Privacy
Last updated: 7 October 2026
Who we are
DJ back 2 back (djb2b.com, and the DJ back 2 back app) is run by Mat, trading as Cadence Highway. Mat decides how your data is used, so he is the "controller".
Address: coming shortly. Contact: support@djb2b.com, or our request form at djb2b.com/privacy-request.
The short version
- We keep what we need to run your account, link you up with other DJs and keep the service safe. We don't record your sets.
- We don't sell or share your data, show ads or track you across other sites.
- DJ back 2 back is for people 18 and over.
- You can download your data, correct it, or delete your account, any time.
What we keep, why, and for how long
Your account
- What: your email, your DJ name, when you signed up and whether that was during the beta, and that you confirmed you're 18 or over, and when. We never keep a date of birth. Your password is kept only as a one-way hash.
- We also keep which Terms you agreed to when you signed up, and when.
- We no longer ask for a bio or your kit. Any you added before stays in Download my data until you delete your account.
- If you save it to your account: the gear and DJ software you picked under Set up your sound, on the download page. It isn't shown on your public page or used for matching, and it goes when you clear it or delete your account.
- Logins: each login is a random token, kept only as a hash. Confirm, reset and change-email links are kept the same way, and each works once.
- Why: to give you the account you signed up for.
- How long: while you have the account. A login lasts 30 days from when you last used it. A link goes once it's used or expired.
Account emails
- What: when we send you one (a confirm link, a "you already have an account", a change of email, a password reset, a "this email can't sign up yet", or a security notice), we keep the kind and the time.
- Why: so it's at most 1 a minute and 5 a day.
- How long: a day. A record of a security notice, kept with our breach log, stays 3 years.
- What: for a service email, which one we sent you and when, kept against your account number only.
- Why: to show we told you.
- How long: 24 months, or until you delete your account.
The monthly update, if you ask for it
- What: when you agreed, how (the sign-up box or your account page), the words you agreed to, and when you stopped.
- Why: to show you asked for it.
- How long: while you get it, and 24 months after you stop. Deleting your account deletes it at once.
Your library, if you add it
- What: artist names (up to 200), genre shares, and which DJ software they came from, plus when you agreed to send them. Never your track list or files. The library reader asks before it reads your library and again before it sends.
- Why: to match you with DJs who play what you play, because you chose to add it.
- How long: until you add a new one, remove it with Remove my library on your account page, or delete your account.
Your genres and public page
- What: up to 3 genres you pick, whether your public page is on, its address, and your live link if you add one (a Mixcloud Live or Twitch channel).
- Matching: we use the genres you pick to match you with other DJs on Live. You can turn matching off on your account page.
- Your public page is off until you turn it on. When it's on, anyone can see your DJ name, genres, your level line, a verified Mixcloud link, your live link if you add one, and the sets you list.
- Why: matching is part of the service you signed up for. Your public page is shown because you chose to turn it on.
- How long: until you change it or delete your account. An address you leave is kept only as a one-way code, so it's never given to anyone else.
Your sessions
- What: the sessions you make or join, when, with whom and how long they ran, the invites you send and answer, and the share links you make.
- Why: to link you up and run the session.
- How long:
- 24 months;
- a session nobody started, a day;
- a share link, 24 hours.
- A session's own working data is deleted when it ends.
Practice partner
- What: when you started and ended each practice with the Practice partner in the app, and the relay's names for it.
- Who sees it: only you, in Download my data.
- Why: for the practice time limits, and so ending a practice early also closes its relay.
- How long: 2 days, or until you delete your account.
Your level
- What: the level you pick, who you'd play with, and when you set it. After a session of 10 minutes or more, your private answers about the other DJ: whether their level felt lower, about right or higher, whether you'd b2b with them again, and when.
- Who sees it: nobody sees your answers; they only steer matching on Live. Other DJs on Live, and anyone on your public page if it's on, see one line: your level, how many sessions you've played and with how many different DJs.
- How long: your answers, 12 months. A "no" to b2b again keeps the two of you from being suggested to each other until either account is deleted. Your level, until you change it or delete your account.
