Privacy Policy
Last updated: June 15, 2026
1. Overview
Wavigate ("we", "us", "our") is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights regarding that data.
2. Data We Collect
Account data
When you create an account, we collect your email address and a hashed password via Supabase Auth. You may optionally provide a display name and profile picture.
Audio files
Audio files you upload are stored on Cloudflare R2 (object storage). Files are associated with your account and are deleted when you remove the project or close your account.
Payment data
Payments are processed by Stripe. We never store credit card numbers or sensitive payment details on our servers. We store your Stripe Customer ID to manage your subscription.
Usage and analytics
For Pro and Studio plans, we collect anonymized page view data including referrer domain, country (via Vercel's IP geolocation header), device type, browser, and OS. IP addresses are hashed before storage and never stored in plain text.
Comments and messages
Comments left on public player pages include the commenter's chosen name and text. Contact messages include the sender's name, email address, and message body.
3. How We Use Your Data
- To provide and operate the Service (authentication, file storage, playback)
- To process payments and manage subscriptions via Stripe
- To send transactional notifications (new comments, messages, downloads) via Resend
- To display anonymized analytics to Pro/Studio subscribers
- To improve the Service and diagnose technical issues
We do not sell your personal data to third parties.
3a. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), we process your personal data under the following legal bases as defined by the General Data Protection Regulation (GDPR):
- Performance of a contract (Art. 6(1)(b)) — account data, audio file storage, and authentication are necessary to provide the Service you signed up for.
- Legitimate interest (Art. 6(1)(f)) — anonymized analytics (device type, country, referrer) to understand how the Service is used and improve it. IP addresses are hashed and never stored in plain text.
- Legal obligation (Art. 6(1)(c)) — Stripe may retain billing records as required by financial and tax regulations.
- Legitimate interest (Art. 6(1)(f)) — transactional emails (comment and message notifications) that are strictly necessary to the operation of the Service and not used for marketing.
We do not use your data for automated decision-making or profiling.
4. Third-Party Services
We use the following third-party services to operate Wavigate:
- Supabase — database and authentication
- Cloudflare R2 — audio file storage
- Stripe — payment processing and subscription management
- Vercel — hosting and edge computing
- Resend — transactional email delivery
Each provider has its own privacy policy. We encourage you to review them.
5. Data Retention and Deletion
We retain your data for as long as your account is active. When you delete your account:
- Audio files are deleted from Cloudflare R2
- Your profile, projects, comments, and analytics data are deleted from our database
- Stripe may retain billing records as required by financial regulations
You can delete your account from the billing settings page. If you need assistance, contact us at beats@lambdabeats.com.
6. Cookies
We use cookies for authentication sessions (managed by Supabase) and to remember access to password-protected projects. We do not use tracking or advertising cookies.
7. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or export your personal data. To exercise these rights, contact us at beats@lambdabeats.com.
8. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via email or a notice on the Service. The "last updated" date at the top of this page reflects the most recent revision.
9. Contact
Questions or concerns? Reach us at beats@lambdabeats.com.