Legal · GDPR

Privacy Policy

Last updated: August 25, 2026

This Privacy Policy explains how ChromaShift ("the Service", "we") collects, uses, and retains personal data of users who create an account on chromashift.qzz.io, in accordance with Regulation (EU) 2016/679 ("GDPR").

01

Data Controller

The data controller is:

Stefano Ceriani
Contact email: privacy@chromashift.qzz.io

02

Data We Collect

2.1 · Account data

When you register, we collect:

  • Email — used for login, two-factor authentication, and account-related communications (e.g. password reset)
  • Password — stored exclusively as a cryptographic hash. No administrator or team member can view your password in plain text
  • Spotify User ID — used to link your preferences and custom presets to your Spotify account and enable cloud sync across devices

2.2 · Usage logs 3 months

To keep the Service running, we log the actions you take within ChromaShift, including: activating a preset; creating, editing, and deleting custom presets; enabling community features; cloud synchronization (push/pull).

These logs are retained for up to 3 months, after which they are automatically deleted.

2.3 · Moderation logs indefinite

When an account is sanctioned (ban, content/preset removal, etc.), we record: the reason for the action; the duration of the action; the email of the account involved; the Spotify User ID of the account involved.

Unlike standard logs, this data is retained indefinitely. This is necessary to make disciplinary actions effective: a banned account will permanently lose access to ChromaShift, and retaining this data allows us to prevent ban evasion through new registrations.

2.4 · What we do not collect

We do not log IP addresses, geolocation/location data, or other categories of sensitive data, except for what the user voluntarily provides or what is strictly necessary to deliver the Service (e.g. email).

03

Legal Basis for Processing

  • Performance of a contract (Art. 6(1)(b) GDPR): for account creation and management, authentication, and cloud sync
  • Legitimate interest (Art. 6(1)(f) GDPR): for usage logs (service security and operation) and moderation logs (abuse prevention and ban enforcement)
04

Data Recipients & Third-Party Transfers

Your data may be processed by the following providers, acting as data processors:

  • Resend — for sending system emails (account verification, two-factor authentication, password reset)

We do not sell or share your data with third parties for advertising purposes.

05

Data Security

Passwords are stored exclusively as hashes and are never accessible in plain text, not even by the Service's administrators. We adopt reasonable technical measures to protect data from unauthorized access.

06

Consequences of a Ban

If your account is banned, your access to ChromaShift is permanently revoked. The record of the action (reason, duration, email, Spotify User ID) remains stored indefinitely for the purposes described in section 2.3.

07

Your Rights

As a data subject, you have the right to:

  • access your personal data
  • request rectification or updating
  • request erasure (except for data retained for moderation purposes, as described in section 2.3)
  • restrict or object to processing
  • request data portability
  • lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or your local supervisory authority

To exercise these rights, write to: privacy@chromashift.qzz.io

08

Minors

The Service is not intended for users below the minimum age required by their country's law to independently consent to the processing of personal data.

09

Changes to this Policy

This policy may be updated over time. Material changes will be communicated via the website or by email.

10

Contact

For any questions regarding the processing of your data: privacy@chromashift.qzz.io