// LEGAL DOCUMENT
Privacy Policy
Effective August 8, 2026 · Version 1.1
This document is provided for general information and to govern your use of the service. It is not legal advice. If you have questions about how it applies to you, please contact us.
01Who we are & our Privacy Officer
GIG (the “Service”) is a business-to-business software-as-a-service platform for the gig and event economy, operated from the Province of Ontario, Canada, and accessible at thegigapp.ca. The Service is provided by The Gig App (“GIG”, “we”, “us” or “our”). This Privacy Policy (the “Policy”) describes how we collect, use, disclose, retain and safeguard personal information in connection with the Service, and the rights and choices available to individuals, consistent with the federal Personal Information Protection and Electronic Documents Act (“PIPEDA”) and applicable provincial privacy laws.
In this Policy, “Personal Information” means information about an identifiable individual, as defined under PIPEDA. “you” or “Customer” means the individual or entity that subscribes to or uses the Service; an “Organization” means a workspace or account created on the Service to which one or more users are linked; a “Gig Worker” means an individual contractor, staff member, performer, crew member or other talent whose information is recorded in or who interacts with the Service; and “Content” means the data, files, records and materials submitted to, stored in or generated through the Service.
We are accountable for Personal Information under our control, including Personal Information we transfer to third parties for processing on our behalf. We have designated a Privacy Officer who is responsible for our compliance with this Policy and with applicable privacy law. You may contact our Privacy Officer as follows:
- Privacy Officer, The Gig App
- Email: Admin@thegigapp.ca
02Scope & our role
This Policy applies to Personal Information we handle in connection with the Service, including information about: (a) account holders and the owners, administrators, employees and staff linked to an Organization; (b) individuals who create a profile or gig profile without an Organization; (c) Gig Workers; and (d) members of the public who interact with the Service without an account — for example, people who submit a published form, register through a gig intake or RSVP link, respond to a day-sheet link, receive a magic-link approval request, or receive a profile-update link.
The Service performs two distinct roles with respect to Personal Information, and your rights and our obligations differ accordingly:
- Where we act for our own purposes (we are the “organization” / controller). For information we collect to create and administer accounts, to bill and collect fees, to secure and audit the Service, to provide support, and to operate and improve the Service, we determine the purposes of processing and this Policy governs that handling.
- Where we act on an Organization’s behalf (we are a processor / service provider). When an Organization uploads or enters Personal Information about its own contacts, clients, staff, contractors, Gig Workers, form respondents and event attendees, that Organization is the party that decides why and how that Personal Information is used. We process it on the Organization’s documented instructions, under our agreement with that Organization. For that information, the Organization is the first point of contact for access, correction and similar requests, and our handling is also governed by our Data Processing Addendum.
03Personal information we collect
We collect Personal Information directly from you, from the Organization you are associated with, from individuals who interact with public features of the Service, and automatically through your use of the Service. The categories below are organized by the module that generates them. Not every category applies to every individual.
3.1 Entity (contacts, businesses & contractor pipeline). The Entity module stores records about contacts, businesses and contractors managed by an Organization, which may include:
- names, email addresses and phone numbers;
- mailing and billing addresses;
- photos, biographies and designations;
- custom fields defined by the Organization; and
- pipeline status and related notes.
3.2 Architect (projects & published pages). The Architect module stores projects and information-card blocks created by an Organization. An Organization may choose to publish a read-only version of a project to a public web page (at a share-link URL under /p/[slug], marked not to be indexed by search engines). Any Personal Information an Organization places in a published block becomes viewable by anyone who has the link.
3.3 Finance (budgets, invoicing, payments & approvals). The Finance module stores budgets, line items, invoices, payments, payouts, disputes, memberships and related dashboard data. Where an Organization invoices and collects from its own clients, we use Stripe and Stripe Connect to process payments. Card details are handled by Stripe; we do not store full payment card numbers — we retain only limited payment metadata such as card brand, the last four digits and the expiry. Where the Finance module uses magic-link approvals, the approval page (at /approve/[token]) records the approver’s email address, IP address and browser user-agent in an immutable approvals audit log, to evidence who approved what and when.
