The Music CRM Guide: from scattered followers to an audience you own
What a music CRM really is: contact records, per-channel consent in plain English, segments that get used, and the hygiene ritual that keeps lists earning.
TL;DR
- A music CRM is a fan relationship record, not sales-team software. One record per fan: identity, per-channel consent, engagement history, purchases, tags and a lifecycle stage.
- You do not own your followers. You own the contacts in your database with consent attached, and UK email marketing returns around £41 for every £1 spent, up from £38 (DMA Marketer Email Tracker, 2026). It all starts with capture.
- Consent is per channel, and it has to be provable. The ICO expects you to be able to show who consented, when, how, what they were told, and whether they have since withdrawn. A spreadsheet with "consent provided" against a name is its own example of a record that fails.
- Consent does not last forever. UK law sets no expiry date, but the ICO suggests refreshing consent every two years if you are in doubt, and not relying on consent a third party collected, such as a ticketing marketplace's opt-in, more than six months after it was given.
- Bought lists are poison twice over: they fail the law, because those people never agreed to hear from you, and they fail the filters, because cold recipients complain.
- Segment-first sending separates lists that earn from lists that decay: past buyers against never-bought, recent clickers against the cold, by city, by genre.
- Hygiene is a feature, not admin. Suppression, a preference centre and a quarterly clean keep spam complaints under the 0.3% line Gmail and Yahoo have enforced since 2024.
Why does a fan database matter more than followers?
Because reach on rented channels is an algorithm's decision, and reach into your own database is yours. The median Instagram post draws likes and comments from 0.30% of followers, down from 0.36% the year before (Rival IQ, 2026), and the platform decides who even sees it. Streaming rarely pays the bills either: 88% of tracks got 1,000 streams or fewer in 2025 (Luminate), and Spotify pays no recording royalty on a track under 1,000 streams a year.
What pays is the fan who buys directly: the ticket, the record, the shirt. Luminate counts 20% of US music listeners as superfans in its 2026 midyear report, and finding and keeping those people is the whole job of a database. Kevin Kelly's "1,000 True Fans" essay (2008) made the underlying maths famous: a modest number of people who genuinely care, reachable directly, can sustain a career. A fan database is the practical machinery behind that idea.
This guide is the reference manual: what a music CRM is, what lives inside a contact record, how consent really works, and the habits that keep a database earning instead of rotting. For the full story of why building on rented platforms goes wrong for promoters, read the promoter playbook. Here, we build the system.
What most people get wrong about fan data
Most fan databases fail in the same handful of ways, and none of them are about list size.
- Scattered records. Ticket buyers in a ticketing platform, newsletter signups in Mailchimp, a contest spreadsheet on a laptop. Nobody can answer "has this person ever bought from us?" because the answer is split across five tools.
- One consent stretched across every channel. Someone joins your email list, so you text them. A phone number collected for order updates is not permission to market by SMS.
- No record of where anyone came from. If you cannot say how and when a contact opted in, you cannot prove consent or segment by source. Provenance is the difference between a database and a pile of addresses.
- The one-giant-blast habit. Every send goes to everyone: the superfan gets bored, the two-years-cold contact hits "report spam", and your deliverability pays for both.
- Hoarding dead weight. Mailbox providers judge you on how recipients behave, so 15,000 silent contacts drag down delivery to the 5,000 still listening.
- Treating a marketplace's buyers as your own customers. A ticket sold through a ticketing marketplace is the marketplace's sale. What reaches you is the opt-in it collected on your behalf, and that has a shorter shelf life than your own customers' (see below).
- No welcome. A fan signs up in a moment of enthusiasm and hears nothing for six weeks. The first 48 hours after capture is the warmest attention you will ever get.
- Making leaving hard. Hiding the unsubscribe link feels protective and is the opposite. The alternative to an easy unsubscribe is not a retained fan, it is a spam complaint.
How a music CRM actually works
What is a CRM in music?
A music CRM is a single database of your fans and contacts where each person has one record combining who they are, what they have agreed to receive, and everything they have done with you. The term comes from sales software, and that heritage misleads people: tools like HubSpot were built around pipelines of deals moving toward a close. Music does not have deals, it has relationships that deepen over years, so a music CRM is better understood as a fan relationship record. The same structure holds industry contacts too, but the fan side is where the money and the longevity live.
