Legal

Privacy Policy

Last updated: 16 June 2026

Who we are

Recommendle (recommendle.co.uk) is a personal music recommendation site that publishes one song and one album each day. This policy explains what data we collect when you visit the site, why we collect it, and the rights you have under UK GDPR and the Data Protection Act 2018.

The data controller is the operator of recommendle.co.uk. To exercise any of the rights below, or to ask a question about this policy, contact us at privacy@recommendle.co.uk.

What we collect

  • Usage data: pages viewed, approximate location (country/region), device type, browser, referrer, and timestamps — collected through our hosting provider and analytics.
  • Cookies and similar technologies: small files stored on your device. See "Cookies" below.
  • Account data (admin only): if you are the site administrator, we store your email address and an authentication token via our backend provider. Public visitors do not have accounts.
  • Voluntary contact: anything you send us by email.

We do not collect names, addresses, payment details or special-category data from visitors.

Why we use your data (legal basis)

  • Legitimate interests — running and securing the site, measuring traffic, and preventing abuse.
  • Consent — for any non-essential cookies (such as advertising or analytics that profile you).
  • Contract — for admin authentication.

Cookies

We use the following types of cookies:

  • Essential — required for the site to function (e.g. admin login session). Always on.
  • Analytics — anonymised traffic measurement. Optional.
  • Advertising — set by third-party ad networks (such as Google AdSense) to serve relevant adverts and measure performance. Optional.

You can change your choices at any time using your browser settings. Blocking cookies may break parts of the site.

Third-party services

We rely on the following processors. Each has its own privacy policy:

  • Supabase — backend, database, and admin authentication.
  • Cloudflare — hosting and content delivery.
  • Spotify — embedded music previews (Spotify may set its own cookies when the player loads).
  • Apple Music — outbound links only.
  • Google AdSense or equivalent — advertising, when ad slots are enabled.

We never sell your data. We share it with these processors only to the extent needed to run the service.

How long we keep it

Server logs and analytics: up to 14 months. Admin account data: for as long as the account exists. Email correspondence: up to 2 years, then deleted.

Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Have inaccurate data corrected.
  • Have your data erased ("right to be forgotten").
  • Object to or restrict our processing.
  • Request a copy of your data in a portable format.
  • Withdraw consent at any time, where consent is the legal basis.
  • Complain to the UK Information Commissioner's Office (ico.org.uk).

To exercise any of these rights, email privacy@recommendle.co.uk.

Children

Recommendle is not directed at children under 13 and we do not knowingly collect data from them.

Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top will change when we do.