Privacy Policy

We take the protection of your personal data very seriously. Personal data is only collected when necessary.

Server Log Files

The hosting provider automatically collects and stores information transmitted by your browser.

Cookies & Browser Storage

For SoundCloud login, we use one strictly necessary, short-lived HttpOnly cookie to bind the login attempt to your browser. It expires after ten minutes or is deleted when the callback is processed. This website also uses localStorage to store the following data locally in your browser:

  • likedDJs: Your favorited DJs or sets
  • savedArtists: The identifiers of artists you save to Bunny Brain
  • bunny_token: A pseudonymous app identifier created when you sign in using SoundCloud
  • festival: The currently selected festival
  • following: The SoundCloud accounts you follow (if logged in)
  • lastLikesUpdate and lastFollowingUpdate: Last-refresh timestamps used to avoid unnecessary API requests
  • now-hide-non-music: Your preference for showing non-music entries in the current view
  • likesSyncEnabled and likesSyncDeviceId and likesSyncRevision and likesSyncOperations and likesSyncInitialized and likesSyncToken and savedArtistsSyncDeviceId and savedArtistsSyncRevision and savedArtistsSyncOperations and savedArtistsSyncInitialized and savedArtistsSyncToken: Your opt-in preference, random device identifier, sync revision, and pending offline like and saved-artist operations
  • shallowbunny_stats_id: A random anonymous identifier used for aggregate usage statistics. It rotates after 30 days and is sent to our API together with the device category (desktop, mobile web, or installed app). It is not linked to your SoundCloud account or bunny_token.

We also use sessionStorage for temporary navigation and display data, such as the selected room and scroll positions. This data is removed when the browser session ends.

Optional SoundCloud Connection

If you connect SoundCloud, our backend temporarily stores a random OAuth state and PKCE verifier for up to ten minutes and deletes them when the login callback is processed. It then stores your SoundCloud user ID, profile URL, and client-specific OAuth access and refresh tokens so the connection can be maintained. Duck and Bunny credentials are stored separately. Followed-account data may be cached to highlight artists and reduce SoundCloud API requests. Disconnecting SoundCloud from this app deletes its stored access and refresh tokens.

Optional Like Synchronization

If enabled while signed in with SoundCloud, liked festival sets, saved artist identifiers, and deletion tombstones are stored pseudonymously on our backend for this app. The data is used only to synchronize your devices and is not public. Turning sync off stops future synchronization. You may request deletion of server data using the contact details below.

PayPal (Third Party)

The Festival App page loads the PayPal SDK for the optional support feature. PayPal may use cookies or similar technologies and may create the __paypal_storage__ localStorage entry. This storage is controlled by PayPal, which acts as an independent controller for that processing. For details, see the PayPal Privacy Statement.

Contact

If you contact us via email, your data will be stored to process your request and handle follow-up questions. We do not share this data without your consent. For privacy-related inquiries, please use the contact details in the Impressum.

Access, Deletion, Blocking

You have the right at any time to request free information about your stored personal data, its origin and recipient, and the purpose of data processing. You also have the right to correct, block, or delete this data.

Last updated: July 2026

Home