We only use anonymous usage analytics to improve the service. We do not use advertising cookies.
Install KIERTUE
Open faster from your home screen
Updated: July 14, 2026 · Version 1.9
JK Musiikkituotanto (auxiliary business name Koodisto Digital) Business ID: 2829298-1 Postal address: Matinkatu 9, FI-02230 Espoo, Finland Email: info@kiertue.com The controller of the KIERTUE application (the "Service") is JK Musiikkituotanto, under whose auxiliary business name Koodisto Digital the Service is provided (Business ID: 2829298-1). The controller is responsible for the processing of your personal data in accordance with this privacy policy and the requirements of the EU General Data Protection Regulation (GDPR, Regulation 2016/679). Dual role: controller and processor. KIERTUE acts as the controller for data relating to your user account and the operation of the Service: authentication, billing, analytics (with consent), security and service messages. This privacy policy covers that processing. However, for the personal data of third parties that you yourself enter into the Service — in particular the names of guests on guest lists and the contact details of venue and production contacts — the controller is you (or your band), and KIERTUE processes that data on your behalf and on your instructions as a processor (GDPR Art. 28). The terms of that processing are set out in the data-processing addendum of the Terms of Service.
Processing of your personal data is based on the following legal grounds: • Contract (GDPR Art. 6(1)(b)): Processing is necessary for providing the Service to you in connection with creating a user account and using the Service. • Legitimate interest (GDPR Art. 6(1)(f)): Service development, ensuring information security, preventing misuse, collecting customer feedback, customer-relationship reminders about incomplete onboarding, and email delivery management (identifying bounced and blocked addresses). You may object to processing based on legitimate interest (Art. 21). • Consent (GDPR Art. 6(1)(a)): By registering, you accept this privacy policy. Direct marketing messages (product updates and newsletter) are sent only on the basis of your separate consent, in accordance with Section 200 of the Finnish Act on Electronic Communications Services (917/2014). You may withdraw your consent at any time. AI-assisted extraction of third-party personal data and receipt of messages forwarded to a band-specific address: for these, KIERTUE acts as a processor (see section 1, dual role), so the legal basis for the processing is the responsibility of the user/band acting as controller. To the extent the processing concerns the user’s own (controller) data, the legal bases per purpose are: (1) AI-assisted extraction of production information: legitimate interest (GDPR art. 6(1)(f)) — to offer a user-initiated, optional and efficient way to enter production information; the processing covers only material the user attaches themselves and the result is always a draft approved by the user (you can object to the processing simply by not using the feature, art. 21); (2) receipt of messages via the email intake: legitimate interest (art. 6(1)(f)) on the same grounds — the address is created by the user and messages reach it only through the user’s own action; (3) technical operation of the Service, prevention of misuse and maintenance of information security: legitimate interest (art. 6(1)(f)).
We collect and process the following personal data: • Authentication data: email address, password (encrypted), sign-in method (email, Google, or Apple). • Profile data: first name and last name. • User-generated content: bands, tours, events, schedules, travel information, setlists, songs, guest lists, production info, and venue data. • Uploaded files: band logos, attachments (e.g., sound and light patches). • Subscription data: subscription type, status, and subscription store (Stripe). • Technical data: device information and log data for error resolution. • Analytics data (with consent): page views, usage events, and device information. Collected via Firebase Analytics only if the user has given explicit consent. • Email settings and consents: marketing consent (given or withdrawn, with timestamps), per-message subscription choices (product updates, tips, surveys), and email delivery status (e.g., bounced or spam-flagged messages). • Feedback and survey responses: the rating, reasons, free-text comments, and price opinion you voluntarily provide. We do not collect special categories of personal data (sensitive data).
Personal data is used solely for the following purposes: • Sending service emails: welcome message, band invitations (at the user’s request), and subscription-related notifications such as a reminder about the end of the trial period. These are messages related to providing the Service, not marketing. • Creating, managing, and securely authenticating user accounts. • Storing and syncing tour, event, and setlist data between band members in real time. • Managing subscriptions and access rights. • Technical maintenance and development of the Service. • Ensuring information security and preventing misuse. • Sending feedback surveys and processing responses to improve the Service. Surveys are voluntary and contain no sales. • Sending product updates and the newsletter if you have given your consent. • Email delivery management: we identify bounced and spam-flagged messages so we do not send to non-working or blocked addresses. • AI-assisted extraction of production information: when you attach text, a PDF file or an email to a gig, its content can be extracted with AI into a proposal of production information. The result is always a draft that a band administrator reviews and approves before it is saved — this is not automated decision-making. • Receipt and extraction of messages forwarded to a band-specific email address: a band can be given its own email address to which forwarded production messages are received, and their content is extracted in the same way into a draft of production information for an administrator to approve. We do not profile you or make automated decisions about you. We send direct marketing (product updates and newsletter) only on the basis of your separate consent, and you can withdraw it at any time via the unsubscribe link or your email settings.
