◈ The unglamorous but necessary bit

Privacy policy

loud.amsterdam is a small operation, and this page is written to be read rather than to be survived. It says plainly what the site collects, why, where it goes and how to make it stop.

Last updated

Who is responsible

loud.amsterdam is run personally by Mr. RÖCK, the organizer behind the site. He is the data controller for everything described here, which in plain terms means he decides what is collected and is answerable for it.

There is no company, no data protection officer and no support desk in between — questions about your data reach the person who can act on them directly, by writing to shout@loud.amsterdam.

The newsletter list

If you enter your email address in one of the signup forms, we store three things: the address itself, the language the site was showing you at the time, and the date you signed up. Nothing else — no name, no location, no tracking pixel in the mail.

The legal basis is your consent, given by submitting the form. We use the address for one thing only: telling you the listings have launched, and after that roughly one email a week about gigs in Amsterdam. It is never sold, rented, swapped or handed to anyone else.

You can withdraw that consent at any time and we will delete the address. Until the automated unsubscribe link is in place, write to shout@loud.amsterdam and it will be removed by hand — we aim to do this within a few days, and no later than the month the law allows.

How we count visits

We use Umami, an analytics tool we run ourselves on our own server rather than a service that resells what it learns. It sets no cookies, assigns you no persistent identifier, and cannot follow you to any other website.

It records which pages were opened, how the page performed while loading, and a small set of deliberate actions — a newsletter signup, a click on a link that leaves the site, a click out of the page-not-found screen. These are counted as totals, not built into a profile of you.

The legal basis is our legitimate interest in understanding how the site is used. We hold it a fair one: the counting runs on our own server, sets nothing on your device, builds no profile of you, and is shared with nobody. You can object to it — see your rights below.

If your browser sends a “Do Not Track” signal, the tracker honours it and records nothing at all.

Session recordings

This one deserves stating clearly rather than burying. While the site is in its pre-launch phase, Umami’s session recorder is switched on. It reconstructs how a visit unfolded — pages viewed, scrolling, mouse movement, and where you clicked or tapped — so we can see which parts of a page people actually use before the listings go live.

The recorder does not capture the characters you type. Your email address reaches us because you submitted the form, not because the recording watched you write it. Recordings stay on our own server alongside the rest of the analytics and are never shared.

The basis is that same legitimate interest, weighed against a heavier intrusion — so the recorder is confined to the pre-launch phase, switches itself off for a browser that asks not to be tracked, and what it captures is deleted inside twelve months. You can object to it at any time.

A “Do Not Track” signal switches the recorder off along with the tracker. If you would rather not be recorded and your browser sends no such signal, blocking analytics.rock-n-code.com in your browser or an ad blocker stops it, and the site works exactly as before.

What the server sees

Like every web server, ours sees the IP address a request arrives from. We use it for exactly one purpose: to limit how often the signup form can be submitted from the same place, so the list cannot be flooded by a bot.

Those counters live in memory, are capped in number and expire within minutes. IP addresses are never written to the database, never attached to a subscription, and do not survive a restart of the server.

The legal basis is our legitimate interest in keeping the form usable: a signup list that anyone can flood with a script is worth nothing to the people on it.

Cookies and browser storage

The site sets no cookies. There is no consent banner here because there is nothing to consent to on that front.

The only things kept in your browser are your choice of light or dark theme and, if you switch languages, that choice too — held in session storage under the names “theme” and “lang”. They never leave your device, are not readable by us, and disappear when you close the tab.

Who else sees any of this

Nobody. The database and the analytics both run on infrastructure we control within the European Union, so nothing described here is transferred outside it.

The site loads album artwork for past DJ sets from Apple’s servers, which means your browser tells Apple it fetched an image. Links out to Instagram, Discogs and Apple Music are ordinary links — those sites apply their own privacy policies once you arrive, and we have no say in them.

How long it is kept

A newsletter address is kept until you ask for it to be removed, or until the list is retired — whichever comes first. There is no reason to keep an address nobody is mailing, so a discontinued list is deleted rather than archived.

Analytics totals and session recordings are kept for as long as they are useful in shaping the site, and no longer than twelve months. Rate-limit counters expire within minutes, as described above.

Your rights

Under the GDPR you have the following rights over the data described here:

  1. To ask what we hold about you, and get a copy of it.
  2. To have anything inaccurate corrected.
  3. To have it deleted.
  4. To have us pause using it while a dispute is resolved.
  5. To receive it in a portable form, or have it sent on to someone else.
  6. To object to a particular use of it.
  7. To withdraw your consent at any time, as easily as you gave it.

Exercising any of them costs nothing and needs no particular form of words. Write to the address below and say what you want done; we will answer within one month.

shout@loud.amsterdam

If we get it wrong

Tell us first — it is usually the fastest way to fix something. If that gets you nowhere, you have the right to complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.

Autoriteit Persoonsgegevens →