3.4 Data (custom tables & charts). The Data module lets an Organization build custom tables and charts. Any Personal Information the Organization enters into those tables is collected and stored as Content under the Organization’s control.
3.5 Forms (published forms & submissions). When an Organization publishes a form (at a public URL under /f/[id]), anyone — including individuals without an account — may submit it. We collect the answers provided and the submitter’s email address, and store them for the publishing Organization.
3.6 Gigs & Events (day sheets, intake & RSVP). For gigs and events, including the public day-sheet (/gig/[token]) and intake/join (/gig/join) flows, we may collect, on behalf of the Organization, an attendee’s name, email address and role; RSVP status and plus-ones; dietary requirements; travel details such as flights and hotels; call times; and rider files uploaded in connection with the gig.
3.7 Profile & gig profiles. An individual profile or gig profile (at /profile, and updatable via a link at /update-profile/[token]) may include a designation, biography, headshot, e-transfer email, social links, rate cards and contractor agreements. The e-transfer email is treated as private and is not shown on the public discovery view; the public discovery view exposes only the designation, biography, logo and social links.
3.8 Account, security & technical information. Across the Service we also collect:
- authentication information, including the email address used to sign in and authenticate (including via magic link);
- IP address and browser user-agent, which are captured and retained in the immutable approvals audit log when an external party uses an approval magic link, as described above;
- usage and log data generated as you use the Service, including event, diagnostic and error information used for security and to operate the Service; and
- cookies and similar identifiers, as described in Section 12 and in our Cookie Policy.
3.9 Notifications. The Service maintains an in-app notification inbox. Notification records may contain Personal Information within their title or message — for example, the name of a person associated with an approval request, a gig RSVP, or a contractor-pipeline change — and are stored for the recipient and their Organization.
04How we use personal information
We identify the purposes for which we collect Personal Information at or before the time of collection. We use Personal Information for the following purposes:
- To operate and deliver the Service, including the Entity, Architect, Finance, Data, Forms, Gigs/Events, Profile and notification features described in Section 3 — for example, to display contacts, render projects and published pages, generate invoices and process payments, accept and route form submissions, organize gig day sheets and intake, and maintain profiles and rate cards;
- To administer accounts and billing, including provisioning Organizations and member roles, calculating seat-based and add-on subscription fees, processing payments, renewals and cancellations through Stripe, and managing Stripe Connect payouts;
- For security, fraud prevention and audit, including authenticating users, enforcing tenant isolation, detecting and preventing misuse, and maintaining the immutable approvals audit log (including approver email, IP address and user-agent);
- To provide support and respond to requests, including responding to inquiries and troubleshooting issues;
- To communicate with you, including sending transactional and service-related messages such as authentication and magic-link emails, approval and profile-update links, billing notices and important Service announcements;
- To maintain, improve and secure the Service, including monitoring for errors and stability through our error-monitoring provider; and
- To comply with legal obligations and to establish, exercise or defend legal claims.
We will not use Personal Information for a new purpose that is materially different from those identified above without first identifying that purpose and obtaining consent, except where permitted or required by law.
05Consent & your choices
We collect, use and disclose Personal Information with your knowledge and consent, except where the collection, use or disclosure without consent is permitted or required by law. The form of consent we rely on depends on the sensitivity of the information and the circumstances:
- Express consent. Where you create an account, you expressly agree to this Policy and our Terms of Use. We also obtain express consent for sensitive information and for any marketing communications.
- Implied consent. Where you, an Organization, or a member of the public voluntarily provide information that is reasonably necessary to deliver a feature you have requested — for example, submitting a published form, completing a gig intake, or responding to a day-sheet link — we may rely on implied consent to use that information to provide the requested function.
