Legal
Privacy Policy
Last updated: August 6, 2026
PatchMap is built and operated by IndieSoft, a product of Indie Pepper Creative LLC. This policy explains what we collect, what we do with it, and — just as importantly — what we don't do with it.
1. Who we are
PatchMap is a product of IndieSoft, an independent software studio operated by Indie Pepper Creative LLC in Texas, USA. Indie Pepper Creative LLC is the data controller for PatchMap and the patchmap.app website. You can reach us at hello@indiesoft.app.
When we refer to "we", "us", or "PatchMap" in this policy, we mean that data controller.
2. What we collect
Account information. When you create an account, we collect your email address and any name you choose to provide. If you subscribe to a paid plan, our payment processor collects your billing details — we never see or store your full card number.
Show data. Everything you build in PatchMap: channel lists, patch assignments, stage plots, gear lockers, wireless assignments, Dante routing, notes, flags, and show history. This is your working data. We store it so the product works.
Live Room participation. When someone joins a Live Room by QR code or invite link, we record their display name, their role, the flags and notes they create, and the messages they send in that room. Live Room guests do not need a PatchMap account.
Usage data. Basic technical information — pages visited, features used, browser and device type, IP address, and error logs. In the application itself these are pseudonymous product-usage events tied to your account identifier rather than your name. We use this to understand what's working and to fix what isn't.
Push notification data. If you opt in to notifications, we store the push subscription details your browser or device provides so we can deliver alerts. This is optional and off by default.
Marketing site analytics. Our public marketing pages use analytics and advertising pixels to measure whether our ads are working. These are on the marketing site only, not inside the application. Section 5 lists exactly what runs and what it collects.
We do not collect your phone number, precise location, contacts, full payment card details, or device sensor data.
3. What we do with it
We use your information to run the product, keep your account secure, process payments, send you transactional email about your account, respond to your support requests, and improve PatchMap.
We do not sell your personal information. We do not share your show data with advertisers, and we do not make it available to other users or customers.
4. AI and your data
PatchMap uses AI in two specific, limited places:
Smart Import. When you upload a CSV, spreadsheet, or PDF to build a show, the contents of that file may be sent to our AI provider to be parsed into channels and gear. The file contents are used to produce your import result and nothing else.
Show Intelligence. Available on the Touring tier, this analyzes your own show history to surface patterns across your shows. It operates on your account's structured show data and returns results only to you.
The commitments that matter:
- Your data is never used to train AI models. Not ours, not our provider's. Our AI provider's commercial terms explicitly prohibit training on customer content, and we have not opted into any program that would change that.
- Your show data is never used to train on behalf of other customers, and it is never pooled, aggregated, or exposed to other accounts.
- Live Room chat is not analyzed by Show Intelligence. Chat is saved with the room so the history is there when you need it. Intelligence reads structured references — which channel a flag was raised against — not the content of your conversations.
- We do not use your show data to build datasets, benchmarks, or demo content. Every demo show in PatchMap is fictional and built by us.
If you are working under an NDA and need a written data processing agreement, email us at hello@indiesoft.app and we'll sort it out.
5. Cookies, analytics, and advertising pixels
We want to be precise about this, because "we don't track you" is easy to say and often untrue. There is a real difference between our marketing site and the application, and we treat them differently.
Inside the application (app.patchmap.app) we run no advertising pixels, no third-party ad SDKs, and no social-media trackers. Product-usage analytics there are first-party, pseudonymous, and stored in our own infrastructure. Your show data is never sent to an advertising platform.
On the marketing site (patchmap.app) — the pages you are reading right now — we run the following:
- Meta Pixel — measures whether our Facebook and Instagram ads lead to sign-ups. Sets cookies and shares page-visit events with Meta.
- Reddit Pixel — the same, for our Reddit ads. Sets cookies and shares page-visit events with Reddit.
- Vercel Web Analytics — aggregate, privacy-preserving page statistics from our hosting provider.
- Our own visit beacon — a first-party record of the page visited, a random visitor identifier stored in your browser, the country your request came from, your browser's user agent, the site that referred you, and any campaign tags in the link. We use this to see which channels bring people to PatchMap.
- Bunny Stream — hosts the product walkthrough video. It loads only when you open the video, and it sets its own cookies for playback.
These marketing-site tools are for measuring our own advertising. They do not have access to your PatchMap account or to anything you build inside the product.
You can block or clear these cookies in your browser at any time, and you can opt out of interest-based advertising through the DAA opt-out tool or your Meta and Reddit ad settings. Blocking them has no effect on how PatchMap works.
