This is an old version of this policy which is no longer valid. The latest version can be found here.

Spotify Privacy Policy

Effective as of 1 February 2021

1 Introduction

2 About this Policy

3 Your rights and your preferences

4 Personal Data we collect from you

5 What we use your personal data for

6 Sharing your personal data

7 Data retention and deletion

8 Transfer to other countries

9 Links

10 Keeping your data safe

11 Children

12 Changes to this Privacy Policy

13 How to contact us

1. Introduction

Thanks for choosing Spotify!

At Spotify, we want to give you the best possible experience to ensure that you enjoy our service. To do this we need to understand your streaming habits so we can deliver an exceptional and personalized service specifically for you. Your privacy and the security of your personal data is, and will always be, enormously important to us. So, we want to transparently explain how and why we gather, store, share and use your personal data - as well as outline the controls and choices you have around when and how you choose to share your personal data.

That is our objective, and this Privacy Policy ("Policy") will explain exactly what we mean in further detail below.

2. About this Policy

This Policy sets out the essential details relating to your personal data relationship with Spotify AB. The Policy applies to all Spotify services and any associated services (referred to as the 'Spotify Service'). The terms governing your use of the Spotify Service are defined in our Terms and Conditions of Use (the "Terms and Conditions of Use").

From time to time, we may develop new or offer additional services. If the introduction of these new or additional services results in any material change to the way we collect or process your personal data we will provide you with more information or additional terms or policies. Unless stated otherwise when we introduce these new or additional services, they will be subject to this Policy.

The aim of this Policy is to:

  1. Ensure that you understand what personal data we collect about you, the reasons why we collect and use it, and who we share it with;
  2. Explain the way we use the personal data that you share with us in order to give you a great experience when you are using the Spotify Service; and
  3. Explain your rights and choices in relation to the personal data we collect and process about you and how we will protect your privacy.

We hope this helps you to understand our privacy commitments to you. For further clarification of the terms used in this Policy please visit our Privacy Center on spotify.com. For information on how to contact us if you ever have any questions or concerns, please see 'Section 13 'How to contact us' below. Alternatively, if you do not agree with the content of this Policy, then please remember it is your choice whether you want to use the Spotify Service.

3. Your rights and your preferences: Giving you choice and control

The General Data Protection Regulation or "GDPR" gives certain rights to individuals in relation to their personal data. Accordingly, we are happy to offer transparency and access controls to help users take advantage of those rights. As available and except as limited under applicable law, the rights afforded to individuals are:

  • Right of access - the right to be informed of and request access to the personal data we process about you;
  • Right to rectification - the right to request that we amend or update your personal data where it is inaccurate or incomplete;
  • Right to erasure - the right to request that we delete your personal data;
  • Right to restrict - the right to request that we temporarily or permanently stop processing all or some of your personal data;
  • Right to object -
    • the right, at any time, to object to us processing your personal data on grounds relating to your particular situation;
    • the right to object to your personal data being processed for direct marketing purposes;
  • Right to data portability - the right to request a copy of your personal data in electronic format and the right to transmit that personal data for use in another party's service; and
  • Right not to be subject to automated decision-making - the right to not be subject to a decision based solely on automated decision making, including profiling, where the decision would have a legal effect on you or produce a similarly significant effect.

In order to enable you to learn more about these rights, exercise these rights with ease and to record your preferences in relation to how Spotify uses your personal data, we provide the following resources:

  • Privacy Settings - (accessed via your account page) allows you to exercise choices about the processing of certain personal data, and an automated 'Download your data' function to download basic account and usage information.
  • Privacy Center - provides a convenient central location where you can find more information about how Spotify uses your personal data, your rights in relation to your personal data, and how to exercise those rights.
  • Notification Settings - (accessed via your account page) allows you to choose which marketing communications you receive from Spotify. You may toggle these settings to opt in or out of receiving different types of email and push notifications. Please note that email marketing messages from Spotify include an opt-out mechanism within the message itself (e.g. an unsubscribe link in the emails we send to you). Clicking on the link in an email will opt you out of further messages of that category (e.g. Artist Updates). You can use the Notification Settings page to exercise choices about all categories of email and push marketing communication; and
  • Customer Support resources - We have several pages on our customer support site which provide further guidance about data protection questions. A key source of information is the Data Rights and Privacy Settings article which includes answers to "frequently asked questions" about personal data processing in the Spotify Service.