The application uses Google Firebase (Firestore Database, Firebase Authentication, Cloud Storage) for data storage and processing. Due to the nature of the service, personal data may be processed and transferred outside the European Union (EU) and the European Economic Area (EEA), particularly to Google servers in the United States. Google complies with the EU-U.S. Data Privacy Framework and provides EU Commission-approved Standard Contractual Clauses (SCCs) to ensure adequate data protection in accordance with the GDPR. For other data processors operating in the United States (such as Stripe and Resend), the protection of data transfers is ensured through Standard Contractual Clauses (SCCs) approved by the EU Commission and data processing agreements (DPAs). We do not sell, rent, or otherwise disclose your personal data to third parties for marketing purposes. AI-assisted extraction of production information and cancellation-feedback reply drafts are processed with Google Cloud Vertex AI in the EU region (europe-west1): the material is processed in the EU under the regional commitments of the Google Cloud Data Processing Addendum and is not used to train AI models. For Cloudflare (USA), used to route incoming email, the primary transfer mechanism is the European Commission’s adequacy decision on the EU–U.S. Data Privacy Framework (GDPR Art. 45; Cloudflare is a framework participant), with the Commission’s Standard Contractual Clauses (SCCs) as a binding fallback under Cloudflare’s Data Processing Addendum. You may obtain a copy of the safeguards applied to transfers outside the EU/EEA — the Commission’s Standard Contractual Clauses (SCC) and, where applicable, the transfer terms of the Data Processing Agreements (DPA) — by sending a request to info@kiertue.com. Data Processing Agreements (DPA): • Google Cloud: cloud.google.com/terms/data-processing-addendum • Stripe: stripe.com/legal/dpa • Apple: apple.com/legal/privacy • Resend: resend.com/legal/dpa
The Service uses the following data processors (GDPR Art. 28): • Google Firebase (Google LLC, USA): Database, cloud storage, authentication, and cloud functions. Privacy policy: https://firebase.google.com/support/privacy • Google reCAPTCHA v3 (Google LLC, USA): Automatic bot protection in the web application. reCAPTCHA collects device and browser information (IP address, browser type, interaction data) to prevent abuse. The service operates invisibly and requires no user action. Privacy policy: https://policies.google.com/privacy • Apple App Attest (Apple Inc., USA): Automatic app integrity verification in the iOS application. The service sends device information to Apple to verify that requests originate from a genuine application. • Stripe Inc. (USA): Payment processing and subscription management. Stripe stores payment card details and invoice history in its own systems. Upon account deletion, Stripe customer data is automatically deleted, but Stripe retains invoice history as required by accounting obligations. Privacy policy: https://stripe.com/privacy • Apple Inc. (USA): Sign-in option (Sign in with Apple). • Google Analytics for Firebase (Google LLC, USA): Usage analytics for service development. Data is collected only with the user's explicit consent. Data collected: page views, usage events, device information. Consent is requested separately and can be withdrawn at any time. Privacy policy: https://firebase.google.com/support/privacy • Resend Inc. (USA): Delivery of service and lifecycle emails (welcome message, band invitations, subscription and onboarding reminders, feedback surveys, and consent-based product updates and newsletter). Data processed: name, email address, language preference, and message delivery status (e.g., bounced or spam-flagged messages) for delivery management. Emails are sent from servers located in the EU. When a user sends a band invitation by email, the recipient address is used solely to deliver the message and is not stored in the service. Privacy policy: https://resend.com/legal/privacy-policy • Google Cloud Vertex AI – Gemini (Google LLC / Google Cloud, processed in the EU region europe-west1): (1) AI-assisted extraction of production information from attached text, a PDF file or an email into a draft; (2) generation of a reply draft based on cancellation feedback. The material processed may contain personal data. The material is not used to train the model. Data processing terms (DPA): https://cloud.google.com/terms/data-processing-addendum • Cloudflare, Inc. (USA): Receipt and routing of messages forwarded to a band-specific email address (in.kiertue.com) (Email Routing / Workers). Incoming messages may contain third-party personal data. Transfer mechanism: