// LEGAL DOCUMENT

Privacy Policy

Effective September 26, 2026 · Version 1.5

This document is provided for general information and to govern your use of the service. It is not legal advice. If you have questions about how it applies to you, write to legal@thegigapp.ca.

01Who we are & our Privacy Officer

GIG (the “Service”) is a business-to-business software-as-a-service platform for the gig and event economy, operated from the Province of Ontario, Canada, and accessible at thegigapp.ca. The Service is provided by The Gig App (“GIG”, “we”, “us” or “our”). This Privacy Policy (the “Policy”) describes how we collect, use, disclose, retain and safeguard personal information in connection with the Service, and the rights and choices available to individuals, consistent with the federal Personal Information Protection and Electronic Documents Act (“PIPEDA”) and applicable provincial privacy laws.

In this Policy, “Personal Information” means information about an identifiable individual, as defined under PIPEDA. “you” or “Customer” means the individual or entity that subscribes to or uses the Service; an “Organization” means a workspace or account created on the Service to which one or more users are linked; a “Gig Worker” means an individual contractor, staff member, performer, crew member or other talent whose information is recorded in or who interacts with the Service; and “Content” means the data, files, records and materials submitted to, stored in or generated through the Service.

We are accountable for Personal Information under our control, including Personal Information we transfer to third parties for processing on our behalf. We have designated a Privacy Officer who is responsible for our compliance with this Policy and with applicable privacy law. You may contact our Privacy Officer as follows:

  • Privacy Officer, The Gig App
  • Email: privacy@thegigapp.ca

02Scope & our role

This Policy applies to Personal Information we handle in connection with the Service, including information about: (a) account holders and the owners, administrators, employees and staff linked to an Organization; (b) individuals who create a profile or gig profile without an Organization; (c) Gig Workers; and (d) members of the public who interact with the Service without an account — for example, people who submit a published form, register through a gig intake or RSVP link, respond to a day-sheet link, receive a magic-link approval request, receive a profile-update link, or ask for access from our website.

The Service performs two distinct roles with respect to Personal Information, and your rights and our obligations differ accordingly:

  • Where we act for our own purposes (we are the “organization” / controller). For information we collect to create and administer accounts, to bill and collect fees, to secure and audit the Service, to provide support, to answer requests for access, and to operate and improve the Service, we determine the purposes of processing and this Policy governs that handling.
  • Where we act on an Organization’s behalf (we are a processor / service provider). When an Organization uploads or enters Personal Information about its own contacts, clients, staff, contractors, Gig Workers, form respondents and event attendees, that Organization is the party that decides why and how that Personal Information is used. We process it on the Organization’s documented instructions, under our agreement with that Organization. For that information, the Organization is the first point of contact for access, correction and similar requests, and our handling is also governed by our Data Processing Addendum.
// In plain terms — When you use GIG for your own account and billing, we decide how that information is used and you can come straight to us. When your Organization puts other people’s information into GIG (its clients, crew, form respondents, event guests), your Organization is in charge of that information — we are just the toolkit that stores and processes it for them. Requests about that data usually go to the Organization first.

03Personal information we collect

We collect Personal Information directly from you, from the Organization you are associated with, from individuals who interact with public features of the Service, and automatically through your use of the Service. The categories below are organized by the module that generates them. Not every category applies to every individual.

3.1 Entity (contacts, businesses & contractor pipeline). The Entity module stores records about contacts, businesses and contractors managed by an Organization, which may include:

  • names, email addresses and phone numbers;
  • mailing and billing addresses;
  • photos, biographies and designations;
  • custom fields defined by the Organization; and
  • pipeline status and related notes.

3.2 Architect (projects & published pages). The Architect module stores projects and information-card blocks created by an Organization. An Organization may choose to publish a read-only version of a project to a public web page (at a share-link URL under /p/[slug], marked not to be indexed by search engines). Any Personal Information an Organization places in a published block becomes viewable by anyone who has the link.

