This Privacy Policy includes important information about your personal data and we encourage you to read it carefully.
Welcome
We provide legal, expertly curated music solutions for hospitality businesses (restaurants, hotels, cafés, and retail) designed to set the perfect atmosphere for business owners in their establishments. This Privacy Policy for Lobby & Lounge Music Inc. ("we," "us," or "our"), describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:
- Visit our website at https://lobby-lounge.vercel.app/ or any website of ours that links to this Privacy Policy
- Use Lobby & Lounge Music. The music streaming web application for hotels, cafés, restaurants and retail. Legal, expertly curated, and designed to set the perfect atmosphere
- Engage with us in other related ways, including any marketing or events
More importantly, our Privacy Policy contains mandatory disclosures under the California Consumer Privacy Act of 2018 (Cal. Civ. Code § 1798.100 et seq.), as amended by the California Privacy Rights Act of 2020 (effective January 1, 2023, enforceable July 1, 2023). We collect identifiers, customer records, commercial data, internet activity, professional information, inferences, and sensitive login/location data to provide legal commercial background music solutions. We do NOT sell personal data for monetary gain, but we engage in digital ad network ‘sharing’ (cross-context behavioral advertising) which you may opt out of via Global Privacy Control (GPC) or by using our Do Not Sell/Share links.
Questions or Concerns. Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services.
1.What information do we collect?
Lobby & Lounge Music Inc. ("we," "us," or "our") provides expertly curated, commercially licensed background music solutions tailored for hospitality businesses, including restaurants, hotels, cafés, lounges, and retail establishments. In providing our web applications and music streaming infrastructure (the "Services"), we collect personal information directly from you, automatically through your interactions with our platform, and from authorized third-party business partners.
A. Personal Information You Disclose to Us
We collect personal information that you voluntarily provide when registering for an account, expressing an interest in obtaining information about our products, subscribing to streaming zones, or contacting customer support.
The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use. The personal information we collect may include the following:
- names
- phone numbers
- email addresses
- mailing addresses
- job titles
- usernames
- passwords
- billing addresses
- debit/credit card numbers
- contact or authentication data
Sensitive Information. We do not process sensitive information.
Payment Data. We collect necessary billing records to process your payment if you choose to make purchases; however, all sensitive card numbers, CVVs, and direct payment card processing are handled securely and directly by our PCI-DSS compliant third-party payment processor, Stripe, Inc. (see Stripe's Privacy Policy at https://stripe.com/privacy). We do not store raw card numbers on our servers.
B. Information Automatically Collected
When you navigate, stream, or interact with our Services, our systems automatically log technical data through server logs, cookies, and diagnostic monitors:
- System & Device Telemetry. Internet Protocol (IP) address, proxy server attributes, browser type and version, device hardware specifications, operating system, language configurations, and referring URL paths.
- Log & Usage Records. Audio playback events, playlist selections, stream duration, zone transitions, search queries, feature interactions, system crash reports, and performance timestamps.
- Geolocation Data. Imprecise geolocation (such as country, state, and city derived from IP address) and precise device location (where permitted by device permissions) to verify physical venue licensing territories and ensure zone-compliant audio synchronization.
C. Sensitive Personal Information (SPI)
Under California Civil Code § 1798.140(ae), certain data points are categorized as Sensitive Personal Information. We collect account login credentials (username and password) and precise device geolocation (GPS coordinates collected strictly to establish venue streaming zone parameters). We process this data exclusively to perform our contract, secure user accounts, and prevent unlicensed rebroadcasting. We do not use Sensitive Personal Information to infer consumer characteristics or for any non-exempt commercial profiling.
2.How do we process your information?
We process your personal information in accordance with applicable legal bases, including contractual performance, legitimate commercial interests, compliance with legal mandates, and your explicit consent where required:
- Service Delivery & Account Management. Authenticating account holders, maintaining secure streaming sessions, configuring venue zone permissions, and delivering uninterrupted audio playback.
- Transaction & Billing Execution. Processing monthly/annual subscription fees, calculating venue licensing fees, issuing tax invoices, and preventing fraudulent transactions.
