Privacy Policy
How we collect, use, and protect your personal data under UK GDPR.
Trust & safety
Need help?
Last updated: 5 August 2026
How we handle your data
How GigXchange collects, uses, and protects your personal data under UK GDPR — what we collect, why, who we share it with, and your rights. Use the chips below to jump straight to any section.
GigXchange is currently in beta. This privacy policy is subject to change as the platform evolves. We will notify registered users of any material changes via email. By using the platform during the beta period, you acknowledge that data practices and policies may be updated without prior notice.
1. Who We Are
This policy applies to the GigXchange website, the GigXchange mobile apps for iOS and Android, and all related services (together, the “Platform”).
GigXchange is operated by Eclipse Labs AI Ltd, registered in England and Wales (company number 17177477, incorporated 23 April 2026), with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. We are the data controller for the personal data described in this policy — meaning we decide why and how it is used, and we are responsible for protecting it.
Eclipse Labs AI Ltd is registered as a data controller with the UK Information Commissioner's Office (ICO) and listed on the public ICO register. Our ICO registration reference is ZC132441.
Data Protection Contact: privacy@gigxchange.app
2. What Data We Collect
| Category | Data | Purpose |
|---|---|---|
| Account | Name, email, password (hashed), account type | Account creation and authentication |
| Profile | Bio, photos, location, genre, links, availability | Public profile display, search and discovery |
| Booking | Event dates, fees, booking status | Facilitating and managing bookings |
| Messaging | Messages, images and files you send other users (including outside a booking), and read status | Letting users communicate on the Platform |
| Payment | Transaction amounts, payment status, and payment references from Stripe (we never see or store your full card number) | Taking payment, holding and releasing booking payments through Stripe Connect, and refunds |
| Usage | Pages visited, features used, device/browser info | Improving the platform, analytics |
| Device permissions (mobile app) | Camera access | Scanning event-ticket QR codes at the door. Images are processed live on your device and are not stored or uploaded. |
| Device permissions (mobile app) | Photos & media access | Uploading a profile photo, cover image, or media you choose from your device. Only the files you select are uploaded. |
| Push notifications (mobile app) | A device push token | Sending you push notifications (for example a new message or a booking update). You can turn these off at any time in your device settings; we delete the token when you log out, disable notifications, or uninstall the app. |
| Ticket sales | Buyer name, email and phone; the ticket QR code and the time it is scanned at the door | Selling and validating event tickets. The scan time records attendance at that event. You do not need a GigXchange account to buy a ticket. |
| Tips | Your name, email and optional message when you tip a performer | Processing a voluntary tip to a performer. You can tip without a GigXchange account. |
| Profile activity | Which profiles you view, and aggregate counts of who viewed yours | Showing view counts and basic insights on your own profile. |
| Diagnostics & security | Error messages and stack traces, the page and browser/device involved, your user ID if signed in, and your IP address (used in hashed form for rate-limiting) | Diagnosing crashes, fixing bugs, and preventing spam, fraud and abuse. Crash reports from the app are handled for us by Sentry (see section 5); those reports contain no name, email or IP address, and are deleted automatically after 90 days. |
| Reviews | The rating and text you write about someone you worked with. For a review you import from a past off-platform client, the email you give us for a one-off verification message. | Building trust on the Platform and confirming imported reviews are genuine. |
| Disputes, reports & blocks | The details you give us when you raise a booking dispute, report content or a user, or block someone | Resolving disputes and keeping the Platform safe. |
| Availability & calendar sync | Your availability, and — if you connect one — an external calendar feed link (e.g. Google Calendar) | Showing when you are free and keeping your availability in sync. |
| Connected accounts | If you connect an account you hold elsewhere (e.g. Eventbrite), the access credential that provider issues, the account or organisation name it returns, and a record of what we sent there on your instruction. Never your password for that account | Carrying out the actions you initiate on that account — and only those. Deleted when you disconnect (see section 5). |
| Mailing list | Your email address, your town or city (required, so we can send you what is on near you), which page you signed up from, and a copy of the exact wording you agreed to | Sending you a recurring weekly email — live music near you if you signed up as a gig-goer, or platform updates if you signed up from one of our pages for artists, venues, agents, promoters or organisers. Both are free, and you can unsubscribe in one click from any email. |
| Contact & survey forms | The name, email and message you send us | Answering your enquiries. |
| Public submissions | Gigs, open mics and rate information you submit for our public directories | Building the public gig, open-mic and rate directories. |
| Business contacts (venue outreach) | Venue / business name and a business email address, sourced from public business directories | Inviting venues to join GigXchange (B2B). We only contact business addresses, and you can opt out at any time — see section 6. |
| Venue directory | Details of UK grassroots music venues gathered from public sources: name, address, capacity, live-music nights, genres, equipment, opening hours, website, socials, public phone number and a business booking email | Publishing a free directory so musicians can find places to play and audiences can find live music — see “Venues in our public directory” below. The booking email is never shown publicly. |
Information about other people you give us
Some features let you give us details about a person who may not have a GigXchange account. In each case we rely on our legitimate interest in growing a trusted live-music community, we keep only the minimum needed, and that person can ask us to delete their details at any time by emailing privacy@gigxchange.app. Where we simply store a small amount of data about someone who has not given it to us directly and we do not contact them (a suggestion), we rely on the disproportionate-effort exemption to the duty to notify them individually (UK GDPR Art 14(5)(b)); where we do contact them (review verification, team invites and venue outreach), that first message carries the required privacy information.
