Privacy policy.
Last updated: July 28, 2026
Showbase is an editorial live-event calendar. Nearly all the personal data we touch is what you actively give us — an email, a follow list, an authenticated session — plus a small amount of technical data (hashed IPs, browser identifiers) we keep for security. No tracking pixels, no ad networks, no data sales. This page is the full list.
What we collect
- Email address— if you subscribe to the weekly digest. Stored to send you that digest. Unsubscribing stops all sends immediately; after that we keep the address only as a suppression record so it can't be accidentally re-added to the list. To have it fully erased, email us a deletion request or delete your account.
- Account data — if you sign in. Includes an authentication identifier from your provider, the artists/venues you follow, and a preference flag or two (e.g. digest cadence).
- Social data— if you use the friends features. Includes your @handle (if you claim one), your show history and “Going” marks (including any past shows you add by hand), your friend list and pending requests, and a personal invite-link token. See “Social features” below for exactly who can see what.
- Spotify connection — if you opt in. We read your followed artists and recent listens to suggest matching shows. We never write to your Spotify account. You can disconnect at any time from
/me. - Hashed IP addresses— when you subscribe, sign in, or hold a session, we store a salted, one-way-hashed version of your IP address for anti-abuse and rate-limiting. We never store the raw IP, and the hash can't be reversed into one.
- Browser user-agent strings — attached to authenticated sessions and push-notification subscriptions so you can recognize your own devices and we can debug delivery. Not used for profiling.
- Anonymous traffic data — we use Vercel Analytics + Speed Insights, which capture page views, referrers, and Core Web Vitals without setting tracking cookies and without identifying individual users. We also count ticket-link clicks (event, venue, city, ticketing source) with no name, email, or account attached.
What we don't collect
- No advertising or retargeting cookies on Showbase itself. One carve-out to be upfront about: when you click a ticket link, the ticketing partner's affiliate network (Impact.com) may set a cookie on the partner's own domain to attribute the sale. See the affiliate disclosure for details.
- No behavioral profiling.
- No payment information of any kind. Tickets are bought on the partner site, not on Showbase.
- No cross-site fingerprinting. Vercel Web Analytics is cookieless by default, and Showbase does not enable any mode that would identify individual visitors.
Social features
The friends features are opt-in and friends-only by design:
- Who sees your shows— only people you have mutually accepted as friends can see the shows you mark “Going” or have been to. Nothing about your attendance is public, and non-friends see nothing.
- Your controls — you can hide any single show from friends (the eye icon in your history), or turn on private mode to hide all of them, at any time from
/me/history. Removing a friend or blocking someone cuts off their view immediately, including everything they could see before. - Handles — your @handle (if you claim one) and display name are visible to signed-in users via search and your profile page, so friends can find you. Everything else on that page stays friends-only.
- Invite links— your invite link contains a random token tied to your account. Anyone you give it to can become your friend by tapping it, so share it like you'd share your number.
- Deletion — deleting your account deletes your show history, friendships, requests, and invite token along with everything else, immediately and irreversibly.
Cookies + local storage
The site uses browser localStorage to remember a few preferences (e.g. saved events, hidden venues, dismissed onboarding banners). This data never leaves your device and is not synced unless you sign in. Authenticated sessions use a standard HTTP-only session cookie set by our auth provider.
Who we share data with
Operationally, we have to share some data with the infrastructure providers that run the site:
- Vercel — hosts the application and captures anonymous analytics.
- Supabase — stores account data, follow lists, and email subscriptions.
- Resend — delivers the weekly digest email when you subscribe.
- Spotify — only if you choose to connect; we exchange OAuth tokens with their API.
- Impact.com + ticketing partners (Ticketmaster, DICE, Resident Advisor, Eventbrite, Fever) — when you click a ticket link, the partner and its affiliate network receive a click referral so a purchase can be attributed to Showbase. We never send them your name, email, or any account data.
We do not sell, rent, or trade personal data, and we do not send it to advertising platforms. Affiliate attribution (above) is the one place a third party learns anything from your visit, and all it learns is that an anonymous click came from Showbase.
Data retention
How long we keep each category of data:
- Digest subscriptions— kept while you're subscribed. After you unsubscribe, the row is kept only as a suppression record (so the address can't be re-added) until you request full deletion.
- Account data — kept while your account exists; deleted immediately and irreversibly when you delete your account, along with follows, saves, show history, friendships, invite tokens, and sessions.
- Sessions + sign-in links — short-lived by design. Sign-in links expire after 15 minutes; sessions expire after 90 days (sooner if you sign out) and are removed with your account.
- Click + view analytics— anonymous and aggregate; they contain no name, email, or account identifier, so they aren't tied to you at all.
Your rights
You can request access to, correction of, or deletion of any personal data we hold about you. The fastest way is to email hi@showbase.dev from the address on file. If you have an account, you can delete it yourself at /account; deletion is immediate and irreversible.
California residents (CCPA / CPRA), residents of the EU/UK (GDPR), and residents of any other jurisdiction with equivalent law have the right to request a copy of their data and to ask that it be deleted. Same email.
California note:Showbase does not sell personal information. The only cross-context activity is affiliate attribution — when you click a ticket link, the partner's affiliate network may set a cookie on the partner's own site. You can opt out of that by declining cookies on the partner site, and you can send a do-not-share request to hi@showbase.dev.
Children
Showbase is not directed at children under 13 and does not knowingly collect data from them. If you believe a minor has signed up, email us and we'll delete the account.
Changes
If we change this policy in a way that materially affects how we handle data, we'll update the date at the top of the page and, for subscribed users, send a note in the next digest.
Contact
Questions or concerns about privacy: email hi@showbase.dev.