3.2a Docs (documents, files & published wikis). The Docs module stores documents an Organization writes, files it uploads alongside them, and “Clusters” that group documents into a wiki with its own navigation and tags. An Organization may publish a Cluster to a public web page (at a URL under /wiki/[slug]). Unlike a published Architect page, a published wiki is by default offered to search engines for indexing, and the Organization can switch that off per Cluster. Any Personal Information an Organization places in a published document — including in an attached file or an image inside a document — becomes viewable by anyone who has the link, and, where indexing is on, may be copied and cached by search engines and internet archives beyond our control and beyond the point at which the Organization unpublishes it.

3.3 Finance (budgets, invoicing, payments & approvals). The Finance module stores budgets, line items, invoices, payments, payouts, disputes, memberships and related dashboard data. Where an Organization invoices and collects from its own clients, we use Stripe and Stripe Connect to process payments. Card details are handled by Stripe; we do not store full payment card numbers — we retain only limited payment metadata such as card brand, the last four digits and the expiry. Where the Finance module uses magic-link approvals, the approval page (at /approve/[token]) records the approver’s email address, IP address and browser user-agent in an immutable approvals audit log, to evidence who approved what and when.

3.4 Data (custom tables & charts). The Data module lets an Organization build custom tables and charts. Any Personal Information the Organization enters into those tables is collected and stored as Content under the Organization’s control.

3.5 Forms (published forms & submissions). When an Organization publishes a form (at a public URL under /f/[id]), anyone — including individuals without an account — may submit it. We collect the answers provided and the submitter’s email address, and store them for the publishing Organization. Unless the Organization switches receipts off for that form, we email the submitter a copy of their own answers, with a PDF of the submission attached, through our email provider (see Section 6.2).

3.6 Gigs & Events (day sheets, intake & RSVP). For gigs and events, including the public day-sheet (/gig/[token]) and intake/join (/gig/join) flows, we may collect, on behalf of the Organization, an attendee’s name, email address and role; RSVP status and plus-ones; dietary requirements; travel details such as flights and hotels; call times; and rider files uploaded in connection with the gig.

3.7 Profile & gig profiles. An individual profile or gig profile (at /profile, and updatable via a link at /update-profile/[token]) may include a designation, biography, headshot, e-transfer email, social links, rate cards and contractor agreements. The e-transfer email is treated as private. The Service does not currently publish profiles on a public page or in a public directory.

3.8 Account, security & technical information. Across the Service we also collect:

  • authentication information, including the email address used to sign in and authenticate (including via magic link);
  • IP address and browser user-agent, which are captured and retained in the immutable approvals audit log when an external party uses an approval magic link, as described above;
  • usage and log data generated as you use the Service, including event, diagnostic and error information used for security and to operate the Service, and page-view analytics (the page visited, the referring page, and general browser, device and approximate-location information) recorded through Vercel Web Analytics;
  • email delivery records: when the Service emails someone on an Organization’s behalf, we keep the recipient’s address, the subject and whether the message was delivered, bounced or reported as spam, and an address that bounces or complains is recorded so that the Service stops mailing it; and
  • cookies and similar identifiers, as described in Section 12 and in our Cookie Policy.

3.9 Notifications. The Service maintains an in-app notification inbox. Notification records may contain Personal Information within their title or message — for example, the name of a person associated with an approval request, a gig RSVP, or a contractor-pipeline change — and are stored for the recipient and their Organization.

3.10 Requests for access. The Service is available by invitation. When someone asks for access from our website, we collect the email address they enter and store it with the status of the request (new, invited, declined or archived). We email a notice of the request, including that address, to our own support inbox so that we can reply. We use the address only to reply about access and to decide whether to send an invitation.

// In plain terms — Most of what GIG stores is information that an Organization enters about the people it works with. We hold relatively little about you directly beyond a sign-in email, billing metadata, and the technical and security records (including the IP address and device details we log when someone clicks an approval link).

