Privacy Policy
- 1.What we collect
- 2.How we use it
- 3.Who can see what
- 4.Who we share it with
- 5.How long we keep it
- 6.Your choices and rights
- 7.Cookies and local storage
- 8.Security
- 9.Children
- 10.International transfers
- 11.Changes to this policy
- 12.Contact
1.What we collect
From the account you sign in with (Google or Slack): your name, email address, profile picture, and a provider account id. From Slack we also receive your Slack user id and workspace id, which we use to match your Slack reactions to your Hivequeue account.
What you do in Hivequeue: tracks you add (title, artist, album, cover art, service id), the sessions you join, your role (host, DJ, listener), your votes and reactions on tracks, your comments, your chosen display name and avatar emoji, your settings (sound cues, "Most Blasted" opt-out), and the time you were last active. The last-active time is how we count "active listeners" for the vote threshold.
From the household's Slack workspace, when connected: reactions and thread replies on Hivequeue's own posts, and the Slack profile (user id, display name, email, avatar) of whoever reacted or replied. If you react to a Hivequeue post before you have ever signed in, we create a placeholder account for you from that Slack profile so your vote counts; it is merged into your account when you sign in with the same email or Slack identity. Where a member reacts 🐝 to a message containing a music link, we read that one message to find the link.
About the workspace itself, when the household owner installs the Slack app: the workspace id and name, the id of the channel chosen for posts, and the bot access token Slack issues to Hivequeue. The token is stored only in our database, is never shown in the app or sent to any browser, and is deleted the moment the owner disconnects Slack or the app is removed from the workspace.
From the household's Sonos system, via the bridge the household runs: speaker names, groupings, volume, and what is playing. This is about the speakers, not about you, but a track you added will be linked to your account when it plays.
If you turn on Tune in (so your own Spotify plays what the office speakers play): your Spotify account id, display name, product tier (we need to know if you have Premium, since playback control requires it), and the access and refresh tokens Spotify issues, plus which of your devices you chose to follow along on. These tokens stay on our server and are used only to keep your device in sync with the office; we don't read your Spotify library, playlists, or listening history beyond what's needed to control playback. Turning Tune in off stops your device following the office. Disconnecting Spotify in Settings removes the stored tokens.
If your household upgrades to a paid plan: the household owner's checkout is handled entirely by Stripe. We receive and store a Stripe customer id and subscription status so the app can tell whether the household is on the paid plan — never card numbers, bank details, or billing addresses, which go straight to Stripe and never touch our servers.
Technical information: when you accept the Terms we record the date, time, document versions and your browser's user-agent string. Our hosting providers keep standard server logs (IP address, request time, URL) for security and debugging. Sentry, our monitoring provider, receives crash and error reports and limited operational logs used to diagnose whether features such as Tune in and scheduled jobs are working. Those records can include the page, IP address, browser version, internal household or session identifiers, device name, playback timing, and—when playback fails—the track title, service and URI involved. We disable Sentry's default collection of personally identifying request data. For every session where an error occurs, and for a small random sample of other sessions, Sentry also records a video-like replay of what was on screen, with all text masked so names, comments and track titles are not readable in it; we do not use this to show ads or build advertising profiles.
We do not collect card numbers, billing addresses, precise location, contacts, or the contents of any Slack messages other than reactions and replies on Hivequeue's own posts and the single message a 🐝 reaction points at.
2.How we use it
- To run the service: sign you in, show who queued what, count votes, decide when a track is booed off, build scoreboards and history, post to and read from Slack, and send you Slack direct messages about your own tracks ("your track is up next", "your pick hit +5", "your pick got booed off").
- To keep it fair and safe: enforce per-person caps, detect abuse, and honour house rules such as quiet hours.
- To improve Hivequeue: understand how features are used, in aggregate.
- To meet legal obligations and enforce our Terms.
Our legal bases, where such a basis is required, are performance of our contract with you (the Terms), our legitimate interest in running a secure and fair service, and your consent where we ask for it (for example, sound cues). We do not use your information for automated decisions with legal or similarly significant effects. A track being skipped because enough people voted against it is a feature of the game, not a decision about you.
3.Who can see what
Hivequeue is a shared room. Assume your coworkers can see what you do in it.
- Members of your household see your display name, avatar, the tracks you add, your votes (votes are public, as Slack reactions are), your reactions, your comments, your presence in a session, and your position on scoreboards, including "Most Blasted" unless you opt out in Settings or the owner turns it off.
