Spotify Advertising - Privacy Policy

Introduction

Thanks for being a business partner of Spotify!

At Spotify, we want to give you the best possible experience to ensure that you enjoy working with us today, tomorrow and in the future. Privacy and security of personal data is, and will always be, enormously important to us. So, we want to transparently explain how and why we gather, store, share and use your personal data - as well as outline the controls and choices you have around when and how you share your personal data.

That is our objective, and this Privacy Policy (“Policy”) will explain exactly what we mean in further detail below.

About this Policy

This Policy sets out the essential details about the processing of your personal data relating to your company’s business relationship with Spotify, (“Spotify”, “we”, “our”, “us”). This Policy also covers the processing of personal data within our Spotify Advertising educational portal (“Spotify Soundcheck”).

For information about how we process your personal data relating to your private Spotify Service account, please be referred to our User Privacy Policy.

We hope this helps you to understand our privacy commitment to you. For information on how to contact us if you ever have any questions or concerns, then please see Section 12 “How to Contact Us”.

Your rights and your preferences: Giving you choice and control

You may be aware that the (EU) General Data Protection Regulation or "GDPR" gives certain rights to individuals in relation to their personal data. As available and except as limited under applicable law, the rights afforded to individuals are:

  • Right of Access
    • the right to be informed of and request access to the personal data we process about you;
  • Right to Rectification
    • the right to request that we amend or update your personal data where it is inaccurate or incomplete;
  • Right to Erasure
    • the right to request that we delete your personal data;
  • Right to Restrict
    • the right to request that we temporarily or permanently stop processing all or some of your personal data;
  • Right to Object
      • the right, at any time, to object to us processing your personal data on grounds relating to your particular situation;
      • the right to object to your personal data being processed for direct marketing purposes;
  • Right to Data Portability
    • the right to request a copy of your personal data in electronic format and the right to transmit that personal data for use in another party’s service; and
  • Right not to be subject to Automated Decision-making
    • the right to not be subject to a decision based solely on automated decision-making, including profiling, where the decision would have a legal effect on you or produce a similarly significant effect.

If we send you electronic marketing messages based on your consent or otherwise permitted by applicable law, you may, at any time, withdraw such consent or declare your objection (“opt-out”) at no cost. The electronic marketing messages you receive from Spotify (e.g. those sent via email) will also include an opt-out mechanism within the message itself (e.g. an unsubscribe link in the emails we send to you).

If you have any questions about your privacy, your rights, or how to exercise them, please contact privacy@spotify.com. We will respond to your request within a reasonable period of time upon verification of your identity. If you are unhappy with the way we are using your personal data you can also contact, and are free to lodge a complaint with, the Swedish Data Protection Authority (Datainspektionen) or your local Data Protection Authority.

How do we collect your personal data?

We collect your personal data in the following ways:

  1. Personal data provided by you – We may collect personal data from our business partners and their representatives at events, when you sign-up for a newsletter and through our business contacts with you. If you create an account for Spotify Soundcheck, we ask for certain additional personal data about you in order to set up the account.
  2. Personal data provided by your employer or by publicly available sources – We may collect personal data from your employer and/or colleagues in our business contacts with them or by publicly available sources such as your LinkedIn profile.
  3. Personal data provided through our business contacts or your use of Spotify Soundcheck – We may collect personal data of our business partners and their representatives, i.e. you, through our business contacts. If you use Spotify Soundcheck, we may also collect personal data provided through your use of the portal.
  4. Personal data collected that enables us to provide you with additional features/functionality – From time to time, you may also provide us with additional personal data or give us permission to collect additional personal data, e.g. to provide you with more features, additional services or invite you to Spotify events.
  5. Personal data collected from third parties – We may receive personal data about you from third parties including partners we work with, in order to contact you with relevant information. We will use this personal data either where you have provided your consent to the third party, or to Spotify to that data sharing taking place, or where Spotify has a legitimate interest to use the personal data in order to provide or market Spotify Advertising.

We use anonymised and aggregated information for purposes that include testing our IT systems, research, data analytics, creating marketing and promotion models, improving Spotify Advertising, and developing new features and functionality within Spotify Advertising including Spotify Soundcheck.

What personal data do we collect from you?

We have set out in the tables below the categories of personal data we collect and use about you.

Personal data provided by you

Account Registration data for Spotify Soundcheck:
This is the personal data that is provided by you or collected by us when creating your account for Spotify Soundcheck. This includes your name, employer, holding company, company position, company department, business email address, Spotify service account email address, password, location, state and country.