04How we use personal information

We identify the purposes for which we collect Personal Information at or before the time of collection. We use Personal Information for the following purposes:

  • To operate and deliver the Service, including the Entity, Architect, Finance, Data, Forms, Gigs/Events, Profile and notification features described in Section 3 — for example, to display contacts, render projects and published pages, generate invoices and process payments, accept and route form submissions, organize gig day sheets and intake, and maintain profiles and rate cards;
  • To administer accounts and billing, including provisioning Organizations and member roles, calculating the subscription fee for the Organization’s plan, processing payments, renewals and cancellations through Stripe, and managing Stripe Connect payouts;
  • For security, fraud prevention and audit, including authenticating users, enforcing tenant isolation, detecting and preventing misuse, and maintaining the immutable approvals audit log (including approver email, IP address and user-agent);
  • To provide support and respond to requests, including responding to inquiries and troubleshooting issues;
  • To communicate with you, including sending transactional and service-related messages such as authentication and magic-link emails, approval and profile-update links, billing notices and important Service announcements;
  • To answer requests for access made from our website, as described in Section 3.10;
  • To maintain, improve and secure the Service, including reviewing the error and request logs kept by our hosting provider, the diagnostics attached to support requests, and page-view analytics; and
  • To comply with legal obligations and to establish, exercise or defend legal claims.

We will not use Personal Information for a new purpose that is materially different from those identified above without first identifying that purpose and obtaining consent, except where permitted or required by law.

06How we share information

We do not sell Personal Information. We disclose Personal Information only as described in this Policy:

6.1 At your direction — Organizations and recipients of links and published pages. The Service is designed to share information at the direction of users and Organizations. Information you place in the Service may be visible to the Organization and to the members and roles within it that have access, and to the recipients of links and pages you choose to share — including recipients of magic-link approval requests, profile-update links, gig day-sheet and intake links, and anyone with the URL of a published page or public form (see Section 11).

6.2 Service providers (sub-processors). We engage trusted service providers to process Personal Information on our behalf, under contractual terms requiring them to protect it and to use it only for the purposes for which we engage them. Our current sub-processors are:

  • Supabase — managed database (Postgres), authentication and file storage, and delivery of authentication and magic-link emails. Hosted in the United States (regions us-east-2 and us-west-2). See supabase.com/privacy.
  • Stripe and Stripe Connect — payment, subscription and invoicing processing, and Stripe Connect payouts. Card details are handled by Stripe; we store only limited card metadata (brand, last four digits, expiry). See stripe.com/privacy.
  • Vercel — application hosting and content delivery, the request and error logs that come with hosting, and Vercel Web Analytics, which records page views across the Service (United States and global edge infrastructure). See vercel.com/legal/privacy-policy.
  • Resend — delivery of the email the Service sends on an Organization’s behalf, such as approval requests, profile-update links, invoice reminders and form receipts, and of the notice we send ourselves when someone asks for access. Resend receives each recipient’s address and the message, including any attachment — a form receipt carries a PDF of the submitter’s answers. Processed in the United States. See resend.com/legal/privacy-policy.
  • Typewire — hosting of the mailboxes behind the addresses we publish on thegigapp.ca, such as support@thegigapp.ca and privacy@thegigapp.ca. An email you send us, and anything in it, is received and stored there.
  • GitHub — our issue tracker. When you send a support request from inside the Service, what you wrote, the page you were on, and your Organization’s name and your role in it are filed there so that we can track the fix. Hosted in the United States.

We maintain accountability for Personal Information transferred to these providers for processing, and we require comparable protection by contract. The sub-processors that process Personal Information on an Organization’s behalf are also listed in our Data Processing Addendum, and we will provide notice of material changes consistent with that addendum.

6.3 Legal and safety. We may disclose Personal Information where we reasonably believe it is required or permitted by law — for example, to comply with a subpoena, court order or other lawful request, to enforce our agreements, to protect the rights, property or safety of GIG, our users or others, or to prevent or investigate fraud or a security incident.

6.4 Business transfers. If we are involved in a merger, acquisition, financing, reorganization, sale of assets, or insolvency, Personal Information may be transferred or disclosed as part of, or in contemplation of, that transaction, subject to the recipient agreeing to protect it on terms consistent with this Policy and applicable law.

07Cross-border transfer & data location

The Service relies on sub-processors named in Section 6 that store and process Personal Information outside Canada, including in the United States — Supabase (United States regions us-east-2 and us-west-2), Stripe (United States), Vercel (United States and global edge infrastructure), Resend (United States) and GitHub (United States). By using the Service and providing Personal Information, you acknowledge and consent to this transfer and to the storage and processing of Personal Information outside Canada.