- Customer Support & Diagnostic Resolution. Troubleshooting hardware/software playback issues, diagnosing streaming packet delivery latency, and resolving customer inquiries.
- Platform Optimization & Research. Analyzing anonymized listening habits, evaluating venue music engagement trends, refining curation algorithms, and developing platform enhancements.
- Operational Communications. Transmitting critical service alerts, license renewals, security notifications, terms modifications, and administrative updates.
- Marketing & Advertising. Delivering targeted commercial updates, promotional offers, and industry newsletters in compliance with your marketing preferences.
- Security & Fraud Defense. Monitoring network integrity, detecting unauthorized commercial distribution or account sharing, and defending our legal rights.
3.When and with whom do we share your personal information?
We disclose personal data to vetted third-party service providers, authorized vendors, contractors, and corporate affiliates who perform services on our behalf pursuant to strict written data processing agreements:
- Cloud Computing & Hosting Infrastructure. Cloud infrastructure hosts, content delivery networks (CDNs), and database providers hosting our music streaming pipelines.
- Payment Gateways. Stripe, Inc., which manages end-to-end tokenized payment execution, recurring billing, and chargeback prevention.
- Identity & Authentication Services. Third-party identity verification, federated login managers, and single sign-on (SSO) infrastructure.
- Data Analytics & System Monitoring. Diagnostic tools, real-time error loggers, and performance monitoring software tracking streaming quality.
- Sales, Marketing & CRM Suites. Customer relationship management (CRM) software, direct email distribution tools, and support ticketing desks.
- Ad Networks & Affiliates. Advertising and marketing partners assisting in commercial outreach and retargeting campaigns.
In the event of a merger, corporate restructuring, divestiture, sale of company assets, or bankruptcy, personal data may be transferred to successor entities, subject to the representations set forth in this Privacy Policy.
6.Comprehensive data retention schedule
In strict accordance with the CPRA's data minimization principles (Cal. Civ. Code § 1798.100(a)(3)), we do not retain personal information longer than is reasonably necessary for the operational purposes disclosed in this policy:
- Account Identifiers & Profile Records. Retained for the active duration of the customer relationship plus up to six (6) months following account deactivation to facilitate account reactivation or audit history.
- Commercial & Transactional Records. Retained for seven (7) years following transaction completion to satisfy federal, state, and local accounting, tax, and commercial statutory audit requirements.
- Diagnostic & Server Logs. Diagnostic telemetry, crash logs, and streaming packet logs are retained for twelve (12) months, after which they are systematically purged or aggregated into non-identifiable statistics.
- Geolocation Information. Real-time GPS coordinates are processed ephemerally during stream handshake verification and are not written to persistent storage; IP-level geographic tags are retained with standard server logs for up to six (6) months.
- Inference & Preference Data. Internal curation profiles and playlist engagement scores are retained for twenty-four (24) months, or until the user submits a verified deletion request.
7.How do we keep your information safe?
We have implemented industry-standard organizational, technical, and administrative controls designed to safeguard personal data against unauthorized access, destruction, loss, or alteration. These measures include TLS/SSL cryptographic encryption in transit, AES-256 encryption for sensitive databases at rest, role-based access control (RBAC), multi-factor authentication for administrative staff, and continuous network vulnerability assessments. However, no internet transmission or electronic storage architecture is 100% immune from security breach, and transmissions are undertaken at your own risk.
8.Do we collect information from minors?
Our Services are designed exclusively for commercial venues, corporate operators, and adult business proprietors. We do not knowingly solicit, collect, process, sell, or share personal data from individuals under eighteen (18) years of age. If we verify that personal data of an individual under 18 has been collected without parental consent, we will promptly terminate the account and purge all related records. Please report minor data concerns to alvin@lobbyloungeinc.com.
9.What are your privacy rights?
Regardless of your geographic location, you maintain standard controls over your data:
- Consent Withdrawal: Where processing relies on consent, you may withdraw consent at any time without affecting past lawful processing.
- Marketing Unsubscribe: You can unsubscribe from marketing communications by clicking the unsubscribe link in promotional emails or updating preferences.
- Account Information: You may review, modify, or correct your profile data by logging into your account settings.