Some of the personal data we will ask you to provide is required in order to create your account. You also have the option to provide us with some additional personal data in order to make your account more personalized, such as uploading a profile image.

Personal data provided by you, your employer or by publicly available sources

Customer Relationship Management data (“CRM Data”):
This is the personal data that is collected about you when you request more information about Spotify Advertising, subscribe to our newsletter, join Spotify events, or otherwise work or integrate with Spotify Advertising. CRM Data could also be collected from your employer and/or colleagues or through publicly available sources, such as LinkedIn. CRM Data includes:

  • Name, business email address, company name, country, type of business, industry, privacy campaign objective, Spotify Advertising products and services that you find interesting, etc.

Personal data provided through your use of Spotify Soundcheck

Spotify Soundcheck Usage Data:
This is the personal data that is collected about you when you are using Spotify Soundcheck. This includes:

  • Information about your interactions with Spotify Soundcheck which includes progress per module, score, i.e. how many questions you got right and completed, lessons (contentful), and other interactions on Spotify Soundcheck.
  • Your interactions with Spotify’s customer support team.
  • Technical Data which may include URL information, cookie data, your IP address, the types of devices you are using to access or connect to Spotify Soundcheck, unique device IDs, device attributes, network connection type and provider, network and device performance, browser type, language, and operating system. Further details about the technical data that is processed by us can be found in our Cookie Policy.

Personal data collected with your permission that enables us to provide you with additional features/functionality

Survey and Contest Data:
If you participate in any survey or contest, you will provide certain personal data as part of your participation, unless you respond anonymously. The exact personal data collected will vary depending on the survey or contest.

Marketing Data:
This personal data is used to enable Spotify Advertising and our partners / service providers to send you marketing communications either:

  • Via email; and/or
  • Direct from the third party.

What do we use your personal data for?

We use a variety of technologies to process the personal data we collect about you for various reasons. We have set out in the table below the reasons why we process your personal data, the associated legal bases we rely upon to legally permit us to process your personal data, and the categories of personal data (identified in Section 5 “What personal data do we collect from you?”) used for these purposes:

Description of why Spotify processes your personal data (´processing purpose´): To provide, customize, and improve your experience with Spotify Soundcheck and other services provided by Spotify Advertising, for example by providing customized or localized advertising (including for third party products and services).
Legal Basis for the processing purpose:
- Legitimate interest
- Consent
Categories of personal data used by Spotify Advertising for the processing purpose :
- CRM Data
- Account Registration Data for Spotify Soundcheck
- Spotify Soundcheck Usage Data
- Marketing Data


Description of why Spotify processes your personal data (´processing purpose´): To understand how you access and use Spotify Soundcheck to ensure technical functionality of Spotify Soundcheck, develop new products and services, and analyze your use of Spotify Soundcheck, including your interaction with applications, products, and services that are made available, linked to, or offered through Spotify Soundcheck.
Legal Basis for the processing purpose: Legitimate interest
Categories of personal data used by Spotify Advertising for the processing purpose :
- Account Registration Data for Spotify Soundcheck
- Spotify Soundcheck Usage Data


Description of why Spotify processes your personal data (´processing purpose´): To communicate with you for Spotify Advertising-related purposes.
Legal Basis for the processing purpose: Legitimate interest
Categories of personal data used by Spotify Advertising for the processing purpose :
- CRM Data
- Account Registration Data for Spotify Soundcheck
- Spotify Soundcheck Usage Data


Description of why Spotify processes your personal data (´processing purpose´): To communicate with you, either directly or through one of our partners, for:
- marketing,
- research,
- participation in surveys,
- promotional purposes, and
- progress updates in Spotify Soundcheck
via emails, notifications, or other messages, consistent with any permissions you may have communicated to us.
Legal Basis for the processing purpose:
- Consent
- Legitimate interest
Categories of personal data used by Spotify Advertising for the processing purpose :
- CRM Data
- Survey and Contest Data
- Marketing Data

If you require further information about the relevant legal basis and the balancing test that Spotify has undertaken to justify its reliance on the legitimate interest legal basis under the GDPR, please see Section 12 “How to Contact Us”.

Sharing your personal data

We have set out the categories of recipients of the personal data collected or generated through your use of Spotify Advertising and Spotify Soundcheck.

Personal data we may share

Categories of recipients: Service Providers Reason for sharing: We use certain reputable third parties to provide us with certain specialized services related to Spotify Soundcheck, in particular providers which host, store, manage and maintain Spotify Soundcheck, its content and the data we process. These third parties will have access to certain data about you, but only where this is necessary in order for those third parties to provide their services to us.

