Privacy Policy
Gig Pool Pty Ltd · Last updated: 9 September 2026
1. About this policy
This privacy policy explains how Gig Pool Pty Ltd (“Gig Pool”, “we”, “us”, “our”) collects, uses, stores, discloses, and protects your personal information when you use the Gig Pool platform at gigpool.app (“the Platform”), including our website, progressive web application (PWA), email notifications, and related services.
Gig Pool is an artist booking and rostering platform that connects performers, booking agents, and entertainment venues. We are committed to handling your personal information responsibly and in accordance with the Australian Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs). Where we provide services to users in the United Kingdom or European Economic Area, we also comply with the UK GDPR and EU GDPR respectively.
Our primary database, file storage, and authentication infrastructure are hosted in the Sydney region of Australia. Some supporting services are located overseas; section 6 sets out the full picture.
We encourage you to read this policy carefully. By using the Platform, you acknowledge that you have read and understood this policy. If you do not agree with our practices, please do not use the Platform.
2. What personal information we collect
The types of personal information we collect depend on how you use the Platform and which role you hold (performer, account owner, venue booker, venue viewer, support agent, or visitor).
Information you provide directly
Account registration: name, email address, password, role selection (performer or venue booker), and country of operation.
Performer profile information: stage name, biography, profile photo, genre preferences, vibe/energy level selections, social media and audio platform links, availability schedule, and performance rates.
Act details you enter during onboarding: the facts you state about your act, including the band style or the artist you pay tribute to, the instruments you play, whether you bring your own PA or amplification, your typical set structure, whether you use backing tracks, your line-up size, and a short free-text description of up to 120 characters. These appear on your public profile and on Gig Pool discovery surfaces when your profile is discoverable. If you are a band, the names you enter for your members are also held and shown on your profile, so tell your members before you add them.
Business and tax information: Australian Business Number (ABN), tax identification numbers for other jurisdictions (such as VAT numbers, EIN, IRD numbers, NIF, or other local equivalents), entity type (sole trader, company, partnership, trust), Goods and Services Tax (GST) or Value Added Tax (VAT) registration status, business name, and any tax rate you enter. For Australian artists, an optional Australian Business Register (ABR) lookup may retrieve public entity and GST registration details when that feature is available. Other tax identification numbers are not verified by Gig Pool.
Venue information: venue name, address (including country, and state or province where applicable), space names and descriptions, venue brief, genre preferences, contact details, and default performance rates.
Invoicing information: invoice line items, amounts, the tax rate and tax amount based on details you provide, payment terms, bank account details (if provided for payment instructions on invoices), and recipient details.
Superannuation details (Australian artists, optional): if you choose to add them, your superannuation fund details (fund name, fund ABN, Unique Superannuation Identifier, member number), your full legal name, date of birth, residential address, and, if you choose to provide it, your tax file number (TFN). We collect these so that venues and bookers who pay super for their artists can do so using accurate details, and only share them when you switch sharing on. Your TFN is encrypted before it is stored, using a key held outside our database; it is never shown in any screen, and it is included in a venue’s download when you have provided one, so the fund is not taxed at the no-TFN rate. Sharing covers your super details (your bank details are not shared here; they reach a venue on your invoice), is off until you turn it on, and you can turn it off at any time. Every venue view and download of your payment details, and every change to your sharing choice, is recorded. Deleting your super details, or your account, permanently deletes the stored TFN. TFN information is protected under the Privacy (Tax File Number) Rule 2015 in addition to the Privacy Act.
Communication data: messages sent through in-app chat (per-booking message threads and support conversations), file attachments shared in chat, support tickets, and any correspondence you send to us directly.
Guest artist details: if you are a venue booker, the name and email address of a guest artist you book who does not have a Gig Pool account. We hold these so the venue can communicate with that artist about the booking, and we email the artist on the venue’s behalf. If you are that guest artist, you can unsubscribe from those emails at any time using the link in each one, and your details are linked to your own account if you later sign up with the same email address.
External promoter contact details: if you are a venue booker and you mark a Space as unavailable because an outside promoter holds it, you can record that promoter’s name, email address, and phone number. That person may have no Gig Pool account. We hold these details so your team knows who has the Space, and we show them only on the surfaces that need them, never on a public page. Enter them only where you have a reason to, and tell the promoter you have done so.
