Privacy Policy

What MXR World collects about you, why, who else sees it, and what you can make us do about it. Written to be read rather than skimmed past.

Last updated 30 July 2026

1. Who we are

MXR World (“MXR”, “we”, “us”) operates www.mxr.digital — a music platform for listening to mixes and releases, exploring editorial collections, and sharing memories attached to music.

For the purposes of the Protection of Personal Information Act 4 of 2013 (“POPIA”) we are the responsible party for your personal information. For the purposes of the UK and EU General Data Protection Regulation (“GDPR”) we are the data controller.

Questions, requests and complaints go to privacy@mxr.digital. That address reaches the person responsible for privacy at MXR.

2. What we collect, and why

We have kept this specific rather than generic. Each row below corresponds to something the platform actually stores.

WhatWhy we hold it
Email addressTo create and secure your account, send sign-in codes, and — separately, only if you ask — send updates about new music.
Your nameOptional, supplied at sign-up. Used to address you in the app. You can change or remove it at any time.
PasswordStored only as a salted hash by our authentication provider. We never see, store or transmit your actual password.
Google account detailsIf you choose Continue with Google, Google sends us your name, email address and profile picture. Nothing else, and we never receive your Google password.
Listening progressThe position you reached in a mix, so playback resumes where you left off across devices.
Activity eventsPlays, saves, downloads, series follows and searches. These power your profile, your library, your listening history and the recommendations you see.
Derived listening statisticsAggregates calculated from the above — total listening time, most-played, and similar — cached so your profile loads quickly.
Saved items and downloadsThe mixes, releases, journal entries and selects you have saved or downloaded, so your library persists.
Feedback you sendThe message, the page you were on, and your browser type — so a bug report is actually actionable. Your email is attached if you were signed in.
Memories you submitThe story and details you choose to share. Submitted through Formspree, which passes them to us by email.
IP addressHeld briefly and only for rate limiting — to stop automated abuse of sign-in and upload endpoints. It is not linked to your account and is deleted automatically.
Beta invite detailsDuring invite-only access, the email an invitation was issued to, and whether it has been used.

3. What we do not do

  • We do not sell your personal information. Not to anyone, in any form.
  • We do not serve advertising, and we do not run advertising or cross-site tracking pixels.
  • We do not build profiles of you for third parties.
  • We do not make decisions about you by automated means that produce legal or similarly significant effects.
  • We do not collect special personal information (POPIA s26) — no health, biometric, religious, political or similar data. Please do not send it to us in a memory or feedback message.

4. Our lawful basis for using it

Under POPIA we rely on the justifications in section 11, and under the GDPR on Article 6. In practice:

What we doOn what basis
Run your account, playback and downloadsNecessary to perform the agreement between us — you asked us for the service.
Rate limiting and abuse preventionOur legitimate interest in keeping the platform available and secure.
Recommendations and your listening statisticsOur legitimate interest in making the platform useful. You can ask us to stop.
Newsletter and update emailsYour consent, given when you subscribe. Withdrawable at any time, with no effect on your account.
Keeping records we are legally required to keepCompliance with a legal obligation.

5. Who else touches your information

We use a small number of service providers (operators under POPIA, processors under the GDPR). They act on our instructions and may not use your information for their own purposes.

ProviderWhat it does
SupabaseDatabase, authentication and image storage.
Cloudflare R2Storage and delivery of audio files and artwork.
VercelHosting the website, and short-lived server logs.
GoogleOnly if you use Continue with Google. Their handling is governed by the Google Privacy Policy.
FormspreeDelivers memory submissions from the site to our inbox.
Spotify, YouTube, Instagram, TikTokEmbedded players and feeds on some pages. When one loads, that platform may set its own cookies and see your IP address. We do not control that, and their own policies apply.

6. Where your information goes

Our providers operate data centres outside South Africa, so your information is transferred across borders. We rely on section 72 of POPIA — these providers are bound by agreements that uphold principles substantially similar to POPIA’s conditions for lawful processing.

For transfers out of the UK and EEA, our providers rely on the European Commission’s Standard Contractual Clauses or an equivalent approved mechanism.

7. How long we keep it

  • Account information — for as long as your account exists. Delete your account and we delete it.
  • Listening progress, activity events and saved items — for as long as your account exists, since they are what your library and history are made of. Deleting your account deletes them too.
  • Newsletter subscription — until you unsubscribe.
  • Feedback and memory submissions — kept while the issue or the memory is still relevant to the platform, and reviewed periodically.
  • IP addresses used for rate limiting — automatically purged; they exist only for the length of the rate-limit window.
  • Anything we are legally required to retain for longer — kept only for as long as that obligation lasts.

8. Your rights

Under POPIA (sections 23, 24 and 25) and the GDPR (Articles 15–22) you can ask us to do all of the following, free of charge, by writing to privacy@mxr.digital. We will respond within 30 days.

  • Access — get a copy of the personal information we hold about you.
  • Correction — have anything inaccurate or incomplete fixed. Most of this you can do yourself in your profile.
  • Deletion — have your account and the information attached to it erased.
  • Portability — receive your information in a structured, commonly used, machine-readable format.
  • Objection — object to processing we carry out on the basis of legitimate interests, including recommendations.
  • Withdraw consent — unsubscribe from emails at any time, using the link in any email or by writing to us.
  • Restriction — ask us to pause processing while a dispute about accuracy or lawfulness is resolved.

9. If you are unhappy with how we handled it

Please raise it with us first at privacy@mxr.digital — most things are resolved quickly that way.

You also have the right to complain to a regulator. In South Africa that is the Information Regulator. In the UK it is the Information Commissioner’s Office; in the EU, your national supervisory authority. Approaching us first does not take away that right.

10. Cookies

We use cookies for one thing: keeping you signed in. They are strictly necessary — without them the site cannot tell that the person loading a page is the person who signed in a moment ago.

We do not use advertising cookies, and we do not use third-party analytics that track you across other websites.

Embedded players from Spotify, YouTube, Instagram and TikTok set their own cookies when they load. If you would rather they did not, most browsers can block third-party cookies for specific sites.

11. How we protect it

No system is perfectly secure, and we would rather say so than imply otherwise. If we ever become aware of a breach that creates a risk to you, we will notify you and the Information Regulator as POPIA section 22 requires. What we do to make that unlikely:

  • Everything travels over HTTPS, and the site is served with a strict Content Security Policy and HSTS.
  • Passwords are salted and hashed by our authentication provider. Nobody at MXR can read yours.
  • Database access is governed by row-level security, so one listener's records are not reachable from another's session.
  • Audio files sit in a private bucket and are served through short-lived signed links rather than public URLs.
  • Sign-in and upload endpoints are rate limited to blunt automated attacks.

12. Children

MXR World is not intended for children. You need to be at least 16 to create an account, and under POPIA section 34 we do not knowingly process the personal information of a child without the consent of a competent person.

If you believe a child has given us their information, write to privacy@mxr.digital and we will delete it.

13. Changes to this policy

The platform is actively being built, so this policy will change as it does. The date at the top always reflects the current version.

If a change materially affects your rights or how we use your information, we will tell you — by email if you have an account with us, rather than by quietly editing this page.