While Personal Information is located in a foreign jurisdiction, it may be subject to the laws of that jurisdiction, including lawful access by courts, law enforcement and government authorities of that jurisdiction (for example, under United States legal process), regardless of the safeguards we put in place. We require our service providers, by contract, to provide a comparable level of protection to the Personal Information they process for us.

// In plain terms — GIG’s data lives mainly on United States servers run by our providers (Supabase, Stripe, Vercel), and the email we send for you goes out through Resend, also in the United States. That means a United States court or government could, in principle, compel access to it under United States law — something no Canadian provider can fully prevent. By using GIG, you agree to your information being stored and processed in the United States.

08Retention & deletion

We retain Personal Information for as long as the relevant account or Organization is active and as needed to fulfil the purposes described in this Policy, and thereafter only as necessary to meet legal, audit, tax, accounting or security obligations, or to establish, exercise or defend legal claims. Retention behaves differently depending on the data:

  • Soft deletion. Certain records — such as subscriptions and memberships — are deactivated by status (soft-deleted) rather than immediately erased, so that the account can be restored and so that we can meet billing and audit obligations.
  • Cascading hard deletion. When an Organization is deleted (by a platform administrator) or an account is deleted, associated Content is hard-deleted on a cascading basis, subject to the exceptions below and to backups described below.
  • Immutable audit logs. The approvals audit log is append-only and is retained as a permanent, tamper-evident record; entries (including approver email, IP address and user-agent) are not individually deletable, as they exist to evidence financial approvals.
  • Form submissions and notifications are retained until deleted by the owning Organization.
  • Email delivery records are kept with the sending Organization’s data and are deleted when the Organization is deleted.
  • Requests for access made from our website are kept, with their outcome, so that we can see whether we have already answered someone. We do not currently delete them automatically; ask our Privacy Officer and we will delete yours.
  • Backups. Our database provider maintains backups for resilience; information may persist in backups for a limited period after deletion before being overwritten in the ordinary course.

To request deletion of Personal Information, contact our Privacy Officer at privacy@thegigapp.ca, or, where the information was provided to an Organization through the Service, the relevant Organization. We will respond consistent with Section 10 and applicable law, and we may retain information we are required or permitted by law to keep.

09Safeguards

We protect Personal Information with security safeguards appropriate to its sensitivity, including organizational, technical and physical measures. These include:

  • Tenant isolation and access controls, including database row-level security so that each Organization’s data is logically separated and access is restricted to authorized users and roles;
  • Encryption in transit, using industry-standard transport encryption (HTTPS/TLS) for data moving between you and the Service;
  • No stored payment credentials, because an Organization’s Stripe account is connected through Stripe Connect and we act on it with our own platform key, keeping only the connected account’s identifier; the Service’s own secrets and API keys are held in our hosting provider’s environment configuration, not in the database;
  • Time-limited and scoped links, using random, app-enforced expiry on magic-link tokens (for example, profile-update links expiring 24 hours after they are generated and gig day-sheet links expiring after the gig), with approval links bound to a session; and
  • Logs and vendor diligence, including review of the error and request logs kept by our hosting provider, and contractual safeguards with the sub-processors named in Section 6.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Files uploaded to public storage buckets (such as headshots, Organization logos and gig rider files) may be served by public or signed URLs and may be accessible to anyone who has the corresponding link (see Section 11).

10Your rights

We rely on you and Organizations to provide accurate information, and we take reasonable steps to keep Personal Information as accurate, complete and up to date as is necessary for the purposes for which it is used. Subject to applicable law, you have the following rights with respect to your Personal Information:

  • Access. You may request confirmation of whether we hold Personal Information about you, a copy of that information, and information about how it has been and may be used and disclosed.
  • Correction. You may request correction of inaccurate or incomplete Personal Information; where appropriate, we will amend it or note the disagreement.
  • Withdrawal of consent. You may withdraw consent as described in Section 5, subject to legal and contractual restrictions.

To exercise these rights, contact our Privacy Officer at privacy@thegigapp.ca. We will respond to access requests generally within 30 days of receiving a request and any required verification of identity, at little or no cost; where we require additional time or must refuse a request in whole or in part, we will tell you and explain our reasons and your recourse. Where the Personal Information was provided to an Organization through the Service and we act only as its processor, we will refer you to, or direct your request to, that Organization, which is responsible for responding.

