Privacy Policy
Last updated: August 2026
1. Who we are
Marrow is an online marketplace connecting Irish venues with DJs, singers, and bands. We are operated by Marrow (contact: hello@joinmarrow.ie). We are the data controller for the personal data we collect through joinmarrow.ie.
2. What data we collect
- Account data: your name, email address, password (hashed), and account type (artist, venue, or fan).
- Profile data: display name, artist type or venue name, city, bio, genres, demo links, and profile photo.
- Fan data: home county, saved counties, music preferences, age, and your Going/Interested activity on public events (visible per your profile privacy settings).
- Transaction data: booking amounts, payment status, and Stripe payment identifiers. We do not store card numbers — these are handled securely by Stripe.
- Communications: messages sent between artists and venues through the platform.
- Usage data: pages visited, actions taken, and technical logs (IP address, browser type) for security and debugging.
- Device data: a device push-notification token and platform type if you allow notifications in the mobile app.
- Analytics data: consented usage events and masked session diagnostics used to understand and improve the service.
- Waitlist data: email address if you signed up to be notified at launch.
- Public event data: when a venue confirms a booking, it is listed publicly by default; the venue can unpublish or opt it out at any time. Public listings include the event title, description, the venue's own address and county (geocoded to a map pin), date, time, genre, artist type, and any optional ticket link, price or age restriction the venue supplies.
3. How we use your data
- To provide the Marrow marketplace service (matching artists with venues, processing bookings).
- To process payments securely via Stripe Connect.
- To send transactional emails (booking confirmations, application updates, payout notifications).
- To notify you of new gig applications or booking activity relevant to your account.
- To maintain the security and integrity of the platform.
- To comply with legal obligations.
- To display an opted-in public event listing, shareable event page and map to any visitor, including people without a Marrow account, for the purpose of event discovery. We do not use public event data for advertising and do not sell it.
We do not sell your personal data to third parties. We do not use your data for advertising.
4. Legal basis (GDPR)
We process your data on the following legal bases:
- Contract: processing necessary to provide the service you signed up for.
- Legitimate interests: platform security, fraud prevention, and service improvement.
- Consent: for the waitlist, where you explicitly opt in to receive launch communications.
5. Third parties we share data with
- Supabase — our database and authentication provider. Data is stored on secure servers. See Supabase Privacy Policy.
- Stripe — payment processing. Stripe handles all card data directly and is PCI-DSS compliant. See Stripe Privacy Policy.
- Resend — transactional email delivery (booking confirmations etc.). See Resend Privacy Policy.
- PostHog — product analytics, used only after you consent. Private-message content, payment-adjacent data, and form inputs are masked from session diagnostics. See PostHog Privacy Policy.
- OpenStreetMap — powers the public gig map (Leaflet tiles) and address verification (Nominatim geocoding). We send only the venue-supplied address string to be geocoded; no personal data, no live location, no tracking. See OSM Foundation Privacy Policy.
- Sentry — error and crash monitoring used to diagnose technical failures. See Sentry Privacy Policy.
- Firebase Cloud Messaging — push-notification delivery in the mobile app when you allow notifications. See Firebase Privacy and Security.
We do not share your data with any other third parties without your consent, except where required by law.
5A. Location
Location information works differently depending on who you are:
- Fans: you choose a home county at signup; it is used to tailor discovery and is not precise location. Marrow does not collect, store, or track your device's precise location. A future "near me" feature would use your device location for a single search and discard it immediately.
- Venues: your public business address is geocoded to a map pin so fans can find your events. This is your own public business information, and you control whether a booking appears publicly at all.
- Artists: only your city/town is shown (as text) on public pages. Artists are never geocoded, pinned, or shown at live or precise locations.
No user — fan, artist, or venue — is ever shown on the map at a live or precise personal location. There is no location history, no background tracking, and no reverse-geocoding of people.
5B. Agency data
If you operate an agency account, we collect your agency's name, contact details, the artists you represent (and their consent records), your Stripe Connect account details, and the commission terms you submit with each quote. We use this data to operate the agency booking and settlement flow described in our Terms of Service, and to verify agency applications before approval. We do not disclose an agency's commission rate to venues, other agencies, or the public — only that a listed artist is agency-represented.
6. Cookies
Marrow uses functional cookies required to keep you logged in (session cookies managed by Supabase Auth). With your explicit consent, PostHog also uses local storage and cookies for product analytics. Analytics remains disabled unless you select "Allow analytics" in the consent banner. We do not use advertising cookies or sell data for advertising.
7. Data retention
We retain your account data for as long as your account is active. If you request account deletion, we will delete your personal data within 30 days, except where we are required to retain it for legal or financial compliance (e.g. Stripe transaction records).
8. Your rights (GDPR)
As a user in the EU/EEA, you have the following rights regarding your personal data:
- Access: request a copy of the data we hold about you.
- Rectification: correct inaccurate data.
- Erasure: request deletion of your account and data ("right to be forgotten").
- Portability: receive your data in a machine-readable format.
- Objection: object to processing based on legitimate interests.
- Restriction: request that we limit how we process your data.
To exercise any of these rights, email us at hello@joinmarrow.ie. To delete an account, you can also use our public account deletion page. We will respond within 30 days.
You also have the right to lodge a complaint with the Data Protection Commission (Ireland's supervisory authority).
9. Security
We take reasonable technical and organisational measures to protect your data, including encrypted connections (HTTPS), hashed passwords, and row-level security on our database. No system is 100% secure — if you suspect a security issue, contact us immediately at hello@joinmarrow.ie.
10. Changes to this policy
We may update this policy as the platform evolves. We will notify active users of significant changes by email. The "Last updated" date above will always reflect the most recent version.
11. Contact
For any privacy questions or data requests: hello@joinmarrow.ie