Privacy Policy

Your Privacy is Our Priority

At Pubdish, we are committed to protecting your personal information and maintaining the highest standards of data security and privacy compliance.

Last Updated: February 3, 2026

Introduction

Welcome to Pubdish's Privacy Policy. This document explains how we collect, use, store, and protect your personal information when you use our music distribution services.

By using Pubdish's services, you agree to the collection and use of information in accordance with this policy. We are committed to transparency and will always inform you about how your data is being used.

Important: We take your privacy seriously. All identity verification information is secured through our official CMS partner, Audicient, who collaborates with Pubdish to distribute music for artists and labels. Users must complete eKYC (electronic Know Your Customer) verification through Audicient before uploading or distributing music. Audicient maintains enterprise-level security standards for data protection.

Privacy Policy Overview

What We Collect

Personal information, identity documents, payment details, and usage data necessary for service delivery.

How We Protect It

Industry-leading encryption, secure storage with Audicient, and strict access controls protect your data.

Your Rights

Access, correct, delete, or export your data. You maintain full control over your personal information.

Information We Collect

Comprehensive overview of data collected through our services

Personal Information

When you create an account or use our services, we collect the following personal information:

  • Full Name:

    Your legal name as it appears on official documents

  • Email Address:

    Primary contact for account communications

  • Phone Number:

    For account security and verification purposes

  • Date of Birth:

    To verify age requirements for service use

  • Mailing Address:

    Physical address for legal documentation and correspondence

  • Country/Region:

    For tax purposes and legal compliance

  • Artist/Label Name:

    Professional identity for music distribution

  • Profile Information:

    Biography, social media links, photos

Identity Verification Documents

SECURED BY AUDIENT

Important Security Notice: All identity verification documents are securely stored and managed by our official CMS partner, Audicient, which collaborates with Pubdish to distribute music for artists and labels. Pubdish does not store these sensitive documents on our own servers. All users must complete eKYC (electronic Know Your Customer) verification through Audicient before they can upload or distribute music.

Audicient employs bank-level encryption, multi-factor authentication, and complies with international data protection standards (GDPR, CCPA, SOC 2 Type II) to ensure the highest level of security for your sensitive information.

To verify your identity and comply with legal requirements (eKYC - electronic Know Your Customer), we collect:

  • Government-Issued ID:

    Passport, driver's license, or national ID card

  • Tax Identification Number:

    SSN, EIN, VAT number, or equivalent

  • Proof of Address:

    Utility bill or bank statement (within 3 months)

  • Business Documentation:

    For labels: business registration, certificates

Data Breach Responsibility

In the unlikely event of a security breach affecting your identity verification documents, Audicient is fully responsible for all consequences, notifications, and remediation. Pubdish maintains comprehensive insurance and legal agreements with Audicient to protect your interests.

Payment & Financial Information

To process royalty payments and subscription fees, we collect:

  • Bank Account Details:

    Account number, routing number, IBAN, SWIFT code

  • Payment Method:

    PayPal, Stripe, wire transfer preferences

  • Billing Information:

    Subscription payment details and history

  • Transaction Records:

    Royalty payments, distribution fees, earnings history

Security Note: Payment information is encrypted and processed through PCI-DSS compliant payment processors. We never store complete credit card numbers.

Music & Content Data

Information related to your music releases and content:

Track Metadata: Song titles, album names, genre, release dates, ISRC codes, UPC codes

Artwork & Media: Album covers, promotional images, artist photos

Rights Documentation: Contracts, licenses, split sheets, ownership agreements

Performance Data: Streams, downloads, playlist placements, listener demographics

Technical & Usage Data

Automatically collected when you use our platform:

  • IP Address and location data

  • Device Information: Browser type, OS, device model

  • Login History: Access times, session duration

  • Usage Patterns: Features used, pages visited

  • Cookies & Tracking: Session cookies, preferences

  • Error Logs: Technical issues, crash reports

How We Use Your Information

Transparency in how your data powers our services

Service Delivery & Account Management

  • Create and manage your Pubdish account

  • Process and distribute your music to 150+ streaming platforms worldwide

  • Collect and distribute royalty payments to your account

  • Provide customer support and respond to your inquiries

  • Send important account notifications, updates, and service announcements

Legal Compliance & Security

  • Verify your identity through eKYC (electronic Know Your Customer) verification with our official CMS partner Audicient to comply with AML (Anti-Money Laundering) regulations and ensure users can upload/distribute music securely

  • Process tax documentation and report earnings to tax authorities as required by law

  • Prevent fraud, copyright infringement, and unauthorized account access

  • Comply with DMCA takedown requests and copyright claims

  • Respond to legal requests, court orders, and government inquiries

Platform Improvement & Analytics

  • Analyze platform usage to improve features and user experience

  • Provide detailed analytics on your music performance across platforms

  • Develop new features based on user behavior and feedback

  • Troubleshoot technical issues and optimize platform performance

Marketing & Communications (Optional)

With your explicit consent, we may use your information to:

  • Send promotional emails about new features, industry tips, and success stories

  • Provide personalized recommendations for distribution strategies

  • Invite you to exclusive events, webinars, and educational content

You can opt out at any time by clicking "unsubscribe" in any marketing email or adjusting your account preferences.

