Privacy Policy
Last updated: 19 August 2026. This is a plain-language summary of how we handle your data. It applies to this website and to the MadGigz app, and it is published in full at both aurasonic.es/privacy and madgigz.aurasonic.es/privacy — the two pages are the same policy.
Who we are
AuraSonic SL (CIF B24914111), Calle de Poeta Esteban de Villegas 14, 28014 Madrid, Spain, operates this website and MadGigz (madgigz.aurasonic.es), and is the data controller for the personal data described here. For anything about your data, write to info@aurasonic.es.
What we collect
Your account email and sign-in method (password, Google or Apple); your date of birth, used only to check you are 16 or older; your profile (name, username, photo, bio, and for artists the artist name and social links); the content you post; the tickets you buy, the events you save and like, and the artists you follow; messages you send us through the contact or feedback forms; and the technical minimum to keep you signed in and remember your language.
If you sell tickets, we also collect your tax identification: your legal or business name, your tax ID (a VAT number or NIF if you are established in the EU, otherwise a government-issued identification number), your country and your fiscal address. We cannot release payouts or issue you our monthly commission invoice without it, as set out in the Organiser Terms. It is never public, never shown to other users, and is visible only to our own staff for invoicing and payouts. If you only buy tickets, we never ask you for it.
Like any website, we also process IP addresses and server logs — our hosting provider and the anti-bot check at sign-up need them to keep the service available and secure. We do not use them to build a profile of you or to track you between sites.
We do not collect your precise location, and we do not track you across other companies' apps or websites for advertising.
What is public
Some information is public by design: your username, artist name, profile photo and bio, and any content you post — reels and event listings — are visible to other users. Your email, date of birth, tax identification and purchase history are never public.
What we use it for
To run the service: accounts, tickets, the feed, and notifications; to send service emails such as purchase confirmations and password resets; to confirm you meet the minimum age; to keep the platform safe by moderating reported content and preventing abuse; and to keep the records the law requires. We do not sell your data and we do not show third-party advertising.
Why we are allowed to
Under the GDPR, every use of your data needs a lawful basis. Ours are:
To perform our contract with you (art. 6.1.b) — creating and running your account, selling and delivering your tickets, paying organisers, and handling refunds.
To comply with a legal obligation (art. 6.1.c) — keeping invoicing and accounting records, collecting organisers' tax identification, and reporting to the tax authorities where platform rules such as DAC7 require it.
Our legitimate interests (art. 6.1.f) — keeping the platform secure, preventing fraud and abuse, checking that sign-ups are people rather than bots, and answering the messages you send us. We have weighed these against your rights and use the minimum data that works.
Checking you are 16 or older sits under the first two: it is a condition of our contract with you and of our obligations around minors. Where we ever rely on consent (art. 6.1.a) we will ask for it separately and you can withdraw it at any time.
Payments
Payments are processed by Stripe. We never see or store your card number. Artists' payout details are held by Stripe Connect, not by us. If you add a ticket to your phone's wallet, the pass — show, venue, date and ticket code — is stored by Apple Wallet or Google Wallet on your device, under their own terms.
Who processes it for us
We use a small set of providers to run the service: Supabase (database, sign-in and file storage), Vercel (hosting), Cloudflare (video hosting and streaming, and the anti-bot check at sign-up), Stripe (payments and payouts), Resend (email), and Odoo (this website, its contact form, and our invoicing records). Each acts on our instructions under a data-processing agreement. Show organisers are not among them: when you buy a ticket, the organiser sees only what is needed to admit you — your ticket and its check-in status, not your email. We never share fan contact details with organisers for marketing; if that ever changes, we will ask for your separate consent first. We may also disclose data where the law requires it.
Where your data is processed
We host the app and its database in the European Union. Some of our providers are established outside the European Economic Area, or support their service from outside it, so certain data may be processed in third countries — principally the United States. Where that happens we rely on the safeguards Chapter V of the GDPR requires: an adequacy decision by the European Commission where one covers the provider, and otherwise the European Commission's Standard Contractual Clauses, which each of these providers has signed as part of its data-processing agreement with us. You can ask us for a copy of the safeguards that apply by writing to info@aurasonic.es.
How long we keep it
We keep your account data for as long as your account exists.
What we do not delete is the record of what was bought and sold. Spanish commercial and tax law requires those books to be kept for up to six years, and GDPR art. 17(3)(b) allows us to keep them for that reason even after you ask for erasure. The profile attached to them is stripped of everything that identifies you, so what is left is an accounting record rather than a person.
Organisers' tax identification is kept on the same basis: it is the identity on the commission invoices we have already issued, and an invoice whose recipient cannot be identified is not a valid accounting record. It stays accessible only to our staff, for invoicing.
These records are kept for as long as those legal obligations require, and are used for accounting and tax purposes only — never for marketing, profiling or any other purpose. If you want to know what we still hold about you, ask us at info@aurasonic.es and we will tell you.
Deleting your account
You can delete your account at any time from Profile, Settings, Delete account — or by writing to info@aurasonic.es. Deleting it erases your profile: your name, username, photo, bio, social links, date of birth, the content you posted, your saved and liked events, and any artist-verification documents you submitted. Your sign-in is permanently disabled. Deletion completes after a 30-day grace period, during which signing back in cancels it. What survives, and why, is described in the section above. Full details are at madgigz.aurasonic.es/delete-account.
Your rights
You can ask for access, correction, deletion, portability, restriction of processing, or object to processing, by writing to info@aurasonic.es. You can also complain to the Spanish supervisory authority, the Agencia Española de Protección de Datos (AEPD, aepd.es).
Cookies
We use only the technical cookies strictly necessary for the service to work — keeping you signed in and remembering your language. We use no analytics cookies, no advertising cookies and no third-party trackers. Our full Cookie Policy has the detail.
Age
MadGigz is for people aged 16 or older. We do not knowingly collect data from anyone under 16.
Changes
If this policy changes, we will update this page and the date at the top, and for significant changes we will also tell you in the app.