Scope
This Privacy Policy explains information practices for the official Mr. Blindbandit website and Blindbandit Records public services. It covers public pages, authentication, community participation, contact and submission forms, newsletters, advertising, browser utilities, and Media Suite features. A separate notice applies to the invitation-only label portal.
Controller, operator, and Data Protection Officer
The website is operated by Kaeleb Savon Heck, professionally known as Mr. Blindbandit, in connection with Blindbandit Records. Postal contact: Purok 6-A, Mabuhay, Barangay Capungagan, Davao del Norte 8113, Philippines. Philippine telephone: +63 962 695 4905. United States telephone: +1 540 926 9791.
Kaeleb Savon Heck serves as Data Protection Officer / Privacy Officer for the website. Privacy questions and rights requests should be sent to privacy@mrblindbandit.net. Legal notices may be sent to legal@mrblindbandit.net.
Scope
This Policy covers information processed through mrblindbandit.net public pages and features under the operator’s control. Third-party destinations, streaming platforms, payment services, identity providers, and embedded services have their own privacy practices. The private label portal has a supplemental notice because it handles additional contractual, royalty, messaging, and client records.
Categories of information
Depending on the feature, the service may process names, artist or organization names, email addresses, telephone numbers voluntarily included in a message, account identifiers, display names, profile details, community posts and comments, poll responses, timestamps, music metadata, project descriptions, listening links, uploaded submission files, support messages, consent choices, accessibility and browser preferences, device and browser information, IP addresses, security and authentication events, rate-limit data, referral information, advertising request information, and records needed to document a request or legal obligation.
The service does not intentionally request passwords, complete payment-card numbers, banking credentials, government identity numbers, or highly sensitive personal data in ordinary public forms. Do not place that information in a public post or an unsolicited message.
Sources
Information comes from visitors, account holders, people making submissions or inquiries, authorized label administrators, service providers performing authentication or delivery functions, ordinary browser/network requests, public professional links intentionally submitted for review, and security or moderation events generated by use of the service.
The operator does not ask a user to provide personal data obtained unlawfully or private information about another person without authorization.
Music submissions
Demo and project submissions may include contact details, project metadata, ownership or permission confirmations, listening links, messages, and optional audio. They are used to receive, secure, organize, evaluate, and respond to the submission; prevent fraud or abuse; document permission; and preserve records needed for an active negotiation or dispute. A submission does not enroll the sender in unrelated marketing.
Professional, licensing, press, partnership, and booking inquiries
Information in a professional inquiry is used to understand the proposal, verify or communicate with the sender, evaluate availability and fit, negotiate terms, prevent abuse, document decisions, and keep records reasonably needed for business and legal purposes. Sending an inquiry is not acceptance of a booking, license, partnership, endorsement, or contract.
Community information
Community display names, posts, comments, poll choices where displayed, and posting times may be public. Public contributions can be indexed or copied by others. Reports, moderator notes, account identifiers, enforcement history, and security signals are restricted to authorized processing except where disclosure is legally required.
Do not post home addresses, private phone numbers, passwords, financial credentials, government identifiers, intimate information, or another person’s personal data without authorization.
Accounts and authentication
Clerk and configured identity providers may process identifiers, email addresses, profile information, device data, cookies, login events, multifactor settings, and fraud signals according to their role and configuration. Community and label-portal permissions are separate even when related authentication technology is used.
Passwords and secret authentication keys should never be sent through ordinary email or community posts.
Audio converter and Media Suite
Supported Media Suite tools are designed to process selected source files locally in the visitor’s browser unless the interface clearly states otherwise before processing. This can include conversion, clipping, silence trimming, waveform analysis, loudness analysis or normalization, metadata editing, artwork resizing, audiogram generation, art-track rendering, lyric-video generation, and related processing.
When local processing is used, the source media is not uploaded to Blindbandit Records merely to perform the transformation. The browser may still download software components, fonts, libraries, codecs, or other assets from the website or an identified content-delivery provider, which can cause the delivery provider to receive ordinary request information such as IP address, browser data, timing, and security logs.
If a future Media Suite feature requires server-side upload, cloud rendering, AI processing, or temporary storage, the interface must disclose that fact before the file leaves the device, and this Policy must be updated if the new processing is material.
Browser utilities and local storage
Accessibility preferences, planner state, checklist state, privacy choices, and certain utility settings may be stored locally on the device. Local storage remains until cleared by the user, browser, site code, or an applicable expiration rule. Clearing browser data can reset those settings.
Advertising
Google AdSense may appear on eligible public pages. Google and advertising partners may process cookies or similar identifiers, IP address, device and browser information, ad requests, consent signals, and interactions to deliver, limit, personalize where permitted, measure, secure, and report advertising.
The site does not intentionally send private messages, uploaded demo audio, private label records, account passwords, or ordinary form contents to Google for ad targeting. Advertising code should not appear in the private label portal or on pages deliberately excluded by the operator.