If you have any questions about your privacy, your rights, or how to exercise them, please contact our Data Protection Officer using the 'Contact Us' form on the Privacy Center. A legal representative may request at any time to view, correct/delete, suspend the processing of, and withdraw consent to personal data. In this case, a legal representative has to contact us by using the contact information above. If you have concerns around our processing of your personal data, we hope you will continue to work with us to resolve them. However, you can also contact and have the right to lodge a complaint with the Swedish Data Protection Authority (Integritetsskyddsmyndigheten) or your local Data Protection Authority.

4. Personal data we collect from you?

We have set out in the tables below the categories of personal data we collect and use about you and how we collect it:

The table below describes personal data collected when you sign up for the Spotify Service:


Categories of personal data
Description of category

User Data
This is the personal data that is provided by you or collected by us to enable you to sign up for and use the Spotify Service. Depending on the type of Spotify Service plan you sign up for, this may include your username, email address, phone number, birth date, gender, street address, and country.
Some of the personal data we will ask you to provide is required in order to create your account. You also have the option to provide us with additional personal data in order to make your account more personalized.
The exact personal data we will collect depends on the type of Spotify Service plan you sign up for, how you create an account, and whether you use third party services (such as Facebook) to sign up and use the Spotify Service. If you use a third party service to create an account, we will receive personal data via that third party service but only when you have consented to that third party service sharing your personal data with us. Please note that the available plans and sign-up options may differ by country.

The table below describes personal data collected through your use of the Spotify Service:


Categories of personal data

Description of category
Usage Data
This is the personal data that is collected about you when you’re accessing and/or using the Spotify Service, including:
  • Information about your type of Spotify Service plan.
  • Information about your interactions with the Spotify Service such as your search queries (including the date and time of any requests you make), streaming history, playlists you create, your library, your browsing history, and your interactions with the Spotify Service, content, other Spotify users. This also may include details of your use of third party applications in connection with the Spotify Service.
  • Inferences drawn about your interests and preferences based on your usage of the Spotify Service.
  • User Content (as defined in the Terms and Conditions of Use) you post to Spotify, such as photos, playlist titles, and interactions with the Spotify Customer Service team. Please note that we will only access your camera or photos from your device if you give us permission to do so, and we will only access images that you specifically choose to share with us and metadata related to those images, such as the type of file and the size of the image. We will never scan or import your device’s photo library or camera roll.
  • Certain technical data, which may include:
  • URL information;
  • online identifiers including cookie data and IP addresses;
  • information about the types of devices you are using such as unique device IDs, network connection type (e.g. wifi, 3G, LTE, Bluetooth), provider, network and device performance, browser type, language, information enabling digital rights management, operating system, and Spotify application version;
  • device attributes of devices on your wifi network that are available to connect to the Spotify Service (such as speakers);
  • your non-precise location, which may be derived or inferred from certain technical data (e.g., your IP address, language setting of your device, or payment currency), to comply with geographic requirements in our licensing agreements, and deliver personalized content and advertising to you; and
  • motion-generated or orientation-generated mobile sensor data (e.g. accelerometer or gyroscope) required for the purposes of providing specific features of the Spotify Service to you.
  • To provide personalized services Spotify uses "cookies" to store and process your data. A cookie is a small file which the http server for the operation of a website or application sends to the user's device browser, and may be saved to their device.
    • Purpose of cookies: Cookies are used to deliver content and ads to you, to understand how you interact with online content and ads, to assess the performance of our website and to personalise the content and ads that you see.
    • Installation, operation and rejection of the cookies: You can withdraw or modify your consent to our use of cookies at any time. If you no longer wish to receive cookies you can use your web browser settings to accept, refuse and delete cookies. To do this, follow the instructions provided by your browser (usually located within the “Help”, “Tools” or “Edit” settings).
Plan Verification Data
For users of certain plans like the Premium Family Plan and Premium Duo Plan, we may use a third party mapping application (such as Google Maps) and/or your device’s location service to help you verify your address. This data is collected for the sole purpose of verifying eligibility for the Premium Family Plan and Premium Duo Plan and is not used for advertising or any other purpose.

