// LEGAL DOCUMENT
Acceptable Use Policy
Effective August 8, 2026 · Version 1.1
This document is provided for general information and to govern your use of the service. It is not legal advice. If you have questions about how it applies to you, please contact us.
01Purpose & Scope
This Acceptable Use Policy (this “AUP”) sets out the rules that govern access to and use of the GIG platform, websites at thegigapp.ca, applications, public-facing pages, and related services (collectively, the “Service”), which are operated by The Gig App (“GIG”, “we”, “us”, or “our”) from the Province of Ontario, Canada. This AUP forms part of, and is incorporated by reference into, the Terms of Use (the “Terms”). Capitalized terms used but not defined in this AUP have the meanings given to them in the Terms. In the event of a conflict between this AUP and the Terms with respect to permitted use of the Service, the more restrictive provision governs.
This AUP applies to every person who accesses or uses the Service in any capacity, whether or not authenticated, including, without limitation:
- organizations that subscribe to or use the Service (each, an “Organization”) and their owners, administrators, employees, staff, and contractors acting under an Organization account;
- individuals who maintain a GIG profile or gig profile without an Organization; and
- members of the public who interact with the Service without an account, including people who submit published forms, register through gig intake or RSVP links, respond to gig day-sheets, or receive magic-link approval or profile-update links (collectively with the foregoing, “you” or, where the context requires, the “Customer”).
Where you use the Service on behalf of an Organization, you represent that you are authorized to do so, and “you” includes that Organization. An Organization is responsible for the acts and omissions of all persons who access the Service through its account (including its administrators, employees, staff, and contractors) as if they were the Organization’s own, and the Organization’s indemnification obligations under the Terms extend to any breach of this AUP by such persons. We may update this AUP from time to time in accordance with the amendment provisions of the Terms, and your continued use of the Service after the effective date of an updated AUP constitutes acceptance of it.
02Lawful & Authorized Data Only
You may use the Service only for lawful purposes and only with content and data that you are legally entitled to provide, store, and process. Where you upload, enter, import, or otherwise make available through the Service any information that identifies or could reasonably identify an individual (“Personal Information”) about a person other than yourself — including, without limitation, contacts and businesses in the Entity module, contractors in your contractor pipeline, gig attendees, day-sheet and intake respondents, form submitters, project collaborators, finance approvers and payees, and your own clients — you represent and warrant on a continuing basis that:
- you have a valid legal basis and any consent required under applicable privacy law, including the federal Personal Information Protection and Electronic Documents Act (“PIPEDA”) and any applicable provincial privacy legislation, to collect that Personal Information and to provide it to GIG for processing through the Service;
- the affected individuals have been given any notice required by law about the purposes for which their Personal Information is collected, used, and disclosed;
- your collection, use, and disclosure of that Personal Information through the Service (including by publishing an Architect project to a public
/p/[slug]page, by collecting submissions through a published form, or by distributing gig links) complies with all applicable laws; and - you will not upload sensitive categories of Personal Information through the Service except where you are lawfully entitled to do so and the Service is intended to receive it (for example, dietary, travel, or accommodation details collected through gig intake).
As between you and GIG, you are the controller (and, under PIPEDA, the “organization”) responsible for the Personal Information you submit about other people, and GIG acts as your service provider and processes that Personal Information on your documented instructions, as further described in the Privacy Policy and the Data Processing Addendum. You are responsible for responding to requests from individuals to access, correct, or delete the Personal Information you have submitted, and for honouring any withdrawal of consent. You must not use the Service to collect Personal Information for purposes that the affected individuals would not reasonably expect, or to repurpose Personal Information collected through the Service for incompatible purposes without a lawful basis to do so.
03Prohibited Content
You must not upload, submit, store, transmit, publish, link to, or otherwise make available through the Service any content (“Content”) — including text, files, images, headshots, organization logos, gig rider files, form answers, profile and rate- card information, project blocks, or finance records — that:
- is unlawful, or that promotes, facilitates, or instructs others in unlawful activity, under the laws of Ontario, Canada, or any other jurisdiction that applies to you;
- infringes or misappropriates the intellectual-property rights, privacy rights, publicity rights, confidentiality rights, or other rights of any person, or that you do not otherwise have the right to provide;
- is defamatory, libellous, harassing, threatening, abusive, hateful, or that promotes discrimination, violence, or harm against any individual or group;
- is obscene, child sexual abuse material, or otherwise sexually exploitative, particularly of minors;
- is fraudulent, deceptive, or misleading, including content designed to impersonate another person or organization, to phish for credentials or payment information, or to misrepresent the source, sponsorship, or approval of a communication or transaction;
- contains or is intended to deliver malware, viruses, worms, ransomware, spyware, or any other malicious or harmful code; or
- violates any policy of our sub-processors (including Supabase, Stripe, or Vercel) where their services are used to transmit, store, or process that Content.
