Label Suite respects your privacy. This policy explains how we collect, use, store, and protect your data when you use our platform, including when you connect third-party accounts. This privacy policy is publicly available at https://www.labelsuite.co/privacy.
1. Information We Collect
We collect information you provide directly (email address, account details) and information from third-party platforms you connect. Below is a breakdown by platform:
TikTok. When you connect your TikTok account, we may access:
- Account information (username, display name, profile picture)
- Analytics data (follower count, like count, video count)
- Public video data (video metadata, view counts, engagement metrics)
Instagram & Facebook. When you connect your Instagram or Facebook account, we may access:
- Account and profile information (username, name, profile picture, account ID, linked Facebook Page)
- Analytics and insights data (follower/fan counts, reach, impressions, engagement, post-level metrics)
- Media and content you have published or that we publish on your behalf
- Page-level data (page name, follower count, published posts, reactions, comments, shares)
YouTube. When you connect your YouTube account, we may access:
- Channel information (channel name, subscriber count, profile picture)
- Video metadata (titles, view counts, engagement metrics)
Spotify. Label Suite accesses the Spotify Web API to retrieve publicly available artist and track information for analytics display. This includes:
- Artist data (name, images, popularity, genres)
- Track data (track names, album information)
- Monthly listener counts (via third-party analytics aggregator)
Google Drive. When you connect your Google Drive account, we may access:
- Account information (email, name, profile picture)
- File metadata for files you select through the Google Picker (file name, type, size)
- File contents, only for files you explicitly choose to import into Label Suite
Dropbox. When you connect your Dropbox account, we may access:
- Account information (email, display name)
- File and folder metadata (names, paths, sizes) for browsing
- File contents, only for files you explicitly choose to transfer into Label Suite
Box. When you connect your Box account, we may access:
- Account information (email, display name, avatar)
- File and folder metadata (names, sizes) for browsing
- File contents, only for files you explicitly choose to transfer into Label Suite
Chartmetric. Label Suite uses the Chartmetric API to retrieve aggregated music industry analytics. This data is sourced from Chartmetric's database (not from individual users) and includes:
- Artist follower counts across platforms (Spotify, Instagram, TikTok, YouTube, Facebook, SoundCloud, Shazam)
- Streaming statistics, playlist placements, and chart positions
- Audience demographics and geographic listening data
We also collect content you upload to the platform (audio files, images, video files) and basic account information (email address) when you register.
2. How We Collect Information
Data is collected through:
- TikTok APIs (Login Kit and Content Posting API), with your explicit authorization
- Meta APIs (Facebook Login, Instagram Graph API, Pages API, Content Publishing API), with your explicit authorization
- YouTube Data API, with your explicit authorization via Google OAuth
- Spotify Web API, using application-level credentials for publicly available data
- Google Drive API and Google Picker API, with your explicit authorization via Google OAuth
- Dropbox API, with your explicit authorization via Dropbox OAuth
- Box API, with your explicit authorization via Box OAuth
- Chartmetric API, using application-level credentials for aggregated industry data
- Content you directly upload or create within the platform
- Your account registration (email address)
3. How We Use Information
We use data only to provide Label Suite's core services:
- Connect and identify user accounts
- Display analytics dashboards for your connected TikTok, Instagram, Facebook, YouTube, and Spotify data
- Display aggregated music industry analytics from Chartmetric
- Enable content upload, editing, and scheduling features
- Post or draft content to your connected TikTok, Instagram, and Facebook accounts on your behalf, with your consent
- Browse and transfer files from your connected Google Drive, Dropbox, or Box accounts at your direction
Data obtained through third-party platform APIs is processed only for these limited purposes. We do not use this data for any other purpose. Your data belongs to you, and we safeguard it accordingly.