- Download my data has your level, your own answers and your "no"s in full, and the answers about you as counts only, so it never shows who said what.
Live
- What: while you're switched on: when you switched on and when you were last active. The DJs you block.
- Your live link: if you've added one, logged-in DJs see it beside your name while you're switched on.
- Why: to show you to DJs who want a b2b now, because you switched it on; and blocks, to keep you safe.
- How long: until you switch off, start a session, log out or go quiet for 10 minutes. Blocks last until either account is deleted.
The app and your session page
- What: while the app is open and you're logged in, it sends us what your session page on djb2b.com shows: the app's version and whether it's on a Mac or Windows; the sound outputs it lists, by name, and the ones and channels you've chosen; only the name of what you chose as your mix; your session code, your partner's DJ name and how the session's going; the app's latest status lines; and whether "Accept handovers automatically" is on.
- Why: so you can see and run the app from your session page. From the page you can join, hand over, accept and leave, and change your partner's output, your headphones, the partner level and "Accept handovers automatically". You can't change your mix there: it's chosen in the app. The app's window says when your session page joined or changed something.
- Who sees it: only you, on djb2b.com while you're logged in.
- How long: only while the app is connected. It's deleted when the app disconnects, and at once if your account is suspended, closed or deleted. We keep no record of what you do from the page: the limit of 30 commands a minute is only a count while the page is in use.
Mixcloud and Mixes
- What: the Mixcloud username you link and when, the one-time code for your Mixcloud bio, and when it was checked. The sets you list: the show's address, its genre and date, the two DJs and who added it.
- Who sees it: anyone can see the sets on Mixes. To visitors who aren't logged in, a DJ is named only if their public page is on, and shows as "another DJ" otherwise; logged-in DJs see both names.
- How we check: our server looks up your public Mixcloud shows by the username you give. It doesn't send Mixcloud anything about you.
- Why: to show your b2b sets, because you chose to.
- How long: until you unlink, delete a set, or delete your account. A username you never verify goes, with its bio code, after 7 days.
- Likes: which sets you like, and when. Anyone can see how many likes a set has; nobody sees who liked it. Likes from a suspended or closed account don't count. We keep a like until you unlike the set, the set is deleted, or you delete your account. Your likes are in Download my data.
- Listen presses: when anyone presses Listen on a set, we add one to that set's total for the day. We never record who pressed, so it isn't in Download my data. We use the totals only to break ties in the Top 10. Each day's total is kept 13 months, and goes sooner if the set is deleted.
The message boards
- What: what you posted and replied before the boards closed, the posts you reported, and a posting ban if we set one.
- Who sees it: nobody. The boards have closed, and nothing on them is shown.
- Why: to deal with any complaint or claim about what was posted.
- How long: 12 months after the boards closed, then it's deleted. A post a court case is about is kept until the case ends. If you delete your account before then, your posts become "[removed]" straight away. To have a post removed sooner, email support@djb2b.com.
Reports and safety
- What:
- reports about a DJ, a public page, a set or a Live entry: who reported, the reason, any details and when;
- if you report while logged out, the email you give, so we can reply;
- if we take a page down or suspend an account, the reason and when;
- while a suspension is active, a one-way fingerprint (a hash) of the account's email, so the same email can't sign up again.
- Why: to keep DJ back 2 back safe and meet the law on online safety.
- How long:
- a report, 12 months after we've dealt with it;
- a logged-out reporter's email, 90 days after;
- a page-down or suspension, 24 months after it's lifted;
- the fingerprint, until the suspension is lifted.
If we close an account, it can't log in and nothing of it is shown. Unless an appeal succeeds, we delete it 6 months later as if its owner had deleted it; an account that appears to belong to someone under 18 is deleted at once. Either way we keep only the record of our decision: what we did and why, and the statement we sent, for 24 months, and any copyright strikes, for 12 months after they stop counting. Reports about it stay for their 12 months, as after any deletion. We also keep a one-way fingerprint (a hash) of its email for 24 months after the close, so the same email can't sign up again. It's deleted sooner if an appeal succeeds.
Requests about your data
- What: what you ask for, what you write, the email we reply to, and when.