Withdrawing consent. Subject to legal and contractual restrictions and reasonable notice, you may withdraw your consent to our continued collection, use or disclosure of your Personal Information at any time by contacting our Privacy Officer at Admin@thegigapp.ca. We will explain the consequences of withdrawal; withdrawing consent for information that is necessary to provide the Service may mean we can no longer provide some or all of the Service to you. Where information was provided to an Organization through the Service, you may also need to direct your request to that Organization.
Electronic communications (CASL). Many of the messages we send are transactional or service-related — for example, authentication and magic-link emails sent through our email provider, approval and profile-update links, billing notices, receipts and responses to your requests. These are necessary to operate the Service. If we send a commercial electronic message of a promotional nature, we will identify ourselves, provide a valid means of contact, and include a functional unsubscribe mechanism that we will honour, consistent with Canada’s Anti-Spam Legislation. You may unsubscribe from promotional messages at any time without affecting transactional or service messages necessary to your account.
07Cross-border transfer & data location
The Service relies on the sub-processors named in Section 6, which store and process Personal Information outside Canada, including in the United States — Supabase (United States regions us-east-2 and us-west-2), Stripe (United States), and Vercel (United States and global edge infrastructure). By using the Service and providing Personal Information, you acknowledge and consent to this transfer and to the storage and processing of Personal Information outside Canada.
While Personal Information is located in a foreign jurisdiction, it may be subject to the laws of that jurisdiction, including lawful access by courts, law enforcement and government authorities of that jurisdiction (for example, under United States legal process), regardless of the safeguards we put in place. We require our service providers, by contract, to provide a comparable level of protection to the Personal Information they process for us.
08Retention & deletion
We retain Personal Information for as long as the relevant account or Organization is active and as needed to fulfil the purposes described in this Policy, and thereafter only as necessary to meet legal, audit, tax, accounting or security obligations, or to establish, exercise or defend legal claims. Retention behaves differently depending on the data:
- Soft deletion. Certain records — such as subscriptions and memberships — are deactivated by status (soft-deleted) rather than immediately erased, so that the account can be restored and so that we can meet billing and audit obligations.
- Cascading hard deletion. When an Organization is deleted (by a platform administrator) or an account is deleted, associated Content is hard-deleted on a cascading basis, subject to the exceptions below and to backups described below.
- Immutable audit logs. The approvals audit log is append-only and is retained as a permanent, tamper-evident record; entries (including approver email, IP address and user-agent) are not individually deletable, as they exist to evidence financial approvals.
- Form submissions and notifications are retained until deleted by the owning Organization.
- Backups. Our database provider maintains backups for resilience; information may persist in backups for a limited period after deletion before being overwritten in the ordinary course.
To request deletion of Personal Information, contact our Privacy Officer at Admin@thegigapp.ca, or, where the information was provided to an Organization through the Service, the relevant Organization. We will respond consistent with Section 10 and applicable law, and we may retain information we are required or permitted by law to keep.
09Safeguards
We protect Personal Information with security safeguards appropriate to its sensitivity, including organizational, technical and physical measures. These include:
- Tenant isolation and access controls, including database row-level security so that each Organization’s data is logically separated and access is restricted to authorized users and roles;
- Encryption in transit, using industry-standard transport encryption (HTTPS/TLS) for data moving between you and the Service;
- Encryption of sensitive tokens at rest, using AES-256-GCM encryption for sensitive tokens within the Service;
- Time-limited and scoped links, using random, app-enforced expiry on magic-link tokens (for example, profile-update links expiring after a set period and gig day-sheet links expiring after the gig), with approval links bound to a session; and
- Monitoring and vendor diligence, including error and security monitoring and contractual safeguards with the sub-processors named in Section 6.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Files uploaded to public storage buckets (such as headshots, Organization logos and gig rider files) may be served by public or signed URLs and may be accessible to anyone who has the corresponding link (see Section 11).
