Your data

Privacy policy.

Last updated: 29 July 2026

The short version: we collect what we need to write your song and get it to you, we don't sell it, and you can ask us to delete it. The longer version follows.

What we collect

  • Order details - your email, the occasion, and the stories and facts you tell us about the person the song is for.
  • Payment - handled entirely by Stripe. We never see or store your full card details; we keep a record of what was paid for which order.
  • Account sign-ins - we use passwordless magic links, so there's no password to store. A session cookie keeps you signed in after you open one.
  • Checkout progress - with analytics permission, a pseudonymous browser ID, the page and offer you saw, broad device type, checkout stages, and any email you begin entering. This helps us understand where checkout fails; it is not a marketing subscription.
  • Usage analytics - see “Analytics and advertising” below.

What we use it for

  • Writing, producing, and delivering your song - the details you share go to the small team working on it, and nowhere else.
  • Emailing you about your order: sign-in links, delivery, and revision updates.
  • Restoring an unfinished checkout on the same device and diagnosing checkout errors.
  • Returning-customer perks, like your encore discount code on your account page.

We don't sell your data, and we don't add you to marketing lists you didn't ask for.

Songs about other people

By nature, you'll tell us things about someone else. Share only what you're comfortable being sung about, and keep it kind - see our terms. The stories you send are used to write the song and are kept with the order so we can handle revisions.

Share links

Delivered songs get a private, unguessable share link and QR code. The share page shows the song and its title - not your email or your order notes. Anyone with the link can listen, so share it deliberately. Email us if you want a link disabled.

Analytics and advertising

  • Warblepop first-party events - with analytics permission, page, offer, button, checkout and purchase stages linked by a random browser ID. We use these to measure the buying journey without building a cross-site profile.
  • DataFast - with analytics permission, site and revenue attribution so we can see which pages and channels lead to orders.
  • Google Ads and Meta Pixel - with advertising permission, these measure whether ads work by reporting events such as page views and purchases. Google Consent Mode receives denied or granted consent signals before measurement starts; when advertising storage is denied, Google may receive cookieless measurement signals rather than advertising cookies. After a confirmed purchase, we may send Google Ads the consented ad click identifier, order reference, value and currency so the sale is attributed and deduplicated. We do not send card details or hashed email addresses for this purpose.

Your privacy choices

Optional storage starts off. The compact banner makes “Accept all” and “Reject optional” equally available, with separate controls for functional preferences, analytics, and advertising. You can reopen “Privacy choices” from any public page and withdraw a choice as easily as you gave it. Essential payment, security, and consent-choice storage stay available either way.

Cookies and local storage

  • A session cookie when you sign in to your account (essential, expires).
  • Your consent choice, kept locally so we can continue respecting it.
  • With functional permission, your region/currency choice and an unfinished checkout draft (email, discount code and song count), kept for up to 30 days. A “Not now” choice suppresses the on-site reminder for 24 hours.
  • With analytics or advertising permission, the measurement tools above may set their own cookies or local identifiers.
  • Stripe may use storage needed to provide secure payment and prevent fraud when you open checkout.

Where it lives and how long

Orders and audio are stored on our secure cloud storage and kept so your account page keeps working and your songs stay listenable. Want an order, a share link, or everything we hold about you deleted? Email us and we'll do it.

First-party activity events are pruned after 90 days. An unfinished checkout draft expires from your browser after 30 days. An unpaid server-side checkout record is normally kept for up to seven days. Before removing one, we check Stripe for a successful or still-processing payment: successful payments are recovered as orders, payments still processing are left alone, and only safely abandoned payment attempts are cancelled. Payment and support records needed for accounting, fraud prevention, disputes, or a support request may be kept longer.

Your rights

You can ask for a copy of the data we hold about you, ask us to correct it, or ask us to delete it. One email does it: [email protected]. We'll respond promptly - a human reads that inbox.