Public booking enquiries: if you send an enquiry to an artist through their public profile, we store your name, email address, message, and any date or venue you propose, together with the IP address and browser details of the request. We use these to pass your enquiry to the artist by email and to limit misuse of the form. You do not need a Gig Pool account to send an enquiry.
Contact details: phone number (if provided for SMS notifications), email address, and postal address.
Notification preferences: push notification subscription data, SMS opt-in status, email category preferences, and quiet hours settings.
Information we collect automatically
Device and browser information: IP address, browser type and version, operating system, device type, screen resolution, and language settings.
Usage information: pages visited, features used, timestamps of actions, booking and invoicing activity, and a small set of typed product events (for example: signup completed, first invoice sent) recorded in our “product_events” log to help us understand activation and engagement at an aggregate level.
Authentication and security data: hashed password (bcrypt), two-factor authentication state, short-lived email verification codes (10-minute TTL, SHA-256 hashed and stored in “email_mfa_codes”), TOTP secret and single-use recovery codes (where you have enabled authenticator-app 2FA), and a signed “trusted device” cookie (HMAC-SHA256, 1-year TTL) that lets your device skip 2FA on future logins. Login timestamps, last-login-at, and account-status history are retained as part of our security and lifecycle audit trail.
Push notification data: when you subscribe to push notifications, we store the subscription endpoint URL and encryption keys required to send notifications to your device. We do not access the content of other notifications on your device.
Location information: we do not track your device’s location. Artists can enter the area they work in, such as a suburb or city. We send that text to Google Maps to turn it into approximate map coordinates, and we store those coordinates so venues can find artists within a distance of them. This happens whether you pick a suggestion or type the area yourself. We may also infer your approximate country from your IP address to suggest initial country and currency defaults, which you can review and change. Invoices use the country details you confirm.
Information from third parties
Calendar authentication: if you connect your Google Calendar account for real-time gig synchronisation, we receive an OAuth token that allows us to create and update calendar events on your behalf. We do not read your existing calendar events.
Australian Business Register lookup: if the optional lookup is available and you use it, we send the ABN you entered to the ABR and receive public registry details such as entity name, entity type, ABN status, and GST registration status.
Payment processing: if you purchase a subscription, an Event Subscription, or an Event Pass, our payment processor (Stripe) collects your payment card details directly. We do not store, process, or transmit full card numbers. We receive from Stripe your subscription status, payment history, last four digits and brand of your card for display purposes, and event-mirror records of refunds, disputes, and payment-method updates which we store to keep our billing state consistent with Stripe.
Sensitive information
We do not intentionally collect sensitive information as defined under section 6 of the Privacy Act (such as health information, racial or ethnic origin, political opinions, religious or philosophical beliefs, or sexual orientation). If you include sensitive information in free-text fields (such as your artist biography), you consent to us holding that information as part of your profile, and you may remove it at any time by editing your profile.
3. How we use your personal information
We use your personal information for the following purposes:
Providing the Platform: creating and managing your account, facilitating bookings between performers and venues, generating rosters and schedules, enabling in-app messaging and support, processing invoices, and synchronising gig schedules with your calendar.
Account communications: sending booking confirmations, gig reminders, fill-in opportunity alerts, invoice receipts, payment reminders, and lifecycle notices (such as trial-ending, payment-failed, inactivity, and account-deletion notices) via email, push notification, and (where you have opted in) SMS. Section 10 sets out which categories you can opt out of.
Authentication and account security: verifying logins, sending one-time codes for two-factor authentication, recognising trusted devices, detecting and preventing fraud, abuse, and unauthorised access, and enforcing our Terms of Service.
Country-aware invoice formatting: Gig Pool uses the country, registration details, and tax rate you provide to format invoice fields and labels and calculate draft totals. You are responsible for confirming whether you must register, which treatment applies, and what rate to use.
Optional ABN lookup: when available and used, displaying public registry information to help an Australian artist review the ABN they entered. The lookup does not confirm your tax treatment, replace professional advice, or guarantee that registry data is current.
Improving the Platform: analysing usage patterns and a small set of typed product events to identify bugs, improve features, and understand how users interact with the Platform. We use Vercel Analytics for aggregate web traffic data and Vercel Speed Insights for page performance measurements; both are privacy-focused and cookieless.
Finding and fixing faults: we use Sentry to record application errors and performance traces so we can diagnose faults. Section 8 sets out the controls we apply to what those error reports contain.
