DJ-CRM
Last updated 14 August 2026
DJ-CRM is booking management software for DJs, magicians, bands and entertainment agencies. This policy explains what the software stores, why, and how Google user data is handled.
DJ-CRM is operated by Paddy Gordon DJ, Glasgow, United Kingdom. For any question about this policy, contact [email protected].
There are two groups of people whose data appears in DJ-CRM.
Where a user's business is the data controller for their own clients, DJ-CRM acts as the processor for that data.
Name, email address, profile photo, role and organisation membership. Sign-in is by Google, by Apple, or by passkey; DJ-CRM never sees or stores a Google or Apple password.
Bookings, events, venues, quotes, contracts, invoices, payments, availability, and the planning information a client submits for their event, such as running order, song choices and venue logistics.
Names, email addresses, phone numbers and event addresses, entered by a user or submitted through an enquiry form.
Emails sent by the software are recorded so a user can see what was sent to whom and whether it was delivered and opened. Where a user has connected a Google account with read access, message content from that user's own mailbox is stored so the conversation with a client can be shown against their booking.
Session cookies, device tokens for push notifications, and server logs containing IP addresses and request paths, kept for security and troubleshooting.
Connecting a Google account is optional and is done by the individual user for their own account. DJ-CRM only ever accesses that user's own calendar and mailbox, never anyone else's, and requests the narrowest scopes that support the features described.
calendar — creates and updates events on the calendar the user selects, so bookings appear in their own calendar and availability stays accurate. Some users also select a second, anonymised calendar which shows only that they are busy, with no client details.gmail.send — sends quotes, contracts, confirmations and reminders from the user's own address, so clients recognise the sender.gmail.readonly — reads messages in the user's own mailbox so the email history with a client can be shown alongside that client's booking.gmail.modify — updates read and archive state so that a message read in DJ-CRM is also marked read in Gmail, and the same message is not handled twice.userinfo.email, userinfo.profile, openid — identifies the user at sign-in and populates their name and profile photo.OAuth tokens are stored encrypted. A user can disconnect their Google account at any time in Settings, which deletes the stored tokens, and can revoke access independently at myaccount.google.com/permissions.
DJ-CRM's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, DJ-CRM does not transfer Google user data to third parties except as necessary to provide or improve the features described above, to comply with applicable law, or as part of a merger or acquisition. DJ-CRM does not use Google user data for serving advertisements, does not sell it, and does not use it to develop, improve or train generalised artificial intelligence or machine learning models. Humans do not read Google user data except with the user's explicit consent for a specific support issue, where required by law, or where it is aggregated and anonymised for security or troubleshooting.
DJ-CRM runs on servers hosted by Hetzner in the European Union. Databases and file storage are held on those servers, with encrypted backups retained on separate machines under the operator's control for disaster recovery. Traffic is encrypted in transit with TLS. Stored credentials, including OAuth tokens and mail passwords, are encrypted at rest.
Data is shared only with services needed to run the product:
Google user data is not shared with any of the others.
Business records such as bookings, contracts and invoices are retained while the account is active and afterwards for as long as needed to meet legal and accounting obligations. Synchronised mail is retained while the Google account remains connected and is removed when it is disconnected or the account is deleted. Server logs are kept for a limited period for security and troubleshooting.
Under UK GDPR you may request access to your personal data, correction of it, deletion of it, restriction of processing, or a copy in a portable format, and you may object to processing. Requests go to [email protected] and are answered within one month.
If a request concerns data entered by a business that uses DJ-CRM about its own client, it is passed to that business as the controller.
You may also complain to the Information Commissioner's Office at ico.org.uk.
DJ-CRM is business software and is not directed at children. Accounts are not knowingly created for anyone under 18.
Material changes to this policy will be notified to account holders by email. The date at the top records the last revision.