This Privacy Policy explains how Shopolo Digital Private Limited (“we”, “us”, “Shopolo”) collects, uses, stores, and protects your information when you use Cue1860 (the “Service”) at playlist.ground1860.in.
Cue1860 is a business-to-business (B2B) playlist management tool intended for use by organisations and their authorised employees. By creating an account or using the Service, you acknowledge that you have read and understood this Policy.
1. Who we are
Shopolo Digital Private Limited is a company incorporated in India. We are the data controller for personal information processed through the Service. For questions about this Policy or your data, contact us at ask@shopolo.in.
2. Information we collect
2.1 Account information
When you (or your employer) create a Cue1860 account, we collect:
- Full name
- Email address
- A password (stored as a one-way hash; we never see or store your plaintext password)
- The role assigned to your account (employee, manager, or super admin)
- The organisation you belong to, if applicable
2.2 Spotify account information (via Spotify OAuth)
When an authorised user (typically the super admin) connects a Spotify account to the Service, Spotify's OAuth 2.0 authorisation flow returns the following information to us, which we store only to operate the Service:
- An access token and a refresh token, used to make API calls on behalf of the connected Spotify account
- The Spotify user ID, display name, and email of the connected Spotify account
- The scopes (permissions) granted during authorisation
- Token expiry times
We do not collect or store your Spotify password. Authentication is handled entirely by Spotify; we never see your Spotify credentials.
2.3 Playlist content cached locally
To operate the Service efficiently and reduce calls to Spotify's API, we cache certain catalogue metadata returned by the Spotify Web API:
- Track name, artist name, album name, album cover URL
- Spotify track ID, URI, and ISRC code
- Track duration and preview URL
This metadata is provided by Spotify and is subject to Spotify's own terms. We do not download, host, or stream audio files. Playback always happens on Spotify's platform.
2.4 Usage and technical data
To keep the Service secure and reliable, we automatically log:
- Actions you take within the Service (creating, editing, approving, publishing playlists)
- Login timestamps and IP addresses
- Browser type and version
- Errors encountered by the application
3. How we use your information
We use the information we collect to:
- Provide and operate the Service (authenticate you, save your playlists, route approvals, sync to Spotify)
- Maintain the audit trail and version history that your organisation relies on
- Communicate with you about Service updates, security notices, or your account
- Diagnose technical problems and improve the Service
- Comply with legal obligations
We do not use your information for advertising, profiling for marketing, or training machine learning models.
4. Spotify integration disclosures
Cue1860 uses the Spotify Web API to read and (where authorised) modify Spotify playlists. When you or your organisation connects a Spotify account, you authorise Cue1860 to act on behalf of that account, limited to the scopes you grant during the OAuth consent flow.
You can revoke Cue1860's access to your Spotify account at any time by visiting:
https://www.spotify.com/account/apps/
Use of Spotify content within Cue1860 is also governed by Spotify's Terms of Use and Spotify's Privacy Policy. We strongly recommend you review them.
5. How we share information
We do not sell or rent your personal information. We share data only:
- With Spotify, to perform the actions you have authorised (reading playlists, creating playlists, adding tracks)
- With service providers that help us run the Service (hosting, email, error logging) under written agreements that restrict their use of the data
- When required by law, valid legal process, or to protect our rights and safety
- With your organisation, since Cue1860 is a team product; managers and super admins in your organisation can see the playlists, tracks, and activity logs you generate within the Service
6. Cookies and similar technologies
We use a small number of strictly necessary cookies to keep you logged in and to protect against cross-site request forgery. We do not use third-party advertising cookies or trackers.
7. Data retention
- Account data is retained while your account is active and for a reasonable period after deletion to comply with our legal obligations.
- Spotify OAuth tokens are retained only while your Spotify account remains connected; revoking access at Spotify or disconnecting in Cue1860 clears them.
- Cached track metadata may be retained indefinitely as it is non-personal catalogue data.
- Activity logs are retained for as long as required by your organisation's audit policies.
8. Security
We use industry-standard measures to protect your data, including TLS for data in transit, hashed passwords, encrypted credentials where possible, role-based access control, and access logs. No method of transmission or storage is perfectly secure; if we ever experience a breach that affects your data, we will notify you and the relevant authorities as required by law.
9. Your rights
Depending on the jurisdiction you reside in (including under India's Digital Personal Data Protection Act, 2023, and the EU General Data Protection Regulation where applicable), you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data (subject to legal retention obligations)
- Withdraw consent for processing (e.g. by disconnecting Spotify or deleting your account)
- Lodge a complaint with the appropriate data protection authority
To exercise any of these rights, contact us at ask@shopolo.in.
10. Children
Cue1860 is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
11. International transfers
Our infrastructure is primarily located in India. When you use Spotify integrations, your data may also be transferred to Spotify, which operates its services from Sweden, the United States, and other countries. Such transfers are subject to Spotify's own privacy practices.
12. Changes to this Policy
We may update this Policy from time to time. When we do, we will revise the “Last updated” date at the top. Significant changes will be communicated through the Service or by email.
13. Contact
If you have any questions, concerns, or requests regarding this Policy or your personal data, please contact us:
Shopolo Digital Private Limited
Email: ask@shopolo.in