Privacy Policy
Last updated: 2026-04-16
TourConductor is an outreach tool built by Sarah Stevens to help independent musicians book their own shows. This page explains what we collect, what we do with it, and what rights you have.
What we collect
- Your email address and name, used to create your account.
- Venue contacts you add or import (name, address, email, notes). These are your data; you own them.
- Gmail messages we read and send on your behalf, only after you explicitly authorize Gmail access via Google OAuth. We use Gmail data to match replies to venues and to let you draft outgoing email.
Where it lives
Data is stored in an SQLite database on Fly.io infrastructure in Amsterdam (EU). OAuth tokens are encrypted at rest with AES-256-GCM. Password hashes are handled by the Better Auth library.
Who has access
Only you. Sarah Stevens (the developer) has operational access to the production database for support, debugging, and maintenance. We never share your data with third parties for marketing or advertising.
Third parties we use
- Google Gmail API — to read and send email on your behalf when you authorize it.
- Resend — to send password-reset emails.
- Cloudflare — for DNS and tunnel routing.
- Fly.io — for hosting.
We don't use analytics, tracking pixels, or advertising networks.
Your rights (GDPR)
You can request access to, correction of, deletion of, or export of your data at any time. Email info@sarahstevens.net and we'll act within 7 days.
Cookies
We use a session cookie managed by Better Auth to keep you logged in. No tracking cookies.
Data controller
Sarah Stevens (individual), based in the Netherlands. Contact: info@sarahstevens.net.
Changes to this policy
If this policy changes, we'll email registered users at least 7 days before the change takes effect.