GETMUSO LEGAL
Privacy Policy
This policy explains how the GetMuso mobile app and public website handle personal information, including the protections and choices available under South Africa’s Protection of Personal Information Act (POPIA).
Effective and last updated 4 September 2026 · Version 2026-09-04
1. Who this policy covers
GetMuso is a marketplace service that helps customers discover musicians and send booking enquiries. Customers can browse, save favourites on their device and enquire without creating an account. Accounts are reserved for musicians who host or manage a profile and for GetMuso administrators.
GetMuso determines why and how personal information described in this policy is processed. For any privacy question or request, email admin@getmuso.co.za.
2. Information we collect
Information you provide
- Guest enquiries: your name, email address, phone number, event dates and times, event type, area, venue, and the message you send.
- Musician accounts: your name, email address, authentication details and the recorded version and time of your Terms and Privacy acceptance. Supabase handles authentication; GetMuso does not receive your plain-text password.
- Musician profiles: stage name, biography, service areas, genres, rates, packages, availability, profile and gallery photos, and video or social links you choose to add.
- Safety reports: for a profile report, the profile reported, selected reason, optional details, a random app-installation identifier used to prevent report spam, and your account identifier if you are signed in. When a musician reports an abusive guest enquiry, GetMuso records the enquiry and its message, selected reason, optional details, the reporting account, a masked sender hint, and the block and resolution history.
- Support and rights requests: the information in emails you send to GetMuso, including information needed to verify an account-deletion or privacy request.
Information created or collected when the service runs
- Authentication sessions and related security records when a musician or administrator signs in.
- An internet protocol (IP) address for a signed-out sender, or the GetMuso account identifier for a signed-in sender, used to limit automated or excessive enquiries. Enquiries are limited to ten per identity over a one-hour window; rate-limit entries older than 24 hours are removed as later requests are processed.
- When a musician blocks an enquiry sender, GetMuso normalises the supplied email address and phone number and stores private, musician-specific cryptographic hashes of those contact identities and, when present, the sender’s GetMuso account identifier. The hashes are used only to reject later enquiries from the same identities to that musician; raw contact details remain on the original private enquiry and are not copied into the block list.
- On Android, Firebase Cloud Messaging and its Firebase Installations dependency automatically collect the app version, limited device/app metadata and a random Firebase installation ID used to identify that app installation. The ID does not identify a person or the physical device.
- When the app checks Expo Application Services for a GetMuso update at launch, Expo may receive the operating system, GetMuso project identifier, a random token used to determine whether that installation requested or downloaded an update, and ordinary network metadata such as the request IP address.
- If a musician allows notifications, an Expo push token, mobile platform, notification delivery status and in-app notification history.
- Basic server, request and error information needed to operate, secure and diagnose the app and website.
Information kept only on your device
Saved favourites are stored locally on your phone or in your browser and are not uploaded as customer account data. The mobile app also stores its sign-in session and small interface preferences locally. You can remove this local information by clearing the app or browser data or uninstalling the app.
3. Optional device access
- Photos: the app opens the device’s image-selection interface only when a musician chooses profile or gallery images. On Android it uses the system photo picker and does not request broad access to the photo library. Selected images are resized before the copies are uploaded. GetMuso does not upload unselected photos.
- Calendar: a musician can ask GetMuso to prepare an enquiry in the phone’s event editor. The phone shows the event for review before saving it. GetMuso does not read existing private calendar events.
- Notifications: a musician can allow notifications for profile-review decisions and new enquiries. Notification permission can be changed in the phone settings. On Android, the Firebase installation ID described above may be created automatically even before notification permission is granted; the permission controls visible notifications and GetMuso’s push-token registration, not that underlying Firebase identifier.
GetMuso does not currently use advertising trackers, sell personal information, take payments, read contacts, or collect precise device location.
4. How we use personal information
We use personal information to:
- create and secure musician accounts;
- host, review and publish approved musician profiles;
- deliver an enquiry to the intended musician and let that musician reply directly using the contact details supplied;
- manage availability, profile-review decisions and service notifications;
- provide support, respond to privacy requests and investigate problems;
- prevent spam, automated abuse, fraud and security incidents;
- receive, investigate and resolve private profile and enquiry safety reports, and enforce musician-controlled sender blocks;
- meet applicable legal obligations and enforce the Terms of Use; and
- protect customers, musicians and the integrity of the marketplace.