The anatomy of a contact
Every useful contact record has six parts. If your setup cannot show all six on one screen for one person, that gap is the first thing to fix.
- Identity. Name, email, phone, social handles, city and country. Rarely complete on day one; records fill in as a fan interacts on more surfaces.
- Per-channel consent. A separate status for email, SMS and WhatsApp (and messaging channels like Instagram DMs), each with provenance: what was agreed, on which surface, when. The legally load-bearing part of the record.
- Engagement history. Clicks, replies, link visits, opens. Treat opens as directional, because Apple Mail Privacy Protection (2021) counts an email as opened whether or not anyone read it; clicks are the honest signal.
- Purchases. Tickets, vinyl, merch, downloads, with dates and values. The strongest predictor of a future buyer is a past buyer.
- Tags. Freeform labels for anything else: the campaign that brought them in, a genre affinity, "met at merch stand".
- Lifecycle stage. One field summarising where the relationship stands. Covered below, because it does more work than any other field.
Consent in plain English
This is a working summary, not legal advice, but the rules are less scary than the folklore. In the UK, two laws matter for fan marketing: UK GDPR, which governs personal data generally, and PECR, which governs electronic marketing like email and SMS. The EU has close equivalents. The Data (Use and Access) Act 2025 changed parts of both between 2025 and 2026, but not the core rule for emailing and texting fans. These ideas cover almost everything:
Affirmative opt-in is the default. Someone takes a clear action to join: ticks an unticked box, submits a form, sends your join keyword. You record what they agreed to and when.
The soft opt-in covers your own customers. The soft opt-in is a recognised exception in UK and EU electronic-marketing rules that lets you market to people who bought from you, about your own similar products, provided you offered a way to opt out at collection and in every message since. In plain terms: someone who bought a ticket to your night on your own checkout can lawfully be emailed about your next night, as long as leaving is easy at every step. It covers your own paying customers only: never free signups, other people's customers, or channels the buyer never used with you. Since 5 February 2026 registered charities have a version of their own for supporters, which matters for community venues and festivals run as charities.
A marketplace's buyers are not your customers. If your tickets sell through a ticketing marketplace, the sale is the marketplace's, so the soft opt-in is not yours to use. What you may get instead is the opt-in the marketplace offered its buyers on your behalf: Ticketmaster UK's privacy policy, for example, tells buyers they "will be given the option to subscribe to receiving marketing" from the artist, promoter, label or venue. That is consent collected by a third party, and the ICO generally recommends not relying on it more than six months after it was given, unless people would expect to hear from you later, as with an annual festival's next on-sale. Its email guidance puts the wider point bluntly: "There is no such thing as a third-party marketing list that is compliant with the soft opt-in."
Consent is per channel. Email consent is consent to email. Texting fans needs its own yes; WhatsApp needs its own yes too, and Meta's business policies require it. This is not bureaucratic overkill: a text interrupts in a way an email does not, and channel-by-channel consent is exactly why those two channels keep working. Everyone receiving them chose to.
Work out the basis once per capture surface, not per fan. The lawful basis is a property of where the contact came from, so the surface decides it and the fan inherits it. A ticket, a vinyl order or a paid download on your own shop can rely on the soft opt-in, because the relationship started with a purchase from you. A contest entry, a merch-table QR scan, a download gate on a link, an inbound DM and a signup form cannot: nobody bought anything, so each needs its own affirmative opt-in taken at the point of capture. Same person, same inbox, two different answers to "may I send this?".
Which is why provenance is a field and not a footnote. The ICO spells out what a consent record must show: who consented, when, how, what they were told at the time, and whether they have withdrawn, and if so when. Record those at the moment you take the detail. A year on, a list is just addresses: the capture record is the only thing that tells you which of them you may still mail, which the sunset policy should retire, and what you say to the fan who asks how you got their email. A consent record you cannot evidence is a claim, not a record. What getting this wrong now costs in the UK, and how the United States handles email and texts, is in the Music Email Marketing Guide.
