Privacy Policy
Last updated: 28 March 2026
This policy explains what personal data VoicingLab collects, why we collect it, and your rights under UK data protection law. We've written it in plain English — no legalese.
Who we are
VoicingLab is operated from the United Kingdom. If you have questions about your data or this policy, you can reach us through the website.
What data we collect and why
Account data
- What:
- Email address, hashed password
- Why:
- To create and manage your account and provide personalised features
- Legal basis:
- Contract performance (necessary to provide the service you signed up for)
- Retention:
- Until you delete your account
Analytics data (only with your consent)
- What:
- Pages visited, features used, session duration, approximate location (country level), device type, browser type
- Why:
- To understand how people use VoicingLab and improve the product
- Legal basis:
- Consent (you can opt in or out at any time via our cookie banner)
- Retention:
- 14 months (Google Analytics 4 default)
We use Google Analytics 4. Google acts as a data processor. See Google's privacy policy. We do not use this data for advertising or share it with advertisers.
Practice session data
- What:
- Which voicings you've practiced, scores, session timestamps, MIDI input data during practice
- Why:
- To track your progress and provide personalised recommendations
- Legal basis:
- Contract performance
- Retention:
- Until you delete your account
Payment data
- What:
- Payment details are processed by Stripe. We do not store your card number. We receive: name, email, subscription status, payment history
- Why:
- To process payments and manage subscriptions
- Legal basis:
- Contract performance
Cookie consent records
- What:
- Anonymous session ID, consent choices, timestamp
- Why:
- To comply with UK law and demonstrate valid consent
- Legal basis:
- Legal obligation (PECR compliance)
- Retention:
- 18 months
Your rights under UK GDPR
You have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data (delete your account)
- Restrict processing of your data
- Port your data to another service
- Object to processing of your data
- Withdraw consent for analytics at any time via the cookie settings in our footer
To exercise any of these rights, contact us through the website. We will respond within 30 days.
Data sharing
We do not sell your data. We do not use your data for advertising.
We use the following categories of third-party processors:
- Google — analytics (only with your consent)
- Database hosting provider — stores account and practice data (United Kingdom)
- Stripe — payment processing
- Hosting provider — serves the website
All processors have appropriate data processing agreements in place.
International data transfers
- Account and practice data is stored in the United Kingdom
- Google Analytics data may be processed in the US (Google LLC is certified under the UK Extension to the EU-US Data Privacy Framework)
- Our hosting provider may use US-based infrastructure (covered by standard contractual clauses)
Security
- All data is transmitted over HTTPS
- Passwords are hashed and never stored in plain text
- Database access is controlled via strict access control policies
- Regular security updates are applied to all dependencies
Changes to this policy
We may update this policy from time to time. Material changes will be communicated via the website. This policy was last updated on 28 March 2026.
Complaints
If you're unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint.