Privacy

Privacy policy

What we collect, what we do not, and who else touches it. Written to be read by a board rather than by a lawyer, and short enough that reading it is realistic.

There are two different things going on here, and almost every confusing privacy policy is confusing because it refuses to separate them. The first is this website, where we hold a handful of details about people who ask us questions. The second is your ensemble's portal, where your board holds records about its own members and we are only the people who keep the lights on. The rules are different in each, so they are set out separately.

Part one — this website

What we collect

Only what you type into a form. There are three of them and that is the whole list.

Two technical items are stored alongside those records. When a form is submitted we take your IP address, combine it with a secret value, hash it one way, keep the hash and throw the address away. The hash lets us notice the same person submitting five times in an hour. It cannot be turned back into an address. Bookings also keep your browser's user-agent string, which is the line every browser sends describing itself, so that a booking failure can be diagnosed.

What we do not collect

This site sets no cookies. Not one — not for analytics, not for preferences, not for a consent banner about the cookies we are not setting. There is no analytics product installed, no advertising pixel, no session recording, no heatmap, no cross-site tracking, and no profile built about you. We do not buy lists, and we do not collect addresses from directories and add them to anything.

One honest exception. The site loads its two typefaces from Fontshare and Google Fonts, which means your browser makes a request to those services and they can see your IP address, as they can for any site using them. They receive nothing else from us, and no information you have typed.

Part two — your ensemble's portal

In your portal, your ensemble decides what goes in and why. In the language the privacy laws use, your ensemble is the controller and we are the processor. Practically, that means the records belong to your board, and we handle them on your instructions rather than for our own purposes.

What is in there is whatever your board puts in there: member names and contact details, sections and instruments, attendance, the dues ledger, the music library, concert programs, and whatever documents the board uploads.

What we will not do with it

  • We will not sell it, rent it, or share it with anyone for their own purposes.
  • We will not use it to train a model, ours or anybody else's, and there is no AI feature in the product that reads it.
  • We will not mine it for aggregate statistics, benchmarks, or marketing claims about our own customers.
  • We will not email your members about Rehearsal Letter. Mail from the portal is mail your board sends.

We look at your data only when we need to: to keep the deployment running, to fix something, or because you asked us to help with a specific problem. One deployment is one ensemble, in its own database, so there is no shared pool to accidentally look across.

The full arrangement, including our obligations when we use a subprocessor and what happens on termination, is set out in the data processing terms that form part of your service agreement.

Who else handles it

We run a small operation on other people's infrastructure, which is the honest and usual answer. These are the companies involved, all of them in the United States.

If we add or change one of these in a way that affects your portal, you will be told in advance under the data processing terms.

How long we keep things

  • Enquiries, bookings and demo sign-ups. While the conversation is live, and for up to twenty-four months after we last hear from you. Then deleted. Ask sooner and it goes sooner.
  • Cancelled bookings. Removed once the slot has passed.
  • Portal records. For as long as your agreement runs. When it ends you get a full export in open formats, and the deployment and its database are deleted within thirty days of that export.
  • Backups. Deleted records persist in database backups for up to thirty days before those roll off.

Your rights

Twenty states now have comprehensive privacy laws and Michigan, where we are, is not yet one of them. Sorting people by postcode to decide who deserves which rights is a tedious way to run a small company, so we do not. Whoever you are and wherever you are, you can ask us to:

  • tell you what we hold about you;
  • send you a copy of it;
  • correct anything wrong;
  • delete it; or
  • stop contacting you.

Email letterc@rehearsalletter.com and say which. We will confirm within a few days and finish within thirty. There is no charge and nothing about your service changes because you asked.

If your request concerns records inside an ensemble's portal, we will pass it to that ensemble's board rather than act on it ourselves — those are their records, and acting on them without instruction is precisely what a processor must not do.

Children

This website is meant for the adults who run ensembles, and we do not knowingly collect anything from a child through it. Some ensembles do have members under eighteen. Where that is so, the ensemble decides what to record about them and is responsible for whatever consent its own rules and local law require. We hold those records on the board's instruction and for no other purpose.

Security

Everything travels over TLS and is encrypted where it is stored. The database uses row-level security so that a signed-in member can reach their own ensemble's records and nothing else. Access on our side is limited to the one person who runs the company, with no shared logins. The public demo runs on a separate, read-only connection to invented data.

None of that is a guarantee, and anyone who offers you one is selling something. It is a description of what is actually in place.

If something goes wrong

Michigan's Identity Theft Protection Act requires notice without unreasonable delay when a breach puts personal information at risk, and we will give it. If the breach touches an ensemble's portal we will notify that board directly, in writing, with what we know and what we are doing — not a status page you have to think to check.

Changes

The date at the top is the date this version took effect. If we change something that matters — a new subprocessor, a new category of data, a shorter or longer retention period — current customers get an email about it rather than a quietly edited page.

Who we are

Rehearsal Letter is a product of The Aisle Collection LLC, Ann Arbor, Michigan. Privacy questions, requests, and complaints all go to the same place: letterc@rehearsalletter.com. A person reads it.

This page describes our practices. It is not legal advice, and it is not a substitute for your own board taking a view on what your ensemble records about its members.