Privacy Policy

Datenschutzerklärung gemäß Art. 12–14 DSGVO. Last updated: September 2026.

1. Controller

Oliver Belavic, Karl-Marx-Straße 196, 12055 Berlin, Germany. Contact: contact@powergate.me. See the Imprint for full details.

2. Scope

This policy covers PowerGate itself (powergate.me): creator accounts, gate pages fans visit, and the data each generates. It does not cover SoundCloud, Spotify, or Instagram themselves — those platforms have their own privacy policies, which apply whenever you interact with them directly (including their embedded players and sign-in screens).

3. Who this applies to — Creators and Fans

PowerGate has two distinct groups of people, and we process different data for each:

  • Creators — artists/labels who register an account to build gates. This is a normal account relationship (Art. 6(1)(b) GDPR — necessary to provide the service you signed up for).
  • Fans — visitors who open a gate link to unlock a download. Fans never need a PowerGate account.

4. Data we collect — Creator accounts

  • Name, email address, password (stored hashed, never in plain text)
  • Profile picture, if uploaded (stored on Cloudflare R2)
  • Region/country, if set (used to place your gates on the leaderboard by region)
  • Billing address fields, if filled in (currently unused — no paid plans are live yet)
  • The gates you create and their settings, and aggregate stats about them (download counts, storage used)
  • Marketing email consent — an explicit opt-in checkbox, unchecked by default, that you can turn on or off any time in account settings

Legal basis: Art. 6(1)(b) GDPR — performance of the contract you enter into by creating an account. Marketing emails specifically are sent only with your separate consent under Art. 6(1)(a), which you can withdraw at any time.

5. Data we collect — Fans using a gate

  • Email address — only if the creator has turned on the email step for that gate.
  • SoundCloud identity — if a gate requires a SoundCloud repost/like/comment/follow, you sign in with SoundCloud through a standalone flow. This does not create a PowerGate account — no name, password, or profile is stored on our side beyond a short-lived access token (kept in an httpOnly cookie, valid up to a year, scoped only to performing that one verification) and your public SoundCloud username.
  • Spotify / Instagram follow confirmation — self-reported by you clicking “I followed”. We do not receive any data from Spotify or Instagram for this — no login, no OAuth, no account connection happens for these two platforms.
  • Usage data for the gate itself — which steps you completed, how long it took from opening the gate to finishing, and a browser/OS string derived from your User-Agent header (e.g. “Chrome · Android”) so the creator can see roughly what device fans use. We do not log or store IP addresses in our own database. (Our hosting provider, Vercel, may process IP addresses transiently at the infrastructure level to serve requests and for security/anti-abuse purposes, under its own privacy policy — this is not something PowerGate itself stores or has access to.)

Legal basis: Art. 6(1)(b) GDPR (providing the download you're requesting) for the core gate mechanics; Art. 6(1)(f) (legitimate interest — abuse prevention, keeping the service working) for technical/security data like the browser string.

6. What creators can see about fans who used their gate

A creator sees, per gate they own: the fan's SoundCloud username or email (whichever identity was available), which steps they completed, and the date — for both completed downloads and gates that were opened but never finished. Creators do not see anything beyond this (no IP address, no precise location, no browser/device info, no data from Spotify or Instagram accounts).

6a. Platform-operator access

PowerGate's operator (see Imprint) has an internal admin view covering every gate on the platform, not just their own — including the additional browser/device and timing detail described in section 5. This exists for running the service (support, abuse prevention, debugging) and is not visible to creators. Legal basis: Art. 6(1)(f) GDPR — legitimate interest in operating and securing the platform.

7. Controller/processor relationship for fan data

For the core mechanics of running a gate (checking whether required steps are done, serving the download), PowerGate acts as the data controller — we decide how the gate mechanism works. Once a fan's email or SoundCloud username is shown to the creator in their dashboard, the creator becomes responsible for what they do with that data going forward (e.g. if they were to email fans directly outside of PowerGate). PowerGate does not currently offer creators an email export or marketing tool — collected emails are visible in the dashboard but not otherwise distributed by us.

