GigTracker legal
Data Retention Policy
How long GigTracker keeps calendar-year records, attachments, account information, operational logs, payments, and encrypted backups.
1. Retention schedule
- Calendar-year records and private attachments: through December 31 of calendar year + 7 while the related entitlement and account remain active, unless deleted earlier on a valid request or retained longer for a lawful reason.
- Account and profile information: while the account is active, then only as long as needed to complete deletion, resolve disputes, prevent fraud, and meet legal obligations.
- Payment, entitlement, refund, and promotion records: generally seven years after the transaction or longer if reasonably required for accounting, dispute, fraud, or legal purposes. Full payment-card numbers are held by Stripe, not GigTracker.
- Support and privacy-request records: as long as reasonably needed to resolve and document the request, normally no longer than two years after closure unless a dispute or law requires longer.
- Security and operational logs: according to operational need and provider capabilities, generally for short periods, but relevant records may be retained longer for an active incident, fraud investigation, legal obligation, or dispute.
- Encrypted production database backups: daily encrypted objects in private R2 storage are automatically scheduled for deletion after 35 days.
2. The calendar-year rule
The schedule is tied to the year represented by the records, not to the date a particular entry or file was uploaded. The app displays the applicable "retained through" date. This structure is intended to make a user's own record organization predictable; it is not tax or legal advice and does not guarantee that the period is appropriate for every user or purpose.
3. Account and data deletion requests
You may request deletion through the app or support email. We may verify identity, ask you to resolve an active transaction, and explain information that must be retained. Once approved, active data is deleted or de-identified from operational systems according to the deletion workflow. Residual encrypted copies may remain in rotating backups until they expire, normally within 35 days, and are not restored except for legitimate disaster recovery.
Deletion is permanent. Download any Record Packages you want before requesting deletion. We may retain a minimal record of the request and information required for security, fraud prevention, legal compliance, or dispute resolution.
4. Backups and recovery
GigTracker creates encrypted database backups for disaster recovery. Backups are not a user archive, cannot be browsed as an account feature, and do not replace your own exports. Backup access is restricted, restore rehearsals use isolated systems, and temporary restoration files are deleted after verification.
5. Expiry notices and exports
The app displays retention dates so users can plan exports. We will use reasonable efforts to provide an in-app or email reminder before scheduled removal where the service supports it, but you remain responsible for maintaining independent copies and current contact information. Record Packages can be downloaded in available formats before expiry.
6. Service discontinuation or transfer
If GigTracker plans to discontinue the service, we will use reasonable efforts to provide at least 30 days' notice and an export opportunity. Urgent security, legal, vendor, or insolvency circumstances may make full notice or export impracticable. If the service is transferred in a genuine business transaction, a successor that receives retained information must assume applicable privacy, security, and retention obligations and provide any notice required by law.
7. Legal holds and operational exceptions
Information may be kept longer when reasonably necessary to comply with law, preserve evidence, enforce an agreement, investigate fraud or a security incident, protect users, or resolve a dispute. Information may be deleted earlier when requested and legally permitted, when it is no longer needed, or when continued storage creates an unacceptable security or legal risk.
8. Secure disposal
When retention ends, information is deleted, overwritten through provider lifecycle processes, or de-identified using methods appropriate to the system and sensitivity. Provider copies may disappear on different schedules, and deletion from active systems may precede expiration from backups and logs.
9. Questions
For a retention, export, or deletion question, email [email protected]. Do not send passwords, payment-card details, identity documents, or sensitive record attachments by ordinary email.