// LEGAL DOCUMENT
Cookie Policy
Effective August 8, 2026 · Version 1.1
This document is provided for general information and to govern your use of the service. It is not legal advice. If you have questions about how it applies to you, please contact us.
01About this policy
This Cookie Policy (this “Policy”) explains how The Gig App (“we”, “us”, “our”), the operator of the GIG platform made available at thegigapp.ca and its associated subdomains and pages (the “Service”), uses cookies and similar technologies when you (the “user”, “you” or “your”) access or use the Service. It applies to all visitors to and users of the Service, including organization owners, administrators, employees, staff and contractors who hold accounts (each an “Organization” user), individual gig-profile and profile-only account holders, and members of the public who interact with the Service without an account — for example, anonymous submitters of published forms, self-registrants and respondents to gig intake, day-sheet and RSVP links, and recipients of magic-link approval and profile-update links.
This Policy forms part of, and should be read together with, our Privacy Policy, which describes more fully how we collect, use, disclose and safeguard personal information in accordance with the federal Personal Information Protection and Electronic Documents Act (“PIPEDA”) and other privacy laws applicable in the Province of Ontario and Canada. Where this Policy uses capitalized terms that are not defined here, they have the meaning given to them in the Privacy Policy or our Terms of Use. To the extent any cookie or similar technology collects information that identifies, or could reasonably be used to identify, an individual, that information is treated as “Personal Information” and is governed by the Privacy Policy.
02What cookies and similar technologies are
A “cookie” is a small text file that a website or application places on your device (such as your computer, tablet or mobile phone) through your web browser. Cookies allow the Service to recognize your browser and, in certain cases, to retain information about your visit, such as whether you are signed in and your stated preferences. Cookies may be “session” cookies, which are deleted when you close your browser, or “persistent” cookies, which remain on your device for a defined period or until you delete them.
In this Policy, references to “cookies” also include other locally-stored data and similar technologies that perform comparable functions, including in particular:
- Local storage and session storage. The Service is a modern web application and uses your browser’s local storage and session storage (collectively, “web storage”) to hold information on your device — for example, authentication and session data used to keep you signed in, and certain interface preferences. Web storage is not transmitted automatically with every request in the way that traditional cookies are, but it serves similar purposes and is addressed here for completeness.
- Tokens and identifiers. The Service stores certain tokens and identifiers (including authentication session tokens) on your device so that the Service can verify your session, protect against unauthorized access, and operate features you have requested.
- Pixels, tags and software development kits. Where third parties we engage to operate the Service (described in Section 4) load their own scripts, those scripts may set cookies or use comparable technologies on your device.
The specific cookies and storage entries set on your device depend on which areas of the Service you use and which third-party services are invoked by those areas. Because cookie names, identifiers and durations are set and may be changed from time to time by us and by the third-party providers described below, we describe cookies by purpose and category in Section 3 rather than by listing exact names. You can inspect the precise cookies and storage entries set in your browser at any time using the developer or privacy tools built into your browser, as described in Section 5.
03How we use cookies and similar technologies
We use cookies and similar technologies only for the purposes described below. We do not use cookies to serve third-party advertising, to track your activity across unrelated websites, or to sell or rent your Personal Information. The categories we use are as follows.
(a) Strictly necessary — authentication, session and security. These cookies and storage entries are essential for the Service to function and cannot be switched off through the Service. They do not require your consent under PIPEDA because, without them, the core service you have requested cannot be delivered. They are used to:
- Sign you in and maintain your authenticated session. The Service uses our authentication and database provider, Supabase, to manage sign-in and to store the authentication session that keeps you logged in as you move between pages. Disabling these will prevent you from signing in or staying signed in.
- Protect the security and integrity of the Service. These technologies support security measures such as protection against cross-site request forgery (CSRF), session validation, detection of unauthorized or anomalous access, and load and routing functions provided by our hosting provider, Vercel.
- Bind certain magic-link sessions. Where you access the Service through a magic link — for example, a finance approval link at
/approve/[token]— the Service may use a session-bound cookie or storage entry to associate your action with the link you opened, so that the approval is recorded against the correct request. As described in our Privacy Policy, certain external approval actions are recorded in an immutable approvals audit log together with the approver’s email address, Internet Protocol (IP) address and browser user-agent.
(b) Preferences. These cookies and storage entries allow the Service to remember choices you make so as to provide a more consistent experience. For example, the Service may store interface preferences such as your selected theme or display options. These technologies are not essential to deliver the Service, but disabling them may mean your preferences are not retained between visits.
(c) Analytics and error monitoring. These technologies help us understand how the Service is performing, diagnose problems and keep the Service reliable and secure. We use:
- Vercel, our hosting and edge platform, which may collect operational, performance and security telemetry necessary to host, route and deliver the Service reliably.