Customer support: responding to your enquiries, resolving disputes, and providing technical assistance. Support agents may see your name and conversation history when handling your ticket.
Legal and regulatory compliance: meeting our obligations under Australian law, including tax record-keeping requirements, responding to lawful requests from regulatory authorities, and protecting our legal rights.
4. Legal basis for processing (UK and EEA users)
If you are located in the United Kingdom or European Economic Area, we process your personal information on the following legal bases under the UK GDPR or EU GDPR:
Performance of a contract (Article 6(1)(b)): processing necessary to provide the Platform services you have signed up for, including account management, booking facilitation, invoice generation, and notifications related to your bookings.
Legitimate interests (Article 6(1)(f)): processing necessary for our legitimate business interests, including improving the Platform, ensuring security, preventing fraud, providing customer support, and giving you reasonable notice before any account is deleted for inactivity. We balance these interests against your rights and freedoms.
Legal obligation (Article 6(1)(c)): processing necessary to comply with legal obligations, including tax record-keeping, responding to lawful data requests, and meeting our obligations under the Privacy Act, GDPR, or other applicable laws.
Consent (Article 6(1)(a)): where we rely on your consent (such as for SMS notifications, marketing communications, or product-update emails to dormant accounts), you may withdraw your consent at any time through your account settings or by contacting us.
5. How we share your personal information
We do not sell your personal information. We share it only in the circumstances below.
Between platform users
Discoverable performer profiles: if you make your artist profile discoverable, it is public on the web and may appear in Gig Pool discovery and search-engine results. Your stage name, biography, profile photo, genres, vibe selections, and availability may appear there. Availability is shown by default, and you can turn it off. Your standard rates are shown to signed-in venue bookers on Gig Pool wherever you are presented, including your public profile and both discovery surfaces. The rates toggle controls whether your rates are published to the open web, and you separately control whether your phone number and email address appear. Your profile can also show the venues you have played, built from confirmed past bookings; this is off unless you turn it on. That choice covers your own profile. It does not cover a venue publishing its own line-up: if a venue shares a public roster link, that page may name you alongside the venue and date. Earnings and invoice history are not public. Search engines may retain a cached copy after you hide or change a profile.
Contact details (email and phone): on your public profile, your contact email and phone appear only when you enable the corresponding visibility toggle. Your contact email is gated by click-to-reveal; a separate booking email, if you choose to publish one, appears as a plain email link. Within a Venue account, its owner may hide artist contact details from non-owner team members. That account setting does not change what you separately choose to publish on the public web. Bookers can still reach you in-app through Gig Pool chat.
Venue information: venue name, address, space details, and venue briefs are visible to artists in the booker’s artist pool.
Booking details: when a booking is confirmed, the artist and the venue booker can see each other’s relevant contact and booking information within the Platform.
Guest artists reached by email: when a venue books an artist who does not have a Gig Pool account, we send that artist transactional emails on the venue’s behalf about the booking (for example, the gig brief or a set-time change), with the sender clearly identified and a working unsubscribe link in every email. We do this only for an artist the venue has actually booked, never an arbitrary address.
Invoices: when you send an invoice through the Platform, the recipient (venue) receives the invoice containing your name, address, ABN or tax ID, and payment details as included by you.
With service providers
We use third-party service providers to operate the Platform. They process information on our behalf under contractual obligations to protect it:
• Supabase: database hosting, authentication, file storage (chat attachments), real-time messaging (Sydney, Australia)
• Vercel: web application hosting, edge network, serverless functions (primary region: Sydney; static assets served from Vercel’s global edge network)
• Cloudflare R2: two separate uses (United States by default). First, a public content delivery mirror of profile photos. Second, a private backup store holding a nightly copy of the files kept in Supabase Storage, such as artist photos, press-kit images, and chat attachments. Every file in the backup store is encrypted before it is uploaded, using a key held outside that store
• Stripe: subscription billing, payment processing (United States)
• Resend: transactional email delivery (United States)
• Sentry: application error and performance monitoring (United States)
• Cellcast: SMS notifications, Australian numbers (Australia). Not currently active
• Twilio: SMS notifications, international numbers (United States). Not currently active
• Australian Business Register: optional ABN lookup (Australia)
• Google: Calendar integration, only if you connect it, and the Google Geocoding API to turn an area you type into approximate map coordinates (United States)
For legal reasons
We may disclose your personal information if required or permitted to do so by law, including in response to a court order, subpoena, or lawful request from a government authority, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
Business transfers
If Gig Pool is involved in a merger, acquisition, or sale of assets, your personal information may be transferred as part of that transaction. We will notify you of any such transfer and any choices you may have regarding your information.
