Last modified on 14 August 2026
1. Introduction
We value your privacy and are committed to protecting your personal data. This privacy statement explains how we collect, use, and protect your personal data when you use our mobile application (the "App"). The data controller responsible for this App is Stichting Hit The City, KVK [93646658], [adres].
By using the App, you acknowledge that your personal data will be processed as described in this privacy statement. If you have questions or concerns, please contact us at info@hitthecity-festival.nl.
2. What Personal Data We Collect
Depending on your use of the App and the features you choose, we may process the following types of personal data:
a. Profile Information (optional) If you fill out the optional profile form, we collect your first name, last name, email address, and whether you consent to receive marketing communications. These fields are not mandatory and not validated.
b. Location Data (optional) If you allow the App to access your location, we may use your location to provide location-based functionalities, such as navigation, event recommendations, or crowd information. Your location data are shared only in pseudonymized form with selected partners (e.g., Crowd Connected). These data contain only a unique device identifier (UUID), coordinates, and optionally a push token.
c. Personalized Timetable via Timegem (optional) If you connect your Spotify account, we work with Timegem (Tenfold Technology VOF) to generate a personalized timetable and artist recommendations, including artists in the line-up or performing at Hit the City. For this purpose, Timegem processes your Spotify listening data, such as your top artists, top tracks, and genres, on our behalf. This data is used solely for this functionality and is not used for training, benchmarking, or any other purpose. You can withdraw your consent at any time by logging out of Spotify within the App, which stops this processing on our side. In addition, Timegem itself deletes this data no later than 24 hours after your session.
d. App Usage and Analytics We collect data on app usage (page views, clicks) to improve our services. These events are tracked via Google Firebase / Google Analytics 4 and processed in de-identified, IP-truncated form. If the App is connected to additional analytics platforms (such as CM.com CDP, Braze, Insider, Tealium, or Salesforce Marketing Cloud), data may also be processed there according to our configuration.
3. Purposes of Processing
We process your personal data for the following purposes:
to enable you to use the App and its features;
to personalize the App experience and display relevant content;
to send updates or marketing information (only with your consent); to analyze and improve the performance of the App;
to handle your questions or requests; to comply with legal obligations or legitimate interests (e.g., security, fraud prevention).
We rely on one or more of the following legal bases:
your consent (e.g., marketing or location use),
performance of a contract (providing app functionalities),
legal obligation, or our legitimate interests.
4. Data Storage and Retention
All data are stored securely, primarily within the European Union, on servers provided by Amazon Web Services (AWS) in the region eu-west-1 (Ireland). By default, your personal data is retained for a period of two (2) years after your last activity in the App. The Spotify listening data processed via Timegem for the Personalized Timetable feature (Section 2c) is an exception to this: processing stops as soon as you log out of Spotify within the App, and this data is in any case deleted by Timegem no later than 24 hours after your session. If the App is connected to additional analytics platforms (such as CM.com CDP, Braze, Insider, Tealium, or Salesforce Marketing Cloud), data may also be processed there according to our configuration.
De-identified aggregated data may be kept longer for analytical purposes in accordance with applicable data protection laws.
5. Data Security
We take appropriate technical and organizational measures to protect your personal data, including:
encryption in transit and at rest;
secure database access through credentials and IP whitelisting;
restricted access for authorized personnel only;
monitoring and logging.
6. Sharing of Personal Data
Your data are not shared with third parties except:
with our trusted partners and service providers who support us in delivering the App (e.g., hosting, analytics, support);
when required by law;
or when you give us your consent.
If you have consented to certain integrations, your data may be shared solely for that purpose, for example location data with Crowd Connected for location intelligence, or Spotify data with Timegem for personalized recommendations.
In some cases, profile data may be manually exported to the Organizer's secure environment (e.g., a Box.com account) for marketing or customer management purposes.
7. Data Transfers
Personal data is primarily stored and processed within the European Union (EU), with appropriate safeguards in place where processing takes place outside the EU, such as with Cloudflare (based in the USA), which is used to ensure the security, performance, and availability of the App and its content.
Any transfer of personal data outside the EU will only occur on the basis of legally permitted transfer mechanisms, such as adequacy decisions or the European Commission's Standard Contractual Clauses, ensuring an adequate level of protection for your personal data.
8. Your Rights
You have the right to:
access your personal data;
correct inaccurate data;
request deletion ("right to be forgotten");
restrict or object to processing;
request data portability;
withdraw consent at any time.
You can exercise these rights by emailing us and including proof of identity.
9. Location and Permissions
You can change your consent for location or push notifications at any time in your device settings. Location data, if enabled, are processed in pseudonymized form.
10. Third-Party Links
The App may contain links to third-party websites or services. We are not responsible for their privacy practices or content. We advise you to read the privacy statement of each website you visit.
11. Changes to This Privacy Statement
We may update this privacy statement from time to time. The most recent version is always available in the App.