account holders can upload their own images for Chatwall backgrounds and overlays. Upload only material for which you have sufficient usage rights, and avoid unnecessary personal data. These operator files remain stored until removed or replaced.
Guest photos are instead subject to the short retention period, initially private storage and organiser-selected approval described in section 7. Guest photos are available only when the organiser has an eligible plan and enables them in Chatwall settings.
13. Cookies and browser storage
Necessary cookies and local storage support login, security, spam prevention, moderation, voting, one-time notices and saved interaction or display preferences. They rely on section 25(2) no. 2 TDDDG and, where personal data is processed, Article 6(1)(b) or (f) GDPR.
We remember your language choice in a functional cookie for up to twelve months. To suggest a language, we read your browser’s preferred languages without requesting your location. Your confirmed choice also applies in this browser the next time you visit or scan a QR code.
When you register, we save the language of the page you use in your account. You can change it in settings. It is also the default language for your guest pages; a guest’s own language choice takes priority.
| Storage | Purpose | Duration |
|---|---|---|
| Shared guest browser identifier | Linking song requests, votes, guest messages and paid requests; moderation and duplicate prevention | 16 hours from issue, without extension through use; also applies to event links |
| Welcome notice | Show a notice once per night | Until the next changeover at 08:00 Berlin time |
| Login session | Keep you logged in and protect your account | Until logout or session expiry |
| Google reCAPTCHA | Protection against automated attacks | Set by Google; Google does not specify a universally applicable fixed cookie lifetime |
You can delete or block cookies and local storage in your browser. This may limit necessary features.
14. Campaign attribution and demo
If you arrive at CrowdFlow Live through a tagged campaign or partner link and then create an account, the campaign, partner, first page visited and time may be assigned to your new account. We use this to evaluate our own information campaigns and agreed partnerships. Without registration, no account-related campaign entry is created. We do not use an additional analytics or advertising cookie for this attribution.
The public song request demo displays the name, artist, song and optional comment in the demo list. Please do not enter private or confidential details. Demo entries become invisible after 24 hours and are then automatically deleted. Time-limited identifiers and quantity limits protect the demo from misuse. The IP address used for this is not stored with the demo request.
A separate demo count may record only the date, type and number of demo visits. If you register afterwards, your path through the demo may be assigned to your account. Campaign attributions and aggregated demo counts are deleted after twelve months.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are a secure demo, preventing misuse and evaluating our own campaigns and partnerships. On grounds relating to your particular situation, you may contact info@crowdflow.live to exercise your right to object.
15. Emails and advertising
Necessary account, security, billing and contract messages are not marketing emails. They are sent only when required for your account, a contract, payment or security. The legal basis is Article 6(1)(b), (c) or (f) GDPR.
We treat all optional offers, promotions, surveys, newsletters, product news and site updates as advertising. We send these emails only if you explicitly consent in your account. The legal basis is Article 6(1)(a) GDPR together with section 7(2) no. 2 UWG.
You can withdraw consent at any time in your account or through the unsubscribe link in any marketing email, with effect for the future. For sending and record-keeping, we process the email address, content, delivery status, times and details of consent and withdrawal. Email addresses may be pseudonymised in records. After withdrawal, we retain proof for up to four years.
16. Recipients and transfers outside the EEA
Only parties needing data for the stated purposes receive it. These may include hosting and infrastructure providers, email, payment, music data and browser push providers, IT maintenance, support, advisers and legally authorised authorities.
Some providers may process data outside the European Economic Area. Transfers take place only under the conditions of Articles 44 et seq. GDPR, for example on the basis of an adequacy decision, the EU-US Data Privacy Framework or standard contractual clauses.
17. Retention periods and deletion
We retain data for the following periods:
- Guest messages and blocks: 16 hours.
- Guest photos: deleted immediately if rejected; otherwise inaccessible from 16 hours after upload, then automatically deleted along with all generated image versions.
- Shared guest browser identifier and session association: 16 hours from issue, without rolling extension; also applies to events created in advance. Event link validity is separate.
- Aggregated vote scores in an imported song request archive: until the archive or account is deleted.
- Public song request demo: invisible after 24 hours, then automatically deleted.
- Error store: cleanup after 30 days without recurrence. Protection identifiers are used for no more than ten minutes and deleted during subsequent cleanup. Section 3 applies to other access and operational logs.
- Contact enquiries: 365 days.
- Browser notification events: seven days after successful delivery, otherwise 30 days.
- Account campaign attributions and aggregated demo counts: twelve months.
- Completed bulk email delivery logs: 90 days.
- Proof of withdrawn marketing consent: up to four years.
- Song request archives, including related conversations, feedback histories, settings and operator uploads: until deleted by the account holder or until the account is deleted. A plan change or cancellation does not automatically delete this data.
- Invoices and accounting vouchers: eight years from the end of the calendar year in which the document was created. Other documents required by tax or commercial law may be retained for six or ten years depending on their type. Necessary payment, refund and dispute data for requests with an extra contribution is retained only as long as required for processing, legal records or defending claims.
To request deletion of your account, email info@crowdflow.live. Documents subject to legal retention requirements remain stored with restricted access until the relevant period ends.
18. Required information and automated decisions
Information required for registration, contracts and payments must be provided. Without it, an account or plan cannot be set up. Comments, push notifications and marketing emails are optional.
CrowdFlow Live does not make solely automated decisions with legal or similarly significant effects within the meaning of Article 22 GDPR. Payment providers may carry out their own automated fraud and risk checks; their privacy notices apply.
19. Your rights
Subject to legal requirements, you have rights including access, rectification, erasure, restriction, data portability and objection. You can withdraw consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing before withdrawal.
To exercise your rights, email info@crowdflow.live. You can also complain to a data protection supervisory authority. The authority responsible for our registered location is:
State Commissioner for Data Protection and Freedom of Information Mecklenburg-Western PomeraniaWerderstraße 74a
19055 Schwerin
info@datenschutz-mv.de
www.datenschutz-mv.de/kontakt
20. Changes to this policy
We update this privacy policy when features, providers or the law change. The current version is always available through the footer.
Last updated: 14 September 2026