- Why: to answer you, and to show we did.
- How long: 24 months, even if you delete your account.
Problem reports
- What: what you tell us went wrong and where, the error code when you came from an error message, the device, system and app version you give, any app log you attach, and your email if you give it. Logged in, your account's email is filled in for you: clear it if you don't want a reply. The app's log holds what the app did: your DJ name, your audio devices, which apps were playing sound, the connection, and any errors. It never has your partner's name. A report isn't linked to your account, and your internet address isn't kept with it.
- Who sees it: Mat, who runs DJ back 2 back, on our admin page. AI tools, run by Anthropic, read problem reports to find the fault. They group the reports, and email Mat a daily digest with a brief for the team, plus a note straight away for a new or serious problem, instead of a copy of each report. For that, what you wrote, with any email address, phone number or internet address in it taken out, where it happened, the device, system and app version you gave, and the error code go to Anthropic's API. Your email address and app log don't.
- Why: to find and fix the problem.
- How long: 90 days on our site. Our support system keeps its own copy for 90 days too: the same report with any email address, phone number or internet address taken out, and without your email address or app log. Anthropic deletes what it read within 30 days, unless its safety systems flag it or the law requires it to keep it longer, and doesn't use it to train its models. The digests are kept in the team mailbox, which Apple's iCloud Mail holds for us, and deleted within 12 months, as are the reports emailed to Mat before this change.
Tries we limit
- What: your internet address (an IPv6 one by its /64 block) each time you do something we limit: sign-up, log-in, forgot password, resending the confirm email, confirming you're 18 or over, changing your email or password, deleting your account, making, checking, joining or sharing a session, invites, the relay, matching on Live, adding or removing your library, editing your DJ name, blocking or unblocking a DJ, switching on Live, turning on your public page, the app checking for your sessions, reports, listing a set, linking Mixcloud, liking a set, changing your live link, pressing Listen on a set, Download my data, requests about your data, reporting a problem, and reading Live or Mixes logged out. Sign-up, log-in, forgot password and a logged-out request about your data also keep the email given, and resending the confirm email keeps your account's email. The others, done logged in, keep your account.
- When you sign up, link up or post, post or pay, we check which country your internet address is in, to see whether we're open there. We don't keep it.
- Why: to stop password guessing and abuse.
- How long: an hour. A refused try is counted by its kind only, with no address, for a week.
Support emails
An email to support@djb2b.com or setup@djb2b.com goes first to our AI assistant, then to Mat, who runs DJ back 2 back. Nobody else reads it.
- Checked first: mail that fails DMARC, or fails SPF with no DKIM pass, is dropped and not read further.
- Answered only when we can check the sender: the receiving checks are there, your address has no unusual characters, the address that delivered the mail is the From address, and DMARC passes (or, for a domain with no DMARC record, SPF or DKIM passes for your own domain). Anything else, and automatic mail (auto-replies, mailing lists, bulk mail, bounces, no-reply senders and mail that asks for no automatic replies), gets no reply and isn't read by the AI; Mat gets it.
- Not read by the AI either: a reply in a thread we've already answered, or more than 5 emails an hour or 20 a day from one sender. Mat gets them, and no reply goes out.
- Read by a person: a reply to one of our site's own emails (a confirm or reset link, a change to your account, a security notice, a report or a decision about your account). Mat gets it, with "Thanks. A person will get back to you."
- Read by the AI: everything else is sorted by Anthropic's Claude models, which process it for us. For that, your email address, the subject and up to 12,000 characters of the text go to Anthropic's API. Spam gets no reply. Anything that needs a person gets "Thanks. A person will get back to you." A routine question gets a reply the AI writes only from this site's own FAQ, How it works, Copyright & Mixcloud and Download pages (and our own setup notes), and the reply says it was written by our AI assistant. A reply goes only to you. One that would link or point anywhere but djb2b.com, mention passwords or payment details, or talk about money, legal matters or dates, goes to a person instead.
- Why: to answer you quickly, and send everything else to a person.