When We Share Your Information

We only share your data when necessary and with trusted partners

Audicient - Official CMS & eKYC Partner

OFFICIAL CMS PARTNER

All identity verification documents (government IDs, passports, proof of address, tax documents) are securely transmitted to and stored by Audicient, our official CMS (Content Management System) partner that collaborates with Pubdish to distribute music for all artists and labels. Users must complete eKYC (electronic Know Your Customer) verification through Audicient before they can upload or distribute music.

Why We Partner with Audicient:

  • Official CMS Partnership: Audicient is our official CMS partner, collaborating with Pubdish to distribute music for artists and labels worldwide

  • Mandatory eKYC Verification: All users must complete eKYC verification before uploading or distributing music

  • Specialized Expertise: Audicient specializes in secure identity verification and document management

  • Advanced Security: Bank-level encryption (AES-256), multi-factor authentication, and biometric verification

  • Compliance Certified: SOC 2 Type II, ISO 27001, GDPR, and CCPA compliant

  • Dedicated Infrastructure: Separate, secure data centers exclusively for sensitive documents

Critical Liability Notice

Audicient assumes full responsibility for the security, storage, and protection of all identity verification documents. In the event of any data breach, security incident, or unauthorized access to identity documents:

  • Audicient is solely liable for all damages, notifications, and remediation costs
  • Audicient will immediately notify affected users and regulatory authorities
  • Audicient maintains comprehensive cyber insurance and legal indemnification
  • Pubdish holds contractual agreements ensuring user protection and compensation

Other Trusted Service Providers

Streaming Platforms

We share your music metadata, artwork, and artist information with Spotify, Apple Music, Amazon Music, YouTube Music, and 150+ other platforms to distribute your content.

Payment Processors

Stripe, PayPal, and banking partners process royalty payments. They receive only the information necessary to complete transactions.

Communication Services

Email service providers (SendGrid, Mailchimp) send you account notifications and updates. They only receive your email address and name.

Cloud Storage

AWS and Google Cloud store your music files, artwork, and non-sensitive account data with enterprise-grade encryption.

Analytics Providers

Google Analytics and similar tools help us understand platform usage. They receive anonymized, aggregated data only.

Legal Disclosure Requirements

We may disclose your information when legally required or to protect our rights:

  • In response to valid legal requests (subpoenas, court orders, government inquiries)

  • To protect against fraud, copyright infringement, or illegal activity

  • To protect the safety and security of our users and the public

  • In connection with a merger, acquisition, or sale of company assets

What We DON'T Do With Your Data

We do NOT sell your personal information to third parties

We do NOT rent your data to advertisers or marketers

We do NOT share your music or earnings data with competitors

We do NOT use your music for training AI models

Data Security Measures

How we protect your information with industry-leading security

Encryption & Data Protection

In Transit

  • TLS 1.3 encryption for all data transmission
  • HTTPS-only connections (no unencrypted HTTP)
  • End-to-end encryption for sensitive documents

At Rest

  • AES-256 encryption for all stored data
  • Encrypted database backups with separate keys
  • Regular key rotation and security audits

Access Controls & Authentication

Multi-Factor Authentication (MFA)

Optional 2FA via SMS, email, or authenticator apps to add an extra layer of account security.

Biometric Verification

Audicient uses facial recognition and fingerprint matching for identity document verification.

Role-Based Access Control

Pubdish employees have strictly limited access based on job requirements. Identity documents are only accessible to Audicient.

Session Management

Automatic logout after inactivity, secure session tokens, and device tracking for suspicious activity.

Infrastructure & Network Security

  • Firewalls: Advanced firewall rules protect against unauthorized access

  • DDoS Protection: Cloudflare shields against distributed attacks

  • Intrusion Detection: 24/7 monitoring for suspicious activity

  • Vulnerability Scanning: Weekly automated security scans

  • Penetration Testing: Quarterly third-party security audits

  • Secure Data Centers: ISO 27001 certified facilities with physical security

  • Geographic Redundancy: Data replicated across multiple regions

  • Daily Backups: Encrypted backups with 30-day retention

Monitoring & Incident Response

Real-Time Alerts

Automated alerts for failed login attempts, unusual access patterns, and potential security threats during business hours

Audit Logs

Comprehensive logging of all data access, modifications, and system events for forensic analysis

Incident Response Plan

Dedicated security team ready to respond to breaches within 1 hour, with clear escalation procedures

User Notification

Immediate notification to affected users in case of any security incident impacting their data

Data Retention & Deletion

How long we keep your information and when it's deleted

Active Account Data

While your account is active, we retain all your data to provide continuous service. You can update, correct, or delete non-essential information at any time through your account settings.

