Privacy Policy - Crosswinds
1. Who We Are
This website is operated by Crosswinds. We are committed to protecting your personal data and your privacy rights under GDPR, CCPA, and other applicable data protection laws.
2. Data We Collect
We may collect the following personal data:
- Account data: name, email address, password (encrypted)
- Purchase data: billing address, payment information (processed securely by Stripe — we do not store card details)
- Usage data: pages visited, features used, device and browser information
- Communication data: messages you send us, support tickets
3. How We Use Your Data
- To process your purchases and deliver digital content, merchandise, and event tickets
- To manage your account and fan subscriptions
- To send order confirmations and important updates
- To improve our website and services
- To comply with legal obligations
4. Legal Basis for Processing (GDPR)
- Contract: processing necessary to fulfill your purchases and subscriptions
- Consent: marketing communications (you can opt out at any time)
- Legitimate interest: improving our services, preventing fraud
5. Third-Party Services
We use the following third-party processors:
- Stripe: payment processing (PCI DSS compliant)
- BandSaaS: website hosting platform
- Email service providers: for transactional emails
6. Cookies
We use cookies to maintain your session, remember your preferences, and operate essential features like the shopping cart. See our Cookie Policy for details.
7. Data Retention
We retain your personal data for as long as your account is active or as needed to provide services. Purchase records are retained for legal and accounting purposes as required by law.
8. Your Rights
Under GDPR and CCPA, you have the right to:
- Access: request a copy of your personal data
- Rectification: correct inaccurate data
- Erasure: request deletion of your data ("right to be forgotten")
- Portability: receive your data in a machine-readable format
- Object: opt out of certain processing activities
- Withdraw consent: at any time for consent-based processing
To exercise any of these rights, please contact us through the website.
9. Data Security
We implement appropriate technical and organizational measures to protect your data, including encryption, secure hosting, and access controls.
10. Children's Privacy
This site is not intended for children under 16. We do not knowingly collect data from children.
11. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes.
12. Contact
For privacy-related inquiries, please contact us through the website.
Last updated: April 2026