Saints U Radio
Privacy Policy
What we collect, why we collect it, how long we keep it, and how to have it removed. Written to be read, not to be survived.
Last updated 6 September 2026
The short version
We do not track you across the internet.
We do not sell, rent or share your information with advertisers.
There are no advertising cookies, no analytics scripts and no tracking pixels on this site.
We collect what is needed to run a radio station people pay for: an email address so you can sign in, a record from our payment processor so we know your membership is live, and a log of what was streamed so we can keep the station working and pay attention to what people actually listen to.
Everything below is the detail. If something here is unclear, or you want a copy of what we hold on you, write to hello@saintsuradio.com and a person will answer.
Who we are
Saints U Radio is operated by Saints University, a Rockit Light Industries project. We are the data controller for the information described on this page — which means we decide what is collected and we are the ones answerable for it.
Write to us at hello@saintsuradio.com about anything on this page, including a request to see or delete what we hold.
United States
Most of our listeners are in the United States, where there is no single federal privacy law covering everything on this page. California's Consumer Privacy Act binds only businesses above thresholds we are nowhere near, and the state laws that followed it work the same way.
So rather than give you rights that depend on which state you happen to live in, we extend everything in the rights section below to every listener, everywhere. Ask us for a copy of what we hold, or to correct it, or to delete it, and we will do it — we are not going to check your postcode first.
The federal Children's Online Privacy Protection Act does apply to us regardless of our size, because we make something aimed at students. How we handle that is in Young people and group passes.
Elsewhere
We handle personal information in line with Jamaica's Data Protection Act, and with the UK and EU General Data Protection Regulation where it applies to a listener in those places.
What we collect, and why
Your account
When you enrol we store your email address, your name if you give one, and a hashed password once you set one. Hashed means the password itself is never stored and cannot be read back by us or by anyone who obtained a copy of the database.
Alongside that we keep your plan, whether your membership is live, the date access runs to, and the dates the account was created, last changed and last signed in to. This is what the site checks every time you press play.
Payment
Card details never reach this site. Payment is handled entirely by Stripe on Stripe's own pages. We never see, receive or store a card number.
What we do store is what Stripe hands back: a customer reference, a subscription reference, which plan was bought, whether it is active, and the date it renews or ends. If you buy a group pass we also store the number of seats and the join code issued for it.
Gifts and donations
If you give through one of our Stripe pages rather than buying a membership, that transaction happens entirely on Stripe. We receive a record of the gift and the email address you gave them, so we can thank you and answer questions about it. We do not create an account for you, we do not add you to the listening records described below, and a gift on its own does not give access to the music.
Giving does not put you on a mailing list. If we ever want to write to givers as a group we will ask first.
Listening
Every time a track is streamed the server writes one line to a log. That line records the time, which track, how many bytes were sent, roughly how long was listened to, where the request came from on the site, and the request's IP address.
It also records who was listening — but not by name. A signed-in member is recorded as their account number. Everyone else is recorded as a scrambled, one-way code derived from their browser session, so repeat visits in the same session count as one listener without us ever knowing who they are.
We keep these logs for three reasons. The first is practical: to know whether the station is coping with demand.
The second is the one that shapes what you hear. Knowing which songs get finished, which get played again, and which get skipped is how we learn what this audience actually loves — so we can make more of it, programme more of it, and put the right things in front of you rather than guessing. Nobody tells us their taste in a form. They tell us by what they play.
The third is to spot a single paid account being streamed from many places at once, which usually means a password has been passed around.
An IP address counts as personal information, which is why it is named here and why it expires on a schedule rather than sitting around indefinitely. See how long we keep it below.
Group passes
When a church, school or ministry buys a pass we record the group, its seat count, its join code, and which member accounts are sitting in its seats. Administrators at Saints U can see the email addresses of people in a group in order to manage the roster. Members of a group cannot see each other's details, and the join code is shown only to the person who bought the pass.
When a seat is released the record of it is kept rather than erased, so we can answer a question like "why did this group run out of seats in March".
Printed magazine orders
If you order a physical copy we store your name, delivery address, phone number, email, what you ordered and what it cost, so it can be printed, packed and posted. Phone numbers are collected because couriers ask for one.
Messages you send us
The enquiry form asks for your name, email, organisation, roughly how many students you have, and your message. That is emailed to us and not stored in the site's database. It stays in our mailbox like any other email.
Beta feedback
If you fill in a feedback survey we store your answers and ratings against your account, so we can tell a considered response from a stray click and come back to you if you asked us to.
Cookies and what your browser stores
This site sets one cookie. It is the sign-in cookie. It holds nothing but a session reference, it cannot be read by JavaScript, it is not sent to other sites, and it disappears when you close your browser. It is only created once you sign in.