- Suggesting someone to join — if you suggest an artist, agent or promoter, we store their name and one social link so we can consider inviting them. We do not contact them automatically, and we delete the suggestion after 12 months.
- Recommendations you publish — if you recommend an act that is not on GigXchange, we store the act name and website link you provide and display them publicly as part of your profile’s recommendations. We store no contact details and never contact them, and the recommendation is deleted the moment you remove it (or your account is deleted).
- Verifying a review — if you add a review from a past client, we use the email you provide to send that client a single message asking them to confirm the review is genuine. We delete the email once it is confirmed, or within 14 days if it is not.
- Inviting a colleague to your venue team — we use the email you provide to send them a one-off invite to help manage your venue. A pending invite is deleted after 30 days; once accepted, the email is replaced by their account.
Venues in our public directory
We publish a free directory of UK grassroots music venues so that musicians can find places to play and audiences can find live music. We build it from publicly available sources — the venue’s own website, its public business listing, and open mapping data — not from anything behind a login. For each venue we may hold its name, address, capacity, the nights it puts on live music, the genres it books, its equipment, opening hours, website, social links, a public phone number, and a business booking email.
We rely on our legitimate interest in helping musicians and audiences find grassroots venues, and in helping those venues be found. Venues publish these details precisely so that people can find and contact them.
We do not email every venue individually to tell them we have listed them — with several thousand venues that would be disproportionate, and it would mean contacting people who have not asked to hear from us. We therefore rely on the exemption at UK GDPR Article 14(5)(b) and publish this information here instead.
A venue’s booking email is never shown publicly. It is used only to pass on an enquiry from a GigXchange member — for example a musician asking whether they can play there — and it is never displayed, exported or sold.
If it’s your venue: you can correct anything that is wrong, ask us to stop contacting you, or ask us to remove the listing entirely. Use the correction link on your venue’s page, or email privacy@gigxchange.app and we will action it.
3. Legal Basis for Processing
We process your personal data under the following legal bases (UK GDPR Article 6):
- Contract — Processing necessary to provide a service you asked for: account management, bookings and payments, and one-off transactions you make without an account (buying a ticket, tipping a performer)
- Legitimate interest — Platform improvement, security, fraud prevention, our own first-party analytics (e.g. profile views and crash diagnostics), B2B venue outreach, publishing our public venue directory, and growing a trusted community (e.g. member suggestions, review verification and team invites)
- Consent — Marketing communications and optional analytics cookies (Google Analytics); you can withdraw consent at any time
- Legal obligation — Tax records, regulatory compliance
4. How We Use Your Data
- To create and maintain your account
- To display your public profile to other users
- To facilitate bookings and payments between users
- To send transactional notifications (booking confirmations, messages)
- To improve the platform through analytics
- To prevent fraud and enforce our Terms of Service
- To let event organisers scan ticket QR codes using the device camera (mobile app only)
5. Data Sharing & Sub-Processors
We do not sell your personal data. We share the minimum data required with the following categories of recipients:
- The public — Your public profile, and anything else you choose to make public (such as a public gig listing), can be seen by anyone on the internet — including search engines, crawlers and AI assistants — not only signed-in GigXchange users. Private data such as your contact details, fees and messages is never part of your public profile.
- AI assistants and search tools — A limited subset of your public profile (name, city, genre, aggregate rating, profile URL) is available via a read-only public API so AI assistants and search crawlers can surface your profile in response to user queries. No contact details, fees, or private data are included. This mirrors what is already visible on your public profile page.
