Privacy policy
Last updated 2026-08-22
GigLogik helps bands plan gigs, confirm who is playing, and find a substitute when someone cannot. To do that it processes personal data about band members, people invited to join a band, and substitute musicians a band keeps on its list. This policy explains what is processed, why, for how long, and what you can do about it.
Who is responsible
The data controller is Pillipoisid OÜ, kallepilli@gmail.com. Privacy questions and requests: kallepilli@gmail.com.
Within a band, the band's Owner and Managers decide which gigs exist, who is asked to play, and who is on the substitute list. For that band-level data they act as controllers too, and Pillipoisid OÜ processes it on their behalf to run the service.
What we process, and why
| Data | Purpose | Lawful basis |
|---|---|---|
| Account: email, name, phone, timezone, display preferences | Signing you in, showing you your bands and gigs, contacting you about them | Contract (providing the service you signed up for) |
| Band membership, roles, instruments | Deciding what you can see and do in each band | Contract |
| Gigs, line-ups, your answers, timeline, setlists, attachments | Planning and running gigs | Contract |
| Your fee per gig, and a band's gross payout | Earnings overview; fees are visible to you and to the band's Managers | Contract |
| Availability blocks and their private notes | Warning a Manager that you clash with a gig. Only the fact and the time window are shared; the note and any calendar detail stay yours | Contract |
| Google Calendar: busy/free intervals, and confirmed gigs written to your calendar | Automatic availability, and your gigs in your own calendar | Consent (you connect it, you can disconnect any time) |
| Substitute contacts kept by a band: name, email, phone, role, notes | Asking a substitute to cover a slot, one at a time, by email | Legitimate interest of the band in finding cover. You can opt out from any offer message, after which that band cannot contact you through GigLogik again |
| Invitations: email of the person invited | Letting a Manager invite someone into a band | Legitimate interest of the band; the link expires in 14 days |
| Notifications: what was sent to whom, when, and whether it was delivered | Sending gig proposals, changes, and substitute offers; not sending them twice | Contract, and legitimate interest in reliable delivery |
| Billing: Stripe customer and subscription ids, plan status | Running a band's subscription. Card details never reach GigLogik | Contract, and legal obligation for accounting records |
| Private gig notes | Your own notes on a gig. Nobody else can read them | Contract |
| Audit log: who changed what, when | Traceability of changes a band relies on, security investigations | Legitimate interest in integrity and security |
| Cookies and local storage | Keeping you signed in (essential); remembering your active band, language, and theme (functional, only with your consent). See the cookie policy | Essential: contract. Functional: consent |
Who sees what inside a band
- Members of a band see each other's name, instruments, and answers to gig proposals.
- Managers additionally see every member's fee, the gross payout, and the substitute list.
- A plain member sees the gross payout only if the band switches that on.
- Nobody in a band ever sees the titles, descriptions, attendees, or locations of your personal calendar events. GigLogik stores only busy time windows from the calendars you select, and shows a Manager only that you are busy, not why. On your own Availability page you see your event titles, read from Google at that moment and never saved here, so you can tell your own entries apart.
- A substitute who accepts a gig sees the gig details and the files attached to it, not the band's other data.
Who we share data with
We use these processors under data processing agreements. They act on our instructions only.
| Processor | Role |
|---|---|
| Supabase | Database, authentication (magic-link sign in), file storage |
| Resend | Sending email (proposals, invitations, substitute offers) |
| Stripe | Subscription billing. Stripe is an independent controller for payment data |
| Calendar API, only for accounts you connect yourself |
Some processors operate outside the European Economic Area. Where data leaves the EEA it is covered by the European Commission's Standard Contractual Clauses or an adequacy decision. We do not sell personal data and we run no advertising or analytics trackers.
How long we keep data
| Data | Kept |
|---|---|
| Account and band data | While your account exists. Deleting your account removes it (see below) |
| Notifications (sent messages) | 180 days |
| Invitation and substitute offer links | Links expire on their own; the secret that makes them work is erased 90 days after expiry. The record that an offer was made stays with the gig |
| Calendar busy windows | Replaced on every sync; windows older than 30 days are deleted |
| Audit log | 24 months |
| Billing records | As long as accounting law requires, at Stripe |
| Substitute contacts | Until the band removes them or you opt out |
Your rights
You can access, correct, export, and delete your data, object to processing based on legitimate interest, withdraw consent, restrict processing, and complain to a supervisory authority. In GigLogik:
- Correct: your name, phone, and preferences are on the Settings page, under your account. Band data is edited inside the band.
- Export: Settings, Privacy and data, “Download my data” gives you a JSON file with everything tied to your account.
- Delete: Settings, Privacy and data, “Delete my account”. Your profile is anonymised, your private data is erased, and your sign-in is removed. Gigs you played keep an anonymous line-up row so the band's history still adds up. If you own a band that still has members, transfer ownership or delete the band first.
- Withdraw consent: disconnect Google Calendar on the Availability page; change cookie consent on Settings.
- Substitutes who are not users: every offer message and the offer page carry a link that removes your details from that band's list and blocks further offers from it. For anything else, write to kallepilli@gmail.com.
We answer requests within one month. If you are in the EU/EEA you can also complain to your local data protection authority.
Security and breaches
Access rules are enforced in the database for every request, integration credentials are encrypted at rest, files are served through short-lived signed links, and changes are audited. If a breach is likely to put you at risk we will notify the supervisory authority within 72 hours of becoming aware of it and tell affected people without undue delay.
Children
GigLogik is for adults organising their work. We do not knowingly process data of children under 16; if you believe we do, contact us and we will delete it.
Changes
We will post changes here with a new date above and, for material changes, tell signed-in users in the app.