The table below describes personal data collected with your permission that enables us to provide you with additional features/functionality

Categories of personal data


Description of category
Voice
If voice features are available in your market, we collect your voice data with your permission to provide you with additional features and functionalities, such as interacting with the Spotify Service with your voice. For more information see our Voice Control Policy.
Payment and Purchase Data
We may collect certain personal data if you sign up for a Trial or purchase any of our Paid Subscriptions (as defined in the Terms and Conditions of Use) or make other purchases through the Spotify Service. The exact personal data collected will vary depending on the payment method (e.g. direct via your mobile phone carrier or by invoice) but will include information such as:
  • Name;
  • Date of birth;
  • Credit or debit card type, expiration date, and certain digits of your card number;
  • Postal code;
  • Mobile phone number; and
  • Details of your purchase and payment history.
Contests, Surveys and Sweepstakes Data
When you complete any forms, respond to a survey or questionnaire, or participate in a contest, we collect the personal data you provide.

The table below describes personal data collected from third party sources

We collect personal data about you from various third parties. These third party sources vary over time and include the following:

Categories of third party sources


Description of category
Authentication partners
If you register for or log into our services using third party credentials (e.g. Facebook), we will import your information from such third party to help create your account with us.
Technical service partners
We work with technical service partners that provide us with certain data, such as mapping IP addresses to non-precise location data (e.g., city, state), to enable us to provide the Spotify Service, content, and features.
Payment partners
If you choose to pay for a service or feature by invoice, we may receive data from our payment partners to enable us to send you invoices, process your payment and provide you with what you’ve purchased.
Advertisers and other advertising partners
We may obtain certain data about you, such as cookie id, mobile device id, or email address, and inferences about your interests and preferences from certain advertisers and advertising partners that allow us to deliver more relevant ads and measure their effectiveness.

5. What we use your personal data for

When you use or interact with the Spotify Service, we use a variety of technologies to process the personal data we collect about you for various reasons. We have set out in the table below the reasons why we process your personal data, the associated legal bases we rely upon to legally permit us to process your personal data, and the categories of personal data (identified in Section 4 'What personal data do we collect from you?') used for these purposes:


Description of why Spotify processes your personal data (‘processing purpose’)

Legal Basis for the processing purpose

Categories of personal data used by Spotify for the processing purpose
To provide and personalize the Spotify Service.
Consent
  • User Data
  • Usage Data
  • Payment and Purchase Data
  • Plan Verification Data
  • Voice Data
To understand, diagnose, troubleshoot, and fix issues with the Spotify Service.
Consent
  • User Data
  • Usage Data
To evaluate and develop new features, technologies, and improvements to the Spotify Service.
Consent
  • User Data
  • Usage Data
  • Voice Data
For marketing, promotion, and advertising purposes.
Consent
  • User Data
  • Usage Data
  • Voice Data
To comply with legal obligations and law enforcement requests.
Compliance with legal obligations
  • User Data
  • Usage Data
  • Voice Data
  • Payment and Purchase Data
  • Plan Verification Data, Contests
  • Surveys and Sweepstakes Data
To fulfill contractual obligations with third parties, for example licensing agreements and to take appropriate action with respect to reports of intellectual property infringement and inappropriate content.
Consent
  • User Data
  • Usage Data
  • Payment and Purchase Data
To establish, exercise, or defend legal claims.
Consent
  • User Data
  • Usage Data
  • Voice Data
  • Payment and Purchase Data
  • Plan Verification Data, Contests
  • Surveys and Sweepstakes Data
To conduct business planning, reporting, and forecasting.
Consent
  • User Data
  • Usage Data
  • Payment and Purchase Data
To process your payment.
Consent
  • User Data
  • Payment and Purchase Data
To detect fraud, including fraudulent payments and fraudulent use of the Spotify Service.
Consent or compliance with legal obligations
  • User Data
  • Usage Data
  • Payment and Purchase Data
To conduct research, contests, surveys, and sweepstakes.
Consent
  • Contests, Surveys and Sweepstakes Data
  • User Data
  • Usage Data

6. Sharing your personal data

We have set out the categories of recipients of the personal data collected or generated through your use of the Spotify Service.

Publicly available information

The following personal data will always be publicly available on the Spotify Service: your name and/or username, profile picture, who you follow and who follows you on the Spotify Service, your recently played artists, and your public playlists. We provide systems (such as "Support Community", etc.) to allow users to communicate with each other by sharing personal data in the above according to the user's choice.

