Privacy Policy
Last updated: 1 June 2026
This Privacy Policy explains how ONTOUR ("ONTOUR", "we", "us") collects, uses, discloses and protects personal information when you use ontour.app and the ONTOUR application (the "Service"). ONTOUR is based in Ontario, Canada and acts as the data controller / business responsible for your personal information.
We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada, the EU/UK General Data Protection Regulation (GDPR) for visitors in the European Economic Area and the United Kingdom, and the California Consumer Privacy Act as amended by the CPRA (CCPA) for California residents.
Information we collect
- Account information: when you sign in with Google we receive your name, email address and profile photo.
- Usage data: the searches you run (the query text, search type and timestamp), which we log to enforce per-account search limits and improve the Service.
- Technical data: your IP address and basic request metadata, used for rate-limiting, security and abuse prevention.
- Marketing preference: whether you opted in to product emails at sign-up.
- Cookies: an essential session/auth cookie, a language-preference cookie, a consent cookie, and — only if you accept — Google Analytics cookies.
How we use your information and our legal bases
We process personal information to: provide and secure the Service and your account; enforce search limits and prevent abuse; respond to your requests; send product emails where you have opted in; and analyse aggregate usage to improve ONTOUR.
Under the GDPR our legal bases are: performance of our contract with you (providing the Service); our legitimate interests (security, abuse prevention, product improvement) balanced against your rights; your consent (analytics cookies and marketing emails); and compliance with legal obligations.
Cookies and analytics
Essential cookies (authentication, language and consent state) are required for the Service to function and are always active. Google Analytics is loaded only after you accept analytics cookies in our consent banner; if you decline, no analytics scripts or cookies are set.
You can withdraw analytics consent at any time by clearing the ontour_consent cookie in your browser; the banner will then reappear.
Third parties and sub-processors
We do not sell or rent your personal information, and we do not share your email with third parties for their own advertising.
We use the following processors and data sources to operate the Service:
- Supabase — authentication, database and hosting of account and usage data.
- Google — OAuth sign-in (authentication).
- Google Analytics — aggregate usage analytics (only with your consent).
- setlist.fm and Wikidata — public concert, artist and venue data we query to build results (we do not send them your personal information).
- Deezer — artist images and popularity counts (public data).
- Anthropic — AI venue-capacity estimation used only in internal admin tooling.
Data retention
We keep account information for as long as your account is active. Search logs are retained for as long as needed to enforce usage limits and improve the Service, and are deleted or anonymised when no longer required. When you delete your account we delete or anonymise the associated personal information within 30 days, except where retention is required by law.
International data transfers
ONTOUR operates from Canada and our processors may store and process data in Canada, the United States and the European Union. Where personal information is transferred outside your region, we rely on appropriate safeguards such as adequacy decisions or the European Commission's Standard Contractual Clauses.
Your rights (GDPR / UK GDPR)
If you are in the EEA or UK you have the right to access, rectify, erase, restrict and port your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time. You also have the right to lodge a complaint with your local supervisory authority. To exercise these rights, email privacy@ontour.app.
Your rights (CCPA / CPRA — California)
California residents have the right to know what personal information we collect and how it is used, to request deletion or correction of their information, and to opt out of the "sale" or "sharing" of personal information. ONTOUR does not sell or share personal information as those terms are defined under the CCPA. We will not discriminate against you for exercising your rights. You may use an authorised agent to submit a request. To make a request, email privacy@ontour.app.
Your rights (PIPEDA — Canada)
You may access the personal information we hold about you, challenge its accuracy, and withdraw consent (subject to legal or contractual restrictions). If you have an unresolved concern you may contact the Office of the Privacy Commissioner of Canada. To make a request, email privacy@ontour.app.
Children
The Service is not directed to children under 13 (or the minimum age of digital consent in your jurisdiction) and we do not knowingly collect their personal information.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, by notice within the Service.
Contact us
For any privacy question or to exercise your rights, contact our privacy team at privacy@ontour.app. ONTOUR, Ontario, Canada.