Who We Are
Russell Nomer Music operates the website at russellnomermusic.com and the PlayThatTune music learning service. The data controller for all personal data collected through this site is:
Russell Nomer
Email: russell@russellnomermusic.com
Phone: 516-628-7877
Data We Collect & Why
We collect the minimum data necessary to operate our services. Here is exactly what we collect and why:
| Source | Data Collected | Purpose / Legal Basis |
|---|---|---|
| Contact Form | Name, email address, phone number (optional), message content | To respond to your inquiry. Legal basis: Legitimate interest in responding to business inquiries. Data is emailed to russell@russellnomermusic.com and not stored in our database. |
| Custom Song Orders | Name, email address, company name, phone number | To process your order, deliver the song, and issue your license certificate. Legal basis: Contract performance. Stored in our secure database. |
| Email Campaigns | Email address, link click timestamps, IP address, browser user-agent | To send music promotion emails and track campaign effectiveness (open/click rates). Legal basis: Legitimate interest in direct marketing, with opt-out available at any time via the unsubscribe link in every email. |
| PlayThatTune Subscription | Email address, Stripe customer ID, Stripe subscription ID, subscription status | To authenticate your access to the PlayThatTune app and manage your subscription. Legal basis: Contract performance. |
| Session Cookies | A session identifier stored in a browser cookie | Authentication only — to keep you logged in to PlayThatTune and the admin dashboard. No tracking or advertising. Legal basis: Legitimate interest in providing a functional, secure service. |
Who We Share Your Data With
We do not sell your personal data. We share it only with the processors necessary to operate our services:
- Stripe, Inc. — Payment processing for custom song orders and PlayThatTune subscriptions. Stripe handles all credit card data; we never see or store card numbers. See Stripe's Privacy Policy.
- Google (Gmail / Google Workspace) — Sending transactional and promotional emails from russell@russellnomermusic.com. See Google's Privacy Policy.
- Google Tag Manager — Present on the site for potential future analytics configuration. No tracking tags are currently activated. See Google's Privacy Policy.
No other third parties receive your personal data.
How Long We Keep Your Data
- Custom song orders: Retained indefinitely as business records and for license certificate validity. You may request deletion (we will anonymize the record while retaining order totals for accounting).
- Email campaign contacts: Retained until you unsubscribe or request deletion. You can unsubscribe at any time via the link in any email.
- PlayThatTune subscribers: Retained while your subscription is active and for 90 days after cancellation (for dispute resolution), then deleted or anonymized.
- Contact form data: Not stored in our database; only exists in the recipient's email inbox.
- Session cookies: Expire when you close your browser, or after a configurable inactivity period.
Your Rights
Under GDPR (EU/UK) and CCPA (California), you have the following rights regarding your personal data:
Request a copy of all data we hold about you. Use our data export endpoint or email us.
Request that we delete your personal data. We will process your request within 30 days and send confirmation.
Object to processing based on legitimate interest (e.g., marketing emails). Use the unsubscribe link in any email.
Receive your data in a machine-readable format (JSON). Use the data export link below.
To exercise any of these rights:
- Delete my data: Use the Delete My Data form on the homepage, or scroll to the footer and click "Delete My Data".
- Export my data: Visit
/api/me/data-export?email=your@email.com— replace with your actual email address. - Unsubscribe from emails: Click the unsubscribe link in any email you receive from us.
- Email request: Send any data request to russell@russellnomermusic.com. We respond within 30 days.
California Residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- The right to know what personal information is collected about you
- The right to know whether your personal information is sold or disclosed
- The right to opt out of the sale of your personal information — we do not sell personal information
- The right to equal service and price, even if you exercise your privacy rights
- The right to request deletion of personal information collected from you
To exercise these rights, contact us at russell@russellnomermusic.com.
Security
We take reasonable technical measures to protect your data:
- All data transmission uses HTTPS/TLS encryption
- Payment processing is handled entirely by Stripe — we never store credit card details
- Stripe webhook signatures are verified to prevent spoofed payment events
- Database access is restricted to application-layer only; no public database ports are exposed
No system is 100% secure. If you believe there has been a security incident affecting your data, please contact us immediately at russell@russellnomermusic.com.
Changes to This Policy
We may update this privacy policy from time to time. When we do, we will update the "Last Updated" date at the top. Material changes that affect your rights will be communicated via email to active subscribers. Continued use of the site after changes constitutes acceptance of the updated policy.