We use analytics and error-monitoring data to maintain, troubleshoot, secure and improve the Service, and not to build marketing or advertising profiles about you. Where analytics or error-monitoring technologies are not strictly necessary to deliver the Service and collect Personal Information, we handle consent in a manner proportionate to the sensitivity of the information, consistent with PIPEDA and, for users in Quebec, with the requirement to obtain consent before activating technology that allows a person to be identified, located or profiled. We do not currently use cookies or similar technologies for behavioural advertising or marketing; if that changes, we will update this Policy and obtain any consent required by law before doing so.
04First-party and third-party cookies
Cookies may be “first-party” (set by us under the thegigapp.ca domain) or “third-party” (set by a service provider whose technology operates within the Service). We engage the following service providers, each of which may set cookies or use similar technologies when the relevant part of the Service is used. These providers are also described, as sub-processors, in our Privacy Policy and our Data Processing Addendum.
- GIG (first-party). We set cookies and store data under our own domain for the strictly-necessary and preference purposes described in Section 3 — principally to maintain your authenticated session, secure the Service, and remember your interface choices.
- Supabase (authentication and database). Our authentication and database provider sets and reads the authentication session and related security tokens that keep you signed in. These are necessary for sign-in and session management.
- Stripe (payments and Stripe Connect). When you interact with payment, subscription, invoicing or payout flows powered by Stripe, including Stripe Connect flows in which an Organization charges its own clients, Stripe may set its own cookies and use similar technologies — for example, to support fraud prevention and the secure operation of its payment forms. These cookies are governed by Stripe’s own policies. We do not store full payment card numbers; card data is handled by Stripe, and we retain only limited details such as card brand, last four digits and expiry as described in our Privacy Policy.
- Vercel (hosting and edge delivery). Our hosting and edge platform may set cookies or use similar technologies to host, route, secure and deliver the Service and to collect operational telemetry.
Third-party providers are independently responsible for the cookies and technologies they set, and their use of any information collected through those technologies is governed by their own privacy and cookie policies. Some of these providers store and process information outside of Canada, including in the United States; where Personal Information is involved, this cross-border processing and the associated foreign lawful-access considerations are described in our Privacy Policy.
05Managing cookies and similar technologies
You have a number of ways to review and control cookies and similar technologies used on your device:
- Browser settings. Most web browsers allow you to view the cookies and storage entries set on your device, to delete some or all of them, and to block or limit cookies — including the ability to block third-party cookies or to be notified when a cookie is set. The controls and their location differ by browser; consult the help or privacy/security settings of the browser you use for instructions.
- Clearing local and session storage. The web storage described in Section 2 can generally be cleared through your browser’s privacy, site-data or developer tools.
- Third-party controls. For cookies set by the third-party providers described in Section 4, you may also be able to exercise controls offered by those providers through their own settings and policies.
Consequences of blocking cookies. The strictly-necessary, authentication, session and security cookies and storage entries described in Section 3(a) are required for the Service to operate. If you block, delete or disable them, you will not be able to sign in to or use authenticated areas of the Service, sessions may not be maintained, and certain features — including magic-link approval, profile-update, gig intake and day-sheet flows — may not function correctly. Blocking preference cookies may mean your interface choices are not remembered, and blocking analytics or error-monitoring technologies may reduce our ability to detect and resolve faults that affect you.
06Do Not Track and global privacy signals
Some browsers offer a “Do Not Track” (“DNT”) setting that sends a signal to websites indicating that you do not wish to be tracked. There is currently no consistent industry or legal standard governing how DNT signals should be interpreted or honoured, and the Service does not respond differently to DNT signals at this time. Because we do not use cookies or similar technologies for cross-site tracking or behavioural advertising, the practical effect of a DNT signal on the Service is limited. You can nonetheless control non-essential cookies and storage as described in Section 5. If applicable law requires us to recognize a particular browser-based privacy signal in the future, we will update our practices and this Policy accordingly.
07Changes to this policy
We may update this Policy from time to time to reflect changes in the cookies and technologies we use, in the providers that support the Service, or in applicable law or regulatory guidance. When we make changes, we will revise the “Effective” date and version shown at the top of this Policy. Where a change materially affects how we use cookies or the information they collect, we will take additional steps to bring the change to your attention and, where required by law, obtain your consent. Your continued use of the Service after an updated Policy takes effect constitutes your acknowledgement of the updated Policy, subject to any consent rights you have under applicable privacy law.
08How to contact us
If you have questions about this Policy or about how the Service uses cookies and similar technologies, or if you wish to exercise any rights you may have in respect of Personal Information collected through these technologies, you may contact us as follows:
- Operator: The Gig App
- General enquiries: Admin@thegigapp.ca
- Privacy enquiries (Privacy Officer): Admin@thegigapp.ca
For more information about how we handle Personal Information, including your access and correction rights and how to make a privacy complaint, please see our Privacy Policy. This Policy should also be read together with our Terms of Use, our Acceptable Use Policy, and, where it applies to your Organization, our Data Processing Addendum.
