Legal

Privacy Policy

What personal data we collect, why we collect it, how long we keep it and the rights you have over it.

Last updated: September 18, 2026

This Privacy Policy explains how Moquz.com ("Moquz.com", "we", "us" or "our") collects, uses, shares and protects personal data when you visit our website, subscribe to our newsletter, contact us or order one of our paid services. Our site is deliberately simple: it is a static website, it loads no analytics or advertising trackers, and it stores only a single preference in your browser.

This policy is designed to meet the requirements of the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, and US state privacy laws including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA). Please read it together with our Cookie Policy and Terms and Conditions.

The short version

We only collect what you choose to send us (for example through the contact form), plus standard server logs that our hosting provider keeps for up to 30 days for security. We do not sell or share your personal information for advertising, we do not run analytics or ad trackers, we never ask for your streaming or app passwords, and you can ask us to access or delete your data at any time by writing to [email protected].

1. Who we are (data controller)

Moquz.com is an independent, English-language guide website about music streaming, app safety and legal streaming alternatives. We also offer a small number of paid, hands-on services such as app safety audits, streaming plan optimization, device setup, playlist curation and podcast launch support, described on our Services page.

For the purposes of the GDPR and UK GDPR, Moquz.com is the data controller of the personal data described in this policy. If you have any question about this policy or about your data, you can reach us at [email protected].

Moquz.com is not affiliated with, endorsed by or sponsored by Spotify AB, Google LLC, Apple Inc. or any other company whose products we write about.

2. Personal data we collect

We collect personal data from a small number of sources. We have listed each one separately so you can see exactly what is collected and when.

2.1 Contact form

When you use the contact form on our Contact page, you give us:

  • your name;
  • your email address;
  • your phone number (optional — only if you choose to provide it);
  • the service you are interested in (if you select one);
  • a subject line; and
  • the content of your message, including anything you choose to include in it.

The form is submitted to our mailbox through our email service provider. Please do not include sensitive information or passwords in your message.

2.2 Newsletter sign-up

If you subscribe to our newsletter we collect your email address and, where the form asks for it, your name. We use this only to send you the newsletter you requested. Every newsletter contains an unsubscribe link, and you can also unsubscribe by emailing [email protected].

2.3 Service orders and quotes

If you request a quote or order a paid service, we process the information needed to deliver it and to invoice you, which may include:

  • your name, email address and, if you provide one, your phone number;
  • billing details such as a billing name, country, and (for business clients) company name and tax/VAT number;
  • details about your devices, apps, streaming plans or podcast that you share so we can perform the service (for example your phone model, Android version or which Spotify plan you use);
  • scheduling information for remote sessions; and
  • records of invoices issued and payments received.

Payments are made on invoice through a third-party payment processor. We do not see or store your full card number; the processor handles card data under its own security standards and sends us confirmation that a payment was made.

We never collect passwords

During audits, device setup or other remote sessions, we will never ask for your Spotify, Google, Apple or other account passwords. If a change needs to be made to an account, you make it yourself, or we guide you over a screen share while you stay in control. If anyone claiming to be from Moquz.com asks for your password, do not share it and let us know at [email protected].

2.4 Server logs

Like almost every website, our hosting provider automatically records basic technical information whenever a browser requests a page or file. These access logs typically contain:

  • your IP address;
  • your browser's user-agent string (browser type and version, operating system);
  • the date and time of the request;
  • the page or file requested, the HTTP status code and the referring page (if your browser sends one).

These logs are kept for up to 30 days and used only for security, abuse prevention and troubleshooting, never for profiling.

2.5 Communications

If you email us directly (for example at [email protected], [email protected] or [email protected]), we receive your email address, any name shown in your email client, the content of your message and any attachments.

2.6 Data we do not collect

  • We do not use analytics tools, heatmaps or session recording.
  • We do not load advertising pixels or retargeting tags.
  • We do not collect streaming, app store or email account passwords.

3. How we use your data and our legal bases

Under the GDPR and UK GDPR we must have a legal basis under Article 6 for each purpose for which we use personal data. The table below sets out each purpose and the legal basis we rely on.