6. Overseas disclosure
Some of our service providers are located outside Australia. By using the Platform, you acknowledge that your personal information may be transferred to, stored, and processed in:
• The United States: Stripe (billing data), Resend (email metadata and content), Sentry (application error and performance reports), Cloudflare R2 (profile photos on the public mirror, and the encrypted nightly backup of files kept in Supabase Storage), Google (Calendar, only if you connect it, and the area an artist enters on their profile), and Twilio (international SMS, not currently active).
• Other countries: Vercel’s edge network may serve cached static content from regional points of presence outside Australia. No personal information is stored at the edge; it is only transited.
Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure that the recipient does not breach the Australian Privacy Principles in relation to that information, in accordance with APP 8. This includes entering into contractual arrangements (typically each provider’s Data Processing Addendum) that require the recipient to handle your information in accordance with standards substantially similar to the APPs.
For users in the United Kingdom or European Economic Area, transfers of personal data outside the UK or EEA are made in compliance with Chapter V of the UK GDPR or EU GDPR, using appropriate safeguards such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum where applicable.
7. Account retention and deletion
We retain your data while your account is useful to you, and we delete it within a reasonable period after sustained inactivity, in line with APP 11.2 (destruction or de-identification of unneeded personal information).
Active accounts. Your profile, booking history, invoices, and other personal data are retained for the life of your account.
Read-only access on subscription expiry. If your trial, beta, or paid subscription ends without renewal, your account moves to read-only mode. You can still log in, view your historical data, and export it (CSVs and invoice PDFs). To create new records or use paid features, you need to re-subscribe. Your data is preserved subject to the inactivity rule below.
For performers: Artist Free includes your first two invoices; Artist Pro adds unlimited invoicing, earnings reports and financial-year exports. If a Pro subscription ends, past invoices remain readable and new invoice creation follows the Artist Free allowance. Core features (availability, profile, gig responses, discovery) remain free and active.
For venues: all venue editing features lock when a venue subscription ends, but your roster history and invoices remain readable and exportable.
Inactivity-based deletion. We retain your account data for up to 12 months after your last login. If you have not logged in within 12 months, we will email you a 30-day notice. The notice includes a one-click “preserve my account” button: a signed link that can preserve the account once without requiring you to log in. We send reminders at 14 days and 3 days before deletion. If you log in, click the preserve link, or subscribe at any point, your account returns to active and the 12-month inactivity clock starts again. There is no lifetime limit on preservation cycles: if the account becomes inactive again, a later notice carries a fresh link.
What happens when an account closes. Both closure paths, the one you request and the one that follows sustained inactivity, run the same process: we de-identify your account. Your profile, venues, bookings, chat messages, notification subscriptions, and draft invoices are removed. Your login email address and phone number are replaced with a non-deliverable placeholder, so they no longer identify you and the address is free to use again.
Invoices you issued are kept in a minimised form, because we hold a business record of a transaction that involved another party. We keep the issuer name and ABN, the recipient name and ABN where the invoice is $1,000 or more, the date, the line-item description, the amount, the GST amount, and the venue address. We remove the bank account name, BSB, and account number, and the email address the invoice was sent to. We keep these minimised records for 5 years from the later of the date the invoice was prepared or completed, and longer where a law requires it. Our basis is APP 11.2(d), together with section 262A of the Income Tax Assessment Act 1936, section 382-5 of Schedule 1 to the Taxation Administration Act 1953, and section 29-70(1) of the GST Act 1999. For users in the United Kingdom or European Economic Area, Article 17(3)(b) of the GDPR covers the same retention.
External promoter contact details you entered are cleared when your account is de-identified.
Aggregate, non-identifying analytics may be retained for product improvement purposes (consistent with APP 11.2, which permits retention of de-identified data).
Full erasure on a lawful order. Where we receive a binding erasure order, a court order, or another lawful demand for complete erasure, a Gig Pool platform administrator can run a true purge on the account. That redacts the personal details held on the retained invoices, clears the promoter contact details recorded anywhere in the account, cancels any live subscription, and removes the account and its login. Each purge records who ran it, when, and the order it was made under.