How long does consent last? UK GDPR sets no time limit. The ICO's view is that consent degrades over time and that how long it lasts depends on what people expect: its working rule is to refresh consent every two years if you are in any doubt, and sooner for consent a third party collected. For a music list, a release cycle or two of silence is the natural moment to ask again, which is exactly what a sunset policy does.
The United States version. There is no federal equivalent of UK GDPR: privacy is state by state. Nineteen states had comprehensive privacy laws in force in September 2026, with four more signed (IAPP), and most apply only above thresholds an independent label or promoter will not reach. California's, for example, starts at $26,625,000 in annual revenue, the data of 100,000 consumers or households, or half your revenue from selling or sharing personal data. Two exceptions are worth knowing: Texas has no volume threshold at all and covers any business serving Texans that the US Small Business Administration would not class as small, and since 1 July 2026 Connecticut's law reaches anyone who sells personal data or processes sensitive data, whatever their size. Day to day, the rules that bite a US list are the channel rules, CAN-SPAM for email and the TCPA for texts, covered in the Music Email Marketing Guide.
Why bought lists are poison. A bought list fails every test at once. Those people never gave consent to you, so you have no lawful basis and no provenance. They also do not know you, so they mark you as spam at rates mailbox providers will not tolerate: Gmail and Yahoo have enforced bulk-sender rules since 2024, including spam-complaint rates under 0.3%, and bought lists blow through that in one send. The damage lands on your sending reputation, so the fans who genuinely opted in stop seeing you too.
Lifecycle stages: what are lead, subscriber, customer and VIP for?
A lifecycle stage is a single field answering "where does this relationship stand?" so you can treat different fans differently without thinking about it per send. Four stages do most of the work:
- Lead. A way to reach them exists but no marketing opt-in yet: someone who messaged you, or entered a contest without ticking the box. Leads are not sendable. The job is to earn the opt-in, never to assume it.
- Subscriber. Opted in, not yet bought. The bulk of most lists. Keep them warm and watch for buying signals.
- Customer. Has spent money with you at least once. The most valuable cohort per head, and the one most lists treat identically to everyone else. Customers hear buyer news first: presales, new stock, early access.
- VIP. Repeat buyers, travel-to-the-show people, true fans. There will not be many, and that is the point. VIPs justify manual attention: first dibs, the personal note, the guest-list surprise. This is the 1,000 True Fans tier made operational.
The stages earn their keep two ways: an instant sanity check on every send ("should leads be getting this at all?"), and a growth diagnostic: if subscribers never become customers, your problem is conversion, not capture.
Which segments actually get used?
A segment is a saved filter over your contacts that updates itself as people match or stop matching. Four workhorses cover most real sending in music:
- Past buyers vs never-bought. The most valuable split in the database. Buyers get presales and new drops; never-boughts get the case for a first purchase.
- Clicked or bought in the last 90 days vs cold. Your engaged core gets everything. Cold contacts get less frequent, higher-stakes sends, not your weekly update. Judge it on clicks and purchases, since opens are inflated.
- By city or region. A London show announced to the whole country trains everyone outside London to ignore you. Geographic segments are the easiest deliverability win for anyone running events.
- By genre or artist affinity. For labels and agencies especially: the drum and bass fans hear about the drum and bass release. Affinity comes from tags, clicks, or which signup surface captured them.
The rule of thumb: build segments you will actually send to this month. A segment nobody sends to is decoration.
Suppression, hygiene and the preference centre
Suppression is a master off-switch on a contact that blocks all sending on every channel regardless of individual consents, used for complaints, hard bounces and anyone who asks to be left alone entirely. It is not an unsubscribe from one topic; it is the nuclear option. When someone opts out, the ICO expects you to keep them on a "do not contact" or suppression list rather than simply deleting them, because deletion is how an old spreadsheet quietly puts them back.
A preference centre is a page, linked from every email, where a fan manages what they receive: which topics, which channels, or nothing at all. It is trust infrastructure, not churn machinery. Given the choice between "fewer emails, just tours" and a spam report, most fans on the fence pick the former.
Hygiene is the ongoing discipline: suppress complainers immediately, remove hard bounces, and periodically confront the cold segment honestly. A list that only ever grows is quietly dying inside; pruning dead weight raises delivery for everyone still listening.