PurposeData usedLegal basis (GDPR Art. 6)
Replying to your contact form message or emailName, email, optional phone, subject, messageLegitimate interests (Art. 6(1)(f)) in answering enquiries; or steps prior to a contract (Art. 6(1)(b)) when you ask about a service
Preparing quotes and delivering paid servicesContact details, service details, device/app information, scheduling dataPerformance of a contract (Art. 6(1)(b))
Invoicing, bookkeeping and tax recordsBilling details, invoice and payment recordsLegal obligation (Art. 6(1)(c))
Sending our newsletterEmail address, name (if given)Consent (Art. 6(1)(a)), which you can withdraw at any time
Keeping the website secure and availableServer log data (IP address, user agent, timestamps)Legitimate interests (Art. 6(1)(f)) in protecting our site and visitors
Remembering your cookie banner choiceThe mq_cookie_choice entry in your browserLegitimate interests / strictly necessary storage to respect your choice
Handling copyright notices and legal claimsNotice contents, contact details, correspondenceLegal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f))
Responding to privacy rights requestsIdentity and contact details, request detailsLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have balanced them against your rights and freedoms. You can object to processing based on legitimate interests at any time (see section 10).

4. How long we keep your data

We keep personal data only for as long as we need it for the purpose it was collected for, and then we delete it or anonymize it. The main retention periods are:

DataRetention period
Server access logsUp to 30 days, then automatically deleted by our hosting provider
Contact form messages and general emails that do not lead to an orderUp to 24 months after our last exchange, so we can refer back to earlier conversations
Newsletter subscription dataUntil you unsubscribe; we may keep a minimal suppression record (your email address) so we do not email you again
Service order records and project correspondenceFor the duration of the service and up to 3 years afterwards, to handle follow-up questions, guarantees and legal claims
Invoices and accounting recordsAs long as tax and accounting law requires (commonly 6–10 years depending on the jurisdiction)
Copyright notices and counter-noticesUp to 3 years after the matter is closed
Privacy rights requestsUp to 3 years, to demonstrate compliance
mq_cookie_choice in your browserUntil you clear your browser storage or reset your choice

If a longer period is required to establish, exercise or defend a legal claim, we may keep the relevant data until the matter is resolved.

5. Who we share data with

We do not sell personal data, and we do not share it with advertisers. We only disclose personal data to the following categories of recipients, and only as far as necessary:

Hosting provider

Stores and serves our website files and keeps the access logs described in section 2.4 on our behalf.

Email service provider

Receives contact form submissions, delivers them to our mailbox, hosts our email and sends our newsletter.

Payment processor

Processes invoice payments for paid services and handles card or bank data under its own security standards.

These providers act as our processors: they may only process personal data on our instructions and under a written data processing agreement that requires confidentiality and appropriate security.

We may also disclose personal data:

  • to professional advisers bound by confidentiality;
  • to authorities, courts or other parties where required by law, or to protect our rights, our users or the public (for example in response to a valid legal request or to prevent fraud);
  • to the person who filed a copyright complaint, or who is the subject of one, as described in our DMCA and copyright policy; and
  • to a successor organization if Moquz.com is ever sold or restructured, under this policy.

6. International data transfers

Our service providers may process personal data outside the European Economic Area (EEA) and the UK, including in the United States.

When personal data from the EEA or UK is transferred to such a country, we make sure it is protected by an appropriate safeguard, such as:

  • an adequacy decision by the European Commission or UK government (including, where applicable, the EU–US Data Privacy Framework and its UK extension for certified US companies);
  • the European Commission's Standard Contractual Clauses (SCCs), together with the UK International Data Transfer Addendum where UK data is involved; and
  • supplementary measures, such as encryption in transit.

Ask [email protected] for details of these safeguards.

7. Cookies and local storage

Our website does not currently set any analytics, advertising or social media cookies. The only item we store in your browser is a localStorage entry named mq_cookie_choice, which remembers whether you accepted or declined non-essential cookies in our cookie banner, so the banner does not reappear on every page.

Share buttons are plain links: no third-party scripts load unless you click one. If we ever add analytics, we will ask for your consent first.

For full details, including how to clear storage in your browser and reopen the banner using the "Cookie settings" link in the footer, see our Cookie Policy.

8. How we protect your data

We use technical and organizational measures appropriate to the small amount of data we hold, including:

  • HTTPS encryption for all pages and form submissions;
  • a static website with no database or user accounts, which greatly reduces the attack surface;
  • strong, unique passwords and two-factor authentication on our hosting, email and payment accounts;
  • choosing reputable providers bound by data processing agreements;
  • automatic deletion of server logs after up to 30 days; and
  • a strict policy of never requesting client passwords during services.

No system is perfectly secure. If a breach occurs that is likely to put your rights at risk, we will notify the supervisory authority and, where required, you, within the legal time limits.