Financial records: your obligation. You are responsible for retaining your own financial records (invoices you generate, earnings reports, tax statements) under Australian taxation law. Typical retention periods are 5 years for tax records under the Income Tax Assessment Act 1997 and Taxation Administration Act 1953, and up to 7 years for some corporate records under the Corporations Act 2001 (Cth), depending on your circumstances. We recommend consulting a registered tax agent. To help you meet that obligation, the Service generates downloadable PDFs for every invoice you create and CCs a copy of every invoice email to your registered email address, so a record automatically lives in your own inbox. You should download or archive what you need before deleting your account or letting it lapse.
Financial records: our obligation. Separately, we retain our own business records (the subscription invoices we issue to you, our payment processor logs, and our own GST and revenue records) for as long as Australian law requires us to do so, typically up to 7 years under the Corporations Act 2001 (Cth) and the relevant tax legislation. These are our records for our compliance, not yours, and they may remain after your account is deleted only as required by law.
User-initiated deletion. You can request immediate deletion of your account at any time from your account settings (Danger Zone). Owner accounts trigger a 30-day grace period during which the deletion can be cancelled; this is to give you a recovery window for accidental deletions. Before you confirm deletion, download any of your own financial records you need to keep, because once the deletion completes your account is de-identified and your data is gone from our active systems, apart from the minimised invoice records described above. Our own business records are retained per the rule above.
Audit logs. A minimal audit trail of account-status transitions (when an account became dormant, when notices were sent, when a deletion completed) is retained indefinitely with only the historical user UUID, for compliance and dispute-resolution purposes. It does not contain re-identifiable personal data after hard deletion.
Other retention specifics
• Capacity-request notes: when a booker asks an account owner to add capacity (such as an extra Space), the optional free-text reason they include (up to 200 characters) and any reason the owner gives when they decide are held with the request and retained for our audit period as part of the account-status history in section 7 (audit logs). Treat these like any other text you type into the Platform: keep them factual and avoid including sensitive personal details.
• Chat messages: retained for the life of the associated booking. When a booking is deleted, associated messages are also deleted.
• Push notification subscriptions: deleted when you unsubscribe, uninstall the PWA, or when the subscription endpoint expires.
• SMS, email, and notification delivery logs: retained for up to 90 days for troubleshooting and deliverability monitoring, then deleted.
• Email 2FA codes: deleted automatically 10 minutes after issue (whether used or not).
• TOTP recovery codes: deleted when used (single-use) or when you disable TOTP 2FA.
• Trusted-device cookies: 1-year TTL; cleared when you sign out of all sessions or clear cookies.
• Signed snooze and unsubscribe tokens: cleared 90 days after use; tokens are time-bounded and single-use.
• Public booking enquiries: the enquiry record, including the sender’s name, email address, message, IP address, and browser details, is retained for 12 months from the date it was sent, then deleted. The artist keeps the notification email they received, which is theirs to manage.
• External promoter contact details: held for as long as the Space unavailability record they belong to exists, and removed with it. They are also cleared when the booker who entered them is de-identified, and account-wide when an account is purged.
• Encrypted file backups: a backup copy is kept while the original file exists in Supabase Storage, and is removed within 28 days after the original is gone.
8. Data security
We take reasonable steps to protect your personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure (APP 11.1). Our security measures include:
Encryption in transit: all data transmitted between your device and the Platform is encrypted using TLS 1.2 or higher (HTTPS).
Encryption at rest: database contents are encrypted at rest using AES-256 encryption provided by Supabase’s infrastructure. Profile photos on the public Cloudflare R2 mirror are encrypted at rest by Cloudflare.
Backups: we copy the files kept in Supabase Storage to a private Cloudflare R2 backup store each night. Every file is encrypted to a backup key before it leaves our systems, and that key is held outside the backup store, so the contents cannot be read from the backup store alone. The backup store is private and is never served to the public.
Error monitoring: Sentry records application errors and performance traces so we can find and fix faults. It is configured to leave out user identifiers by default, and tax file number fields are stripped from every report before it is sent. Error reports can still carry the page address, technical request details, and, inside a short diagnostic window an administrator opens deliberately, the values held by the code at the point of the error.
Access controls: Row Level Security (RLS) policies are enforced at the database level, ensuring users can only access data they are authorised to view. Administrative access is restricted to a small number of authorised personnel and is audit-logged.
