Privacy

Privacy notice

This explains what the site collects, why, where it is kept and for how long. There are no advertising cookies and no tracking that identifies visitors.

Updated 2026-09-14

Controller

Joel Matikainen, sole trader. Business ID: 3550308-9.

Privacy matters: joel.matikainenmusic@gmail.com

No data protection officer has been appointed, and an operation this size does not require one.

What is collected

From a booking: name, email address, the time booked and whether the lesson is on-site or online.

From a gift certificate: the recipient’s name and a greeting, if the buyer writes them. They travel through Stripe as part of the payment record and are printed on the gift certificate sent to the buyer, who passes it on. The recipient’s own booking is made with the details given at the time of booking; for anyone under 18 those are the guardian’s.

From a quote request: name, email address, a date if you give one, and whatever you write in the message field.

From a payment: Stripe handles the payment and stores the card details. The site receives no card data at all — not the card number, not the security code, not the last four digits. I can see the last four digits only in Stripe’s own dashboard.

From a bug report: the description you write, the page address, the name of your browser and operating system, the browser window size, and your email address if you give it. The report reaches me as an email and is not stored in the database.

The site collects no location, no browsing history and no device identifiers.

Why, and on what basis

Booking details are processed to perform the contract: without them the lesson cannot be held or confirmed.

A quote request is handled to take steps at your own request before a contract: you asked for an answer, and it cannot be given without handling the request.

Accounting records are kept because the law requires it.

A bug report is handled on the basis of legitimate interest: the site has to work, and the report shows where it does not.

Where the data is

The database runs on Supabase servers in Stockholm. The site itself runs on Vercel, also in Stockholm; Vercel’s own account administration and support data sit in the United States.

Email goes out through Resend, which stores message content, delivery logs and account records in the United States for 30 days. The transfer rests on the Standard Contractual Clauses approved by the Commission and on Resend’s EU–US Data Privacy Framework certification.

Payments go through Stripe. Stripe also processes data outside the EU under safeguards approved by the Commission.

Finished recordings are delivered through Google Drive. The folder is shared with the email address you give. Google also processes data outside the EU under safeguards approved by the Commission.

Images are served from the ImageKit network. No personal data is attached to them.

Analytics data is processed by Vercel, the same service that runs the site.

For how long

Accounting records are kept six years from the end of the financial year, as Finnish accounting law requires.

An abandoned payment is deleted after 30 days. No money changed hands, so accounting law does not require it to be kept — the name and email address do not linger in the database.

Quote requests are deleted automatically after 12 months. If the matter is settled sooner, I will delete the request as soon as you ask.

A cancelled booking stays in the accounts, but its time is freed back into the calendar immediately.

A bug report is deleted from my inbox once the bug is fixed. Resend’s copy is removed after 30 days.

Cookies

The site sets one cookie: your language choice. It tracks nothing and goes to no third party.

There is no ad network and there are no social media buttons. That is why there is no cookie banner — none is needed when nothing requiring consent is set.

Signing in to the admin area sets a session cookie. That applies to me only.

The site uses Vercel Web Analytics. It counts page views and referrers without setting cookies, and it does not identify visitors or follow them to other sites. That is why no consent is asked.

Your rights

You have the right to see what is stored about you, to have incorrect information corrected and to ask for your data to be deleted.

You can also ask for processing to be restricted while the accuracy of a detail is being checked, and receive the details you gave in a machine-readable form so they can be transferred.

Deletion does not cover accounting records that the law requires to be kept.

An email is enough. I answer within a month.

If you are not satisfied, you can complain to the Finnish Data Protection Ombudsman.

Security

Traffic to the site is encrypted. The browser gets no direct connection to the database: everything goes through the server, which checks every request.

The database has row-level security that blocks access to booking details even if someone knew a booking id.

No automated decision-making and no profiling take place.