9. Children's privacy

Our website and services are not directed at children, and we do not knowingly collect personal data from anyone under the age of 16. Paid services may only be ordered by adults who can enter into a binding contract. If you are a parent or guardian and believe that a child under 16 has sent us personal data, please contact [email protected] and we will delete it promptly.

10. Your rights in the EEA and UK

If you are in the European Economic Area or the United Kingdom, you have the following rights under the GDPR or UK GDPR. Some rights only apply in certain circumstances.

RightWhat it means
Access (Art. 15)Ask whether we process your personal data and receive a copy of it, along with information about how we use it.
Rectification (Art. 16)Ask us to correct inaccurate data or complete incomplete data.
Erasure (Art. 17)Ask us to delete your data, for example when it is no longer needed or you withdraw consent, unless we must keep it (for example invoices for tax law).
Restriction (Art. 18)Ask us to pause the use of your data while a complaint about accuracy or lawfulness is being resolved.
Data portability (Art. 20)Receive data you gave us, processed by consent or contract, in a structured, commonly used, machine-readable format, or have it sent to another controller.
Objection (Art. 21)Object to processing based on legitimate interests. You have an absolute right to object to direct marketing.
Withdraw consent (Art. 7(3))Withdraw consent at any time, for example by unsubscribing from the newsletter. This does not affect processing carried out before withdrawal.
Complain (Art. 77)Lodge a complaint with a supervisory authority, in particular in the country where you live or work or where an alleged breach occurred.

10.1 How to exercise your rights

Email [email protected] with a description of your request. We may ask for information to confirm your identity, usually by replying from the same email address you used to contact us. We will respond within one month, which may be extended by up to two further months for complex or numerous requests; if so, we will tell you why.

10.2 Supervisory authorities

You can complain to a data protection authority at any time. In the UK this is the Information Commissioner's Office (ICO); in the EU, each member state has its own authority.

11. Your rights in US states (CCPA/CPRA)

If you are a resident of California, or of another US state with a comprehensive privacy law (such as Colorado, Connecticut, Virginia, Utah, Texas, Oregon and others), you may have the rights described below. We honor these rights for all US residents.

11.1 Categories of personal information

In the last 12 months we collected identifiers (name, email, phone, IP address), commercial information (services ordered, invoices), network activity (server logs) and message contents, as described in sections 2 and 3, and disclosed them only to the service providers in section 5.

11.2 Your rights

  • Right to know / access: request the categories and specific pieces of personal information we have collected about you, the sources, the purposes and the categories of recipients.
  • Right to delete: request deletion of personal information we collected from you, subject to legal exceptions.
  • Right to correct: request correction of inaccurate personal information.
  • Right to opt out of sale or sharing: opt out of the "sale" of personal information or its "sharing" for cross-context behavioral advertising.
  • Right to limit use of sensitive personal information: we do not collect sensitive personal information for purposes that would trigger this right.
  • Right to non-discrimination: we will not deny you services, charge different prices or provide a different quality of service because you exercised your rights.
We do not sell or share

Moquz.com does not sell personal information and does not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We have not done so in the preceding 12 months, and we have no actual knowledge of selling or sharing the personal information of consumers under 16.

11.3 Submitting a request

Email [email protected] with the subject line "US privacy request". We will confirm receipt within 10 business days and respond within 45 days, extendable by a further 45 days where reasonably necessary. You may use an authorized agent, who must provide proof of authorization. If we decline your request, you may appeal by replying to our decision, and if you are unhappy with the result of the appeal you can contact your state Attorney General.

12. Do Not Track and Global Privacy Control

There is no agreed standard for responding to "Do Not Track" (DNT) signals, but because we do not track visitors across websites, our site behaves the same whether or not DNT is enabled.

Global Privacy Control (GPC) is a browser signal that communicates a request to opt out of the sale or sharing of personal information. We treat GPC as a valid opt-out request. We do not sell or share personal information, and if that ever changed we would honor GPC automatically.

13. Automated decision-making

We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you. Every enquiry, quote and service order is handled by a person.

14. Third-party websites and links

Our guides link to official external websites such as Spotify, Google Play Help and the US Copyright Office. When you click one of those links you leave Moquz.com, and the other website's privacy policy and cookie practices apply. We are not responsible for their content or privacy practices.

15. Changes to this policy

We may update this Privacy Policy when our practices, our service providers or the law change — for example if we introduce analytics in the future. We will change the "Last updated" date above, highlight significant changes on the site, notify you directly where the law requires it, and ask for consent before any change that requires it.

16. How to contact us

For any question about this policy or to exercise your rights, please contact us:

You can also use the form on our contact page.