Categories of recipients: Marketing Partners Reason for sharing: We may share personal data with certain marketing and advertising partners to send you marketing communications about Spotify Advertising.

Our marketing partners may help us to serve ads or relevant information to you by combining this information with data which they have collected about you elsewhere. They collect this information when you use their services or the websites and services of third parties. This Privacy Policy does not apply to the collection of your information by our marketing partners.

Categories of recipients: Statistical Analysis Portal Reason for sharing: We may aggregate your personal data with similar data relating to other users of Spotify Soundcheck in order to create statistical information regarding Spotify Soundcheck and its use, which we may then share with third parties or make publicly available. However, none of this information would include any email address or other contact information, or anything that could be used to identify you individually, either online or in real life.

Categories of recipients: Other Spotify Group Companies Reason for sharing: We will share your personal data with other Spotify Group companies to carry out our daily business operations and to enable us to maintain and provide the Spotify Advertising services to you.

Categories of recipients: Law Enforcement and Data Protection Authorities Reason for sharing: We will disclose your personal data if we believe in good faith that we are permitted or required to do so by law, including in response to a court order, subpoena or other legal demand or request.

We may disclose your personal data if we feel this is necessary in order to protect or defend our legitimate rights and interests, or those of our users, employees, directors or shareholders, and/or to ensure the safety and security of Spotify Soundcheck.

Categories of recipients: Purchasers of our business Reason for sharing: We may transfer your personal data to any person or company that acquires all or substantially all of the assets or business of Spotify Advertising, or on a merger of our business, or in the event of our insolvency, provided that such person or company be bound by this Policy or terms substantially similar.

Data retention and deletion

We keep your personal data only as long as necessary to provide you with the Spotify Advertising services and for legitimate and essential business purposes, such as maintaining the performance of Spotify Soundcheck, making data-driven business decisions about new features and offerings, complying with our legal obligations, and resolving disputes.

If you request, we will delete or anonymise your personal data so that it no longer identifies you, unless we are legally allowed or required to maintain certain personal data, including situations such as the following:

  • If there is an unresolved issue relating to you and/or your company, such as an outstanding credit on your account or an unresolved claim or dispute, we will retain the necessary personal data until the issue is resolved;
  • Where we are required to retain the personal data for our legal, tax, audit and accounting obligations, we will retain the necessary personal data for the period required by applicable law; and/or,
  • Where necessary for our legitimate business interests, such as fraud prevention or to maintain the security of our users.

You can always delete your personal data and your Spotify Soundcheck account by contacting us at support@spotify.com at any time.

Transfer to other countries

Spotify may subcontract processing to, or share your personal data with third parties located in countries other than your home country. Your personal data may therefore be subjected to privacy laws that are different from those in your country of residence.

Personal data collected within the European Union and Switzerland may, for example, be transferred to and processed by third parties located in a country outside of the European Union and Switzerland. In such instances Spotify shall ensure that the transfer of your personal data is carried out in accordance with applicable privacy laws and in particular that appropriate contractual, technical, and organisational measures are in place, such as the Standard Contractual Clauses approved by the EU Commission.

Keeping your personal data safe

We are committed to protecting our data subjects’ personal data. We implement appropriate technical and organisational measures to help protect the security of your personal data; however, please note that no system is ever completely secure.

Your password protects your Spotify Soundcheckl account, so we encourage you to use a unique and strong password, limit access to your computer and browser, and log out after having used Spotify Soundcheck.

Changes to this Privacy Policy

We may occasionally make changes to this Policy.

When we make material changes to this Policy, we’ll provide you with prominent notice as appropriate under the circumstances, e.g., by displaying a notice on the Spotify Advertising website or by sending you an email. We may notify you in advance. Please therefore make sure you read any such notice carefully.

How to contact us

Thank you for reading our Privacy Policy. If you have questions about this Policy, please contact privacy@spotify.com or by writing to us at the address indicated below.

Spotify USA Inc. is the data controller for the purposes of the personal data processed under this Policy if you are based in the US.

Spotify USA Inc. 4 World Trade Center, 150 Greenwich Street, 62nd Floor, New York, NY 10007 USA

Spotify AB is the data controller for the purposes of the personal data processed under this Policy if you are based in any other country.

Spotify AB Regeringsgatan 19, SE-111 53 Stockholm Sweden

We hope you enjoy Spotify Advertising! © Spotify.

Let’s talk

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.