Legal
Privacy Policy
How ArnieWaves handles your data — in plain language, with your GDPR rights spelled out.
ArnieWaves is a small, one-person audio-software workshop based in the European Union, run by Arnout Van Nieuwenhove. I make audio plug-ins for music producers, including AudioTeleporter, which streams a producer's audio to listeners. This policy explains what personal data I collect, why, and what you can do about it. I've tried to write it in plain language, with no legalese theatre and no dark patterns. If anything here is unclear, just email me at arnout.van.nieuwenhove@gmail.com.
In this policy, "I", "we", "us" and "ArnieWaves" all mean the same thing: me, the developer running ArnieWaves. "You" means you — whether you have an account, or you're just listening to a stream or browsing the site.
Who I am (the data controller)
ArnieWaves is operated by Arnout Van Nieuwenhove, an individual developer based in the European Union, trading as ArnieWaves (arniewaves.com).
- Legal entity: Studio Arnout (company number 1028683812, VAT BE1028683812)
- Registered / postal address: Doornzelestraat 28, 9000 Gent, Belgium
- Contact for anything, including privacy requests: arnout.van.nieuwenhove@gmail.com
There is no phone line and no other contact channel. Email is how you reach me for support, privacy requests, and refunds.
What data I collect and why
I try to collect as little as possible. Here's the full list.
Account and profile
When you create an ArnieWaves account (you need one to use the plug-in beyond just listening), I store the following in Google Firebase Firestore:
- Your email address
- Your display name
- Your country (optional — you don't have to provide it)
- The date and time your account was created
- An internal role flag (user or admin)
- The time you last logged in
I use this to run your account, sign you in, and provide support.
Entitlement record
I keep a separate record of what you're allowed to use — your plan and the products your account can access, your subscription status, and your Paddle customer id (see Payments below). I use this to give you the right tier and features.
Authentication
Sign-in is handled by Firebase Authentication (a Google service), using your email address and a password. You can optionally turn on two-factor authentication (2FA) using a TOTP authenticator app for extra security.
Payment and billing data
I do not see or store your full payment-card details. Payments are handled by Paddle (see Payments below). All I keep on my side is a Paddle "customer id" and your subscription status and tier.
Anonymous server-side metrics
To keep the service healthy and know it's working, I keep anonymous, aggregate counters — for example, the total number of logins or signups. These are just numbers. There's no per-user profiling, and I don't sell data.
Audio streams
When you use AudioTeleporter, your audio is streamed in real time through relay servers so listeners can hear it in their browser. That audio is never recorded, never stored, and never persisted. A relay session lives only in server memory for the duration of the stream, and it's gone the moment the stream ends. Listeners don't need an account or an install, and I don't build any profile of who's listening.
Website analytics
On the arniewaves.com website (not in the plug-in), I use two third-party analytics tools to understand how the site is used and improve it. These are covered in detail in the Cookies and tracking section below, because they're only used with your consent.
Payments (handled by Paddle)
My payments are handled by Paddle (Paddle.com), acting as the merchant of record. That means Paddle — not ArnieWaves — is the seller of record for the transaction. Paddle runs the checkout, processes your card or other payment, charges any applicable tax/VAT, issues your invoice or receipt, and provides a self-serve customer portal where you can manage or cancel your subscription and download invoices.
Because Paddle is the merchant, ArnieWaves never sees or stores your full payment-card details. Refunds are requested from and processed through Paddle. Paddle handles your payment data under its own privacy terms.
Lawful bases for processing (GDPR)
Under the GDPR I need a lawful basis for each thing I do with your data. Here's mine:
- To provide the service (contract): creating and running your account, authenticating you, managing your entitlement and subscription, and delivering the streaming service. Without this data I can't provide what you signed up for.
- Legitimate interests: keeping the service secure and monitoring its health using anonymous, aggregate server metrics. I've balanced this against your privacy — the metrics are anonymous and there's no profiling.
- Consent: the non-essential website analytics cookies and tracking (Google Analytics and Microsoft Clarity). These only run if you agree, and you can decline or withdraw at any time.