You are solely responsible for your Content and for ensuring it complies with this AUP and all applicable laws. GIG does not pre-screen Content and is under no obligation to monitor it, but we reserve the right to review, remove, restrict access to, or refuse to publish any Content that we reasonably believe violates this AUP, the Terms, or applicable law, including Content on public pages such as /p/[slug], published forms at /f/[id], public gig profiles, and gig day-sheets at /gig/[token].
04Prohibited Conduct
You must not, and must not attempt to, and must not permit or encourage any other person to:
- Probe or breach security. Access, probe, scan, or test the vulnerability of any part of the Service or its underlying systems, or breach or circumvent any security, authentication, or access-control measure, except through a coordinated disclosure process we have authorized in writing;
- Access other tenants’ data. Access, or attempt to access, any data, account, Organization workspace, or Personal Information that you are not expressly authorized to access, including the data of other Organizations or users sharing the multi-tenant Service;
- Circumvent access controls or limits. Bypass, disable, or interfere with any access control, role-based permission, seat limit, plan entitlement, usage limit, magic-link expiry, token, or other technical restriction, including by sharing, guessing, harvesting, or reusing the random tokens used for approval links, profile-update links, gig day-sheet links, or gig intake links;
- Scrape or use bots. Use any robot, spider, crawler, scraper, or other automated means to access, harvest, index, or collect Content or data from the Service, except through interfaces and to the extent we expressly document and permit;
- Reverse engineer. Decompile, disassemble, reverse engineer, or otherwise attempt to derive the source code, underlying ideas, or algorithms of any part of the Service, except to the limited extent applicable law expressly permits despite this restriction;
- Interfere with or overload the Service. Interfere with, disrupt, or impose an unreasonable or disproportionate load on the Service or its infrastructure, including by means of a denial-of-service attack, flooding, or generating excessive or automated requests;
- Impersonate. Misrepresent your identity or affiliation, impersonate any person or entity, or falsely state or imply a relationship with GIG or any other person, including when submitting forms, registering for gigs, responding to day-sheets, or approving items through magic links; or
- Misuse the Service. Use the Service to develop a competing product, to resell or sublicense access without authorization, or in any manner not contemplated by the Terms.
You must protect the confidentiality of your account credentials and any magic links or tokens issued to you, and you must promptly notify us at Admin@thegigapp.ca if you become aware of any actual or suspected unauthorized access, security vulnerability, or breach. You must not conduct penetration testing or other intrusive security testing against the Service without our prior written consent.
05Anti-Spam & CASL
The Service enables you to cause electronic messages to be sent to other people — including organization and team invitations, magic-link approval requests sent to approvers, profile-update link requests, gig day-sheet links, and gig RSVP or intake requests. Some of these messages are sent through GIG’s email sub-processor (currently Supabase) at your direction. Where any such message is a “commercial electronic message” within the meaning of Canada’s Anti-Spam Legislation (S.C. 2010, c. 23) (“CASL”), or is otherwise subject to anti-spam or electronic-marketing laws, you are responsible for ensuring that the message and the underlying campaign comply with those laws.
In particular, when you use the Service to send or trigger messages to recipients, you must:
- have the recipient’s consent (express or, where permitted, implied) to be contacted for the relevant purpose, and maintain records of that consent sufficient to demonstrate compliance;
- ensure each commercial electronic message clearly identifies you (and any person on whose behalf it is sent) and includes valid contact information, including a mailing address and a working means to contact you that remains valid for at least 60 days;
- where required, provide a clear and functional unsubscribe or opt-out mechanism and give effect to opt-out requests promptly and at no cost to the recipient; and
- send only to recipients who have a genuine relationship with the gig, project, form, or approval to which the message relates, and only for the purpose for which their contact information was provided.
You must not use the Service to send spam, unsolicited bulk or commercial messages, chain communications, or messages with false or misleading sender information, subject lines, or headers, or to harvest electronic addresses or send messages to addresses collected without consent. Transactional and relationship messages that the Service sends to operate features you have requested (such as authentication and magic-link emails, and notices about an item awaiting your approval) are sent at your direction; you remain responsible for ensuring you had a lawful basis to direct that they be sent. As between you and GIG, you are the sender of, and are responsible for, the messages you cause to be sent through the Service, and your indemnification obligations under the Terms extend to any claim arising from those messages.