EU–U.S. Data Privacy Framework (Cloudflare is a framework participant), with EU Standard Contractual Clauses (SCCs) as a binding fallback under Cloudflare’s Data Processing Addendum. Handled messages are automatically deleted 90 days after receipt (see section 8). Privacy policy: https://www.cloudflare.com/privacypolicy/ All processors comply with GDPR requirements and have committed to appropriate data protection measures. Use of AI for travel and train lookups (no personal data): The Service uses Google Gemini (Google LLC, USA) for the automatic lookup of flight and train details (the Look up feature). Only non-personal lookup data is sent to the interface — the vehicle number, the date, and public station and airport names — never names, passenger lists, emails, or other personal data. It therefore does not constitute processing of personal data under Article 28. Privacy policy: https://ai.google.dev/gemini-api/terms AI-assisted extraction of production information (Google Cloud Vertex AI): When you ask the Service to extract production information from text, a PDF file or an email you have provided, the content is processed with Google Cloud Vertex AI (the Gemini model) in the EU region (europe-west1). The material you submit may contain third-party personal data (for example the names, phone numbers and email addresses of contacts), so this constitutes processing of personal data under Article 28. The Service is configured so that the material is not used to train the AI model. The result of the extraction is always a draft that a human (a band administrator) reviews and approves before it is saved. This processing is covered by the Google Cloud Data Processing Addendum (DPA). AI-assisted processing of customer feedback (Google Cloud Vertex AI): When your subscription is cancelled and you leave free-text feedback about the reason, a service administrator may use AI to draft a personal reply to you. The feedback text you provide is processed with Google Cloud Vertex AI (the Gemini model) in the EU region (europe-west1); the text is not used to train the AI model. The reply is always a draft that an administrator reviews and edits before sending — this is not automated decision-making. Legal basis: legitimate interest (GDPR art. 6(1)(f)) in managing the customer relationship and developing the Service. Address geocoding and routing: When you add a travel or venue address, it is sent to geocoding and routing services to compute coordinates, driving routes, distances, and the time zone. The web app uses OpenStreetMap Nominatim (geocoding) and OSRM (routing) — open services with their own terms and privacy policies. The iOS app uses Apple’s map service (Apple Inc., USA). Only the entered address or coordinates derived from it are transmitted — never names, passenger lists, emails, or other data. If an entered address (for example a departure point) constitutes personal data, it is used solely to compute the route and coordinates. OpenStreetMap privacy: https://osmfoundation.org/wiki/Privacy_Policy
The Service does not use third-party tracking cookies without consent. Cookies and local storage are divided into two categories: Necessary (no consent required): • Firebase Auth sign-in identifiers — maintaining the authentication state. • Browser local storage (localStorage): kiertue_consent_v2 (your consent choice), kiertue_lang and other preferences (language, time format, timezone), and kiertue_offline_* (offline cache for the week's shows). • Google reCAPTCHA v3 cookies (e.g. _GRECAPTCHA) to ensure the proper functioning of bot protection. These are strictly necessary for the functioning and security of the Service and do not require separate consent. Analytics (only with consent): • Google Analytics 4: _ga cookies and analytics identifiers are set only if you accept analytics in the cookie banner or app settings. Data collected includes page views, usage events (e.g. login, event creation), device information and basic browser data. The data is used for service development — we do not use it for advertising, profiling, or automated decision-making. Withdrawing consent immediately stops collection. Consent log: consent choices are recorded to fulfil the GDPR accountability obligation (Art. 7). The log stores the choice (accepted/declined per category), a timestamp, the consent version and the platform (web/iOS). No IP address is stored — only an anonymised identifier is derived from the request. Log entries are retained for a maximum of 24 months. You can change or withdraw your choice at any time in the app settings or via the Cookie settings link in the site footer. The iOS application stores settings in the device local storage (UserDefaults).