After Account Closure

When you close your Pubdish account, we follow this deletion schedule:

  • Immediate: Your account is deactivated and music distribution stops within 24 hours

  • 30 Days: Personal information, login credentials, and marketing data deleted

  • 90 Days: Music files, artwork, and content metadata permanently deleted

  • 7 Years: Financial records, tax documents, and transaction history (required by law for accounting purposes)

Identity Documents (Audicient)

Identity verification documents stored by Audicient are retained according to their security and compliance policies. Upon account closure, Audicient will delete identity documents within 90 days, unless legal obligations require longer retention (such as ongoing investigations or tax audits).

Legal Retention Requirements

Some data must be retained longer to comply with legal, tax, and regulatory requirements:

  • • Tax documentation and financial records: 7 years (IRS requirement)
  • • Copyright registration information: Indefinite (to defend against claims)
  • • DMCA takedown notices and counter-notifications: 3 years minimum
  • • Legal dispute records: Duration of proceedings plus 3 years

Your Privacy Rights

You have full control over your personal information

GDPR Rights (European Union Users)

If you are located in the European Union, you have the following rights under GDPR:

Right to Access

Request a copy of all personal data we hold about you

Right to Rectification

Correct any inaccurate or incomplete information

Right to Erasure

Request deletion of your personal data ("right to be forgotten")

Right to Restrict Processing

Limit how we use your data in certain circumstances

Right to Data Portability

Receive your data in a machine-readable format

Right to Object

Object to processing for direct marketing or legitimate interests

CCPA Rights (California Users)

If you are a California resident, you have these rights under CCPA:

Right to Know

Know what personal information is collected, used, shared, or sold

Right to Delete

Request deletion of personal information (with certain exceptions)

Right to Opt-Out

Opt-out of the sale of personal information (Note: We do not sell your data)

Right to Non-Discrimination

Exercise your privacy rights without being discriminated against

Universal Rights (All Users)

Regardless of your location, all Pubdish users have these rights:

Update Your Information

Access your account settings anytime to update personal details, contact information, and preferences

Export Your Data

Download a complete copy of your account data, music metadata, analytics, and transaction history

Close Your Account

Permanently delete your Pubdish account and stop all music distribution at any time

Manage Communications

Control email preferences and opt-out of marketing communications while still receiving essential account updates

How to Exercise Your Rights

To exercise any of your privacy rights, you can:

Through Your Account

Log into your Pubdish dashboard and access Privacy Settings to manage most of your data preferences

Contact Support

Email [email protected] with your request. We respond within 30 days (GDPR) or 45 days (CCPA)

Verification Required: To protect your privacy, we will verify your identity before processing requests involving access or deletion of personal data.

Children's Privacy

Age requirements and protection for minors

Pubdish's services are NOT intended for children under the age of 18. We do not knowingly collect personal information from minors.

Age Requirement

You must be at least 18 years old to create a Pubdish account and use our distribution services. By creating an account, you certify that you meet this age requirement.

Parental Consent

If you are under 18 and wish to distribute music through Pubdish, your parent or legal guardian must create the account and manage all legal agreements on your behalf.

Accidental Collection

If we discover that we have accidentally collected information from a child under 18, we will delete it immediately. Parents who believe we may have collected information from their child should contact us at [email protected].

International Data Transfers

How we handle data across borders

Pubdish operates globally and may transfer your data to countries outside your residence, including Vietnam (our headquarters), the United States (cloud infrastructure), and the European Union (Audicient data centers).

Safeguards in Place

  • Standard Contractual Clauses (SCCs) approved by the European Commission for EU data transfers
  • Binding Corporate Rules ensuring consistent data protection standards globally
  • Encryption of all data in transit between countries
  • Audicient stores EU citizen identity documents within EU data centers only

By using Pubdish's services, you consent to the transfer of your information to these countries. We ensure that all transfers comply with applicable data protection laws and maintain the same level of protection regardless of location.

Contact Us About Privacy

Questions, concerns, or requests about your data

If you have any questions about this Privacy Policy or how we handle your personal information, please contact us:

Email

General Privacy Inquiries:

[email protected]

Data Protection Officer:

[email protected]

Mailing Address

Pubdish Privacy Team

90/12 Ha Huy Tap, Thanh Khe
Da Nang, Vietnam, 550000

Response Time: We aim to respond to all privacy inquiries within 5 business days. For formal data subject requests (GDPR/CCPA), we will respond within the legally required timeframes (30-45 days).

Changes to This Privacy Policy

How we notify you of policy updates

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

How We Notify You

  • Email Notification: For significant changes, we'll send an email to your registered address
  • Dashboard Alert: A notice will appear when you log into your account
  • Updated Date: The "Last Updated" date at the top of this page will reflect the most recent changes

Your Continued Use: By continuing to use Pubdish after policy changes take effect, you acknowledge and accept the updated Privacy Policy. If you disagree with changes, you may close your account.