Cookies and tracking
I split browser storage into two clear groups. The first group is essential and always on; the second is optional and only runs with your consent.
Essential / functional storage (no consent needed)
These are needed for the site and your account to work, so they don't require consent:
- Your chosen light/dark theme (stored in your browser's localStorage)
- A "signed-in" flag (localStorage) so the site knows you're logged in
- Firebase Authentication's own session storage, which keeps you signed in
Non-essential analytics (consent-based)
On the website I use two analytics tools to understand how visitors use the site and improve it. Under EU ePrivacy and GDPR rules, these are non-essential, so they only run on the basis of your consent. The site asks for / relies on your consent before setting them, and you can decline them or withdraw your consent at any time.
- Google Analytics (via the Google "gtag" tag): collects pages and screens visited, the referring site, an approximate/coarse location derived from your IP address, your device and browser type, and interaction events. This data is processed by Google. It sets analytics cookies or uses similar browser storage.
- Microsoft Clarity: product and behavioural analytics, including session replay and heatmaps — how visitors move, click and scroll, with sensitive fields masked. This data is processed by Microsoft. It sets analytics cookies.
There are no advertising or ad-targeting trackers, and I don't sell your data.
How to decline or withdraw consent
You can decline the non-essential analytics when the site asks, and you can change your mind and withdraw consent later — declining or withdrawing won't stop the site or your account from working. If you'd like help, email me at arnout.van.nieuwenhove@gmail.com.
Sub-processors (who else touches your data)
To run the service I rely on a few trusted third parties that process data on my behalf:
- Google Firebase — authentication and database (your account, profile and entitlement records).
- Google Analytics — website analytics (consent-based).
- Microsoft Clarity — website analytics, including session replay and heatmaps (consent-based).
- Paddle — payments, billing and tax.
- Hetzner Online — server hosting for the website, the billing API, and the streaming relays. Hetzner servers used here are located in Germany, the United States, and Singapore.
International transfers
Some of these providers process data outside the European Union — including in the United States (for example, some Hetzner hosting, and Google and Microsoft as processors) and Singapore (some Hetzner hosting). Where data is transferred outside the EU/EEA, it's protected by appropriate safeguards required under the GDPR. If you'd like more detail on the safeguards that apply, email me at arnout.van.nieuwenhove@gmail.com.
How long I keep your data (retention)
- Your account, profile and entitlement data are kept for as long as your account exists.
- When you delete your account, that account data is removed.
- Paddle keeps billing and invoice records for as long as the law requires it to, independently of ArnieWaves.
- Audio streams are never stored — see above.
Your rights under the GDPR
You have the following rights over your personal data:
- Access — ask for a copy of the data I hold about you.
- Rectification — correct data that's wrong or out of date.
- Erasure — delete your account and its data.
- Portability — receive your data in a portable form.
- Objection — object to processing based on legitimate interests.
- Complaint — lodge a complaint with a supervisory authority (a data protection regulator) if you think I've mishandled your data.
What you can do directly in the product
Some of these you can act on yourself right away:
- View and update your profile (name and country).
- Change your password (via an email reset link).
- Enable or disable TOTP two-factor authentication.
- Permanently delete your account, which removes your account data.
- Cancel or manage your subscription and download invoices through the Paddle customer portal.
Security
Sign-in and passwords are handled by Firebase Authentication (a Google service), and you can turn on optional two-factor authentication (TOTP) for an extra layer of protection. No system is ever perfectly secure, but I aim to keep your data safe and to work with trusted providers.
Children
ArnieWaves isn't intended for children. You must be at least 16 — or the applicable digital-consent age in your country, if it's different — to create an account. I don't knowingly collect data from anyone under that age.
How to exercise your rights, and how to reach me
For any privacy request — access, correction, deletion, portability, objection, or a question about this policy — email me at arnout.van.nieuwenhove@gmail.com. That's the single contact for everything at ArnieWaves. You can also delete your account and manage your consent and subscription yourself, as described above.
This policy is governed by the law of Belgium, and any mandatory EU consumer-protection and data-protection rules that apply to you.