- A note on AI-assisted features. Where you actively use an AI feature on the Platform, the prompt content you submit is sent to the AI sub-processor listed in the table below (currently Anthropic). You control what you put into that prompt. Please do not include personal data unless necessary for the feature to work, and do not include special-category data (e.g. health, biometric, racial or ethnic origin, religious belief, sex life or sexual orientation). Our current AI API provider states that API prompts and outputs are not used to train its models unless we expressly opt in, and we have not opted in. Standard provider retention applies — currently up to 30 days for Anthropic API data; we have not enabled zero-data-retention terms, so that 30-day period is the actual retention. Core Platform features remain available without using optional AI assistance. We do not make decisions that produce legal or similarly significant effects about you using solely automated processing — AI features generate suggestions that you or another person decide whether to act on.
- Sub-processors — The third-party services listed in the table below, which process data on our behalf under contract (UK GDPR Art 28).
- Sign-in providers — If you choose to sign in with Google, Microsoft or Apple, that provider confirms your identity and shares your name and email with us. We do not post anything to those accounts.
- Accounts you connect yourself — If you connect an account you hold elsewhere (for example Eventbrite for ticketing, Stripe for payments, or your calendar), we send data to it only to carry out actions you initiate, such as publishing an event you chose to publish. We never receive or store your password for that account, only a limited access credential, and we use it strictly within the permissions you approved — never to promote GigXchange, contact your customers, or for any purpose of our own. Once your data is in that provider’s platform, they handle it as their own controller under their privacy policy. You can disconnect at any time in your settings: we delete the credential and, where the provider supports it, withdraw our access at their end too. Deleting your account removes it as well. The commitments we make about connected accounts are set out in section 12 of our Terms.
- Law enforcement or regulators — Where required by law, court order, or to protect the safety of users.
Sub-processors we use
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase (Supabase Inc.) | Database, authentication, file storage | All account, profile, booking, message and uploaded file data | EU (Frankfurt, Germany) |
| Stripe (Stripe Payments UK Ltd / Stripe Inc.) | Payment processing, payouts, KYC for Connect accounts | Name, email, card details (tokenised); for performers/venues receiving payouts, the identity verification and business / bank details Stripe collects to meet its legal “know your customer” obligations; and transaction data | UK & United States |
| Eventbrite (Eventbrite, Inc.) | Ticketing — only if you connect your own Eventbrite account, and only for events you choose to send there | The access credential for your connected account, and the details of the events you send: title, description, date and time, venue name and address, capacity, and the booked act’s stage name where the event came from a booking. Eventbrite acts as its own controller for data in your Eventbrite account | United States |
| Resend (Resend, Inc.) | Transactional & outreach email delivery | Name, email address, email content | United States |
| Google Analytics 4 (Google Ireland Ltd / Google LLC) | Website analytics (only with your consent — see section 8) | IP address (used transiently for approximate location, not stored by GA4), device / browser info, pages visited | United States (EU data is routed via EU servers where possible) |
| Cloudflare (Cloudflare, Inc.) | Hosting (Cloudflare Pages), CDN, DDoS protection, worker-based edge logic | IP address, request metadata, served page content | Global edge network; company headquartered in the United States |
| Sentry (Functional Software, Inc.) | Error & crash monitoring, so we can find and fix bugs users hit | Technical crash reports: the error and stack trace, browser and device type, the page involved, your account ID if signed in, and the in-app actions just before the error. No name, email or IP address is included, and reports are deleted after 90 days | EU (Frankfurt, Germany) |
| Anthropic (Anthropic PBC) | AI-assisted features (e.g. AI matching, SEO content generation) — only processed on explicit action | Prompt content you submit, which may include profile or booking data you choose to include | United States |
| Google Workspace (Google Ireland Ltd) | Company email (e.g. support@, privacy@, legal@) and internal documents | Any personal data included in emails or support requests you send us | EU & United States |
| Firebase Cloud Messaging (Google) & Apple Push Notification service | Delivering push notifications to the mobile apps (Android via Firebase, iOS via Apple) | A device push token and the notification content | United States |
| CARTO (CARTO DB Inc.) | Map tiles / basemap for the maps shown on the Platform | Your IP address and the map area requested when you view a map | United States |
| Unsplash (Unsplash, Inc.) | Stock-image search and library when you choose a photo | Your search terms, and your IP address when images load | United States |
| Postcodes.io | Turning a UK postcode you enter into an approximate location for search | The postcode you type, and your IP address when the lookup is made | United Kingdom |
| jsDelivr | Content-delivery network that serves the map library used for our maps | Your IP address when the map library loads | Global edge network |
Each provider’s name above links to its own privacy policy, where you can read how it handles the data it processes on our behalf.