Spotify Connect

After you have created a Spotify account you may choose to connect it to a compatible device over wi-fi. You may choose to connect Spotify via wi-fi to an integrated device such as a speaker, tv, a car, or even a fridge. This is called Spotify "Connect". You may choose to "Connect" to other devices, and may share your data by doing so.

Personal data you may choose to share

The following personal data will only be shared with the recipients outlined if:

  • you choose to make use of a specific Spotify Service feature where sharing of particular personal data identified in section 4) is required for the proper use of the Spotify Service feature; or
  • you grant us your permission to share the personal data, e.g. by selecting the appropriate setting in the Spotify Service or authorizing Spotify through a presented consent mechanism.
The name of the third party


The purposes of use of the data by the third party

The period of use and retention of the data by the third party
The items of personal data to be provided to the third party

Third Party applications and devices you choose to connect to your Spotify Account

You can review a list of the Third Party apps you have granted access to your Spotify account (if any) here.
To connect your account to third parties services which may request or require that we share information about you with them, pursuant to your choice


We will only share your data where you choose to connect your Spotify account to a third party application or device.
Your consent will always be requested before we provide your information to such third parties.
Third Parties use and retain the data until the purposes of the use have been achieved (or until cancellation/termination of subscription by the user).
You will be informed about which data the third party will receive at the point where you choose to connect your account. It may differ slightly depending on the third party application, but may include: information about what you are currently playing and your connected devices, email address, username, information about your playlists or library, information about your subscription details, artists you follow, your followers, recently played and top tracks.
For more information about how these third party applications and devices will handle your data, such as whether they will transfer it overseas or for how long they will retain it, please see the privacy policy of the application or device you are choosing to connect with.
The following record label partners:

Warner Music Inc.

Warner Music Inc. and WEA International Inc. 1633 Broadway, New York, New York 10019

Warner Music International Services Ltd.

27 Wrights Lane
London, England W8 5SW
UMG Recordings Services Inc.
2220 Colorado Avenue, Santa Monica, California, 90404-4506, USA

Universal International Music, B.V.

Gravelandseweg 80 NL – 1217 EW Hilversum, The Netherlands

Sony Music Entertainment

25 Madison Avenue
New York, NY 10010
To directly send you news or promotional offers by email.
Only if you choose to share your account registration data with the record labels, we will share your data when you sign up for Spotify via transmission over the network at the time of service.

You will always have the option to change your mind and withdraw your consent at any time in your account settings.
Third Parties use and retain the data until the purposes of the use have been achieved (or until cancellation/termination of subscription by the user).
Account registration data

Learn more about how to manage notifications, your publicly available information, and what you share with others in the Section 3 'Your rights and your preferences: Giving you choice and control' of this Policy and on the Privacy Center.

Information we may share

The name of the third party


The work to be processed by third parties
Spotify service providers listed at this link
We work with service providers that work on our behalf which may need access to certain personal data in order to provide their services to us. We have listed the work performed by each service provider at this link.
Please see section 8 “Transfer to other countries & entrustment” of this policy for more information about these service providers.
Spotify group companies
Our group companies may process your data on our behalf. We have listed the work performed by the Spotify group companies at this link.
Please see section 8 “Transfer to other countries & entrustment” of this policy for more information about these service providers.
Spotify partners
Depending on how you sign up for the Spotify Service (e.g. through a bundle deal with a mobile telecoms provider), we share your Spotify username or other User Data as necessary to enable your account. We may also share personal data with that third party about your use of the Spotify Service, such as whether and to what extent you have used the offer, activated a Spotify account, or actively used the Spotify Service.

7. Data retention and deletion

We keep your personal data only as long as necessary to provide you with the Spotify Service and for legitimate and essential business purposes, such as maintaining the performance of the Spotify Service, making data-driven business decisions about new features and offerings, complying with our legal obligations, and resolving disputes. We keep some of your personal data for as long as you are a user of the Spotify Service. For example, we keep your playlists, song library, and account information.

