Policy

Privacy Policy

Last updated 2026-06-26

ConcertQueue is a Denver concert-discovery app operated by ConcertQueue LLC, a Colorado limited liability company. This document explains what data ConcertQueue collects, how we use it, and what controls you have over it.

Questions about this policy: support@concertqueue.com.

1. What we collect

1.1 Account data

1.2 Usage data

1.3 Device data

1.4 Moderation data

2. What we do NOT collect

3. How we use your data

DataUsed for
EmailAuthentication, account-related notifications
Apple subRecognizing you across Apple Sign In sessions
Google subRecognizing you across Sign in with Google sessions
Username, avatarShowing you to other users in friend search, profile views, and friend lists
Display nameAccount records and support. Never displayed to other users
Swipe decisionsBuilding your personalized calendar; computing social signal ("3 friends going to this show")
Attendance confirmationsDistinguishing "claimed Going" from "confirmed attended" for friends and aggregate analytics
FriendshipsRouting friend-aware features (mutual counts, friend activity in feeds, push notifications about friend activity)
Sign-up source / InviterAggregate attribution analytics; auto-friending the inviter when you signed up via their share link
Public-schedule preferenceControlling whether your upcoming shows render on your /@username share page
Ticket clicksAggregate analytics for ticketing partnership pitches
Listen-link tapsAggregate analytics on Listen usage and platform preference
Share opensAggregate analytics on how often and from where users share
Session pingsAggregate DAU/WAU/MAU for product health
APNs / FCM device tokenSending push notifications you've opted into
Reports, blocks, correctionsModerating the catalog and the user base

We do not use any of this data for cross-app advertising, behavioral targeting, or sale to third parties.

4. Third-party services

ServicePurposeData sent
AppleSign in with Apple, Push Notifications (iOS)Identity token (for verification), device token (for push)
Firebase Cloud Messaging (Google)Push notifications on AndroidDevice token (for push), notification content in transit
GoogleSign in with GoogleOIDC ID token (for verification). When you tap "Sign in with Google," Google sees that you're signing in to ConcertQueue and returns your email, name, and a stable identifier to us. Google does not receive any of your in-app activity.
Cloudflare R2Profile-photo hostingYour uploaded photo, processed to WebP at 256×256
ResendTransactional email: magic-link sign-in, admin sign-in links and codes, and operational summary emails to the operatorRecipient email address and the content of the email being sent
RailwayApplication and database hostingAll account, usage, device, and moderation data described above, stored in our Postgres database
Anthropic ClaudeGenre classification of public show metadata + automated avatar pre-screeningShow titles + artist names (public concert data) + your uploaded avatar bytes (one-off NSFW screening; not retained by Anthropic)
TicketmasterPublic show metadata (when applicable)None of your personal data. Outbound public catalog reads only.
Operator notification toolsRouting content reports and system alerts to the operator for reviewThe report or alert being routed

These services are bound by their own privacy policies and are required, by contract or by their published policies, to protect your data to a standard consistent with this policy. None of them are used for tracking you across other apps.

A note on the Sign in with Google SDK: Google's iOS Sign-In SDK ships a privacy manifest declaring that it may collect Phone Number, Coarse Location, and usage data. Apple aggregates every bundled SDK's manifest into the app's App Store privacy label, so those data types appear on ConcertQueue's label. ConcertQueue requests only your email and basic profile from Google and never requests, receives, or stores your phone number or your location.

IP address: When you sign in, load a public share-link preview page, or submit a show correction as a guest, we briefly process your device's IP address to rate-limit those requests and prevent abuse. We do not store your IP address or link it to your account.

5. Your controls

5.1 What people see on your public profile page

Your /@username page is a public web page at app.concertqueue.com/@yourhandle. It always shows: your @username, your profile photo (if you have one), and aggregate counts of your Going + Interested shows. Your display name is never shown. When you choose to show your concert list publicly in the app's privacy settings, the page additionally renders your upcoming Going shows, plus your upcoming Interested shows if you also choose to include them.

A small image preview (1200×630 PNG) is generated server-side at /@username/og.png and referenced via Open Graph meta tags. This image renders the same data the page shows: avatar, name, top three upcoming Going shows (only when public-schedule is ON). iMessage / Twitter / Slack request this image when someone shares your link. Public pages and preview images may be cached briefly by browsers and messaging apps, and a preview image already fetched by a third-party app may persist as a copy that ConcertQueue cannot recall.

Profile pages for users with the hidden-from-search flag (typically: admin or internal accounts) return 404 to deny direct access. Toggling public-schedule OFF does not hide the page itself, only the list of shows.

6. Data retention

7. Children's privacy

ConcertQueue is rated 17+ on the App Store. Concert metadata may reference alcohol, late hours, and similar themes appropriate for a mature (17+) audience. We do not knowingly accept signups from users under 13. If you believe a minor has created an account, email support@concertqueue.com and we will delete it.

8. Security

9. Changes to this policy

If we make material changes to this policy, we'll update the "Last updated" date at the top of this page.

10. Your rights under California and Colorado law

If you reside in California or Colorado, state privacy law gives you the right to:

ConcertQueue does not sell your personal information. We do not share it for behavioral advertising or build advertising profiles.

To exercise any of these rights, email support@concertqueue.com. We aim to respond promptly, typically within a few days, and always within the timeframe state law requires. We may ask you to verify your identity before fulfilling a request, to make sure we don't release your data to someone impersonating you.

11. Contact

Email: support@concertqueue.com
Operator: ConcertQueue LLC
Mailing address: 1500 N Grant St Ste N, Denver, CO 80203

In-app deletion (Settings → Danger Zone → Delete account) takes effect immediately; best-effort cleanup of copies stored with external hosting services (such as a profile photo) completes shortly after. If you instead email a deletion request, we process it promptly, typically within a few days. For formal rights requests under state privacy law, we respond within the timeframe the law requires.