International transfers
Several of the sub-processors above are located in, or transfer data to, the United States. Where we transfer your personal data outside the UK, we rely on one of the following lawful safeguards under UK GDPR Article 46:
- UK adequacy regulations — where the UK Government has made an adequacy decision for the destination country.
- UK International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses with the UK Addendum, incorporated into our contract with the sub-processor.
- UK-US Data Bridge extension to the EU-US Data Privacy Framework, where the US recipient is certified under that scheme.
We assess these transfers where required and rely on the safeguard appropriate to each provider. You can ask which safeguard applies to a specific provider by emailing privacy@gigxchange.app.
6. Account Deletion & Data Retention
You can delete your account two ways: in the app via Settings → Delete Account, or — if you can no longer sign in — by requesting it at gigxchange.app/delete-account, where we email a confirmation link to verify the request is yours. Either way, your account then enters a 28-day grace period. During this time:
- Your profile is immediately hidden from search results and other users
- You can still sign in during the grace period — simply signing back in immediately cancels the scheduled deletion and restores your account
- You can also cancel by contacting us at privacy@gigxchange.app within 28 days
At a glance, here is what happens to your data when your account is deleted:
| Your data | What happens to it |
|---|---|
| Profile, media, messages, notifications and connections | Permanently deleted (your sent messages are removed from the other person's copy too) |
| Bookings you were part of | Your personal details are removed and your side shows as “deleted user”, so the other party's own records stay intact |
| Reviews other people wrote about you | Kept but anonymised — they are another user's content |
| Payment, invoice and tax records | Kept in identifiable form for 6 years (a legal obligation to HMRC); also held independently by Stripe |
| A minimal deletion record | Kept as proof we honoured your request; any contact identifier in it is removed within 12 months |
| Aggregated, anonymous analytics | May be kept indefinitely — it cannot identify you |
We will not permanently delete your account while you have unresolved activity that affects another user — specifically an open or in-progress booking, an active dispute, or an outstanding balance or pending payout. While any of these exist, your account stays in the pending-deletion state (hidden from other users), we restrict our use of your data to what is needed to conclude that activity, and we complete the deletion once it is resolved. This protects the people you have live bookings with.
Once any such activity is resolved (and the 28-day grace period has passed), we permanently delete:
- Your profile information (name, bio, location, contact details, photos)
- Your messages, notifications, and social connections
- Your uploaded media (photos, audio tracks, videos)
We are finalising an automated process that carries out these deletions on a regular cycle; until it is switched on, we complete confirmed deletion requests operationally on the same 28-day timetable. Either way, your data is erased as described here once the grace period ends and any live activity is resolved.
Messages you sent to other users are deleted along with your account, including the recipient’s copy of those messages. Photos, audio, and files you shared in messages are also deleted from our storage, and may no longer display in the recipient’s copy of the conversation.
We are legally required to keep certain financial records that identify each transaction (the parties, amounts and dates) for 6 years to meet our tax and accounting obligations to HMRC. Payment, invoice and contract records are therefore kept in identifiable form for that period under the legal-obligation basis, even after you delete your account. Booking details we no longer need for that purpose are anonymised.
Our payment processor (Stripe) independently retains transaction data as required by payment regulations and its own legal obligations. See Stripe’s privacy policy for details.
We keep a minimal deletion record (an internal account identifier and the date your account was deleted) as evidence that your erasure request was honoured, under our accountability obligation (UK GDPR Art 5(2)). Any contact identifier held in that record is removed within 12 months.
Where a booking involved another user, we remove your personal details from that record and show your side of it as “deleted user” to the other party, rather than erasing the booking entirely. This keeps the other party’s own records, payments, and obligations intact.
Reviews written about you by other users are anonymised (attributed to “deleted user”) but not removed, as they form part of another user’s content.
Anonymised, aggregated analytics data that cannot identify you may be retained indefinitely.
If you buy a ticket or tip a performer without a GigXchange account, we keep your contact details (name, email, phone) until the event has taken place plus 90 days, and then delete them. The payment record itself is kept for 6 years for tax, as described above.
If you joined our mailing list through a sign-up box on this site, the following applies:
- There is no confirmation email. You are subscribed as soon as you submit the form — we do not send a “click here to confirm” message, so please check the address before you submit it.
