Last updated 9 September 2026. Effective 1 November 2026.
This explains what we collect, why, and what we do not do. The short version: we collect what the app needs to work, we do not sell anything about you, and we do not use your music to train machine-learning models.
Who is responsible
The Stack Technologies LLC, 7681 W Ottawa Pl, Littleton, CO 80128, USA, operates The Score Stack. Questions go to support@thescorestack.com.
What we collect
Information you give us
- Account details — name, email address, password (stored only as a cryptographic hash), and an optional profile photo.
- Group content — sheet music, recordings, documents, annotations and markings, messages, calendar events, setlists, tasks and RSVPs that you or your group upload or create.
- Support correspondence — what you write to us.
Information we collect automatically
- Usage data — which screens are opened and which features are used, so we can tell what is worth improving.
- Device and log data — device type, operating system, app version, IP address, and error diagnostics.
- Push tokens — if you allow notifications.
- Website visits — our public web pages use Google Analytics, which sets first-party cookies to count visits and which link or ad brought you there. If your browser sends a Global Privacy Control signal, these pages do not load it.
Payment information
If your group buys a plan, payment is processed by Stripe. Card details go to Stripe, not to us — we never see or store your full card number. We keep a customer reference, the plan, and its status.
Why we use it
| Purpose | What it covers |
|---|---|
| Running the service | Signing you in, showing your groups their content, sending the notifications you asked for |
| Keeping it working | Diagnosing errors, preventing abuse, protecting accounts |
| Improving it | Understanding which features are actually used |
| Billing | Taking payment for group plans and handling failed payments |
| Talking to you | Service notices, and answering your emails |
Where the GDPR or UK GDPR applies, our legal bases are: performance of a contract (running the service and billing), legitimate interests (security, abuse prevention, product improvement), consent (push notifications and optional analytics), and legal obligation (tax and accounting records).
What we do not do
We do not sell or rent your personal information. We do not share it with advertisers or data brokers. We do not use your uploaded music, recordings or messages to train machine-learning models. We do not run advertising in the app.
Who else processes data for us
We use a small number of service providers, each only for the purpose listed:
| Provider | Used for |
|---|---|
| Amazon Web Services (USA) | Hosting, databases, file storage, sign-in |
| Google Firebase and Google Analytics (USA) | Push notifications, product and website analytics, web hosting |
| Stripe (USA) | Payment processing for group plans |
| Apple and Google | Optional “sign in with” if you choose it |
We may also disclose information where the law requires it, or to protect the rights and safety of people using the service. If the business is ever transferred, information may transfer with it, and we will tell you first.
Who can see your content
Content uploaded into a group is visible to the members of that group, and to the admins and owner of that group. Where a group belongs to an organization, that organization’s owners and admins may also have access. Content is not public, and is not indexed by search engines — except for pages you deliberately publish, such as a public performance programme, which are visible to anyone with the link.
A small number of our staff can access data where it is genuinely necessary to run the service or to help you with a support request.
Where data is held
Our infrastructure runs in the United States (AWS us-east-1). If you use the
service from outside the USA, your information is transferred there. For transfers from the
EEA or UK we rely on Standard Contractual Clauses with our providers.
How long we keep it
- Account data — while your account exists, then deleted or anonymised within 90 days.
- Group content — while the group exists. It is not deleted because a plan lapsed; a group without an active plan becomes read-only, not erased.
- Billing records — up to 7 years, because tax law requires it.
- Logs and diagnostics — typically 30–90 days.
Security
Traffic is encrypted in transit with TLS, files are encrypted at rest, passwords are hashed, and access to production systems is restricted and logged. No service can promise perfect security, but we take it seriously, and we will tell you promptly if a breach affects your data.
Your choices and rights
- Access, correct or delete your information — most of it directly in the app, or by emailing us.
- Delete your account from within the app at any time.
- Turn off notifications, by category, in settings or in your device settings.
- Export your information — ask us and we will provide it.
- Object or restrict processing, and withdraw consent where we relied on it.
If you are in the EEA or UK you may complain to your data protection authority. If you are in California, you have the rights described above, we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we will not discriminate against you for exercising your rights.
To exercise any of these, email support@thescorestack.com. We reply within 30 days.
Children
The service is not directed to children under 13 and we do not knowingly collect their information. Many ensembles include young singers; where that is the case the account should be set up with the involvement of a parent, guardian or the adult running the ensemble. If you believe a child under 13 has given us information, contact us and we will delete it.
Changes
If we make a material change we will give notice in the app or by email before it takes effect, and update the date at the top of this page.