Depending on the activity, our POPIA justification is your consent, steps you ask us to take or performance of our agreement with you, our legitimate interest in operating and securing GetMuso, or a legal obligation. You may withdraw consent where consent is the basis, but that does not undo processing already carried out lawfully.
5. What is public and what is private
- An approved musician’s chosen profile details, rates, availability indicators, photos and external media links are public in the app, on the website and on shareable profile pages.
- A guest enquiry and its contact details are private to the intended musician, authorised GetMuso administrators and service providers that process the data for GetMuso.
- Account email addresses, authentication records, unpublished drafts, internal review notes, push tokens and notification records are not public.
- Profile-safety reports are visible only to authorised GetMuso administrators. The reported musician does not receive the reporter’s account or installation identifier through the reporting feature.
- Enquiry-safety reports are visible only to authorised GetMuso administrators and include an excerpt of the reported message. The moderation queue omits the structured sender name, email address, phone number, account/contact hashes and masked block hint, although the message excerpt may contain personal information the sender chose to write in the message. The reporting musician can view a private list of active sender blocks using masked hints and can remove a block.
Public profile content may be indexed or cached by search engines and may remain in third-party caches for a period after GetMuso removes it.
6. Service providers and international processing
GetMuso uses providers that process information only to supply infrastructure and delivery services. These include Supabase for authentication, databases, file storage and backend functions; Expo for app-update checks and opted-in push delivery; Google Firebase Cloud Messaging for Android app installations and opted-in push delivery; the phone platform’s notification service and app store; and the approved website and app-distribution hosts used for the public service.
Some providers may process information outside South Africa. GetMuso will use providers and contractual, organisational or legal safeguards intended to give personal information an appropriate level of protection. If you choose an external social, video, email, messaging or map link, that separate provider handles your activity under its own terms and privacy policy.
7. Retention and deletion
- Musician account and profile information is kept while the account is active and until it is deleted or no longer needed. Hiding or removing a public profile is recoverable and does not delete the account.
- Guest enquiries are kept for as long as reasonably needed to deliver and track the request, support the parties, handle disputes or abuse, and meet legal obligations. They are reviewed for deletion or anonymisation when no longer needed.
- Push tokens remain registered while notification delivery is enabled, but are disabled on sign-out when the device can reach GetMuso, when a delivery service reports that the device is no longer registered, or when the account is deleted.
- Firebase retains an Android Firebase installation ID until GetMuso makes the provider’s installation-deletion API call. Firebase states that, after that call, it removes the ID from live and backup systems within 180 days. This installation identifier is not the musician’s GetMuso account ID.
- Expo retains app-update request metadata under its service privacy and retention practices. The random EAS Update token is an installation token, not the musician’s GetMuso account ID.
- Security logs and limited backup copies may remain for a restricted period before rotating out. Data required for a legal obligation, dispute or fraud-prevention purpose may be retained for that purpose with access limited.
- Safety reports and their resolution history are retained as reasonably needed to investigate abuse, enforce the Terms and prevent repeat harm. If a reporter later deletes an account, the account link is removed from reports about another musician while the moderation record may remain.
- An active enquiry-sender block and its private account or contact hashes remain until the musician removes the block or deletes the musician profile. Removing a block deletes its identity hashes. Deleting the source enquiry removes its enquiry-safety report, although an active block may remain to prevent repeat abuse.
Musicians can permanently delete an account and its associated data. Guests can request deletion of information submitted with an enquiry. See Account deletion for the steps and what is removed.
8. Security
GetMuso uses access controls, row-level database rules, encrypted network connections, server-side secrets and restricted administrative access designed to protect personal information. No online system is perfectly secure, so please use a strong, unique password and contact us if you suspect unauthorised access.
9. Your POPIA choices and rights
You may ask GetMuso to:
- confirm whether we hold personal information about you and request access to it;
- correct or update inaccurate or incomplete information;
- delete information when there is no lawful reason to keep it;
- object to processing or request a restriction where applicable;
- withdraw consent where processing depends on consent; and
- explain a privacy decision or complaint response.
Email admin@getmuso.co.za. We may request enough information to verify your identity and protect the account or enquiry from an unauthorised request. You may also lodge a complaint with South Africa’s Information Regulator.
10. Changes to this policy
We may update this policy when the service or legal requirements change. The effective date and version at the top identify the policy in force. If a material change needs renewed agreement, GetMuso may ask account holders to accept the updated version before continuing to use account features.
11. Contact
Privacy questions, requests and complaints: admin@getmuso.co.za.