European advertising consent
Optional advertising is disabled by default and is subject to the site’s advertising activation gate and visitor choice. A Google-certified consent platform must be verified before advertising is activated for regions requiring it. The site’s own Privacy Choices dialog is not a certified advertising consent platform. You can reopen Privacy Choices to decline optional advertising and media.
Purposes and legal grounds
Account authentication, service delivery, requested communications, submission review, and steps requested before entering a contract may be processed because they are necessary to provide a requested feature, take requested pre-contract steps, perform an agreement, or pursue legitimate operational interests where permitted.
Security logging, abuse prevention, moderation, access control, audit trails, service integrity, accessibility improvement, and fraud prevention may rely on legitimate interests, legal obligations, contract necessity, or another lawful basis appropriate to the jurisdiction.
Optional marketing generally relies on consent or another legally permitted direct-marketing basis, subject to the right to unsubscribe or object. Advertising personalization and non-essential cookies use consent where required. Legal records may be processed to comply with law, establish or defend claims, preserve evidence, or meet contractual and accounting duties.
Where consent is the applicable basis, consent can be withdrawn for future processing. Where legitimate interests are relied on, the operator considers the purpose, necessity, and impact on the individual and provides objection rights where applicable.
Service providers and recipients
Relevant providers can include website and Cloudflare-backed infrastructure, databases and storage, Clerk and connected identity providers, transactional-email services such as Resend, form providers, Google for advertising, Spotify, Apple Music, YouTube and other media platforms, content-delivery networks such as jsDelivr for optional browser software, and payment providers such as PayPal and Wise for off-site transactions.
Providers receive only the information reasonably related to the function they perform, subject to provider terms, settings, legal requirements, and contractual safeguards appropriate to their role. Information may also be disclosed to professional advisers, courts, regulators, law enforcement, emergency recipients, or transaction successors when legally permitted and reasonably necessary.
Cookies and similar technologies
The service may use cookies, local storage, session storage, authentication tokens, consent records, fraud-prevention signals, and comparable technologies. Strictly necessary technologies can support authentication, security, load balancing, accessibility choices, session continuity, and requested functionality. Optional advertising, analytics, or personalization technologies are handled according to applicable consent and choice requirements.
The Cookie and Storage Notice explains categories, choices, and implementation rules in more detail. Browser settings can block or delete technologies, but doing so may break account sessions or requested features. Where law requires prior consent for a non-essential technology, the site should not activate that technology until the required choice has been obtained.
Do Not Track, Global Privacy Control, and privacy signals
This site treats Global Privacy Control as a refusal of optional advertising and analytics in its first-party privacy controls. It does not claim control over independently visited third-party websites. Legacy Do Not Track does not change the site’s settings. You can also reject optional processing through Privacy Choices.
Retention
Personal information is retained only for as long as reasonably necessary for the purpose collected, a compatible purpose, an active account or relationship, security and abuse prevention, legal or contractual obligations, accounting, tax or royalty records, dispute resolution, enforcement, or establishment or defense of claims.
Operational retention targets are maintained internally and are reviewed against the actual website configuration. Examples include shorter periods for rejected demo media and temporary technical files, moderate periods for support and moderation records, and longer periods for contracts, royalties, tax, accounting, litigation holds, or legally required records. Backups may retain deleted information for a limited rolling period before normal overwrite.
When information is no longer reasonably needed and no preservation duty applies, it should be deleted, anonymized, or allowed to expire according to the configured lifecycle. A deletion request does not require deletion of information that must lawfully be retained, but unnecessary copies should not be kept indefinitely.
International processing and transfers
The website may use service providers or infrastructure located in countries other than the visitor's country. This can result in information being processed in the Philippines, United States, or other locations in which a configured provider operates.
Where a jurisdiction requires a transfer mechanism or additional safeguard, the operator will use an applicable lawful mechanism, contractual protection, provider arrangement, consent where valid, necessity exception where lawfully available, or another authorized method. The service will not falsely claim that a particular transfer mechanism is in place unless it has actually been implemented for the relevant vendor and data flow.
Security
The site uses HTTPS, server-side role checks for portal data, rate limits on relevant requests, audit records for administrative changes and provider-managed Clerk authentication. Use available multifactor authentication and protect your devices. No internet service can guarantee complete security. Report suspected vulnerabilities privately to security@mrblindbandit.net.
Individual privacy rights
Depending on residence and applicable law, an individual may have rights to request access, confirmation, correction, deletion or erasure, restriction, data portability, objection, withdrawal of consent, information about processing, or another legally established privacy right. Some rights are subject to exceptions, identity verification, proportionality, and record-preservation duties.
Requests may be sent to privacy@mrblindbandit.net. The operator may request information reasonably necessary to verify identity or authority and should avoid collecting excessive verification data. An authorized agent may be required to provide proof of authority where law permits. The service should document the request, response, legal basis for any denial or limitation, and completion date.
