Privacy Policy
Last updated: September 28, 2026
PlaceMint ("we," "our," or "us") is operated by No Labels Necessary LLC. This Privacy Policy explains what information we collect when you use placemint.us (the "Service"), how we use it, and the choices you have.
1. Information we collect
We collect only the information needed to provide the Service:
- Account info: email address, password (hashed), and — if you sign in with Google — basic profile information returned by Google (name, profile picture, Google ID).
- Artist profile: artist name, monthly listener count, genres, similar artists, release details, and project themes you enter during onboarding.
- Usage data: platforms you save, skip, or flag; campaign status; budget allocations; outreach notes you write.
- Payment data: handled entirely by Stripe — we never see your card number. Stripe sends us a confirmation event so we can grant access.
- Analytics and advertising data: pages you visit, buttons you click, the campaign link that brought you here, and — for advertising measurement — a browser ID, an ad click ID, your IP address, and a hashed email when you sign up or buy. See sections 3 and 4.
2. How we use it
- To match you with the most relevant platforms based on your sound, stage, and goals.
- To remember your progress so you can resume where you left off.
- To process subscription payments and grant access to paid features.
- To communicate with you about your account, the Service, and (with your consent) product updates.
- To understand how the Service is used and to measure our own advertising, including reaching people who have visited PlaceMint (see sections 3 and 4).
- To improve the matching algorithm in aggregate — we do not sell or rent your data.
3. Third parties
We use the following processors to operate the Service. Each handles data under its own privacy terms:
- Supabase — authentication and database hosting.
- Vercel — application hosting and analytics.
- Stripe — payment processing.
- Google — OAuth sign-in (only if you choose "Continue with Google").
- OpenAI — generates embeddings of your project description to power semantic matching. Project text is sent to OpenAI; we do not include your email or name.
- Meta (Instagram Graph API) — used to fetch public metrics for platforms in our directory. We do not access your personal social accounts.
- Meta (Pixel and Conversions API) — advertising measurement and audiences. Separate from the Graph API entry above: the Pixel runs in your browser, and our server reports sign-ups and purchases to Meta so we can measure our ads and reach people who visited PlaceMint. Every event we send to Meta carries Meta's Limited Data Use flag (see section 4).
- PostHog — product analytics (which pages and features get used, where the sign-up funnel drops off). Events are sent through our own domain to PostHog's US servers.
- Resend — transactional email delivery.
4. Cookies and session storage
We set three kinds of cookies:
- Session cookies (first-party): keep you signed in. Signing out ends your session.
- Analytics cookies (first-party): one cookie remembers the campaign link and page that first brought you to PlaceMint (kept for about 90 days), and PostHog sets a cookie so it can tell your visits apart. Neither is shared with advertisers.
- Advertising cookies (Meta): the Meta Pixel sets cookies that identify your browser and the ad you clicked, so Meta can measure our ads and show them to people who visited PlaceMint. Meta may combine this with your Meta account under its own privacy policy.
Your choices. You can control how Meta uses this data at Meta's ad preferences, and opt out of interest-based advertising across many companies through the Digital Advertising Alliance and the Network Advertising Initiative. Blocking or clearing cookies in your browser also works, though you will be signed out.
Limited Data Use. We send Meta's Limited Data Use flag with every Pixel and Conversions API event, which tells Meta to restrict how it uses your data where California's privacy law applies.
No cookie banner. The Service is offered in the United States, so we do not show a cookie consent banner. If we ever offer the Service in the EU or UK, we will add a consent flow for those visitors first.
5. Data retention
We retain your account data as long as your account is active. If you delete your account, we remove your personal information from our active databases within 30 days. Aggregated, non-identifiable analytics may be retained for product improvement.
6. Your rights
You can request access, correction, or deletion of your personal data at any time by emailing the address below. If you're in the EU, UK, or California, you have additional rights under GDPR / CCPA — same email works.
7. Security
Data is transmitted over HTTPS. Passwords are hashed by Supabase Auth using industry-standard algorithms. Service-role keys are never exposed to the browser. We follow OWASP best practices for input validation, rate limiting, and row-level security on every database table.
8. Children
The Service is not directed at anyone under 16. We do not knowingly collect data from minors.
9. Changes
If we make material changes to this policy, we'll post the updated version here and update the "Last updated" date at the top.
10. Contact
Questions, requests, or concerns: nolabelsnecessaryadmin@gmail.com