- What the log keeps: for each email, the time, your address, which of our addresses it came to (support or setup), the email's message ids and our reply's, how it was sorted and routed, the SPF, DKIM and DMARC results and your address's domain, how many AI tokens it used, whether Mat's copy went, and a short problem code (which can include the web address or email address a reply was stopped for). Never the text, the subject, attachments, names, the AI's summary or its reply. Each row is deleted after 30 days, with no other copy.
- What Anthropic keeps: Anthropic deletes it within 30 days, unless its safety systems flag it or the law requires it to keep it longer. It doesn't use your email to train its models.
- Mat's copy: every email, except one dropped by the checks, is copied to Mat's mailbox with the sender, the subject, a two-line summary by the AI, any reply we sent, the text (up to 100,000 characters) and the original email when it's 4 MiB or less. At most 5 an hour and 20 a day from one sender are copied; past that, only the log entry is kept. The copies are kept in the team mailbox, which Apple's iCloud Mail holds for us, and deleted within 12 months.
Payments
- Today: payments are off during the beta, so we take no money and keep no card details.
- When they start: Stripe takes them. We send Stripe your email and your account number, and you enter your card on Stripe's own page, so we never see it. We'll keep each purchase record for as long as tax law requires, and Stripe keeps its own record.
The app on your computer
The app keeps your login and four settings (your partner level, the VirtualDJ option,
your key for the big button and "Accept handovers automatically"), and a log of what it did, including what your
session page asked it to do, one file a day for 7 days. The log never has your partner's name. It stays on your
computer unless you send it to us. On a Mac, the sound switch also keeps DJb2b's sound settings, a copy of yours
from just before each switch so it can put them back, and, while DJb2b's are on, when you switched. The settings
are your sound output and input, by name and device ID, with their sample rate, channel layout and volume. They
stay in the app's folder (~/Library/Application Support/djb2b-app/sound) until you delete them, even
if you delete the app, and they're never sent to us. On Windows, the app only notes that you've read how to set
your sound.
What we don't keep
- Your sound goes from your app to the other DJ's, or through Cloudflare's relay when you link up from Live, or when your networks need it. A practice always goes through Cloudflare's relay and back to you. We don't record it.
- We don't keep your track list, your files or a date of birth.
Who sees what
- Other DJs see your DJ name.
- On Live they also see your genres, if you match on them. They also see your level line, as does anyone on your public page if it's on.
- When you link up by an invite by DJ name or a link, the DJ you link with also gets your internet address, so the two apps can connect directly. When you link up from Live, the link goes through Cloudflare's relay, so they don't.
- Anyone can see your public page, if it's on.
- Mat, who runs DJ back 2 back, sees reports, problem reports, requests about your data, support emails, and the newest sign-ups' DJ names.
Who works for us
- Cloudflare runs the site, the database, the session rooms and the relay, and sends our emails. So it handles everything the site keeps (listed above), your internet address, the emails we send you, and, when a link-up goes through the relay (from Live, or when your networks need it), your session's sound as it passes through. A practice always goes through the relay and back, and isn't recorded.
- Anthropic reads support emails and problem reports for us (see Support emails and Problem reports). It works under its data processing agreement with us.
- Stripe will take payments, when they start. It will get your email, your account number and the card you enter on its page.
- Apple holds the team mailbox for us (iCloud Mail): the copies of support emails, the problem-report digests, and email forwarded from support@ and hello@. They're deleted within 12 months.
- Postmark sends the monthly update for us. It gets the email address of each DJ who asked for it, and nothing else.
Cloudflare and Stripe work under their data processing terms with us.
We don't sell or share your personal information, show ads or track you across other sites. So "Do Not Track" and Global Privacy Control have nothing to switch off.
Where your data goes
- Cloudflare and Stripe are US companies, and Cloudflare's network is worldwide. Apple, which holds the team mailbox, is a US company too.
- Postmark is a US company.
- Anthropic may process support emails and problem reports in the US, Europe, Asia or Australia, and stores them in the US. When your data leaves the UK for Anthropic, it's protected by the EU's standard contractual clauses with the UK's addendum, in its data processing agreement.
- When your data leaves the UK for Cloudflare or Stripe, it's protected by the safeguards in their data processing terms.
