Legal

Privacy Policy

Effective September 5, 2026

This policy explains how Fun Entertainment Services LLC (“we,” “us,” or “our”) handles information through the public website at bandpocket.com, the private BandPocket workspace, the administrator tools, and the limited Charts Automation reviewer screen at band.guajiron.com (together, the “Services”). It does not govern third-party services, which handle information under their own policies.

Public website information

This website has no account registration or contact form. It uses Meta Pixel to measure page visits, product-page views, and clicks on email contact links. We do not send your email address or message to Meta.

Meta may receive the page URL and routine browser, device, and network information and may use cookies or similar technologies under the Meta Privacy Policy. The public website does not provide a tracking opt-out. If you do not agree to this measurement, do not use the website.

The hosting system may process routine technical information needed to deliver and protect the site, such as an IP address, request time, requested page, browser information, referring page, and error details.

If you email us, we receive the address, message, and other information you choose to include. Your email provider and ours also process that message under their own terms.

Private workspace and Google Sign-In information

BandPocket is a private workspace for approved Guajirón musicians and administrators. Google Sign-In provides the user's name, email address, and basic profile information so we can authenticate the account, enforce the approved access list, and show the correct workspace. BandPocket also handles information entered by approved users, including musician profiles, schedules, set lists, assignments, availability, practice materials, feedback, and other band operations.

An invited reviewer may instead enter a temporary invite code. We verify the code on the server and create a limited GUEST session using the fixed, non-personal email guest@example.com. This address does not represent the reviewer or an approved user and has no Google account or People-directory profile. The session can access only the read-only Charts reviewer screen and the BandPocket Library song and YouTube practice-video surface; charts, downloads, member data, and other workspace features remain unavailable. The invite code is not included in public browser files or activity records, and repeated failed attempts are temporarily rate-limited.

The authenticated service uses essential secure session cookies. It does not use advertising cookies or cross-site tracking. Its limited activity records identify the signed-in user, page, time, and a compact device category for security and troubleshooting; invite-code records identify GUEST, guest@example.com, and the invite method instead of a person. Activity records do not retain raw IP addresses, raw browser user-agent strings, or Google passwords.

Guajirón Admin and YouTube API Services

Guajirón Admin uses YouTube API Services. The YouTube channel owner authorizes access through Google OAuth. The tool accesses the owner's Google identity, configured Google Drive chart and media files, YouTube channel and upload information, video identifiers and metadata, and playlists and playlist items owned by the authorized channel.

After the administrator prepares and reviews a complete plan, the tool may upload locally generated rehearsal and practice-track videos as unlisted videos; update managed titles, descriptions, and tags; add, replace, remove, or reorder playlist items; and delete superseded or obsolete managed videos after live safety checks. The approximately ten band members who receive the resulting unlisted YouTube links do not authorize or operate Guajirón Admin.

An invited reviewer may start a nonpublishing calculation that reads current YouTube video and playlist metadata using the channel owner's existing authorization. The reviewer sees only a sanitized API-call and quota ledger plus planned changes; OAuth credentials, private API responses, provider locations, owner identity, and raw logs are not shown. Planned uploads, updates, inserts, moves, and deletions are estimates and are never sent from reviewer mode.

We store the channel owner's OAuth access and refresh tokens, name and email address, and the identifiers and metadata needed to prepare, review, execute, verify, and safely resume the current managed workflow. Tokens are stored only in private server files and are never exposed to other workspace users or the public. The tool does not request or store a Google or YouTube password, does not collect YouTube viewing history, and does not use search.list.

Use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google and YouTube handle information under the Google Privacy Policy.

How information is used

We use information only to operate, secure, troubleshoot, and improve the Services; authenticate approved users; provide the band workspace; perform administrator-reviewed chart, media, video, and playlist workflows; respond to requests; protect rights and safety; and meet legal obligations. We do not use Google user data for advertising, credit decisions, surveillance, or training a general-purpose artificial-intelligence model.

When information may be disclosed

Google and YouTube receive the OAuth and API requests needed to provide the authorized features. Information may also be handled by providers that host and secure the Services, store approved source files, or deliver email, subject to their agreements with us. We may disclose information when required by law, to protect rights or safety, or as part of a business transaction subject to applicable safeguards. We do not sell personal information, Google user data, or YouTube API data, and we do not use or share it for targeted advertising.

Retention and security

Google OAuth credentials are retained while the administrator keeps the integration connected and, after disconnection or revocation, only until deletion is completed as described below. YouTube API data in the current staged workflow or isolated reviewer calculation is refreshed from YouTube when a permitted user prepares a plan and is retained only as needed to review, verify, or safely resume the applicable workflow. Managed videos and playlists remain on YouTube until the channel owner changes or deletes them. Routine server records follow the hosting system's operational rotation, and email and workspace records are kept only as long as reasonably needed for the purposes described here or to meet legal obligations.

If authorization is revoked or can no longer be refreshed, we stop using it and delete the stored OAuth credentials and related Google and YouTube API data as soon as practical and within seven calendar days after we become aware of the revocation. We use access controls, private credential files, encrypted transport, scoped sessions, and other reasonable safeguards, but no internet transmission or storage system is guaranteed to be completely secure.

Your choices, revocation, and deletion

You may revoke Guajirón Admin's Google and YouTube authorization through your Google Account third-party connection settings. You may also email info@bandpocket.com to request disconnection or deletion of personal information, OAuth credentials, or stored Google and YouTube API data. We will verify the request and complete deletion as soon as practical and within seven calendar days, except for information we are legally permitted or required to retain.

Deleting information stored by our Services does not delete information stored by YouTube. To delete a video, playlist, or other content from YouTube, use YouTube directly or use an authorized workflow that expressly supports that action.

Changes to this policy

We may update this policy when the Services, data practices, or legal obligations change. If a change materially expands how Google or YouTube user data is used, affected users will be asked to review and accept the updated policy before that new use begins. The effective date above identifies the current version.

Contact

Fun Entertainment Services LLC
info@bandpocket.com