4. Data We Do Not Collect or Use
Label Suite does not:
- Sell, license, or share your data with third parties for their own purposes
- Transfer data to advertising networks, ad exchanges, data brokers, or information resellers
- Use platform API data to build profiles, databases, or supplemental records on individuals beyond what is necessary to operate the service
- Use platform API data for cross-context behavioral advertising, retargeting, or personalized advertising
- Use platform API data for eligibility determinations related to housing, employment, insurance, credit, or government benefits
- Use platform API data for surveillance purposes
- Sell or redistribute Spotify content or data for any purpose other than displaying it back to users within Label Suite
- Resell, syndicate, or redistribute raw Chartmetric data to third parties
- Share user personally identifiable information (PII) without proper authorization
- Collect sensitive personal information beyond what is required to operate the platform
- Store Dropbox or Box login credentials (authentication is handled entirely through each platform's OAuth flow)
5. Data Storage and Security
We implement technical, physical, and administrative safeguards consistent with industry standards to protect your data against unauthorized access, disclosure, alteration, or destruction. These measures include:
- All data in transit is protected using SSL/TLS encryption (HTTPS)
- Access tokens for connected accounts are stored securely and are never exposed to other users
- Application-layer encryption is used for sensitive data fields
In the event of a security breach, we will promptly notify affected users, relevant platform partners (Meta, TikTok, Dropbox, etc.), and applicable authorities as required by law.
6. Subprocessors
Where we engage subprocessors or third-party services to handle user data (such as cloud hosting, database, or storage providers), we ensure those parties comply with applicable data protection laws and maintain equivalent protections for your data. Label Suite is responsible for the privacy, security, and integrity of user data collected or accessed through connected platforms.
7. User Control & Data Deletion
You may:
- Disconnect any connected account at any time from the Connections or Settings page in Label Suite. Disconnecting revokes our access and deletes the stored access tokens and account metadata for that connection
- Request deletion of all your data by contacting us at rey@labelsuite.co
- Revoke Label Suite's access directly through each platform's own settings:
If you remove Label Suite from your Facebook or Instagram account, Meta sends us a data-deletion request and we delete the data associated with that connection. You can also trigger this directly. See our Data Deletion Instructions.
8. Data Deletion Timelines
When you disconnect a connected account or request data deletion, we delete the associated data according to the following timelines:
- Spotify: Data deleted within 5 days of account disconnection
- Meta (Instagram/Facebook): Data deleted promptly upon disconnect or upon receiving a Meta data-deletion callback
- TikTok: Data deleted promptly upon disconnect
- YouTube / Google Drive: API data deleted promptly upon disconnect
- Dropbox / Box: Access tokens and account metadata deleted upon disconnect. Files previously transferred to Label Suite's storage at your request remain available (they are copies, not linked references)
9. Data Retention
We retain data only as long as necessary to provide our services or as required by applicable law. Platform API data is not retained beyond what is needed for the service to function. If you request account deletion, we will remove your personal data within a reasonable timeframe. Aggregated, anonymized analytics data that cannot be linked back to an individual may be retained.
10. Google API Limited Use Disclosure
Label Suite's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. This means Google API data is used only to provide and improve user-facing features that are prominent in Label Suite's interface. Google API data is not transferred to third parties except as necessary to provide the service, with user consent, or for security/legal purposes.
11. Cookies
Label Suite uses cookies for the following purposes:
- Authentication cookies: Used to maintain your login session and keep you signed in
- OAuth state cookies: Temporary cookies used during the account connection process to prevent cross-site request forgery. These are deleted immediately after the connection is completed
Label Suite does not place third-party tracking cookies or advertising cookies. We do not allow third parties to place cookies on your browser through our platform.
12. Notification Obligations
If Label Suite becomes subject to a regulatory investigation related to data handling, receives a government request for user data disclosure, or becomes aware that we can no longer maintain compliance with applicable data protection laws, we will take appropriate steps including notifying affected users and relevant authorities as required by law. We will cooperate with platform partner audits (such as those requested by Meta) where required by their developer terms.
13. Third-Party Services
This application integrates with multiple third-party platforms. Your use of those services is governed by their own privacy policies:
14. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes to how we handle data from connected platforms, we will notify users through the platform and, where required, prompt you to consent to the updated policy before continuing to use affected features. Continued use of the platform after changes are posted constitutes acceptance of the updated policy.