8. Cookies

Across the main site (accounts, gate pages) PowerGate uses only functional cookies, strictly necessary for the site to function (§25(2) TTDSG):

  • A session cookie for logged-in creator accounts (NextAuth, JWT-based)
  • Short-lived cookies during the SoundCloud sign-in flow (OAuth state/verifier), and a longer-lived one (sc_fan_token) holding your SoundCloud access token once verified, so you don't have to re-verify every visit
  • A language-preference cookie if you use the site's translation feature (Google Translate)

Gate pages (powergate.me/g/…) and release smart-link pages (powergate.me/r/…) additionally load the Meta Pixel, which sets an advertising/measurement cookie (_fbp) and passes data to Meta — see section 9. These are the only page types where a non-functional cookie is used; the creator dashboard, account area and the rest of the site do not.

9. Analytics and ad measurement

Site-wide: Vercel Analytics, a privacy-focused, cookie-free tool that reports aggregated page-view counts without tracking individual visitors across sites. We do not use Google Analytics anywhere on the site.

Gate pages (powergate.me/g/…) and release smart-link pages (powergate.me/r/…): these pages load the Meta Pixel (Facebook/Instagram). Its purpose is to measure which of the operator's ad campaigns bring visitors to these pages, how many complete a gate or click through to a streaming service, and to build audiences for further ads. When you open such a page, complete a gate, or click a platform button, the pixel sends to Meta: your IP address, browser and device information, the page URL, the artist / gate / streaming platform involved, and the _fbp cookie identifier. Recipient: Meta Platforms Ireland Ltd., with onward transfer to Meta Platforms, Inc. (USA) under the EU–US Data Privacy Framework and Standard Contractual Clauses. For the collection and transmission of this data, the operator and Meta are joint controllers under Art. 26 GDPR (Meta's Controller Addendum applies). Legal basis: Art. 6(1)(f) GDPR — the operator's legitimate interest in measuring and improving its advertising. You can object to this processing at any time (contact us, use a browser ad-blocker or tracking protection, or adjust your Meta ad preferences / youronlinechoices.eu). The creator dashboard and the rest of the site contain no such tracking.

10. Third-party services we rely on

  • Cloudflare R2 — stores uploaded track files and profile/cover images
  • Vercel — hosts the application and processes requests at the infrastructure level
  • Neon (PostgreSQL) — stores our database
  • SoundCloud — fan sign-in and repost/like/comment/follow verification, per their own API terms and privacy policy
  • Google Translate — optional, only if you switch the site language
  • Meta Platforms Ireland — Meta Pixel on gate pages and release smart-link pages (see section 9)

We currently have no payment provider integrated — all plans are free during beta.

11. Data retention

Creator accounts and their gates are kept until you delete them. Deleting a gate removes its file from storage and its download history. Download/attempt records for a gate are kept as long as the gate exists — there is currently no automatic retention limit, since this data is what makes the “who used this gate” feature useful to creators. If you want your data deleted, contact us.

12. International transfers

Our infrastructure providers (Vercel, Neon, Cloudflare) may process data outside the EU/EEA depending on region configuration. Where that happens, it's covered by their own Standard Contractual Clauses or equivalent safeguards under their respective data processing agreements. The Meta Pixel on gate pages and release smart-link pages (section 9) transfers data to Meta Platforms, Inc. in the USA under the EU–US Data Privacy Framework and Standard Contractual Clauses.

13. Your rights

Under Art. 15–21 GDPR, you have the right to access, correct, delete, restrict, or port your personal data, and to object to processing based on legitimate interest. To exercise any of these, contact us at contact@powergate.me. You also have the right to lodge a complaint with your local data protection authority.

14. Children

PowerGate is not directed at children under 16. We don't knowingly collect data from anyone under that age.

15. Changes to this policy

We may update this policy as the service changes. Material changes will be reflected here with an updated date.

16. Contact

contact@powergate.me — see the Imprint for our full address.