SptecaTerms of Service →

Legal

Privacy Policy

Effective date: 9 June 2026

Spoteca ("Spoteca", "we", "us", or "our") is a music school management platform operated by Hawa Music SAL, registered in Lebanon, with offices at Mkales Roundabout, Sin el Fil, Lebanon.

This Privacy Policy explains what personal data we collect when you use spoteca.com, why we collect it, how we use it, and your rights regarding that data. By creating a Spoteca account or using the platform, you agree to this policy.

Age requirement: Spoteca accounts (admin, super-admin, teacher roles) may only be created by individuals aged 18 or older. By registering, you confirm that you are at least 18 years old. Schools are solely responsible for obtaining appropriate parental or guardian consent before entering any personal data relating to minor students into the platform.


1. Who This Policy Covers

This policy applies to three groups of people:

  • School operators — individuals or organisations who register a school on Spoteca (the "subscriber").
  • Platform users — administrators, super-admins, and teachers who have accounts on the platform.
  • Student & guardian records — personal data entered by a school operator about their students and guardians. Spoteca processes this data on behalf of the school operator, who remains the data controller for that data.

2. Data We Collect

2.1 Data you provide when signing up

  • School name, address (street, city, region, country), phone number, and email address.
  • Administrator full name, username, and password (stored as a one-way bcrypt hash — we cannot read your password).

2.2 Data school operators enter about their users

School operators may enter the following data about their teachers, students, and guardians:

  • Teachers: name, username, email, phone, address, instrument(s), biography, CV/resume.
  • Students: name, username, email, phone, address, date of birth, instrument, skill level, enrollment plan.
  • Guardians: name, relationship to student, phone, email, address.

Spoteca processes this data as a data processor on behalf of the school operator. The school operator is responsible for having a lawful basis for entering and processing this data, and for notifying their users that their data is stored on Spoteca.

2.3 Data generated through use of the platform

  • Attendance records, lesson notes, payment records, and reschedule history.
  • Messages sent between users within the platform.
  • Push notification subscription tokens (to deliver in-app notifications to your device).
  • Audit log entries (recording which actions were taken by which user, for security and accountability).

2.4 Technical data

  • Session data: We use a secure, encrypted session cookie (JWT) to keep you logged in. This cookie is essential for the platform to function. We do not use advertising cookies, tracking pixels, or analytics cookies of any kind.
  • Server logs: Our hosting provider (SiteGround) may collect standard server access logs (IP address, browser type, request timestamps) for security purposes.

3. How We Use Your Data

  • To provide the service: Storing and displaying your school's data so administrators, teachers, and students can manage lessons, payments, and schedules.
  • To send transactional emails: Account creation confirmations, billing invoices, trial expiry warnings, and payment reminders. You cannot opt out of these while you have an active account.
  • To send push notifications: Lesson reminders and platform alerts, delivered to devices where you have enabled browser push notifications. You can disable these at any time in your browser settings.
  • To process billing: Calculating your monthly subscription fee based on active enrollments and sending invoices.
  • To improve the platform: Internal review of usage patterns (without identifying individual users) to fix bugs and develop features.
  • Legal compliance: Where required by Lebanese law or a lawful authority.

4. Third-Party Services

We share minimal data with the following trusted third parties, only as necessary to operate the platform:

ServicePurposeData shared
SiteGround (EU)Hosting & database storageAll platform data stored on SiteGround servers
Google Maps PlatformAddress autocomplete during school signupThe address text you type into the search field
SiteGround SMTPTransactional email deliveryRecipient email address and email content

We do not sell your data. We do not share your data with advertisers, data brokers, or any other third party not listed above.

Google Maps Platform is used solely for the address autocomplete field during school registration. Its use is governed by Google's Privacy Policy.


5. Data Storage & Security

  • All data is stored in a MySQL database hosted by SiteGround in the EU.
  • All connections between your browser and our servers use TLS encryption (HTTPS).
  • Passwords are hashed using bcrypt and are never stored or transmitted in plain text.
  • Session tokens are encrypted JWTs stored in secure, HttpOnly cookies.
  • Access to production data is restricted to authorised Spoteca personnel only.

No method of transmission or storage is 100% secure. While we take reasonable measures to protect your data, we cannot guarantee absolute security.


6. Data Retention

  • Active subscriptions: We retain all data for as long as your school has an active Spoteca account.
  • Cancelled or suspended accounts: We retain data for 90 days after account cancellation or suspension, after which it is permanently deleted, unless we are legally required to retain it longer.
  • Billing records: Invoice and payment records may be retained for up to 7 years for legal and accounting compliance.

7. Your Rights

As a Spoteca subscriber or platform user, you have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate data.
  • Deletion: Request deletion of your personal data. Note: deleting an account will delete the entire school workspace and all associated data.
  • Portability: Export your school's data at any time using the Export feature in the Super Admin panel (available in Excel format).
  • Objection: Object to certain types of processing.

To exercise any of these rights, email us at support@spoteca.com. We will respond within 30 days.


8. School Operators as Data Controllers

When a school operator enters personal data about their teachers, students, or guardians into Spoteca, the school operator is the data controller for that data. Spoteca acts as a data processor.

School operators are responsible for:

  • Having a lawful basis for collecting and processing their users' personal data.
  • Informing students, teachers, and guardians that their data is managed via Spoteca.
  • Obtaining parental or guardian consent before entering personal data relating to minors.
  • Complying with applicable data protection laws in their own jurisdiction.

9. Cookies

Spoteca uses only one cookie: a session cookie set by NextAuth to keep you logged in. This cookie is strictly necessary for the platform to function and does not track you across other websites.

We do not use Google Analytics, Meta Pixel, or any other analytics or advertising cookies.


10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. For material changes, we will notify subscribers via email at least 14 days before the change takes effect. Continued use of Spoteca after a change takes effect constitutes acceptance of the updated policy.


11. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

Hawa Music SAL
Mkales Roundabout, Sin el Fil, Lebanon
Email: support@spoteca.com
WhatsApp: +961 3 243 847

© 2026 Spoteca · Hawa Music SAL · Terms of Service