Privacy
Privacy policy
Last updated 25 July 2026
This explains exactly what Launcher Codes stores about you, why, and how to get rid of it. It's written to be read rather than to cover anyone's back, so if something here is unclear, ask.
Who is responsible
Launcher Codes, Vasagatan 10, 111 20 Stockholm, Sweden, is the data controller for this service. Contact: hello@launchercodes.com.
What is collected
If you create an account
- Your email address. Used to log you in — there are no passwords, so a one-time code is emailed to you instead.
- Anything you type in. Artist name, bio, release titles and descriptions, batch labels, and any private notes you keep on press contacts.
- Images you upload. Artist photos and cover art.
If you claim a code
- A one-way hash of your IP address. Not the address itself. It is put through a keyed hash that cannot be reversed, and exists only so the service can tell that one visitor has already taken a code without knowing who or where they are. This is the mechanism that stops one person emptying a release meant for hundreds.
- Which code you received, and when. If you were logged in, that record is linked to your account so the code shows up in your collection. If you weren't, it isn't linked to you at all.
If you join a waitlist
- Your email address, for exactly one message. It is used to tell you when that specific release has more codes, and then marked as notified so it can't be used again. It is not added to any list, newsletter or other mailing.
If you report a broken code
- The code you pasted, and a one-way hash of your IP address to limit how many reports can come from one connection per hour.
If a creator invites you as press
Creators can reserve codes for named reviewers, curators and streamers. When they do, they enter your name, optionally your email address and outlet, and may keep a private note about you. The service also records whether you opened the private link, whether you took the code, and whether the creator marked you as having covered the release.
Be aware that this data is entered and controlled by the creator, not by us — for that information they are the controller and we are processing it on their behalf. If you want it removed, ask the creator who sent you the link, or write to us and we'll pass it on.
What is deliberately not collected
- No third-party analytics, no advertising trackers, no profiling. A count of unique visits per page is kept — described below — and nothing beyond that.
- No advertising, and no data shared with advertisers. Ever.
- No tracking cookies. The only cookie set is the one that keeps you logged in, which is why there is no consent banner — an essential login cookie doesn't require one.
- No third-party fonts. Typefaces are served from this domain, so visiting a page doesn't tell Google anything about you.
- No embedded player loads on its own. See below — it takes a deliberate click.
- Your data is never sold, and never will be.
Visit counts
Creators can see how many people looked at their release and artist pages. Making that work needs some way to tell a returning visitor from a new one, so here is exactly what happens and what it can't do.
When you open one of those pages, your IP address is combined with today's date and put through a keyed one-way hash. The result is stored once per page per day, purely so a second look on the same day isn't counted twice. Your address itself is never stored.
Because the date is part of the hash, the value for the same visitor is completely different tomorrow. Visits cannot be linked across days by anyone, including us. There is no visitor record to build on, and the hashes are deleted once they're no longer needed for that day's deduplication — the counts remain, the hashes don't.
What is deliberately not recorded:
- Nothing about which pages one person looked at, or in what order.
- Nothing linking a visit to an account, even if you're signed in.
- No device, browser, referrer or location details.
- Nothing shared with any third party.
A creator sees two numbers for their own pages: unique visits in total, and unique visits in the last 30 days. Not who, not when, not from where.
Embedded players
A creator can add a Bandcamp, Ampwall or YouTube player to their release page. Those are the only three platforms allowed, and the player is always built by us from a checked reference — a creator can never paste code that runs on the page.
Nothing loads until you ask it to. You'll see a play button with the platform's name on it; only when you press it does your browser contact that platform. Until then Bandcamp, Ampwall and Google learn nothing about your visit — not even that it happened.
Press play and your browser connects to them directly, at which point their privacy policy applies to that connection and their normal logging, including your IP address, applies. YouTube embeds use the no-cookie player, which sets no tracking cookie until playback starts. We don't receive anything back from them, and we don't know whether you pressed play.
Why it's allowed (legal bases)
| What | Basis under GDPR |
|---|---|
| Your account and email login | Performance of a contract |
| Handing out and recording codes | Performance of a contract |
| Hashed IP, rate limits, captcha | Legitimate interest in preventing abuse and keeping distribution fair |
| Waitlist email | Consent, given when you enter your address |
| Press contact details | Legitimate interest of the creator running a release campaign |
Who else touches it
The service runs on a handful of providers. Each one only sees what it needs to do its job.
| Provider | What it handles |
|---|---|
| Supabase | Database, login and image storage. Data is stored in the EU (Frankfurt, Germany). |
| Vercel | Hosting and delivery, including short-lived server logs |
| Cloudflare Turnstile | The "are you a robot" check. Sees your IP and basic browser signals, and is designed not to profile or track you across sites. |
| Resend | Sending login codes and waitlist notifications |
How long it's kept
- Account data: until you ask for it to be deleted.
- Waitlist addresses: until the notification has been sent, or until you or the creator remove them.
- Claim records and hashed IPs: kept while the release exists, because that's what enforces one-code-per-person. Deleting a release deletes them.
- Uploaded images: until you replace or delete them.
Your rights
Under GDPR you can ask for a copy of your data, have it corrected, have it deleted, take it elsewhere, or object to processing based on legitimate interest. Write to hello@launchercodes.com and you'll get an answer within 30 days, usually much sooner.
One honest limitation: the hashed IP addresses cannot be traced back to a person, by us or anyone else. That means if you claimed a code without logging in, we have no way to find "your" record in order to delete it — there is nothing linking it to you. That's a consequence of storing as little as possible, not an evasion.
If you think this is being handled badly, you can complain to the Swedish Authority for Privacy Protection (IMY).
Children
This service isn't aimed at children and accounts aren't knowingly created for anyone under 13. If you believe a child has an account here, tell us and it will be removed.
Changes
If this policy changes in a way that affects you, the date at the top changes and anyone with an account is told by email. Cosmetic corrections won't get an email.
See also the terms of use and what this service is.