We also store a few small settings in your browser itself, which never leave your device and are never sent to us:
- Which colour theme you picked, so the site looks the same next time.
- Whether you are signed in, so the header shows the right button immediately instead of flickering.
- Whether the comics and magazine readers should open in dark mode.
That is the complete list. There are no advertising cookies, no analytics cookies, and no third-party trackers — no Google Analytics, no advertising pixels, no session recording, nothing that follows you to another website.
This is why you will not see a cookie consent banner here. Under the rules that put those banners on other sites, a cookie needed to keep you signed in and a setting that remembers your colour theme are exempt from consent — consent is required for tracking and advertising, and we do neither. If that ever changes, this page changes first and you will be asked properly.
Who else sees your information
We do not sell your information. We do not share it for advertising. It is passed on only where a service is needed to run the station:
Stripe
Takes every payment and holds the card details we never see. Stripe receives your email address and payment information directly from you at checkout, and handles it under its own privacy policy at stripe.com/privacy.
Hostinger
Hosts the site and the database, and delivers email sent from it. Servers are in Europe, and a content delivery network serves images and page files from locations closer to you for speed. Audio and anything requiring a sign-in is never cached by that network.
The printer
If you order a printed magazine, your name and delivery address are given to the printing and shipping company for that order. Nothing else is shared, and nothing is shared if you never order a print copy.
Google Fonts
The typefaces on this site are currently loaded from Google's font service, which means your IP address reaches Google when a page loads. No cookie is set by it. We are moving these files onto our own server so that this stops happening; this paragraph will be removed when that is done.
We may also disclose information if the law requires it — a court order or a lawful request from an authority. If that ever happens we will tell you unless we are legally forbidden from doing so.
How long we keep it
Things that identify a person expire on a timer, so nothing depends on somebody remembering to clear them out.
| What | Kept for |
|---|---|
| Raw listening logs, including IP addresses | 7 days, then deleted |
| Daily figures broken down by address | 30 days, then deleted |
| Failed sign-in attempts, used to slow down guessing | 24 hours |
| The address a member first streamed from | While the account exists |
| Your account, membership and group records | While the account exists |
| Print orders and payment records | 7 years, as tax law requires |
| Anonymous listening totals — plays per song, listeners per hour | Kept indefinitely |
The last row is worth explaining. Once the raw logs are folded into totals, what remains is counts — how many people listened in a given hour, how many finished a given song. There is no name, no email and no address in any of it, and it cannot be turned back into a person. That is what lets us delete the detailed records so quickly.
Young people and group passes
Saints U Radio is made for students, and group passes are bought by churches, schools and youth ministries who then hand a join code to the young people in their care.
When somebody redeems a code we collect an email address and a password, and from then on their listening is logged like anyone else's. We collect no more than that, and we never build an advertising profile from it.
If you are a leader distributing a join code: please get a parent's or guardian's permission before giving one to a child under 13, and follow your own country's rules where the age is higher. We do not knowingly collect information from a child under 13 without it.
A parent or guardian can write to hello@saintsuradio.com at any time to see what we hold about their child, or to have the account and everything attached to it deleted. We will not ask why.
Your rights
Whatever country you are in, you can ask us to:
- Show you what we hold. We will send a copy of your account record and anything attached to it.
- Correct it. A wrong name or email can be changed straight away.
- Delete it. We will remove your account and its records. Payment records we are legally required to keep are the exception, and we will tell you exactly what those are.
- Export it. We will send your information in a format you can take elsewhere.
- Object to how we use it, including asking us to stop logging your listening against your account.
Email hello@saintsuradio.com and we will answer within 30 days. There is no charge, and asking will never affect your membership.
If you are in the UK or EU and you think we have handled something badly, you also have the right to complain to your national data protection authority. We would rather you told us first so we can put it right.
How your information is protected
- The whole site runs over an encrypted connection.
- Passwords are stored as one-way hashes and cannot be read back, by us or by anyone else.
- Password reset links are stored hashed too, expire, and stop working once used.
- Music files sit outside the public web folder. Every play is checked against a live membership before a single byte is sent, so there is no address that reaches the audio directly.
- Sign-in and join-code attempts are rate limited, so a code or a password cannot be found by guessing repeatedly.
- Administrator access is limited to a small fixed list of addresses. Nothing stored in the database can grant it, which means nothing that gets into the database can take it.
No system is perfect. If we ever discover a breach affecting your information, we will tell you and the relevant authority promptly, and we will tell you what was involved rather than issuing a vague notice.
Changes to this policy
When this policy changes, the date at the top changes with it. If a change materially affects what we collect or who sees it, we will email members rather than relying on you to notice.
Contact
Questions about this policy, requests to see or delete your information, or anything else on this page:
A person reads that mailbox and will reply.