← Back to homepage

Privacy Policy

1. Data Controller

The data controller within the meaning of the General Data Protection Regulation (GDPR) is the operator named in the Legal Notice.

2. Data Collected

We collect and process the following categories of personal data:

2.1 Registration Data

DataPurposeLegal Basis
NameDisplay in profile, identification in groupsPerformance of contract (Art. 6(1)(b) GDPR)
Email addressAuthentication, verification, communicationPerformance of contract
PasswordAuthentication (stored hashed, no plaintext)Performance of contract
Profile picture (optional)Display in profile and groupsConsent (Art. 6(1)(a) GDPR)

2.2 Location Data

DataPurposeLegal Basis
City / DistrictRegional statistics ("How did your city vote?")Consent
State / CountryNational and international statisticsConsent
Coordinates (one-time)Automatic assignment to city/district during registration via GPS or manual selectionConsent

Location data is collected once during registration – either via the device's GPS sensor or through a manual location search (Google Maps Places API). The coordinates are used to determine the city/district/state/country information and are stored with the user profile.

2.3 Phone Number and Contact Data

2.4 Usage Data

DataPurposeLegal Basis
Song ratings / RankingsCore app functionality, statistics generationPerformance of contract
Song ratings (1–10)Individual song ratingPerformance of contract
Group membershipsComparison with friends, group featuresPerformance of contract
Group messagesCommunication in groups (chat)Performance of contract
Invite codes / Referral codeReferral program, group joiningPerformance of contract
Blocked usersUser protection, moderationLegitimate interest (Art. 6(1)(f) GDPR)

2.5 Technical Data

DataPurposeLegal Basis
FCM token (push notifications)Delivery of push notificationsConsent
App versionCompatibility checks, bug fixingLegitimate interest
Device language settingAutomatic language selection in the appLegitimate interest

Additionally, the following data is stored locally on the user's device: app settings, cached song/artist data (Deezer), and ranking drafts. This local data is not transmitted to servers unless the user actively publishes their ranking.

3. Contact Matching (Find Friends)

Contact matching works as follows:

4. Data Processing and Data Processors

To provide the app, we use the following services and data processors:

ServiceProviderPurposeData TransmittedServer Location
SupabaseSupabase Inc.Authentication, database, file storage (profile pictures), Edge FunctionsAccount data, rankings, groups, messages, profile picturesEU (eu-west)
Amazon SESAmazon Web Services Inc.Sending verification emails and password resetsEmail addressEU
RevenueCatRevenueCat Inc.Management of in-app purchases and premium subscriptionsAnonymous user ID, purchase/subscription status, transaction IDUSA (EU Standard Contractual Clauses)
Firebase AnalyticsGoogle LLCAnonymized app usage statistics (no ad tracking)Anonymized usage eventsUSA (EU Standard Contractual Clauses)
Firebase Cloud MessagingGoogle LLCDelivery of push notificationsFCM tokenUSA (EU Standard Contractual Clauses)
Google Maps APIGoogle LLCLocation detection during registration (Places Autocomplete, Reverse Geocoding)Coordinates or search query (one-time)USA (EU Standard Contractual Clauses)
Deezer APIDeezer SA30-second song previews, artist imagesNo personal data (content queries only)EU (France)
Google FontsGoogle LLCFont renderingIP address (when loading fonts)USA (EU Standard Contractual Clauses)

For services based in the USA, EU Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR serve as the basis for data transfers to third countries.

5. Data Sharing with Third Parties

Personal data is not sold, rented, or shared with third parties for advertising purposes.

Data is only shared with the data processors listed in Section 4, which are technically necessary for operating the app, as well as in the following cases:

6. Data Subject Rights (GDPR)

Every user has the following rights:

To exercise your rights, please use our support chat or contact us by email (see Section 1).

7. Account Deletion and Data Erasure

8. Cookies and Tracking

9. Push Notifications

10. Group Chat

11. Referral Program

12. Data Security

13. Minors

The app is not specifically targeted at children under 16 years of age. Use by persons under 16 requires the consent of a legal guardian. Should we become aware that personal data of a child under 16 has been collected without parental consent, it will be deleted immediately.

14. Changes to this Privacy Policy

We reserve the right to update this privacy policy as needed – for example, due to changes in legislation, new features, or modified data processing procedures. Significant changes will be communicated via email or in-app notification. The current version is always available at eurovisionscore.com/privacy.

15. Contact

For questions about data protection, please use our support chat.

Legal Notice / Impressum

Eurovision Score
Josef David Pucher
Ljuba-Welitsch-Promenade 12/44
1030 Vienna
Austria

VAT ID: ATU68336222
Email: contact@eurovisionscore.com
(This email address is equipped with an automatic response service. For inquiries, please use the support chat.)

Responsible for content pursuant to § 55(2) RStV:
Josef David Pucher, address as above