10.Controls for Do-Not-Track and opt-out preference signals
Most web browsers include a Do-Not-Track ("DNT") setting. Because no universal technological consensus exists regarding generic DNT headers, our system does not currently alter data handling practices upon encountering generic DNT signals. In compliance with the California Consumer Privacy Act and Title 11 California Code of Regulations § 7025, Lobby & Lounge Music Inc. fully recognizes and honors the Global Privacy Control (GPC) opt-out preference signal. When our web application detects an enabled GPC signal transmitted by your browser or operating system, we automatically process that signal as a valid, friction-free consumer request to opt out of the ‘sale’ and ‘sharing’ of personal information (including cross-context behavioral advertising) for that specific browser, application, or connected device.
Do Not Sell or Share My Personal Information
Opt out of the ‘sharing’ of your personal information for cross-context behavioral advertising on this browser. Strictly necessary and functional cookies are unaffected.
11.Do California residents have specific privacy rights?
This section applies exclusively to California residents pursuant to the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, "CCPA/CPRA").
A. Categories of Personal Information Collected, Disclosed, and Shared (Past 12 Months)
Below is the statutory disclosure of personal information categories to be collected or disclosed for business operational purposes, and shared for cross-context behavioral advertising over the preceding twelve (12) months:
| Statutory Category | Examples Collected | Collected | Disclosed to Providers | Sold / Shared |
|---|---|---|---|---|
| A. Identifiers | Real name, business email, IP address, username, phone number | YES | Cloud hosts, CRM, identity providers | NO |
| B. Cal. Customer Records | Name, business contact info, payment verification details | YES | Stripe (payment processor), cloud hosting | NO |
| C. Protected Characteristics | Age, race, ethnicity, gender, marital status | NO | None | NO |
| D. Commercial Information | Subscription records, streaming tiers, payment history | YES | Payment gateways, accounting tools | NO |
| E. Biometric Information | Voiceprints, fingerprints, facial scans | NO | None | NO |
| F. Internet / Network Activity | Log data, browsing history, crash reports, feature telemetry | YES | Analytics providers, cloud monitors | YES (Ad Pixels) |
| G. Geolocation Data | IP-derived city/region; device GPS location for streaming zones | YES | Cloud providers, licensing routing engines | NO |
| H. Sensory / Audio Data | Customer service voice recordings, facility footage | NO | None | NO |
| I. Professional Information | Job title, company name, establishment role | YES | CRM systems, email automation platforms | NO |
| J. Non-Public Education Data | Student directory data, academic records | NO | None | NO |
| K. Inferences | Playlist preference profiles, venue audio profiles | YES | Internal recommendation engines | NO |
| L. Sensitive Personal Information | Account login credentials; precise device GPS coordinates | YES | Authentication providers, cloud host | NO |
B. Your California Consumer Privacy Rights
Under the CCPA, as amended by the CPRA, California residents possess comprehensive rights regarding their personal information:
- 1. Right to Know and Access: You have the right to request that we disclose: (1) the categories of personal information collected, (2) the categories of sources, (3) the commercial or business purposes for collection, (4) the categories of third parties to whom data is disclosed, and (5) the specific pieces of personal information collected about you in the preceding 12 months.
- 2. Right to Request Deletion: You have the right to request deletion of personal information we have collected, subject to statutory exceptions (such as fulfilling commercial contracts, detecting security incidents, debugging code, or complying with legal obligations).
- 3. Right to Correct Inaccuracies: You have the right to request correction of inaccurate personal information maintained in our systems.
- 4. Right to Opt-Out of Sale or Sharing: You have the right to opt out of the ‘sale’ of your personal information or the ‘sharing’ of your personal information for cross-context behavioral advertising. You can exercise this via our website footer link (‘Do Not Sell or Share My Personal Information’) or via the Global Privacy Control (GPC).
- 5. Right to Limit Sensitive Personal Information: Under Cal. Civ. Code § 1798.121, businesses using sensitive personal information for inferring characteristics must offer an opt-out. Because we use sensitive personal information (credentials and GPS) strictly for essential operational services and security, we are exempt from providing a ‘Limit Use of Sensitive Personal Information’ link.
