last updated · 2026-06-22
Privacy Policy
REQ ("REQ", "we", "our") is a tool that lets a DJ receive song requests from their audience during a live set. The audience scans a QR code, requests a track, and pays a small amount through Stripe. The DJ accepts or declines the request from the REQ mobile app.
This document describes the data we collect, why we collect it, with whom we share it, and the rights you have over it. It applies to both the REQ mobile app (iOS & Android, bundle fm.req.dj) and this website.
The data controller is Erwan André, entrepreneur individuel (auto-entrepreneur) opérant sous le nom commercial « DirtyLab », SIRET 788 503 225 00039, 58 rue Césaria Evora, 75019 Paris, France. For any question about your data or to exercise your rights, email contact@dirtylab.fr.
1 · Data we collect
From DJs (REQ mobile app users)
- Email address and authentication credentials (Supabase Auth).
- Stage name, slug, profile image URL, minimum request amount, Instagram handle.
- Stripe Connect account identifier and payout status flags (no banking details are stored on REQ servers — Stripe handles them).
- Device push notification token (Expo) for incoming-request alerts.
- Session history (requests received, accepted, declined).
From requesters (audience scanning the QR)
- Email (optional, used for receipt and waitlist if you opt in).
- Song title and artist you typed in the request form.
- Payment information: handled directly by Stripe Checkout. REQ never sees your card number, CVC, or expiry — only the resulting payment intent ID and amount.
- Anonymised technical data (IP, device type) via Vercel logs and Stripe.
2 · Why we collect it
- Operate the request flow (display the DJ, route requests, send push notifications).
- Process payments through Stripe (authorise, capture on DJ accept, cancel on decline or 20-minute timeout).
- Pay out DJs via Stripe Connect.
- Prevent fraud, debug issues, comply with legal obligations.
- Send opt-in product updates if you joined the newsletter.
3 · Third parties we share data with
- Supabase — database & authentication (privacy).
- Stripe — payments & Connect payouts (privacy).
- Vercel — web hosting & logs (privacy).
- Expo — push notification delivery for the mobile app (privacy).
- Airtable — newsletter list storage when you opt in (privacy).
REQ does not sell your data. We do not run third-party advertising trackers.
4 · Payment data & manual capture
When you request a song, your card is authorised but not charged immediately. The amount is captured only after the DJ accepts your request. If the DJ declines or does not respond within 20 minutes, the authorisation is automatically cancelled — your bank releases the hold and no funds leave your account.
5 · Data retention
Account data is retained for as long as your REQ account exists. Request and payment records are retained for accounting and legal obligations (typically 10 years in the EU). Push tokens are deleted as soon as the device unregisters or the token becomes invalid.
6 · Your rights (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the right to access, rectify, port, restrict, or delete your data, and to lodge a complaint with your local data protection authority (in France, CNIL).
To exercise any of these rights, email us at contact@dirtylab.fr.
7 · Children
REQ is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has used REQ, contact us and we will delete the data.
8 · Changes to this policy
We may update this policy. Material changes will be flagged on this page and, for DJs, communicated via in-app notice. The "last updated" date at the top reflects the current version.
9 · Contact
Questions? Email contact@dirtylab.fr.