06File Uploads
The Service allows you to upload files, including profile headshots, organization logos, and gig rider files, which are stored using our storage sub-processor and may be served through public URLs or time-limited signed URLs depending on the feature. When you upload any file, you represent and warrant that:
- you own or have all rights and permissions necessary to upload, store, and (where the feature does so) publish or share the file and its contents;
- the file does not contain malware, viruses, or any other malicious or harmful code, and has not been engineered to exploit, disable, or interfere with the Service or its sub-processors;
- the file complies with the Prohibited Content section above and with any applicable size or format limits we publish (for example, the published maximum size for headshots); and
- you understand which files are served publicly versus through signed URLs, and you are responsible for not uploading confidential or sensitive material to a feature that serves files publicly where doing so would be inappropriate.
You are solely responsible for the files you upload, including gig rider files and any documents attached to gigs, profiles, or projects. We may scan, quarantine, restrict, or remove files that we reasonably believe violate this AUP, and we may rely on our sub-processors’ controls in doing so. We are not responsible for the loss of files you fail to retain a copy of, and you should keep your own backups of important material.
07Fair Use & Resource Limits
The Service is offered on a shared, multi-tenant basis, and its capacity is finite. You must use the Service in a manner consistent with normal, good-faith operation and must not consume resources in a way that degrades the Service for others or imposes an unreasonable burden on our infrastructure or that of our sub-processors. Without limiting the foregoing, you must not:
- exceed any usage, rate, storage, seat, or transaction limits applicable to your plan or add-ons, or attempt to evade those limits (including by creating multiple accounts to avoid seat-based pricing or other entitlements);
- generate automated, repetitive, or excessive requests that materially affect the availability, performance, or integrity of the Service; or
- use the Service in a way that risks triggering rate limits, suspensions, or additional charges imposed on GIG by a sub-processor.
Where your usage materially exceeds normal patterns or your plan entitlements, we may, on reasonable notice where practicable, throttle, suspend, or require you to upgrade or adjust your usage. Specific quantitative limits, where they apply, are set out in your plan documentation or order and may be updated from time to time in accordance with the Terms.
08Enforcement & Consequences
We aim to apply this AUP proportionately and, where the circumstances reasonably permit, to escalate from notice to suspension to termination. However, we reserve the right to act immediately where a violation poses a risk to the security, integrity, or lawful operation of the Service, to other users, or to GIG, or where required by law. Depending on the nature and severity of a violation (whether by you or by a person using the Service through your account), we may, at our discretion and without liability:
- issue a warning and require you to remedy the violation within a stated period;
- remove, disable access to, restrict, or refuse to publish any Content, file, public page, or message that we reasonably believe violates this AUP;
- suspend, throttle, or restrict your access to the Service or to particular features, including immediate suspension in the case of a security, legal, or fraud threat;
- terminate your account or your Organization’s access in accordance with the Terms; and
- preserve, and report to or disclose to law enforcement, regulators, or affected third parties, information about activity that we reasonably believe is unlawful, where we are permitted or required to do so by law.
Enforcement action under this AUP does not relieve you of your obligations under the Terms, including payment obligations, and does not limit any other right or remedy available to us at law or in equity. Certain records, including the immutable approvals audit log and other append-only logs, are retained and are not deletable, as described in the Privacy Policy; enforcement of this AUP does not alter those retention obligations. Nothing in this AUP requires us to take enforcement action, and our failure to enforce any provision is not a waiver of our right to do so later.
09Reporting Abuse
If you become aware of any actual or suspected violation of this AUP — including unlawful, infringing, deceptive, or harmful Content, a security vulnerability or suspected breach, abusive messaging, or misuse of another person’s Personal Information — please report it to us promptly at Admin@thegigapp.ca. For matters concerning Personal Information or privacy specifically, you may contact our Privacy Officer at Admin@thegigapp.ca, as described in the Privacy Policy.
Please include enough detail to allow us to locate and assess the issue, such as the relevant account, Organization, public page, link, or message, and a description of the conduct or Content at issue. We will review reports we receive and respond as we consider appropriate, but we do not guarantee any particular outcome, and we may decline to act on reports that are incomplete, abusive, or made in bad faith.
