Privacy Policy
Effective: 2 September 2026 Last updated: 2 September 2026
1. Who is responsible for your data
The controller of your personal data under the GDPR is:
Mohamed Aziz Talbi Schlörstr. 6 80634 München Germany
Email: privacy@gigaway.app
You can reach a human at that address for any question about your data, including to exercise the rights described in section 9.
2. What GigAway is
GigAway is an invite-only app for professional performing artists who travel for auditions, competitions and guest contracts. Members post trips and availability, find verified colleagues in a city, and arrange informal hospitality — a couch, local knowledge, or company.
No money changes hands in the app. GigAway is not a party to any stay, does not provide accommodation, and takes no fee.
Membership is restricted to verified artists. Until your profile is approved, the database returns no member content to you at all.
3. What we collect, and why
3.1 Your profile
| Data | Why | Lawful basis |
|---|---|---|
| Display name | So colleagues know who they are talking to | Contract |
| Discipline and specialisation | Matching, and establishing professional standing | Contract |
| Home city and district | Showing you people in your city, and you to them | Contract |
| Short biography | Letting others decide whether to host or stay with you | Contract |
| Profile photo | The same | Contract |
| Professional links | Evidence of professional standing | Contract |
The district is free text and deliberately coarse. GigAway never asks for or stores your street address.
3.2 Contact details
Email address, phone number and WhatsApp number, plus which of those you prefer.
These are held separately from your profile and are not visible to other members by default. They are disclosed to one other member only when a stay is agreed — see section 5.
Lawful basis: contract.
3.3 Getting in: invites and verification
There are two routes into GigAway, and each collects something.
By invite. We record which member invited you, and when the invite was redeemed. This chain is permanent — see section 7.
By document review. If you apply without an invite, you submit a note, professional links, and supporting documents such as a CV, proof of conservatory enrolment, or performance recordings.
Documents are handled deliberately:
- They are used only to confirm professional standing.
- A human reads every application. There is no automated decision-making.
- Documents are deleted immediately when a decision is made, whether you are approved or rejected.
- Applications never decided are purged automatically after 90 days.
- We do not ask for, and do not accept, government ID documents. If you send one anyway, we delete it.
Lawful basis: contract, and our legitimate interest in a verified community.
3.4 What you post
Trips (destination city, dates, what you are looking for, an optional note), availability (city, date ranges, what you offer, maximum nights, household constraints such as no smoking or no pets, an optional note), requests and offers including any message you write, and agreed stays.
Lawful basis: contract.
3.5 Reviews
After a stay, both parties may leave a review: a yes/no answer to whether they would do it again, plus optional text. Reviews are double-blind — neither side sees the other's until both have submitted, or until 14 days have passed.
Lawful basis: legitimate interest in a community where reputation carries weight.
3.6 Safety: blocks and reports
You can block another member, which makes you mutually invisible. You can report a member, choosing a category (safety, harassment, no-show, misrepresentation, spam, other) and writing a description.
Reports are private. The reported person is never shown the report or told who made it.
Lawful basis: legitimate interest in member safety. This is the interest that justifies retaining reports even after an account is deleted — see section 7.
3.7 Notifications
If you enable push notifications we store a device push token and the platform it belongs to. We also record the notifications we send you and whether you have read them.
Lawful basis: contract.
3.8 Crash reports and analytics
Crash reports (Sentry) are collected to find and fix faults. Lawful basis: legitimate interest.
Product analytics (PostHog) are collected only with your consent, and are switched off entirely unless you opt in.
3.9 What we do not collect
GigAway does not collect or store:
- Your street address
- Government identity documents
- Payment or bank details — there are no payments in the app
- Precise device location — cities are chosen from a list, never sensed
- Gender, health, ethnicity, religion, political opinions, or sexual orientation
No special category data under Article 9 GDPR is collected.
4. Where your data lives
All member data is stored in the European Union, in Frankfurt, Germany, on infrastructure operated by Supabase.
5. When contact details are revealed
This is the one moment GigAway discloses your contact details to another member.
When an offer is accepted, or a co-accommodation request is agreed, the two members involved are granted access to each other's email address and WhatsApp number. Both sides see each other's — the exchange is symmetrical.
Nothing is revealed before that point. Browsing a profile, sending a request, or receiving an offer discloses nothing.
