GigAway

Privacy Policy

Effective: 2 September 2026 Last updated: 2 September 2026


1. Who is responsible for your data

The controller of your personal data under the GDPR is:

Mohamed Aziz Talbi Schlörstr. 6 80634 München Germany

Email: privacy@gigaway.app

You can reach a human at that address for any question about your data, including to exercise the rights described in section 9.


2. What GigAway is

GigAway is an invite-only app for professional performing artists who travel for auditions, competitions and guest contracts. Members post trips and availability, find verified colleagues in a city, and arrange informal hospitality — a couch, local knowledge, or company.

No money changes hands in the app. GigAway is not a party to any stay, does not provide accommodation, and takes no fee.

Membership is restricted to verified artists. Until your profile is approved, the database returns no member content to you at all.


3. What we collect, and why

3.1 Your profile

Data Why Lawful basis
Display name So colleagues know who they are talking to Contract
Discipline and specialisation Matching, and establishing professional standing Contract
Home city and district Showing you people in your city, and you to them Contract
Short biography Letting others decide whether to host or stay with you Contract
Profile photo The same Contract
Professional links Evidence of professional standing Contract

The district is free text and deliberately coarse. GigAway never asks for or stores your street address.

3.2 Contact details

Email address, phone number and WhatsApp number, plus which of those you prefer.

These are held separately from your profile and are not visible to other members by default. They are disclosed to one other member only when a stay is agreed — see section 5.

Lawful basis: contract.

3.3 Getting in: invites and verification

There are two routes into GigAway, and each collects something.

By invite. We record which member invited you, and when the invite was redeemed. This chain is permanent — see section 7.

By document review. If you apply without an invite, you submit a note, professional links, and supporting documents such as a CV, proof of conservatory enrolment, or performance recordings.

Documents are handled deliberately:

Lawful basis: contract, and our legitimate interest in a verified community.

3.4 What you post

Trips (destination city, dates, what you are looking for, an optional note), availability (city, date ranges, what you offer, maximum nights, household constraints such as no smoking or no pets, an optional note), requests and offers including any message you write, and agreed stays.

Lawful basis: contract.

3.5 Reviews

After a stay, both parties may leave a review: a yes/no answer to whether they would do it again, plus optional text. Reviews are double-blind — neither side sees the other's until both have submitted, or until 14 days have passed.

Lawful basis: legitimate interest in a community where reputation carries weight.

3.6 Safety: blocks and reports

You can block another member, which makes you mutually invisible. You can report a member, choosing a category (safety, harassment, no-show, misrepresentation, spam, other) and writing a description.

Reports are private. The reported person is never shown the report or told who made it.

Lawful basis: legitimate interest in member safety. This is the interest that justifies retaining reports even after an account is deleted — see section 7.

3.7 Notifications

If you enable push notifications we store a device push token and the platform it belongs to. We also record the notifications we send you and whether you have read them.

Lawful basis: contract.

3.8 Crash reports and analytics

Crash reports (Sentry) are collected to find and fix faults. Lawful basis: legitimate interest.

Product analytics (PostHog) are collected only with your consent, and are switched off entirely unless you opt in.

3.9 What we do not collect

GigAway does not collect or store:

No special category data under Article 9 GDPR is collected.


4. Where your data lives

All member data is stored in the European Union, in Frankfurt, Germany, on infrastructure operated by Supabase.


5. When contact details are revealed

This is the one moment GigAway discloses your contact details to another member.

When an offer is accepted, or a co-accommodation request is agreed, the two members involved are granted access to each other's email address and WhatsApp number. Both sides see each other's — the exchange is symmetrical.

Nothing is revealed before that point. Browsing a profile, sending a request, or receiving an offer discloses nothing.

If you later delete your account, that access is removed.


6. Who else processes your data

Processor Purpose Location
Supabase Database, authentication, file storage EU (Frankfurt)
Expo Push notification delivery USA
Sentry Crash reporting EU
PostHog Product analytics (only with consent) EU
Resend Transactional email USA
Vercel Website hosting USA / global
Apple App distribution, push delivery on iOS USA
Google App distribution, push delivery on Android USA

International transfers. Expo, Resend, Vercel, Apple and Google process data in the United States. These transfers rely on the European Commission's Standard Contractual Clauses, and where applicable the EU–US Data Privacy Framework.

We do not sell your data. We do not share it for advertising. There is no advertising in GigAway.


7. How long we keep things

Data Retention
Profile and posts Until you delete your account
Contact details Until you delete your account
Verification documents Deleted on decision; 90-day backstop if undecided
Unused invites Expire after 30 days
Invite chain Permanent, including after account deletion
Trips, availability, requests, offers Until deleted, or until the account is deleted
Stays Retained after deletion — they are the other person's record
Reviews you wrote, published Retained, shown as written by "Deleted member"
Reviews about you Deleted with your account
Reports Retained after deletion, in both directions
Blocks you created Deleted with your account
Blocks against you Retained
Push tokens, notifications Deleted with your account

Why some things survive deletion

Three retentions are deliberate, and we want to be direct about them.

Reports. If deleting an account erased the reports made about it, anyone could clear their safety record by deleting and rejoining. Reports are kept, and point at an anonymised record rather than at you.

Published reviews you wrote. If these vanished, deleting and rejoining would launder reputation in the other direction. They stay, attributed to "Deleted member".

Blocks made against you. If these were removed, someone who blocked you for a reason would be silently re-exposed to you if you rejoined.

Legal basis for all three: our legitimate interest, and the legitimate interests of other members, in a community where safety records and reputation cannot be erased by leaving and returning. You may object under Article 21 GDPR (section 9).


8. What deletion actually does

Deleting your account is irreversible. When you do:

Permanently erased: your login and password, email address, phone and WhatsApp numbers, profile photo, biography, specialisation, home city and district, professional links, verification application and any documents, push tokens, notification history, contact-sharing grants, blocks you created, reviews written about you, unpublished reviews you wrote, pending requests and offers, your availability, and trips that never led to a stay.

Retained, no longer linked to you: your profile becomes an anonymised record showing "Deleted member". Stays you took part in, published reviews you wrote, reports in both directions, blocks made against you, and your position in the invite chain all survive and point at that anonymised record. Trips that produced a stay survive as dates and a city, with your notes removed.

You can never sign in again, and the account cannot be restored.


9. Your rights

Under the GDPR you have the right to:

A limit on the export you should know about. The export deliberately excludes reports, in both directions. Returning reports you filed would reveal which counterparties you raised concerns about; returning reports about you would expose who reported you. Either would destroy the private reporting channel that makes the community safe. Unpublished reviews are excluded for the same reason — an export must not be a way around the double-blind window.

If you want to exercise a right the app does not cover, email privacy@gigaway.app. We respond within 30 days.

Right to complain. You may lodge a complaint with a supervisory authority. Ours is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), and you may also complain to the authority where you live.


10. Security

Data is encrypted in transit and at rest. Access is enforced at the database level by row-level security, not only in the app — an unapproved or suspended account receives no member content even if the interface were bypassed. Contact details are readable only by someone holding an explicit grant.


11. Children

GigAway is for professional and pre-professional performing artists and is not intended for anyone under 18. We do not knowingly collect data from children.


12. Changes

If we change this policy materially we will notify you in the app before the change takes effect. The date at the top always reflects the current version.


13. Contact

Mohamed Aziz Talbi Schlörstr. 6, 80634 München, Germany privacy@gigaway.app