Seshn is a marketplace where musicians find each other, agree terms, and get paid for collaboration. Doing that well means handling some personal information. This policy explains what we collect, why, who we share it with, how long we keep it, and the control you have over it. We've written it to be read, not to hide behind.
The short version.We collect what we need to run the marketplace , your account, your public profile, the gigs and applications you create, the messages you send, and (when you transact) contract and payment records. We don't sell your personal information, and we don't use your private messages or unreleased work to train AI. You can access, correct, export, or delete your data at any time.
Seshn is operated by Seshn Pty Ltd("Seshn", "we", "us", "our"), a company registered in New South Wales, Australia. We are the data controller for the personal information described in this policy.
For any privacy question, request, or complaint, contact our privacy team at privacy@seshn.fm. See section 17 for more ways to reach us.
This policy applies to the Seshn website, web app, and related services (the "Platform"). It covers everyone who uses Seshn, wherever you are.
Depending on where you live, different privacy laws give you rights. We comply with:
Where these overlap, we apply the standard most protective of you. If a specific law gives you a right not described below, you still have it, this policy doesn't limit your statutory rights.
We only collect information we actually use to run the Platform. Most of it you give us directly; a small amount is generated as you use Seshn or comes from services you connect.
| Category | What it includes | Where it comes from |
|---|---|---|
| Account | Email address, password (stored only as a secure hash by our auth provider), sign-in timestamps, and email-verification status. | You, at sign-up |
| Public profile | Display name, username, bio, location, pronouns, roles, genres, skills, influences, languages, availability, avatar and cover images, photo gallery, credits/discography, featured links, and the services and rates you list. | You, in onboarding & profile editing |
| Connected accounts | Links and basic public stats (e.g. follower counts) from music platforms you choose to connect, such as Spotify or SoundCloud. | You & the linked platform |
| Gigs & applications | Collaboration briefs you post, and the pitches and attachments you submit when applying. | You |
| Messages | Direct messages between you and other members, including any audio or file attachments you send. | You & other members |
| Contracts & signatures | Collaboration agreements you draft or sign, the agreed terms, the generated agreement PDF, and electronic-signature evidence (timestamp, IP address, browser/device user-agent, and a hash of the signed document). | You & the other party |
| Payments & payouts | Escrow and transaction records (amounts, currency, status, platform fee) and your payout-account identifiers. Card numbers and bank details are handled by Stripe, we never see or store your full payment credentials. | You, via Stripe |
| Deliverables & disputes | Files, links, and notes submitted against a contract, and any dispute you open (including the reason and evidence). | You & the other party |
| Notifications & preferences | Your in-app notifications, read state, notification preferences, and locale. | Generated as you use Seshn |
| Trust & safety | Reports you file or that are filed about you, blocks, and any account-restriction history. | You, other members & us |
| Technical & security logs | IP address, browser/device information, and an append-only audit log of security-sensitive actions (e.g. signing a contract, funding or releasing escrow). | Generated automatically |
Sensitive information.We don't ask for sensitive information (such as health, racial or ethnic, political, or biometric data). Please don't put it in free-text fields like your bio or messages. Anything you publish on your public profile is, by design, visible to anyone.
We use your information to:
What we don't do.We don't sell your personal information. We don't use your private messages, attachments, or unreleased work to train AI models. We don't run third-party advertising networks inside the Platform.
If you are in the EEA or UK, we rely on the following legal bases:
We rely on a small set of trusted providers to operate the Platform:
Each provider is bound by a data-processing agreement and may only use your information to provide their service to us. We review this list as our stack evolves.
Seshn is based in Australia, and some of our providers process data in other countries (including the United States and the European Union). Where we transfer personal information across borders, including from the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, and we take reasonable steps to ensure recipients protect it consistently with this policy and APP 8. By using Seshn, you understand your information may be processed outside your home country.
We keep personal information only as long as we need it, then delete or de-identify it:
We take security seriously. Access to your data is governed by database row-level security so that, for example, your messages are visible only to you and the person you're talking to, and your contracts only to the parties to them. We encrypt data in transit, restrict internal access on a need-to-know basis, store passwords only as secure hashes, and never handle your full payment-card or bank details (Stripe does). No system is perfectly secure, so we also maintain an audit trail and an incident-response process (see section 15).
Subject to the law that applies to you, you have the right to:
A note on account deletion.If you have an in-progress contract or funds held in escrow, we may need to pause deletion until those are resolved, because the other party has rights and obligations tied to them. We'll tell you if that's the case. Some joint records, like a shared conversation or a signed contract, are retained for the other party even after you leave.
Email privacy@seshn.fmfrom the address associated with your account, or use the support tools in the app. To protect your data, we'll first verify that you are the account holder.
We respond within 30 days(the legal maximum under the APPs and GDPR), and usually much sooner. There's no charge for a reasonable request. If we can't fully action a request, we'll explain why.
If you're not satisfied with our response, you can complain to a regulator: in Australia, the Office of the Australian Information Commissioner (OAIC); in the EEA, your local supervisory authority; or in the UK, the Information Commissioner's Office (ICO). We'd appreciate the chance to resolve it with you first.
Seshn is not intended for children. You must be at least 16 years oldto create an account, and at least 18 (or the age of majority where you live) to enter contracts or transact. We don't knowingly collect personal information from children under 16. If you believe a child has given us their information, contact us and we'll delete it.
We maintain an incident-response process. If a data breach is likely to result in serious harm, we will notify the OAIC and affected individuals as required by the Notifiable Data Breaches schemeunder Part IIIC of the Privacy Act (and the equivalent GDPR/UK GDPR obligations, generally within 72 hours of becoming aware where they apply). We'll tell you what happened, what information was involved, and the steps you can take.
We may update this policy as Seshn evolves or the law changes. When we make material changes, we'll update the "Last updated" date above and, where appropriate, notify you in the app or by email before the change takes effect. Continuing to use Seshn after an update means you accept the revised policy.
Seshn Pty Ltd, Privacy team
Email: privacy@seshn.fm
General support: support@seshn.fm
Registered in New South Wales, Australia.
If you have a disability and need this policy in an accessible format, let us know and we'll help.