10Your rights
We rely on you and Organizations to provide accurate information, and we take reasonable steps to keep Personal Information as accurate, complete and up to date as is necessary for the purposes for which it is used. Subject to applicable law, you have the following rights with respect to your Personal Information:
- Access. You may request confirmation of whether we hold Personal Information about you, a copy of that information, and information about how it has been and may be used and disclosed.
- Correction. You may request correction of inaccurate or incomplete Personal Information; where appropriate, we will amend it or note the disagreement.
- Withdrawal of consent. You may withdraw consent as described in Section 5, subject to legal and contractual restrictions.
To exercise these rights, contact our Privacy Officer at Admin@thegigapp.ca. We will respond to access requests generally within 30 days of receiving a request and any required verification of identity, at little or no cost; where we require additional time or must refuse a request in whole or in part, we will tell you and explain our reasons and your recourse. Where the Personal Information was provided to an Organization through the Service and we act only as its processor, we will refer you to, or direct your request to, that Organization, which is responsible for responding.
11Public information
Several features of the Service are designed to be publicly accessible by anyone who has the relevant link or URL, without an account and without authentication. Information made available through these features can be viewed, copied or shared by recipients, and we cannot control what they do with it. These features include:
- Published Architect pages at
/p/[slug](read-only share links, marked not to be indexed by search engines); - Public forms at
/f/[id]; - Public gig profiles and the public discovery view (which exposes designation, biography, logo and social links, but not the private e-transfer email); and
- Gig day-sheet links at
/gig/[token]and gig intake/join links.
You should only publish or share Personal Information through these features if you have the right to do so, and you should treat any link to a public page as something that may be forwarded beyond the people you originally intended.
13Children
The Service is a business tool intended for use by organizations and adults, and is not directed to children. We do not knowingly collect Personal Information from individuals under the age of 16. If you believe a child has provided Personal Information to us, please contact our Privacy Officer at Admin@thegigapp.ca and we will take reasonable steps to delete it, unless we are required to retain it by law.
14Data breach notification
We maintain processes to detect, assess and respond to security incidents involving Personal Information. Where a breach of security safeguards creates a real risk of significant harm to an individual, we will report the breach to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible, consistent with PIPEDA, and will notify other organizations or institutions that may be able to mitigate the harm. We will keep records of breaches of security safeguards as required by law.
Where we act as a processor for an Organization (see Section 2), we will notify that Organization of a security incident affecting its data without undue delay so that it can meet its own notification obligations, as further described in our Data Processing Addendum.
15Quebec & other provinces
In addition to PIPEDA, provincial privacy laws may apply to individuals located in certain provinces. In particular, Quebec’s Act respecting the protection of personal information in the private sector (as amended, commonly referred to as “Law 25”) imposes additional requirements where Personal Information of individuals in Quebec is involved, including in relation to transfers of Personal Information outside Quebec. We endeavour to handle Personal Information in a manner consistent with applicable provincial requirements. Individuals in Quebec or other provinces with specific questions may contact our Privacy Officer at Admin@thegigapp.ca.
16Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices, the Service, our service providers, or the law. When we make material changes, we will revise the effective date shown above and, where appropriate, provide additional notice. The law governing privacy in Canada continues to evolve, and we will update this Policy as needed to reflect changes in applicable legislation. Your continued use of the Service after an update takes effect constitutes acceptance of the updated Policy, except where additional consent is required by law.
17How to contact us & the OPC
If you have a question, request or complaint about this Policy or our handling of Personal Information, please contact our Privacy Officer first so that we have an opportunity to address it:
- Privacy Officer, The Gig App
- Privacy email: Admin@thegigapp.ca
- General email: Admin@thegigapp.ca
If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada (the “OPC”):
- Office of the Privacy Commissioner of Canada
- 30 Victoria Street, Gatineau, Quebec K1A 1H3
- Toll-free: 1-800-282-1376
- Website: www.priv.gc.ca
Depending on your province, you may also have recourse to a provincial privacy regulator, such as the Commission d’accès à l’information du Québec for individuals in Quebec.