6. Where your data lives
PatchMap runs on third-party infrastructure. The providers that process data on our behalf:
- Supabase — database, authentication, and file storage. Privacy policy →
- Vercel — application hosting, delivery, and site analytics. Privacy policy →
- Stripe — payment processing and subscription billing. Privacy policy →
- Resend — transactional email. Privacy policy →
- Anthropic — AI processing for Smart Import and Show Intelligence. Privacy policy →
- Meta, Reddit, and Bunny.net — marketing site advertising measurement and video hosting only, as described in Section 5.
Each of these processes data only to provide their service to us. Data is stored in the United States.
7. How long we keep it
We keep your account and show data for as long as your account is active. When you close your account, we delete your data within 30 days, except where we're legally required to retain billing records. Content you delete inside PatchMap is removed from our servers within 30 days, subject to the same exceptions.
Live Room chat is stored with the room it belongs to, so the history remains available after the show; deleting a room deletes its messages. Data sent to our AI provider for Smart Import is deleted from their systems within 30 days under their standard commercial terms.
Aggregated, non-identifying usage statistics may be retained indefinitely.
8. Legal basis for processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data on the following legal bases under the General Data Protection Regulation (GDPR):
- Performance of a contract (Article 6(1)(b)) — processing necessary to provide the PatchMap service you have requested, including account creation, data storage, and collaboration features.
- Legitimate interests (Article 6(1)(f)) — processing necessary for our legitimate interests in maintaining, securing, and improving PatchMap, including product-usage analytics, where these interests are not overridden by your rights.
- Legal obligation (Article 6(1)(c)) — processing required to comply with applicable law.
- Consent (Article 6(1)(a)) — where we rely on consent, such as opt-in push notifications, you may withdraw it at any time using in-app controls or by contacting us.
9. International data transfers
Indie Pepper Creative LLC is based in the United States. If you access PatchMap from the EEA, UK, or Switzerland, your personal data will be transferred to and processed in the United States, which may not provide the same level of data protection as your home country.
Where such transfers occur, we rely on appropriate safeguards including Standard Contractual Clauses (SCCs) as approved by the European Commission, or equivalent mechanisms recognised under applicable law. You may request a copy of the applicable safeguards by contacting us at hello@indiesoft.app.
10. Your choices and your rights
You can access and edit your show data at any time from inside the app, export your data as CSV on any plan, and correct your account information from account settings.
To close your account and have your data deleted, email us at hello@indiesoft.app from the address on the account. We'll confirm and delete your data within 30 days.
If you're in a jurisdiction with additional rights over your personal data — such as the EU, UK, or California — those rights apply and you can exercise them by emailing us. We won't discriminate against you for doing so. Specifically, you have:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — correct inaccurate or incomplete data, in-app or by contacting us.
- Right to erasure — request deletion of your personal data; we will action this within 30 days.
- Right to restriction — ask us to restrict processing in certain circumstances.
- Right to data portability — request your data in a structured, machine-readable format where applicable.
- Right to object — object to processing based on legitimate interests, including usage analytics, at any time.
- Right to withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.
- Right not to be subject to automated decision-making — we do not use automated decision-making or profiling that produces legal or similarly significant effects.
We will respond within 30 days and may need to verify your identity first.
11. Right to lodge a complaint
If you are in the EEA and believe we have not handled your personal data lawfully, you may lodge a complaint with your local data protection supervisory authority (a list is available at edpb.europa.eu). In the UK, you may contact the Information Commissioner's Office (ICO). We encourage you to contact us first so we can help directly.
12. Sharing and collaboration
PatchMap is built for crews. When you share a show or invite someone to a Live Room, the people you share with can see the content you contribute to that shared space, along with any labels or assignments within it. You control what you share and with whom, and you can revoke access by closing the room or removing collaborators.
Outside of these features you choose to use, we do not sell, rent, or share your personal data with any third party for marketing or advertising purposes, and we have no commercial relationship with data brokers. We may disclose data if required by law or valid legal process; where legally permitted, we will notify you first.
13. Security
Data is encrypted in transit (TLS 1.2 or higher) and at rest. Database access is enforced at the row level, so accounts can only reach their own data. Live Room access is controlled by room-scoped join tokens, and those tokens stop granting access once the room closes.
No system is perfectly secure. If we ever discover a breach affecting your data, we'll tell you.
14. Children
PatchMap is a professional tool and isn't directed at children under 13 (or under 16 where required by local law). We don't knowingly collect their information. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
15. Changes
If we change this policy in a way that materially affects you, we'll update the date at the top and notify account holders by email.
Contact
Questions about this policy, or about your data:
hello@indiesoft.app
IndieSoft — a product of Indie Pepper Creative LLC
Texas, USA