Authentication: user authentication is managed through Supabase Auth with secure session handling. Passwords are hashed using bcrypt. Two-factor authentication (email codes or TOTP) is available for all users and required for administrators and support agents.
Token security: HMAC-SHA256 with timing-safe comparison is used for all signed tokens (booking confirmations, fill-in actions, deletion-notice snooze, magic-link logins, trusted-device cookies).
Infrastructure security: the Platform is hosted on Vercel (SOC 2 Type II) and Supabase (SOC 2 Type II), both of which maintain comprehensive security programs. Cloudflare R2 (used for avatars only) is also SOC 2 Type II.
Payment security: payment card data is handled exclusively by Stripe (PCI DSS Level 1 certified). We do not store, process, or transmit full card numbers on our servers; we only ever see the last four digits and the brand for display purposes.
While we take reasonable precautions, no method of electronic transmission or storage is completely secure. We cannot guarantee the absolute security of your information.
9. Cookies and tracking
The Platform uses only first-party cookies that are necessary for it to operate or to remember your preferences. We do not use advertising cookies, third-party tracking pixels, or marketing cookies.
Authentication session cookies (sb-access-token, sb-refresh-token, and related Supabase auth cookies): used to keep you signed in. Required for any logged-in functionality.
Trusted-device cookie (gp_trusted_device): an HMAC-signed cookie set after you complete two-factor authentication, valid for up to 1 year. It lets your device skip 2FA on subsequent logins on the same browser. You can clear it by signing out of all sessions or clearing cookies.
Theme preference cookie: stores your light/dark mode preference.
Vercel Analytics: we use Vercel Analytics for aggregate website usage data. Vercel Analytics is privacy-focused, cookieless, and does not personally identify visitors. It collects anonymised usage data such as page views, visit duration, and device type.
Vercel Speed Insights: we use Vercel Speed Insights to measure how quickly pages load and respond. It sends a page performance measurement for a page view, is cookieless, and does not personally identify visitors.
Sentry: our error monitoring runs without setting a cookie. Section 8 sets out what an error report can contain.
You can manage cookies through your browser settings. Disabling functional cookies will affect the Platform’s operation. For example, you will not be able to stay signed in.
10. Account-related emails
Gig Pool sends emails to keep you informed about your account, your bookings, and the status of your subscription. This section explains what we send, how we categorise it, and what you can opt out of.
Categories of email
• Critical (always on, cannot be disabled): booking confirmations, invoice receipts, payment reminders for outstanding invoices to bookers, fill-in responses you receive, and account-deletion notices (see below).
• Actionable (can be disabled in settings): gig offers, fill-in opportunities, pool invitations, chat-message notifications, venue Broadcasts, opportunity applications, and lifecycle emails (trial/beta countdowns, payment-failed warnings, inactivity nudges, snooze confirmations).
• Informational (can be disabled in settings): pool-invite reminders, team invitations, and product-update emails to dormant accounts.
You can update your preferences at any time in your account settings, or by clicking the unsubscribe link at the bottom of any non-critical email.
Identification and unsubscribe (Spam Act 2003 (Cth) compliance)
Every commercial or transactional email we send identifies the sender as Gig Pool, operated by Gig Pool Pty Ltd (Brisbane, Australia), and includes a functional unsubscribe link where Schedule 1 of the Spam Act requires it. Unsubscribe requests are honoured within 5 business days, in practice immediately via the signed-token unsubscribe handler.
Account-deletion notice exception
The 30-day, 14-day, and 3-day account-deletion notices, plus the deletion-confirmation email, are classified as critical and cannot be opted out of. This is because we have an obligation under APP 11.2 to give you a reasonable opportunity to log in, export your data, or subscribe before any account is deleted. Sending you no warning before deleting your data would, in our view, be a worse privacy outcome than sending a small number of notices to a previously-unsubscribed user. These notices are sent only when an account is genuinely scheduled for deletion under section 7 above; they stop the moment you log in, click the preserve link, or subscribe.
11. Your rights
Under Australian Privacy Law
If you are an Australian resident, you have the following rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles:
Access (APP 12): you may request access to the personal information we hold about you. We will respond within 30 days. Most data is also accessible directly through your account settings, including in-app export of invoices and bookings.
Correction (APP 13): you may request that we correct personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading. You can update most information directly through your account settings. If your subscription is in read-only mode, you can still update core profile information; editing of paid-feature data (such as invoice content) requires re-subscribing or contacting support.
