Wristband

Privacy Policy

Last updated 5 September 2026 · Applies to the Wristband app for iOS, Android and web

The short version

What matters most, in plain language

1. Who we are

Wristband ("we", "our", "us") is a private tool for musicians and the people who work with them — managers, agents and crew. It keeps a team's shows, venues, contacts, schedules, setlists, stage plots and internal messages in one place. This policy explains what the app collects, who else handles it, and what you can ask us to do with it.

It covers the Wristband app — on iOS, Android and the web — and the systems behind it. It does not cover anything you reach by tapping a link out of the app — a ticketing site, a map, a social platform — each of which has its own policy.

2. What we collect

Your account

What you put into the app

Everything you create is stored so your team can see it and so it's there when you come back:

Contacts you import

If you use the CSV import, you're uploading details about people who may not be Wristband users. We store that information on your team's behalf and don't use it for anything else. You are responsible for having a legitimate reason to hold those contacts.

Device and technical information

Subscription status

If you subscribe, we store which tier you're on. We never see or store card numbers or billing addresses — payment is handled entirely by Apple or Google, and our subscription provider tells us only whether an entitlement is active.

3. What we don't collect

There is no analytics package, advertising software, or third-party tracking code in Wristband. We don't collect an advertising identifier, we don't track your location in the background, we don't build a profile of your behaviour, and we don't sell or rent anything about you to anyone.

4. What your team can see

Wristband exists so a team can share information, so most of what you create is visible to your teammates. Access is enforced at the database level: people on one artist's team cannot read another artist's data. Within a team, what you can see and change depends on your role — admin, manager or artist. Direct messages are visible only to the people in that conversation.

If you leave or are removed from a team, the work you contributed to that team's shared records stays with the team.

5. Files you upload

Stage plots, post media and profile photos are stored at public web addresses. The links are long and unlisted, so they aren't discoverable by browsing or search, but they are not protected by a password or login. Anyone you send a link to — or anyone who obtains one — can open that file. Please don't upload anything through Wristband that would cause harm if it were seen outside your team.

6. Messages, and what "remove" means

When you remove a conversation from your inbox, it disappears from your view but the messages themselves are not deleted from our servers, and other participants keep their copy of the thread. We're telling you this plainly because "delete" in most apps implies erasure and here it does not. If you want message content genuinely erased, ask us using the contact details below.

7. Who else handles your data

We use a small number of outside services to run Wristband. Each receives only what it needs to do its job.

ServiceWhat it doesWhat it receives
Supabase Database, sign-in, file storage and live sync, running on Amazon Web Services Effectively everything in section 2
Expo Builds the app, delivers updates, and relays push notifications Push tokens and notification contents
Apple Push Notification service Delivers notifications to iPhones and iPads Push token and notification contents
Google Firebase Cloud Messaging Delivers notifications to Android devices, where enabled Push token and notification contents
RevenueCat Tracks whether a subscription is active An anonymous account identifier and purchase status
Apple App Store / Google Play Processes subscription payments Your payment details, which never reach us
Bandsintown Fills in show details when you paste a ticket link The link or artist name only. The request is made by our server, so your device and IP address are not exposed.
OpenStreetMap (Nominatim) Venue search The venue or place text you type into the search box
ipwho.is Detects your approximate country so venue results are nearer to you Your device's IP address. We store only the resulting country code, and only for the current session.

8. Permissions the app asks for

9. Keeping and deleting your data

We keep your information for as long as your account is active, because the app's purpose is to hold a record of your shows and your team's work over time. Some records — a past show, a bulletin the team relied on — remain with the team after you leave it.

You can delete your account from Settings, or ask us to do it. Either way we erase your profile and profile photo, your personal calendar and any calendar sharing, the messages you sent, and your feedback, and we remove you from every team. Records your team still depends on — a past show, a task someone else has to finish, a file you added to a shared library — stay with the team, no longer linked to you. If you were the last admin of a team, another member is made admin so the team isn't stranded; if you were its only member, the team and its contents are deleted with your account. To ask us instead, email feedback@wristband.app from the address on your account and we'll do it within 30 days and confirm when it's done.

10. Your rights

Wherever you live, you can ask us to:

Email feedback@wristband.app and we'll respond within 30 days. We won't charge you or treat you differently for asking. If you're in the UK or EU, you also have the right to complain to your data protection authority.

11. Children

Wristband is a professional tool and isn't directed at children. We don't knowingly collect information from anyone under 16. If you believe a child has created an account, contact us and we'll remove it.

12. Where your data is processed

Our database and files are hosted in the United States. If you use Wristband from elsewhere, your information is transferred and processed there, under the safeguards our providers maintain for international transfers.

13. Security

Data is encrypted in transit and at rest, and access between teams is enforced by the database itself rather than by app code alone. No system is perfectly secure, and the sharing behaviour described in sections 4 and 5 is by design rather than a flaw — please read those two sections before uploading anything sensitive.

14. Changes to this policy

If we change how we handle your information, we'll update this page and change the date at the top. For anything significant, we'll tell you in the app.

15. Contact

Questions, requests, or anything that looks wrong: feedback@wristband.app, or use the feedback form in the app's settings.