How we use your data, and on what basis
- To run your account, sessions and posts, to email you about the service, and to match you on the genres you pick: because it's the service you signed up for (contract). You can turn matching off on your account page.
- Your library, your public page, Live, Mixcloud and the monthly update: because you chose to turn them on (consent). You can turn each off any time.
- Limits, blocks, reports, bans, support emails, the record of service emails we sent, and security: to keep DJ back 2 back safe and working (legitimate interests).
- Payment records, safety duties, and answering requests about your data: because the law requires it (legal obligation).
- No automated decisions with legal or similar effects are made about you.
Your rights
- Get a copy: use Download my data on your account page for everything tied to your account, in one file. Or ask us.
- The support log (which of your emails, when, and how each was handled; never the email itself) is kept apart from your account, so it isn't in Download my data. Ask for it with the request form and we send it.
- Correct it: change your DJ name, genres and email on your account page.
- Delete it: delete your account on your account page. To remove only your library, use Remove my library on your account page.
- Change your mind: turn off your public page, Live, or matching on your genres, any time.
- Object, or ask us to pause using your data: ask us.
- How to ask: use our request form at djb2b.com/privacy-request. Mat reads each one and replies by email, within one month.
- Complain: to us, the same way. Or to the Information Commissioner's Office (ico.org.uk).
When you delete your account, we remove:
- your email, DJ name, bio, kit, password and logins;
- your library, the genres you picked, your invites and share links;
- your Mixcloud link and your live link, the likes you gave, and the sets on Mixes whose show is on your own Mixcloud account, with their likes and Listen totals;
- your Live status and the blocks you made or that name you;
- your practice times;
- your board ban, the record of account emails we sent you (a security notice's record stays 3 years), and your rate-limit counts;
- your level, the answers you gave after sessions and the answers about you, and any "no" to b2b again, yours or another DJ's about you.
What happens to the rest:
- Your board posts and topic titles become "[removed]", and any words you added to a board report are deleted. The report keeps its reason, which is a category, and when you made it.
- Your public page goes, and its address is retired.
- Your past sessions and purchases stay, under "Deleted DJ" with no email, and so does a set your partner put on their own Mixcloud.
- A request you sent us about your data stays for its 24 months.
Age
DJ back 2 back is for people 18 and over. You confirm it when you sign up. We keep only that you did, and when. We close an account we learn belongs to someone under 18.
Cookies
We use one cookie, for your login. In your browser's storage we keep up to three things, each only if you use its button: that you closed the launch banner, that you paused the home page's motion, and the gear and DJ software you last picked on the download page. The details, and how to undo each, are on our Cookies page.
Keeping your data safe
- Passwords, logins and links are kept only as one-way hashes.
- Your login cookie can't be read by the page's scripts, and is only sent over a secure connection.
- The current app joins a session, and links to your session page, with a one-use ticket, never your login. The older beta.2 app sends your login in the session's address, over a secure connection, until it's retired.
- If a security problem puts your data at risk, we'll tell you, and the Information Commissioner's Office where the law requires.
Emails we send
We send account emails (confirming your email, changes to your account, security notices) and replies to your emails. We also email every account about the service itself: before the beta ends, before the transition after it ends, at least 30 days before a change to our Terms that affects you, and at least 30 days before we shut DJ back 2 back down. These are about your account, not marketing, so they come to every account. When you report something, we email you a receipt and then our decision. If we restrict your account or something you posted, we email you why and how to appeal. If we get a copyright notice about something of yours, we forward it to you, and tell whoever sent it that we did.
The monthly update: if you turn it on on your account page, we'll send you one email a month about what's new. We haven't sent one yet. It goes through Postmark, an email service. Every one will have a one-click unsubscribe, and you can stop on your account page any time. We don't send any other marketing emails.
Changes to this page
When we change this page, we change the date at the top. If a change matters to how we use your data, we'll say so at the top of this page. If a change matters to how we use your data, we'll email you.
Contact
Email support@djb2b.com, or use djb2b.com/privacy-request. DJ back 2 back is run by Mat, trading as Cadence Highway. Address: coming shortly.