Nightflat is built as a calm listening flat. We use the data and storage needed to keep accounts, playback, rooms, fair use, payments, and support working. Google Analytics is optional and only uses analytics storage when you allow it.
Operator
Who looks after the flat.
Nightflat.com is operated by Madeliz, registered with the Dutch Chamber of Commerce under KvK number 77510194, The Netherlands.
When this notice says "Nightflat", "we", "us", or "our", it means the Nightflat.com service operated by Madeliz.
Tracking
No marketing or advertising tracking.
Nightflat does not use marketing cookies, advertising identifiers, personalized ad tracking, or cross-site profile tools.
We may use Google Analytics to understand broad site usage, such as which pages and features are visited. Analytics storage is denied by default and is only enabled on this browser after you choose "Allow".
Analytics consent
Your analytics choice.
Nightflat saves your analytics choice in this browser's localStorage as nightflatAnalyticsConsent. Choosing "No thanks" keeps Google Analytics storage denied. Choosing "Allow" lets Google Analytics use analytics storage for this browser.
No analytics choice has been saved yet.
Account data
What we process when you join.
If you create an account, we process account details such as your email address, display name, password hash, profile settings, avatar, public profile choices, saved playlists, favorites, rooms, My Space data, achievements, Flat Coins, and premium status.
We use this data to provide the account features you choose, protect login security, show public profile details only when you allow them, and keep your listening space available across visits.
Listening and fair use
Playback needs a little operational memory.
Nightflat processes listening activity, room presence, player requests, signed audio-token checks, track IDs, estimated audio bandwidth, and fair-use counters so music can play reliably and the service can stay fair for Visitors, Residents, Night Owls, and Rooftop members.
Fair-use actor keys and IP-based abuse controls are stored as hashed technical identifiers where the app uses them. They are used for quota, security, and abuse prevention, not for advertising or profiling.
Essential cookies
The cookies Nightflat may set.
PHPSESSID keeps your session alive while you move through the site, including access checks, login state, CSRF protection, flashes, checkout state, and other essential session features. It is a first-party session cookie.
nightflat_remember is used only when a logged-in user chooses remember-me style login. It stores a selector and token value, with the real token checked against a hashed database value. It lasts up to 30 days and is cleared when you log out.
nightflat_fair_use gives guest listeners a stable first-party visitor key for audio fair-use limits. It lasts up to 180 days and helps avoid relying only on IP addresses for bandwidth protection.
Google Analytics cookies may be set by Google only after you allow analytics on this browser. If analytics is off, Nightflat keeps analytics storage denied through Google's consent mode.
Browser storage
Storage on your own device.
localStorage may store comfort settings such as your selected neon theme, whether the sidebar is collapsed, and My Space panel positions for your own browser. These values stay on your device until you clear them or change browser storage.
sessionStorage may store short-lived interface state such as the player, focus timer, and current interface tab during the current browser session. This helps the room feel continuous while you browse.
Service-worker asset cache may be used by the browser to keep Nightflat interface files available and refreshed efficiently. Protected audio is deliberately not cached by the service worker, and old Nightflat audio caches are removed when the worker activates.
Payments
Mollie may handle payment details.
If you buy a paid Nightflat pass, payment handling may be processed by Mollie and the payment method you choose. Nightflat stores payment status, order references, plan details, and activation information needed to provide the paid feature.
Nightflat does not need to store full card numbers or banking credentials. Mollie's own privacy and legal information is available at mollie.com/legal.
Support
Messages sent to the flat.
If you contact Nightflat, we process the details you provide so we can read, route, and answer your request. Please avoid sending sensitive personal information unless it is truly needed for the question.
Legal basis
Why this processing is allowed.
Under GDPR, Nightflat may process data to perform the service you request, protect the service and its users, comply with legal obligations, handle payment records, answer support messages, and maintain legitimate operational interests such as security, abuse prevention, and fair-use controls.
Essential service storage is used to provide and protect Nightflat. Optional analytics is based on your consent and can be turned off from this page.
Retention
We keep data only as long as needed.
Session data, remember tokens, password reset tokens, fair-use counters, payment records, account records, support messages, logs, and security data are kept only for as long as needed for their purpose, legal requirements, dispute handling, accounting, security, or abuse prevention.
You can clear localStorage, sessionStorage, service-worker storage, and cookies from your browser settings. Clearing essential cookies may log you out or reset local Nightflat preferences.
Your rights
You can ask about your data.
Depending on your situation and applicable law, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data. You may also have the right to complain to the Dutch data protection authority or another relevant supervisory authority.
Logged-in users can start a JSON data export or account anonymization from the profile privacy controls. For manual privacy requests, use the official contact page and include enough detail for us to understand the account or message involved.
Updates
This notice can change with the building.
Nightflat may update this privacy notice when the service, storage, payment setup, legal requirements, or safety needs change. The latest version lives on this page.