The operator will not unlawfully discriminate against a person for exercising an applicable privacy right.
Philippine data-subject rights and complaints
Where the Philippine Data Privacy Act and related rules apply, data subjects may exercise applicable rights recognized under Philippine law and may contact the Data Protection Officer at privacy@mrblindbandit.net.
A person who believes Philippine data-protection rights have been violated may also have the right to lodge a complaint with the National Privacy Commission of the Philippines. The operator encourages direct contact first when practical so a concern can be investigated promptly, but this does not remove a person's right to contact a competent regulator.
European and United Kingdom privacy rights
Where the GDPR, United Kingdom GDPR, or comparable European privacy law applies to a particular processing activity, individuals may have rights including access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to a competent supervisory authority. Where processing is based on consent, withdrawal applies prospectively. Where direct marketing is based on a legally permitted basis, an objection to direct marketing will be respected as required by law.
The operator does not claim that every European privacy regime applies merely because the website can be opened from Europe. Territorial scope depends on the facts, including establishment, targeting, offering goods or services, or monitoring where relevant.
California and other United States state privacy rights
Certain United States state privacy laws apply only when statutory thresholds and scope requirements are met. The service does not claim coverage or exemption without evaluating the actual business facts. If an applicable state law gives a visitor rights to know, access, correct, delete, opt out of sale or sharing, limit certain sensitive-data uses, or use an authorized agent, those rights will be handled as legally required.
The operator does not intentionally sell personal information for cash. Advertising technology can nevertheless be treated as "sharing," targeted advertising, or another regulated disclosure under some state laws depending on configuration and scope. If a law requires a "Do Not Sell or Share" or comparable mechanism, the site must provide and technically implement the required choice rather than relying only on a statement in this Policy.
Children and minors
The public community is not intended for children under 13. A person known to be under 13 must not create a public community account, post or comment, subscribe to marketing, submit music through an adult-facing workflow, or use a private messaging feature intended for older users. If the operator learns that prohibited personal information from a child under the applicable threshold was collected without valid authorization, reasonable deletion and account-protection steps should be taken.
Older minors may be subject to parental or guardian authorization, age-of-majority rules, platform rules, or jurisdiction-specific consent requirements. A minor must not represent that they have legal authority to sign a record, licensing, booking, release, or other professional agreement when they do not. Music from a minor may require parent or legal-guardian participation before negotiations or contracting proceed.
The Child Safety Policy provides additional safety and reporting rules. The site is not intended to create a child-directed service merely by providing family-safe public content.
Marketing communications
A newsletter or promotional mailing should require an affirmative signup or another lawful basis. Marketing records can include the address, signup source, timestamp, consent state, and unsubscribe or suppression state. Every marketing message must provide the notices and opt-out mechanism required by applicable law.
An unsubscribe request should be honored promptly and, where United States CAN-SPAM applies, no later than the legally required period. A minimal suppression record may be retained so the service does not accidentally re-add an address that opted out. Transactional, security, account, contractual, or legally required messages may still be sent when appropriate and are not automatically marketing messages.
Automated decision-making and profiling
The public site does not intentionally make decisions producing legal or similarly significant effects about individuals solely by automated processing. Automated tools may be used for spam filtering, security, abuse detection, fraud signals, rate limiting, content organization, or advertising technology. Human review should be available for material moderation or account decisions where law or fairness requires it.
If the service later introduces significant automated eligibility, contracting, credit, employment, or comparable decisions, the privacy documentation and product controls must be updated before deployment.
Security incidents and breach response
Suspected unauthorized access, disclosure, loss, alteration, or destruction of personal information is evaluated under an internal incident-response process. The process should preserve evidence, contain the incident, assess affected information and people, document decisions, involve the Data Protection Officer, and provide regulator or individual notices where legally required.
Philippine rules can require notification of qualifying personal-data breaches within a specified statutory period, including a 72-hour framework in applicable circumstances. The operator should maintain incident records and required annual security-incident reporting processes even when no public notice is required.
Security concerns should be sent to security@mrblindbandit.net. Good-faith reports should not include unnecessary personal information or destructive testing.
Policy changes and contact
Material changes will be reflected by updating the effective or last-updated date and, where required, by providing additional notice or renewed consent. A change to this Policy does not retroactively create a lawful basis that did not exist when information was collected.
Privacy and data-rights contact: privacy@mrblindbandit.net. Legal contact: legal@mrblindbandit.net. Security contact: security@mrblindbandit.net. Postal contact: Purok 6-A, Mabuhay, Barangay Capungagan, Davao del Norte 8113, Philippines.
Professional review notice
These public documents explain current website practices and user expectations. They are not a substitute for advice from a lawyer or regulator about a particular person, contract, jurisdiction, or dispute. Applicable rights that cannot lawfully be waived remain available.