If you request, we will delete or anonymise your personal data so that it no longer identifies you, unless, we are legally allowed or required to maintain certain personal data, including situations such as the following (In such cases, we will transfer the relevant data to a separate database or storage place) :

  • If there is an unresolved issue relating to your account, such as an outstanding credit on your account or an unresolved claim or dispute we will retain the necessary personal data until the issue is resolved; and/or
  • Where necessary for our legitimate business interests such as fraud prevention or to maintain the security of our users.

The process and method of destruction are as follows

(1) Destruction process

Once the purpose is achieved, user's personal data is moved to a separate database and is destroyed after storage for a certain period depending on data protection reasons under our internal policy and other applicable laws and regulations

(2) Destruction method

We delete personal data stored in the form of electronic files by using technical means which makes it impossible to restore the data. We destroy your personal data through de-identification so that the individuals cannot be identified.

8. Transfer to other countries & entrustment

Spotify shares your personal data globally with Spotify group companies in order to carry out the activities specified in this Policy. Spotify may also subcontract processing to, or share your personal data with, third parties located in South Korea and outside of it. Your personal data, therefore, may be subject to privacy laws that are different from those in your country. In such instances Spotify shall ensure that the transfer of your personal data is carried out in accordance with applicable privacy laws and, in particular, that appropriate contractual, technical, and organizational measures are in place in order to protect your data. You can find out more about where your data is processed at this link.

For further details of the security measures we use to protect your personal data, please see Section 10 'Keeping your personal data safe' of this Policy.

9. Links

We may display advertisements from third parties and other content that links to third-party websites. We cannot control or be held responsible for third parties' privacy practices and content. If you click on a third-party advertisement or link, please understand that you are leaving the Spotify Service and any personal data you provide will not be covered by this Policy. Please read their privacy policies to find out how they collect and process your personal data.

10. Keeping your personal data safe

We are committed to protecting our users' personal data. We implement appropriate technical and organizational measures to help protect the security of your personal data; however, please note that no system is ever completely secure. We have implemented various policies including pseudonymization, encryption, access, and retention policies to guard against unauthorized access and unnecessary retention of personal data in our systems.

Your password protects your user account, so we encourage you to use a strong password that is unique to your Spotify account, never share your password with anyone, limit access to your computer and browser, and log out after having used the Spotify Service.

11. Children

With the exception of Spotify Kids, a separate Spotify application available in certain markets, the Spotify Service is not directed to children under the age of 14 years. The Spotify Service is also not offered to children whose age makes it illegal to process their personal data or requires parental consent for the processing of their personal data under the GDPR or other local law.

We do not knowingly collect personal data from children under 14 years or under the applicable age limit (the "Age Limit"). If you are under the Age Limit, please do not use the Spotify Service, and do not provide any personal data to us.

If you are a parent of a child under the Age Limit and become aware that your child has provided personal data to Spotify, please contact us using the 'Contact Us' form on the Privacy Center, and you may request exercise of your applicable rights detailed in Section 3 'Your rights and your preferences: Giving you choice and control' of this Policy.

If we learn that we have collected the personal data of a child under the age of 14 years, we will take reasonable steps to delete the personal data. This may require us to delete the Spotify account for that child.

12. Changes to this Privacy Policy

We may occasionally make changes to this Policy.

When we make material changes to this Policy, we'll provide you with prominent notice as appropriate under the circumstances, e.g., by displaying a prominent notice within the Spotify Service or by sending you an email and/or a device notification. We may notify you in advance.

Please, therefore, make sure you read any such notice carefully.

If you want to find out more about this Policy and how Spotify uses your personal data, please visit the Privacy Center on spotify.com to find out more.

13. How to contact us

Thank you for reading our Policy. If you have any questions about this Policy, please contact our Data Protection Officer by using the 'Contact Us' form on the Privacy Center, emailing privacy@spotify.com, or by writing to us at the following address:

Spotify AB

Regeringsgatan 19

Stockholm

111 53

Sweden

Spotify AB is the data controller for the purposes of the personal data processed under this Policy.

For users in South Korea, Spotify's Korean Domestic Representative is as follows:

Name and Representative: Bae, Kim & Lee LLC, Yangho Oh

Telephone: 02-3404-0105

Email: privacyrep.spotify@bkl.co.kr.

Address: Centropolis B, 26 Ujeongguk-ro, Jongno-gu, Seoul, Korea 03161

For general customer service queries not related to personal data processing, please contact our Customer Service .

We hope you enjoy Spotify!

© Spotify AB.