// In plain terms — You can ask us what personal information we hold about you, get a copy, and have mistakes fixed — usually within 30 days, at little or no cost. If the data was entered by an Organization that uses GIG, we may point you to that Organization, since it controls that data.

11Public information

Several features of the Service are designed to be publicly accessible by anyone who has the relevant link or URL, without an account and without authentication. Information made available through these features can be viewed, copied or shared by recipients, and we cannot control what they do with it. These features include:

  • Published Architect pages at /p/[slug] (read-only share links, marked not to be indexed by search engines);
  • Published wikis at /wiki/[slug] (read-only, and — unless the Organization turns indexing off for that Cluster — offered to search engines, so copies may be cached by third parties and persist after unpublishing);
  • Public forms at /f/[id]; and
  • Gig day-sheet links at /gig/[token] and gig intake/join links.

You should only publish or share Personal Information through these features if you have the right to do so, and you should treat any link to a public page as something that may be forwarded beyond the people you originally intended.

12Cookies & similar technologies

We and our service providers use cookies and similar technologies that are necessary to authenticate users and maintain sessions, and, where applicable, to understand and improve how the Service is used — including Vercel Web Analytics, which counts page views. For details about the cookies we use, their purposes and duration, and how to manage your preferences, please see our Cookie Policy.

13Children

The Service is a business tool intended for use by organizations and adults, and is not directed to children. We do not knowingly collect Personal Information from individuals under the age of 16. If you believe a child has provided Personal Information to us, please contact our Privacy Officer at privacy@thegigapp.ca and we will take reasonable steps to delete it, unless we are required to retain it by law.

14Data breach notification

We maintain processes to detect, assess and respond to security incidents involving Personal Information. Where a breach of security safeguards creates a real risk of significant harm to an individual, we will report the breach to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible, consistent with PIPEDA, and will notify other organizations or institutions that may be able to mitigate the harm. We will keep records of breaches of security safeguards as required by law.

Where we act as a processor for an Organization (see Section 2), we will notify that Organization of a security incident affecting its data without undue delay so that it can meet its own notification obligations, as further described in our Data Processing Addendum.

Reporting an incident to us. If you believe Personal Information has been exposed, or you have found a vulnerability that could expose it, report it to security@thegigapp.ca. Our machine-readable disclosure details are published at /.well-known/security.txt. Reports reach us fastest at that address; a report sent anywhere else still reaches us, but a security address is monitored as one.

15Quebec & other provinces

In addition to PIPEDA, provincial privacy laws may apply to individuals located in certain provinces. In particular, Quebec’s Act respecting the protection of personal information in the private sector (as amended, commonly referred to as “Law 25”) imposes additional requirements where Personal Information of individuals in Quebec is involved, including in relation to transfers of Personal Information outside Quebec. We endeavour to handle Personal Information in a manner consistent with applicable provincial requirements. Individuals in Quebec or other provinces with specific questions may contact our Privacy Officer at privacy@thegigapp.ca.

16Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices, the Service, our service providers, or the law. When we make material changes, we will revise the effective date shown above and, where appropriate, provide additional notice. The law governing privacy in Canada continues to evolve, and we will update this Policy as needed to reflect changes in applicable legislation. Your continued use of the Service after an update takes effect constitutes acceptance of the updated Policy, except where additional consent is required by law.

17How to contact us & the OPC

If you have a question, request or complaint about this Policy or our handling of Personal Information, please contact our Privacy Officer first so that we have an opportunity to address it:

  • Privacy Officer, The Gig App
  • Privacy email: privacy@thegigapp.ca
  • General email: support@thegigapp.ca

If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada (the “OPC”):

  • Office of the Privacy Commissioner of Canada
  • 30 Victoria Street, Gatineau, Quebec K1A 1H3
  • Toll-free: 1-800-282-1376
  • Website: www.priv.gc.ca

Depending on your province, you may also have recourse to a provincial privacy regulator, such as the Commission d’accès à l’information du Québec for individuals in Quebec.