What the law asks of whoever holds the list
Three duties catch small music businesses out in the UK, and all three are cheap to get right. A summary, not legal advice:
- The ICO's data protection fee. Most organisations holding personal data pay it, sole traders included, but not all: processing only for your own marketing, your accounts and staff administration can be exempt, and the ICO's self-assessment decides. The smallest tier (turnover up to £632,000 or no more than ten staff) has cost £52 a year since 17 February 2025, £5 less by direct debit. Not paying when you should can mean a fine of up to £4,350.
- Data requests inside a month. A fan can ask for a copy of everything you hold on them. You have one month, extendable by two for complex requests; since 5 February 2026 the clock pauses while you wait for the fan to clarify what they are asking for, and the search you owe is a reasonable and proportionate one, not an impossible one.
- A way to complain. Since 19 June 2026 every organisation needs a process for data protection complaints: an easy way to make one (the law's example is an electronic form), an acknowledgement within 30 days, and a response without undue delay.
The playbook
Step 1: inventory your capture surfaces
List every place a fan could conceivably join your database, then rank by monthly traffic. Typical surfaces: ticket and merch checkout, the signup form on your site, smart link landing pages, link-in-bio, contest entries, event RSVPs, a join keyword on posters and screens, DM conversations, the merch stand. Mark which ones are yours and which belong to someone else, because a marketplace's checkout hands you third-party consent, not your own customers. Most operations find that their busiest surface, usually checkout, captures marketing consent badly or not at all, and that half their surfaces feed a different tool than the other half.
Fix the top three first. For each: is there a clear opt-in? Does the contact land in the same database as everyone else? Is consent recorded with the ICO's five facts? Three surfaces done properly will outperform ten neglected ones.
Shortcut: this consolidation step is the part a unified platform removes entirely. When your site, shop, ticketing, smart links and messaging run in one place, every surface already feeds one contact record, with consent recorded at capture.
Step 2: build the welcome journey
The hours after signup are the warmest attention you will ever get from that fan, so meet them there with an automated welcome. Keep it short: a first email that delivers what was promised and says plainly what you send and how often; a second a few days later with your best introduction, the release that defines you or the story of the night; a third that invites one small action. Set it up once and every future signup gets the same warm start, at 3pm or 3am.
Step 3: adopt segment-first sending
Make "who exactly is this for?" the first question of every send, before subject lines, before copy. The default audience is a segment; whole-list sends become a deliberate exception reserved for the two or three genuinely everyone-needs-to-know moments a year. Expect smaller send counts and better results per send: more clicks per email, fewer complaints, and a sender reputation that compounds instead of eroding.
Step 4: run the quarterly hygiene ritual
Put 90 minutes in the calendar every quarter:
- Re-engage the cold. One honest email to contacts with no click or purchase in six months or more: here is what you have missed, no click and we will take the hint.
- Let go of the silent. Contacts who ignore it get suppressed. It stings and it is correct: they were already gone, and keeping them cost you reach to the fans still listening.
- Refresh what is getting old. Consent from a marketplace or other third party that is past six months, and anything you are unsure of that is two years old, gets a "still want these?" email of its own.
- Audit the capture surfaces. Re-run the Step 1 inventory. Surfaces drift: a form breaks, a new page launches without an opt-in.
- Spot-check consent records. Pick ten random contacts and confirm you could show the ICO's five facts for each: who, when, how, what they were told, and any withdrawal. If not, fix the surface that produced them.
The PDF: the anatomy of a contact, consent in plain English and by channel and capture surface, lifecycle stages, the four workhorse segments, suppression and the preference centre, the welcome journey, the quarterly hygiene ritual, moving your lists in, and the condensed checklist. Free for an email address.
Doing it in SoundOps
Everything above can be run with spreadsheets, a form tool and discipline. SoundOps' CRM exists to remove the duct tape, and it is included on every plan. Capability by capability:
- One contact record, fed by every surface. Checkout, ticket purchases, RSVP forms, smart link capture gates, contest entries, list signup pages, the SMS signup page and WhatsApp and Instagram join keywords all write to the same database, and each capture records consent provenance automatically: which surface, on what basis, when. A fan known only by their Instagram account folds into their existing contact when the email they send in a DM already belongs to one. The Step 1 inventory becomes a checklist of switches instead of a consolidation project.