If you later delete your account, that access is removed.
6. Who else processes your data
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | EU (Frankfurt) |
| Expo | Push notification delivery | USA |
| Sentry | Crash reporting | EU |
| PostHog | Product analytics (only with consent) | EU |
| Resend | Transactional email | USA |
| Vercel | Website hosting | USA / global |
| Apple | App distribution, push delivery on iOS | USA |
| App distribution, push delivery on Android | USA |
International transfers. Expo, Resend, Vercel, Apple and Google process data in the United States. These transfers rely on the European Commission's Standard Contractual Clauses, and where applicable the EU–US Data Privacy Framework.
We do not sell your data. We do not share it for advertising. There is no advertising in GigAway.
7. How long we keep things
| Data | Retention |
|---|---|
| Profile and posts | Until you delete your account |
| Contact details | Until you delete your account |
| Verification documents | Deleted on decision; 90-day backstop if undecided |
| Unused invites | Expire after 30 days |
| Invite chain | Permanent, including after account deletion |
| Trips, availability, requests, offers | Until deleted, or until the account is deleted |
| Stays | Retained after deletion — they are the other person's record |
| Reviews you wrote, published | Retained, shown as written by "Deleted member" |
| Reviews about you | Deleted with your account |
| Reports | Retained after deletion, in both directions |
| Blocks you created | Deleted with your account |
| Blocks against you | Retained |
| Push tokens, notifications | Deleted with your account |
Why some things survive deletion
Three retentions are deliberate, and we want to be direct about them.
Reports. If deleting an account erased the reports made about it, anyone could clear their safety record by deleting and rejoining. Reports are kept, and point at an anonymised record rather than at you.
Published reviews you wrote. If these vanished, deleting and rejoining would launder reputation in the other direction. They stay, attributed to "Deleted member".
Blocks made against you. If these were removed, someone who blocked you for a reason would be silently re-exposed to you if you rejoined.
Legal basis for all three: our legitimate interest, and the legitimate interests of other members, in a community where safety records and reputation cannot be erased by leaving and returning. You may object under Article 21 GDPR (section 9).
8. What deletion actually does
Deleting your account is irreversible. When you do:
Permanently erased: your login and password, email address, phone and WhatsApp numbers, profile photo, biography, specialisation, home city and district, professional links, verification application and any documents, push tokens, notification history, contact-sharing grants, blocks you created, reviews written about you, unpublished reviews you wrote, pending requests and offers, your availability, and trips that never led to a stay.
Retained, no longer linked to you: your profile becomes an anonymised record showing "Deleted member". Stays you took part in, published reviews you wrote, reports in both directions, blocks made against you, and your position in the invite chain all survive and point at that anonymised record. Trips that produced a stay survive as dates and a city, with your notes removed.
You can never sign in again, and the account cannot be restored.
9. Your rights
Under the GDPR you have the right to:
- Access your data — the app has a built-in export
- Rectify anything inaccurate — editable in your profile
- Erase your account — built into the app, described in section 8
- Port your data — the export is machine-readable
- Object to processing based on legitimate interest, including the retentions in section 7
- Restrict processing while a dispute is resolved
- Withdraw consent for analytics at any time, without affecting anything else
A limit on the export you should know about. The export deliberately excludes reports, in both directions. Returning reports you filed would reveal which counterparties you raised concerns about; returning reports about you would expose who reported you. Either would destroy the private reporting channel that makes the community safe. Unpublished reviews are excluded for the same reason — an export must not be a way around the double-blind window.
If you want to exercise a right the app does not cover, email
privacy@gigaway.app. We respond within 30 days.
Right to complain. You may lodge a complaint with a supervisory authority. Ours is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), and you may also complain to the authority where you live.
10. Security
Data is encrypted in transit and at rest. Access is enforced at the database level by row-level security, not only in the app — an unapproved or suspended account receives no member content even if the interface were bypassed. Contact details are readable only by someone holding an explicit grant.
11. Children
GigAway is for professional and pre-professional performing artists and is not intended for anyone under 18. We do not knowingly collect data from children.
12. Changes
If we change this policy materially we will notify you in the app before the change takes effect. The date at the top always reflects the current version.
13. Contact
Mohamed Aziz Talbi
Schlörstr. 6, 80634 München, Germany
privacy@gigaway.app