- 6. Right to Non-Discrimination: We will not discriminate against you (by denying services, altering streaming audio bitrates, or assessing penalties) for exercising any statutory privacy rights.
C. How to Exercise Your California Rights
To submit a verifiable consumer request to know, access, correct, or delete personal information:
- By Email: Submit an electronic inquiry to privacy@lobbyloungeinc.com with ‘CCPA Request’ in the subject.
- Online Privacy Form: Use the request button below to open a prefilled request with the details we need.
- By Telephone: Contact our designated compliance team at +1 (919) 438-3093.
D. Request Verification and Authorized Agent Procedures
To ensure data security, we verify all consumer requests prior to processing. We require you to match two or more identity points already in our records (such as your account email and recent transaction timestamp). For requests seeking specific pieces of personal data, a signed declaration under penalty of perjury may be required.
Authorized Agents: If you submit a request via an authorized agent, the agent must present valid written authorization signed by you. You must also verify your own identity directly with us before personal records are disclosed or deleted.
E. Statutory Response Timelines
- Confirmation of Receipt (10 Days): We will confirm receipt of your verifiable consumer request within ten (10) business days and provide an explanation of how the request will be investigated and processed.
- Substantive Response (45 Days): We will provide a substantive response within forty-five (45) calendar days of receipt. If reasonably necessary, an extension of up to forty-five (45) additional days may be utilized, provided written notice explaining the delay is sent within the initial 45-day window.
F. Appeals and Regulatory Recourse
If we decline to take action on your consumer request, you may appeal our determination by emailing privacy@lobbyloungeinc.com within thirty (30) days of receiving our denial notice. We will evaluate the appeal and render a written determination within forty-five (45) calendar days. If your appeal is denied, you may file a formal complaint with the California Privacy Protection Agency (CPPA) at https://cppa.ca.gov/ or the Office of the California Attorney General.
G. California ‘Shine the Light’ Law
California Civil Code Section 1798.83 permits California residents who are customers of Lobby & Lounge Music Inc. to request once per calendar year a list of categories of personal information (if any) we disclosed to third parties for direct marketing purposes, alongside third-party contact details. To submit a request, contact privacy@lobbyloungeinc.comwith the reference line ‘Shine the Light Request.’
12.Do we make updates to this notice?
We update this Privacy Policy periodically to reflect evolving platform architecture, legal precedents, and regulatory directives. When changes occur, the updated policy will feature a revised ‘Last Updated’ date at the top. If material changes are made, we will notify registered account holders via prominent web notifications or direct email correspondence prior to the effective date.
13.How can you review, update, or delete the data we collect?
To exercise your rights to review, update, download, or delete personal data collected by Lobby & Lounge Music Inc., please submit an electronic request through our online privacy portal or email privacy@lobbyloungeinc.com. Your request must state your legal name, business account name, registered email address, the specific statutory right you wish to invoke, and whether you are a California resident requesting relief under CCPA/CPRA.
14.How can you contact us about this Privacy Policy?
If you have questions, inquiries, or complaints regarding this Privacy Policy or our data protection practices, please contact our Data Protection Officer (DPO) and compliance department:
Lobby & Lounge Music Inc. – Data Protection Office
- Attention
- Data Protection Officer (DPO) / Legal Department
- Corporate Entity
- Lobby & Lounge Music Inc.
- DPO Direct Email
- alvin@lobbyloungeinc.com
- Privacy Intake Email
- privacy@lobbyloungeinc.com
- Direct Telephone
- +1 (919) 438-3093
- Website
- https://lobby-lounge.vercel.app/
- Mailing Address
- Lobby & Lounge Music Inc., Attn: Data Protection Officer, 1000 Main Campus Drive, Suite 200, Raleigh, NC 27606
5.How do we handle work email and social logins?
Our Services may enable authentication via third-party providers (such as Google, Facebook, or X). When utilizing single sign-on (SSO), we obtain verified profile data from the provider (including name, business email address, and unique user identifier). We utilize this information exclusively to create and authenticate your account. We encourage you to review the privacy notices of external identity providers before linking accounts.