Complaint: you may complain about how we have handled your personal information. We will investigate and respond within 30 days. If you are not satisfied, you may complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
Anonymity and pseudonymity (APP 2): we offer the use of a stage name as your public identity, so you can transact under a name that is not your legal name. Some invoice fields may require your legal name where the rules that apply to you require it on a business document.
Under UK and EU Data Protection Law
If you are in the United Kingdom or European Economic Area, you have additional rights under the UK GDPR or EU GDPR:
Right to erasure (Article 17): you may request that we delete your personal information. We de-identify your account as described in section 7. Two things survive that: the minimised invoice records section 7 lists, retained under Article 17(3)(b) for the period stated there, and our own business records (the subscription invoices we issue to you, payment processor logs, and our own tax and corporate records) retained for tax and corporate-law compliance. Where an order requires complete erasure, the true purge described in section 7 is the path we use.
Right to restriction (Article 18): you may request that we restrict the processing of your personal information in certain circumstances.
Right to data portability (Article 20): you may request a copy of your personal information in a structured, commonly used, machine-readable format. In practice the in-app export tools cover most of this; contact us if you need a fuller export.
Right to object (Article 21): you may object to the processing of your personal information where we rely on legitimate interests as the legal basis.
Right to withdraw consent: where processing is based on your consent, you may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
Right to lodge a complaint: you may lodge a complaint with the Information Commissioner’s Office (ICO) in the UK (ico.org.uk) or the relevant supervisory authority in your EEA country of residence.
To exercise any of these rights, contact us using the details in section 16 below.
12. Automated decision-making
Gig Pool does not use automated decision-making or profiling that produces legal effects or similarly significant effects on users. Every offer, booking, roster, and fill-in decision is made by a person.
The Platform does rank and filter candidate lists, so that a booker has a shorter list to choose from. When a booker fills a slot, quick-books, or sends a fill-in call-out, we order artists by how well their genres, availability windows, and vibe fit the slot. For a fill-in call-out, artists who have marked that night as blocked are left out by default; the booker is told how many were left out and can tick a box to ask them anyway, and the request still appears in those artists’ opportunities feed. An artist’s opportunities feed shows work within a distance of the area they entered, 150 km by default, which the artist can change. None of this decides anything: it orders and narrows a list a person then acts on.
Aggregate analytics (Vercel Analytics, Vercel Speed Insights, our internal product-events log) operate at a non-individual level and are used for product improvement, not for any decision affecting an individual user.
If we introduce automated decision-making in the future, we will update this policy to describe the process and your rights, including the right to request human review under Article 22 of the GDPR for UK and EEA users.
13. Children’s privacy
The Platform is not directed at children under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us.
14. International users
Gig Pool is operated from Australia. If you access the Platform from outside Australia, you do so on your own initiative and are responsible for compliance with local laws. We aim to provide a consistent privacy standard for users in the United Kingdom and European Economic Area by complying with the UK GDPR and EU GDPR in addition to the Australian Privacy Principles. Where local law in your country provides stronger rights, we will honour those rights to the extent practical.
15. Changes to this policy
We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, in particular changes to how we retain or delete your data, or to who we share it with, we will notify you by email and in-app at least 30 days before the changes take effect. Other changes will be announced by posting the updated policy on the Platform with a revised “Last updated” date.
We encourage you to review this policy periodically. Your continued use of the Platform after changes are posted constitutes your acceptance of the revised policy, except where applicable law requires a fresh opt-in.
16. How to contact us
If you have any questions, concerns, or requests regarding this privacy policy or how we handle your personal information, please contact us:
Gig Pool Pty Ltd (ABN 86 695 742 459)
Brisbane, Australia
Email: support@gigpool.app
For privacy complaints: if you believe we have breached the Australian Privacy Principles, please contact us first. We will investigate your complaint and respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with:
Office of the Australian Information Commissioner (OAIC)
Website: www.oaic.gov.au
Phone: 1300 363 992
Email: enquiries@oaic.gov.au
For users in the United Kingdom:
Information Commissioner’s Office (ICO)
Website: ico.org.uk
Phone: +44 303 123 1113
For users in the EEA, you may lodge a complaint with the data protection supervisory authority of your country of residence.
Gig Pool is operated by Gig Pool Pty Ltd (ABN 86 695 742 459), Brisbane, Australia.