Test version GigLogik is still being tested. Features may change, and data may be reset without notice.

Privacy policy

Last updated 2026-08-22

GigLogik helps bands plan gigs, confirm who is playing, and find a substitute when someone cannot. To do that it processes personal data about band members, people invited to join a band, and substitute musicians a band keeps on its list. This policy explains what is processed, why, for how long, and what you can do about it.

Who is responsible

The data controller is Pillipoisid OÜ, kallepilli@gmail.com. Privacy questions and requests: kallepilli@gmail.com.

Within a band, the band's Owner and Managers decide which gigs exist, who is asked to play, and who is on the substitute list. For that band-level data they act as controllers too, and Pillipoisid OÜ processes it on their behalf to run the service.

What we process, and why

DataPurposeLawful basis
Account: email, name, phone, timezone, display preferencesSigning you in, showing you your bands and gigs, contacting you about themContract (providing the service you signed up for)
Band membership, roles, instrumentsDeciding what you can see and do in each bandContract
Gigs, line-ups, your answers, timeline, setlists, attachmentsPlanning and running gigsContract
Your fee per gig, and a band's gross payoutEarnings overview; fees are visible to you and to the band's ManagersContract
Availability blocks and their private notesWarning a Manager that you clash with a gig. Only the fact and the time window are shared; the note and any calendar detail stay yoursContract
Google Calendar: busy/free intervals, and confirmed gigs written to your calendarAutomatic availability, and your gigs in your own calendarConsent (you connect it, you can disconnect any time)
Substitute contacts kept by a band: name, email, phone, role, notesAsking a substitute to cover a slot, one at a time, by emailLegitimate interest of the band in finding cover. You can opt out from any offer message, after which that band cannot contact you through GigLogik again
Invitations: email of the person invitedLetting a Manager invite someone into a bandLegitimate interest of the band; the link expires in 14 days
Notifications: what was sent to whom, when, and whether it was deliveredSending gig proposals, changes, and substitute offers; not sending them twiceContract, and legitimate interest in reliable delivery
Billing: Stripe customer and subscription ids, plan statusRunning a band's subscription. Card details never reach GigLogikContract, and legal obligation for accounting records
Private gig notesYour own notes on a gig. Nobody else can read themContract
Audit log: who changed what, whenTraceability of changes a band relies on, security investigationsLegitimate interest in integrity and security
Cookies and local storageKeeping you signed in (essential); remembering your active band, language, and theme (functional, only with your consent). See the cookie policyEssential: contract. Functional: consent

Who sees what inside a band

  • Members of a band see each other's name, instruments, and answers to gig proposals.
  • Managers additionally see every member's fee, the gross payout, and the substitute list.
  • A plain member sees the gross payout only if the band switches that on.
  • Nobody in a band ever sees the titles, descriptions, attendees, or locations of your personal calendar events. GigLogik stores only busy time windows from the calendars you select, and shows a Manager only that you are busy, not why. On your own Availability page you see your event titles, read from Google at that moment and never saved here, so you can tell your own entries apart.
  • A substitute who accepts a gig sees the gig details and the files attached to it, not the band's other data.

Who we share data with

We use these processors under data processing agreements. They act on our instructions only.

ProcessorRole
SupabaseDatabase, authentication (magic-link sign in), file storage
ResendSending email (proposals, invitations, substitute offers)
StripeSubscription billing. Stripe is an independent controller for payment data
GoogleCalendar API, only for accounts you connect yourself

Some processors operate outside the European Economic Area. Where data leaves the EEA it is covered by the European Commission's Standard Contractual Clauses or an adequacy decision. We do not sell personal data and we run no advertising or analytics trackers.

How long we keep data

DataKept
Account and band dataWhile your account exists. Deleting your account removes it (see below)
Notifications (sent messages)180 days
Invitation and substitute offer linksLinks expire on their own; the secret that makes them work is erased 90 days after expiry. The record that an offer was made stays with the gig
Calendar busy windowsReplaced on every sync; windows older than 30 days are deleted
Audit log24 months
Billing recordsAs long as accounting law requires, at Stripe
Substitute contactsUntil the band removes them or you opt out

Your rights

You can access, correct, export, and delete your data, object to processing based on legitimate interest, withdraw consent, restrict processing, and complain to a supervisory authority. In GigLogik:

  • Correct: your name, phone, and preferences are on the Settings page, under your account. Band data is edited inside the band.
  • Export: Settings, Privacy and data, “Download my data” gives you a JSON file with everything tied to your account.
  • Delete: Settings, Privacy and data, “Delete my account”. Your profile is anonymised, your private data is erased, and your sign-in is removed. Gigs you played keep an anonymous line-up row so the band's history still adds up. If you own a band that still has members, transfer ownership or delete the band first.
  • Withdraw consent: disconnect Google Calendar on the Availability page; change cookie consent on Settings.
  • Substitutes who are not users: every offer message and the offer page carry a link that removes your details from that band's list and blocks further offers from it. For anything else, write to kallepilli@gmail.com.

We answer requests within one month. If you are in the EU/EEA you can also complain to your local data protection authority.

Security and breaches

Access rules are enforced in the database for every request, integration credentials are encrypted at rest, files are served through short-lived signed links, and changes are audited. If a breach is likely to put you at risk we will notify the supervisory authority within 72 hours of becoming aware of it and tell affected people without undue delay.

Children

GigLogik is for adults organising their work. We do not knowingly process data of children under 16; if you believe we do, contact us and we will delete it.

Changes

We will post changes here with a new date above and, for material changes, tell signed-in users in the app.

Privacy policy, GigLogik