Privacy Policy
Effective date: September 21, 2026
This Privacy Policy explains how Bajache, LLC ("Mosaic Biz", "we", "us") collects, uses, and discloses information when you use the Mosaic Biz platform (the "Service"). It applies to account holders and members of a customer organization ("you").
1. Information We Collect
Account and organization information
- Name and email address, used for authentication (one-time email login codes) and account management.
- Organization name, role, and team membership.
- Billing contact and transaction history, handled by our payment processor (see Section 3).
Customer content you provide
- Catalog and business data you enter or upload, including artist, release, track, credit, split, sample-clearance, lyrics, booking, deal, sync-brief, and document records, and any files you upload to Studio or Artist & Track Documents.
- Content connected from linked social media accounts, where you choose to connect one.
Usage and device data
- Log data such as IP address, browser type, pages visited, and timestamps, collected automatically to operate, secure, and improve the Service.
- Cookies and similar technologies used to keep you signed in and remember preferences.
2. How We Use Information
- To provide, maintain, and secure the Service, including authenticating sign-ins and enforcing organization-level access controls;
- To operate AI Features, which send relevant portions of your organization's data to the AI subprocessors listed below to generate reports, suggestions, and drafts;
- To send transactional email (sign-in codes, invitations, billing notices) through our email delivery subprocessor;
- To process payments and manage subscriptions through our payment processor;
- To monitor, debug, and improve the Service's reliability and performance;
- To communicate with you about the Service, including updates to these policies; and
- To comply with legal obligations and enforce our Terms of Service.
We do not sell personal information, and we do not use your Customer Content to train third-party AI models.
3. Subprocessors and Third Parties
We use the following categories of subprocessors to operate the Service. We will update this list as our vendors change.
- Infrastructure & database: Supabase (hosting, authentication, Postgres database, file storage) and Vercel (application hosting and scheduled jobs).
- AI providers: Anthropic and OpenAI, used to power AI Features (research agents, suggestions, and generated content). Data sent to these providers is limited to what is needed to generate the requested output.
- Email delivery: Resend, used to deliver authentication and transactional email.
- Payments: Stripe, used to process subscription payments (Stripe receives payment details directly; we do not store full card numbers).
- Streaming/DSP data: Chartmetric, where an organization enables DSP Growth features, to retrieve public streaming and playlist metrics.
- Social platforms: Meta (Instagram), TikTok, X, and YouTube, only where you choose to connect an account for the Marketing module.
4. Data Retention
We retain account and Customer Content data for as long as your organization's account is active. After termination, we retain Customer Content for up to 30 days to allow for export or reactivation, after which it is deleted from active systems, subject to a limited backup retention period and any legal obligation to retain records longer.
5. Your Rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. Organization owners can export or delete organization data directly from account settings. To exercise these rights, or if you have difficulty doing so through the Service, contact us at legal@mosaicbiz.app. We will respond within the time required by applicable law.
6. International Data Transfers
Our subprocessors may process data in the United States and other countries. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for transfers of personal data out of the European Economic Area, the United Kingdom, or Switzerland.
7. Security
We use industry-standard technical and organizational measures to protect information, including encryption in transit, row-level access controls that isolate each organization's data, and role-based permissions within an organization. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
8. Children's Privacy
The Service is intended for business use by adults and is not directed to children under 18. We do not knowingly collect personal information from children.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or through the Service before they take effect.
10. Contact
Questions about this Privacy Policy or requests regarding your personal information can be sent to legal@mosaicbiz.app.
This document is a general-purpose template based on common SaaS industry practice and does not constitute legal advice. If your customers include organizations subject to GDPR, CCPA, or similar laws, have this reviewed by a privacy attorney before relying on it commercially.