Personal data is retained as long as your user account is active and the Service is in use. You can delete your account and all associated data at any time: • From the application settings by selecting "Delete account". • By contacting us via email: info@kiertue.com When your account is deleted: • All your personal data is permanently removed from the database. • If you own bands, you must first transfer ownership to another member or delete the band. • Any active Stripe subscription is automatically cancelled. • Your Stripe customer data (card details, contact information) is deleted. Stripe retains invoice history as required by accounting obligations. • Band data remains available to other members if the band has other members. Deletion is carried out without undue delay, within 30 days of the request at the latest. Retention periods: • Event and tour data is retained as long as the band is active • Archived tours are retained until the band owner deletes them • Stripe invoice history: 6 years (Finnish Accounting Act 1336/1997) • Server logs: ~30 days (Google Cloud Logging) • Survey and feedback responses: data linked to you (identifier and email address) is removed when your account is deleted; anonymous feedback may be retained to develop the Service • Consent and email-settings data: for the lifetime of the account as a record of consents given and withdrawn; removed when your account is deleted • Incoming emails (band-specific address): we store the subject, sender, text content and the AI-extraction result (not the original message file or attachments). Unprocessed messages remain in the band admin’s triage queue until handled; handled messages are automatically deleted 90 days after receipt • Text or PDF attached in the app (AI fill): not stored — processed in memory only for the extraction. The extraction result is saved as a draft that an admin approves or rejects • Production-information drafts: rejected drafts are automatically deleted 90 days after rejection. The data of an approved draft becomes part of the gig’s production information, and the approval record is retained as part of the gig’s data (deleted when the gig is deleted) • AI-extraction material (Google Vertex AI): KIERTUE does not retain the material after extraction. Google may hold the material in a short-lived cache (in memory only, not on disk; up to 24 hours; stays in the selected EU region) to speed up the service, and does not use the material to train AI models
Under the EU General Data Protection Regulation, you have the following rights: • Right of access (Art. 15): You may request a copy of all personal data concerning you. • Right to rectification (Art. 16): You can correct inaccurate or incomplete data directly in the application or by contacting us. • Right to erasure (Art. 17): You can request deletion of all your data ("right to be forgotten"). • Right to restriction of processing (Art. 18): You can request restriction of processing in certain situations. • Right to data portability (Art. 20): You can request your data in a machine-readable format. • Right to object (Art. 21): You can object to processing based on legitimate interest. • Right to withdraw consent (Art. 7): You can withdraw marketing consent at any time via the unsubscribe link or your email settings — without deleting your account. You may also withdraw other consents and delete your account entirely. All requests are processed without undue delay, within one month at the latest. Contact: info@kiertue.com
We protect your personal data with appropriate technical and organizational measures: • All data transmission is encrypted (TLS/HTTPS). • Passwords are stored encrypted (Firebase Authentication). • Database access is restricted by security rules (Firestore Security Rules). • File storage is protected by access restrictions (Firebase Storage Rules). Any data breaches will be reported to the supervisory authority within 72 hours (GDPR Art. 33) and to data subjects without undue delay if the breach is likely to result in a high risk to rights and freedoms (GDPR Art. 34). Technical server logs may contain user identifiers (user ID, email) for debugging purposes. Logs are automatically deleted after approximately 30 days.
The Service is not directed at persons under 16. This is the Service’s own minimum age — KIERTUE is intended for professional tour management, and its use is based on a contract, not on a child’s consent. We do not knowingly collect personal data from persons under 16. If we become aware that we have collected data from a person under 16, we will delete it without delay.
We reserve the right to update this privacy policy. The updated policy is published in the Service, and significant changes will be separately communicated via an in-app notification or by email. We recommend reviewing this policy regularly. The updated policy takes effect on the date of publication.
For all questions and requests regarding personal data processing, please contact: JK Musiikkituotanto (auxiliary business name Koodisto Digital) Business ID: 2829298-1 Postal address: Matinkatu 9, FI-02230 Espoo, Finland Email: info@kiertue.com If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority: Office of the Data Protection Ombudsman (Finland) Visiting address: Lintulahdenkuja 4, 00530 Helsinki, Finland Postal address: P.O. Box 800, 00531 Helsinki, Finland Email: tietosuoja@tietosuoja.fi Phone: +358 29 566 6700 Website: tietosuoja.fi
When using KIERTUE as a Venue Manager, we collect and process the following additional information: 14.1 Data collected: - Venue name, address, and contact information (data you provide) - Official profile: contact person, phone number, email, technical details, description, website - Team members' email addresses and roles - Gig-specific technical notes and driving instructions (data you provide) - Subscription data (Stripe): payment transactions, subscription period 14.2 Purpose: - Displaying the gig calendar with bands' permission - Maintaining the venue's official profile - Subscription management and billing - Service development 14.3 Data sharing: - Bands can see your official profile if they have approved its use - Team members can see gigs marked for the venue - Stripe processes payment data (see Stripe Privacy Policy: stripe.com/privacy) 14.4 Retention period: - Venue data is retained as long as the account is active - Upon subscription cancellation, data is deleted within 30 days upon request 14.5 Your rights: - You have the right to request deletion of your data (GDPR Art. 17) - You can export your data under GDPR Art. 20 by requesting it at info@kiertue.com