- Per-channel consent, built in. Every contact carries a separate status for email, SMS and WhatsApp, so the per-channel rule is enforced structurally. A fan who sends your join keyword to your WhatsApp number lands in the database with verified WhatsApp consent, because the message itself is the proof.
- Consent history on the contact. Opt-ins and opt-outs are logged on the contact's page: when, on which channel and how (the basis and the surface), double opt-in confirmations included, and for signups through a public list signup page or a smart link's capture form, the wording the fan was shown. A signup through your website's newsletter section without double opt-in records only its source, time and IP on the contact, so keep a dated copy of that form's wording yourself. The Step 4 spot-check becomes a lookup. The log is kept apart from the contact for seven years, with IP addresses stored only as a one-way hash.
- Dynamic segments. Saved filters over purchases, email clicks, location, tags, channel reachability and lifecycle stage, updating live. Where checkout records only a UK postcode, the buyer's town is filled from its postcode area, and a booking enquiry fills an unplaced promoter's city and country from the venue; both are marked approximate on the contact. The four workhorse segments take minutes to build, and every campaign shows a live count of who will actually receive it.
- Lifecycle stages. Lead, subscriber, customer and VIP are first-class fields, updated by real behaviour: buyers become customers automatically, because ticketing and the shop live in the same system as the database.
- Batch operations with previews. Tag, change stages, add to lists, suppress or export in bulk, with a preview of exactly what will change before anything does. The quarterly ritual runs in minutes.
- A preference centre on every email. Fans manage topics and channels themselves from a link in every send, so per-topic unsubscribes replace all-or-nothing exits. It will not switch texts or WhatsApp back on for a number that sent STOP, and a new SMS opt-in made there is confirmed by text.
- Data rights handled. From the preference centre, fans can download everything you hold on them, consent history included, or ask for deletion; deletion requests land in a queue in your admin with a 30-day deadline tracked, inside the legal month.
- CSV import that protects you. Importing an existing list requires you to declare the consent source for the contacts you bring in, so provenance survives the move and an unlabelled mystery list never silently enters your database.
Plans start at £19/month, every core feature is on every plan, and there is a 14-day free trial on Starter.
How the CRM connects to everything else
The CRM is the centre of the wheel: every channel guide in this series is really about a different way of filling it or spending it. Capture flows in from smart links, Instagram automation, direct-to-fan commerce, event data and demo submissions; sending flows out through email, SMS and WhatsApp, with automations running the welcome journeys between them. Label promo work keeps its own segregated contact pool, covered in promo campaigns, and the music website guide explains why it all belongs behind one front door. For the ownership argument told as a promoter's story, read the promoter playbook.
The condensed checklist
Foundations
- One database. Every capture surface feeds the same contact records.
- Every record shows identity, per-channel consent, engagement, purchases, tags and lifecycle stage.
- Consent recorded per channel with the ICO's five facts: who, when, how, what they were told, any withdrawal.
- Suppression list live and honoured across all channels.
- Preference centre linked from every email.
Capture
- All capture surfaces inventoried, ranked by traffic, and marked yours or a third party's.
- Top three surfaces have a clear opt-in and feed the database directly.
- Your own checkout captures marketing consent (soft opt-in where lawful, with easy opt-out).
- A join keyword (text or WhatsApp) live for posters, screens and the merch stand.
Operating habits
- Welcome journey live: three messages inside the first two weeks.
- Four workhorse segments built: buyers vs never-bought, recent clickers vs cold, by city, by genre.
- Segment-first sending: whole-list blasts are a justified exception.
- Quarterly hygiene ritual in the calendar: re-engage, prune, refresh old consent, audit surfaces, spot-check records.
UK legal basics
- ICO data protection fee paid, or the self-assessment says you are exempt.
- Data requests answered inside a month.
- A way to take data protection complaints, acknowledged within 30 days.
Never
- No bought or borrowed lists, ever.
- No texting or WhatsApp without that channel's own opt-in.
- No hidden unsubscribe links.
Frequently asked questions
What is a music CRM?