- Your Slack channel, if the household connects one, receives posts naming who queued each track, vote counts, comments, and the daily scoreboard. Anyone with access to that channel can see them; Slack's own privacy policy governs that copy.
- Anyone with a Hive link can view the session's now-playing screen and queue, including contributor names, without signing in. Hive links are meant to be shared inside the workplace; treat them accordingly.
- The household owner can additionally see the household's settings and bridge key.
5.How long we keep it
- Account details (name, email, avatar, provider ids): until you delete your account.
- Plays, votes, reactions and comments: kept as the household's history and scoreboard record. When you delete your account they are anonymised, not removed: the track stays in history attributed to "a former member", comments keep their text with the author replaced, and vote counts are unchanged.
- Live reactions (the floating emoji): about a minute; the durable copy is on the track's history entry.
- Placeholder accounts created from Slack reactions: until merged into a real account or deleted on request.
- Slack workspace connection (workspace id and name, channel id, bot token): until the owner disconnects Slack in Settings or the app is uninstalled from the workspace, at which point it is deleted immediately.
- Spotify account and tokens (Tune in): until you disconnect Spotify in Settings or delete your account, at which point our stored tokens are deleted and following stops. Deleting your account also deletes our device-following record. You can separately remove the app's access in your Spotify account.
- Billing records (Stripe customer id, subscription status): for as long as the household has ever had a paid plan, so we can show billing history and handle disputes; Stripe retains the underlying payment records per its own policy.
- Acceptance records (that you accepted the Terms, when, and which version): kept for as long as we may need to demonstrate acceptance, including after account deletion, with your identity reduced to an internal id.
- Server logs at our hosting providers: per their standard retention, typically 30 days or less.
- Sentry reports, operational logs and masked replays: according to the retention configured for our Sentry account, and no longer than needed to diagnose reliability and security problems.
- Backups: deleted data may persist in encrypted backups for up to 30 days before it is overwritten.
6.Your choices and rights
- Access and correction: your profile, settings and acceptance history are in Settings. History and Scoreboard show everything recorded about your picks.
- Delete your account yourself in Settings at any time. This signs you out everywhere, removes your name, email, avatar and provider links, deletes any Spotify tokens and device-following record we store, and anonymises your history as described above. If your household has a paid plan, the Stripe customer id and billing history are kept as described above rather than deleted, since they belong to the household's billing record rather than to any one member.
- Disconnect Tune in separately in Settings at any time, without deleting your account, to stop your device following the office speakers and remove your stored Spotify tokens.
- Opt out of the "Most Blasted" board in Settings. Turn off sound cues there too.
- Slack messages: direct messages from the bot stop if you leave the household's Slack channel or the owner disconnects Slack. You can also block the bot in Slack.
- Export: email privacy@hivemind.app and we will send you a copy of the personal information we hold about you, in a machine-readable format, within 30 days.
Depending on where you live you may have additional rights, such as to object to or restrict processing, to data portability, and to complain to a supervisory authority. To exercise any right, email privacy@hivemind.app. We will not discriminate against you for exercising them.
If you are a member of a household, your employer or organisation may also be a controller of information about you under its own workplace policies. Requests about how your workplace uses Hivequeue should go to the household owner as well.
8.Security
Data is encrypted in transit (TLS) and at rest by our hosting providers. Access to production data is limited to people who need it to run the service. Sign-in is delegated to Google and Slack; we never see or store your password. The bridge connects outward from your network and accepts no inbound connections. Slack requests are verified with Slack's signing secret. No system is perfectly secure; if we learn of a breach affecting your information we will notify you and the household owner as required by law.
9.Children
Hivequeue is a workplace tool and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe we have, contact us and we will delete it.
10.International transfers
Our providers store data in the United States. If you use Hivequeue from elsewhere, your information is transferred to and processed there. Where required, we rely on our providers' standard contractual clauses or equivalent safeguards.
11.Changes to this policy
When we change this policy we update the date at the top. For material changes we will ask you to accept the new version before you continue using Hivequeue, and where practical we will announce the change in the household's Slack channel. Earlier versions are available on request.
12.Contact
Hivequeue · privacy@hivemind.app. The Terms of Service are the companion to this policy; for help using Hivequeue, see Support.