Privacy Policy — Lisnin Party

Last updated: 2026-05-25

What this policy covers

This policy describes the data Lisnin Party (a feature of Lisnin.io) collects when you opt in as a listener inside a partnered Discord community, or when you launch a campaign as an artist. The general Lisnin platform privacy policy applies in addition to this one.

Listener data

When you connect your accounts via /start we store:

  • Discord identity — your Discord user ID, username, and (if you grant the scope) email address.
  • OAuth tokens — Discord + Spotify access + refresh tokens, encrypted at rest with AES-256-GCM.
  • Spotify identity — your Spotify user ID. One Spotify account per Lisnin account (anti-fraud).
  • Verified listens — each row carries the track ID, played_at timestamp, and which campaign credited it. We do NOT store anything else about your listening history.
  • Monthly points rollup — your point total per community per month, used to seed the raffle.
  • If you win a prize — the shipping address (for physical prizes) or delivery handle (for digital) you submit on the claim form, plus IP + a browser fingerprint hash for duplicate-claim detection.

What we do NOT store

We deliberately don't persist things we don't need:

  • Your Discord presence events. We receive them, filter for relevance, and discard.
  • Your full Spotify listening history. We only see the items returned by /v1/me/player/recently-played that match an active campaign track.
  • Your messages on Discord. The bot has no message-content intent.

Why we collect it

  • Verify listens against Spotify's own API (anti-fraud).
  • Award points per the published rules (10/3/5 ladder, 50-stream cap).
  • Run the monthly raffle and notify winners.
  • Send prize claims + fulfill them.
  • Audit logging for ops + compliance (who claimed what, when, from what IP).

How long we keep it

  • Listening history (`streams`) — 12 months rolling. After 12 months individual stream rows are purged by a nightly cron. Aggregated monthly_points rollups are retained indefinitely so raffle history stays auditable.
  • OAuth tokens — until you disconnect or request deletion. Revoked tokens are deleted immediately.
  • Prize-claim PII — retained as long as tax-records law requires (typically 7 years in most jurisdictions). Shipping addresses are purged 90 days after fulfillment unless required for a return.
  • Audit events — indefinitely. These are the compliance backbone.

Your rights

You can, at any time:

  • Export your data — visit Settings → Privacy → Download my data. We email you a JSON archive within minutes.
  • Delete your account — Settings → Privacy → Delete my account. We queue a 30-day deletion window (so you can cancel) and then anonymise every row tied to you. Audit events keep your USER ID as a string for compliance, but no other PII survives.
  • Disconnect Discord or Spotify — Settings → Connections. This stops future verification immediately.
  • Opt out of community pings — run /notifications in Discord to remove the Party Listener role.

Third parties we share with

  • Stripe — for artist token purchases. Stripe receives only what's needed to process payment (card details never touch our servers).
  • Resend — for outbound emails (raffle winner notifications, deletion confirmations).
  • Spotify — your OAuth grant authorises us to read your recently-played items. Nothing else.
  • Discord — your OAuth grant authorises us to read your identity + guild list. Nothing else.
  • Sentry — error reports, PII-scrubbed before upload.

We don't sell your data. We don't run advertising. We don't cross-sell to other artists' campaigns based on what you've listened to.

Jurisdiction-specific notes

GDPR (EEA + UK)

Lawful basis: your consent (via the connect flow) and our legitimate interest in running an anti-fraud listen-verification service. Withdraw consent at any time via the disconnect or delete flows above.

PIPEDA (Canada)

We process personal information only for the purposes described above. To file a complaint about how we handle your data, contact privacy@lisnin.io first; if unresolved, you can escalate to the Office of the Privacy Commissioner of Canada.

CCPA / CPRA (California)

We don't sell or share your personal information in the sense those laws use. You retain the right to know, delete, and opt-out — exercise it via Settings → Privacy.

Contact

Questions, requests, or complaints: privacy@lisnin.io

See also: Terms of Service.