A music CRM is a single database of your fans and industry contacts where each person has one record combining identity, per-channel marketing consent, engagement history, purchases, tags and a lifecycle stage. Unlike sales CRM software built around deal pipelines, it is organised around long-term fan relationships: capturing people from every surface, proving their consent, and segmenting so every send goes to the people it is actually for.
Do I need a CRM with only a few hundred fans?
Yes, and it is the best time to start. A few hundred properly captured contacts with consent and history attached will outperform ten thousand scattered followers, and the habits are far easier to build now than to retrofit later. Kevin Kelly's "1,000 True Fans" argument (2008) is precisely about the leverage of a small, reachable, genuine audience.
Can I legally email people who bought a ticket but never joined my list?
Usually yes, if they bought from you: the soft opt-in recognised in UK and EU electronic-marketing rules applies when the details came from a sale with you, you are marketing your own similar products or events, and you offered an opt-out at collection and in every message since. A ticket bought through a marketplace is the marketplace's sale, so rely instead on the opt-in it collected for you, which the ICO recommends using within six months. A plain-English summary, not legal advice.
Can I text or WhatsApp my email subscribers?
Not on the strength of their email consent alone. Consent is per channel: SMS and WhatsApp each need their own opt-in, which Meta's business policies also require. The clean pattern is to invite email subscribers to add another channel, for example by sending a join keyword or ticking an SMS box on a signup page, so the new consent is affirmative and provable.
Are bought email lists ever worth it?
No. The people on them never consented to hear from you, which fails UK GDPR and PECR; the ICO's own guidance says there is no such thing as a third-party marketing list that is compliant with the soft opt-in. They also do not know you, which produces spam-complaint rates above the 0.3% threshold Gmail and Yahoo have enforced since 2024, so one send can damage delivery to the fans who genuinely opted in.
What should I do with subscribers who never open anything?
Judge silence on clicks and purchases rather than opens, because Apple Mail counts emails as opened whether or not anyone read them. After six or more months with no click or purchase, send one honest re-engagement email, then suppress the contacts who ignore it. Mailbox providers judge senders on how recipients behave, so a smaller list that clicks is worth more than a big one that does not.
What does GDPR actually require from a small label or promoter?
In practice: a lawful basis for each contact (usually consent, or the soft opt-in for your own customers), records showing who consented, when, how and what they were told, an easy opt-out in every message, and answers to data requests within a month. In the UK you also pay the ICO's data protection fee unless its self-assessment says you are exempt (£52 a year for the smallest tier since February 2025), and since 19 June 2026 you need a way to take data protection complaints, acknowledged within 30 days. General guidance, not legal advice.
What is a preference centre and do I really need one?
A preference centre is a page, linked from every email, where fans choose which topics and channels they receive or unsubscribe entirely. You need one because it converts "too many emails" from a spam complaint into a smaller, still-alive subscription, and because easy exits are both a legal expectation and the cheapest deliverability protection there is.
How do I move my existing lists and spreadsheets in without breaking anything?
Import in labelled batches, one source at a time, recording the consent source for each: where these contacts came from and what they agreed to. Anything you cannot vouch for goes into a no-send holding state until those people re-confirm. Labelled importing gives you a database you can defend; a bulk dump gives you a liability.
How long does marketing consent last?
UK law sets no expiry date, but the ICO says consent degrades over time and depends on what people expect. Its working rule is to refresh consent every two years if you are in any doubt, and not to rely on consent collected by a third party, such as a ticketing marketplace, more than six months after it was given. A "still want these?" email to anyone quiet for a release cycle or two is the practical version.
Did the Data (Use and Access) Act 2025 change the rules on emailing fans?
Not the core rule: email and texts to individuals still need consent or the soft opt-in under PECR. The Act lists direct marketing as an example of a legitimate interest under UK GDPR, but the usual balancing test still applies and it does not override PECR. What did change: PECR fines rose to UK GDPR levels (up to £17.5 million or 4% of worldwide turnover) on 5 February 2026, charities gained their own soft opt-in, the clock on data requests now pauses while you seek clarification, and a complaints process became mandatory on 19 June 2026.
Know someone who needs this?
Send them the guide. It is free to read, no signup needed.