- We keep your address for 24 months from the last time you engaged with one of our emails (clicking a link), or from the date you signed up if you never have, and then we delete it. Us sending you an email does not extend that period — only something you do does.
- We store a copy of the wording you were shown when you signed up, along with the page and the date. This is how we evidence your consent, and we will provide that record on request.
- Every email carries a one-click unsubscribe. There is no confirmation step, no login, and no questions asked.
- If you unsubscribe, we keep your email address on a permanent suppression register so we can be certain never to email you again. This outlives the deletion above — we cannot honour an opt-out we have erased. That record is used for nothing else.
- We do not sell or share this list, and we never pass it to another organisation for their own marketing.
For business contact records held for B2B outreach (venue names and business email addresses sourced from public directories), we apply the following retention schedule:
- Contacts who have not engaged with any outreach are retained for a maximum of 24 months from the date of collection, after which they are moved to a restricted archive, isolated from active processing systems, and deleted.
- Contacts who have actively engaged (replied, met with us, entered into a commercial relationship) are retained for the duration of the relationship plus 24 months.
- Unsubscribe / opt-out records are retained indefinitely in a persistent suppression register. This outlives any lead record, so if you opt out your email is permanently blocked from future outreach, even if we re-encounter it in a public directory later.
- Audit trail records (who / when / what was processed) are retained for 6 years for accountability purposes under Art 5(2) UK GDPR.
7. Your Rights
Under UK GDPR, you have the right to:
- Access — Request a copy of your personal data
- Rectification — Correct inaccurate data
- Erasure — Request deletion of your data (“right to be forgotten”). Account deletion follows the 28-day grace period described in section 6.
- Restriction — Limit how we process your data
- Portability — Receive your data in a machine-readable format
- Objection — Object to processing based on legitimate interest
- Withdraw consent — Where we rely on consent (e.g. analytics cookies or marketing), withdraw it at any time
These rights are not absolute. For example, we may need to verify your identity before we act, some data must be kept to meet a legal obligation, and complex requests can take a little longer (we will tell you if so). Withdrawing consent does not affect processing we already carried out lawfully. You can object to direct marketing at any time, and we always honour that.
To exercise any of these rights, use our self-service tool at gigxchange.app/your-data — data exports (access and portability) are automated and arrive in minutes, and other requests are logged with a tracked one-calendar-month deadline. You can also contact privacy@gigxchange.app. Either way, we respond within one month.
8. Cookies & Similar Storage
We use two categories of cookies and similar browser storage (such as localStorage). Essential items are always on (they're needed for the site to work); analytics cookies only run if you accept them in the banner.
Essential (always on)
These items are strictly necessary for the site to work or to remember preferences you have actively set. They do not track you across other websites. All first-party.
- Sign-in cookie (a Supabase auth cookie named
sb-<id>-auth-token, sometimes split into numbered parts) — keeps you signed in. Session + up to 30 days. - Consent record (
gx-cookie-consent-v2) — remembers your cookie-banner choice so we don't ask again on every visit. - Display preferences (e.g.
sb-themefor light/dark,gx_territoryfor your UK region,gx_user_typefor your role, an invoice-theme preference) — remember choices you actively set so the site shows the right content. - Functional state (e.g. a dismissed-banner flag, onboarding and coachmark dismissals, an offline message queue, a one-vote-per-device record for ratings, a short-lived map-tile cache, and a cached display name) — make features work and remember what you've already seen or done on this device.
These items live in your browser (as cookies or local/session storage). They are first-party and do not track you across other websites. A full list is available on request.
Analytics (consent required — off by default)
We use Google Analytics 4 with Consent Mode v2. Until you click Accept all, GA4 does not set cookies and only receives anonymous, cookieless pings. If you accept:
_ga— distinguishes unique visitors. 2 years. Google._ga_G-4PXZQCWRHJ— session state for our GA4 property. 2 years. Google.
Google processes this data under its privacy policy. You can change your mind at any time via Cookie settings in the footer.
9. Security
We implement appropriate technical and organisational measures to protect your data, including:
- Encryption in transit (TLS/HTTPS)
- Hashed passwords (never stored in plain text)
- Row-level security on database access
- Regular security reviews
10. Children’s Privacy
GigXchange is intended for users aged 18 and over. The Platform involves entering into bookings and handling payments, which require the legal capacity to contract. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact privacy@gigxchange.app and we will delete it.
11. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email or a notice on the Platform. The "Last updated" date at the top of this page reflects the most recent revision.
12. Complaints
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
See also: Terms of Service












