Gigiddy (the “Platform”) connects gig-goers, artists, and venues to list and promote live events.
3507.co.uk
We process personal data in line with the UK GDPR, the Data Protection Act 2018, and PECR (cookies).
-
Account
Email address and password (for login and account security), and a phone number if you choose to add one — it is optional and used only to contact you about your account.
-
Artists / Venues
Artist name, profile picture, bio, event details (time, date, location), optional Spotify embed links.
-
Gig-Goers
Email only (no name or profile data).
-
Gig alerts
The criteria you pick for alerts — distance, genres, venue types, ticketed or not — against your email address. You don’t need an account for this: if you set an alert from the pop-up while signed out, the email you type there is stored with those criteria purely to send you matching gigs. Every alert email carries an unsubscribe option (in the footer, and as your mail app’s own unsubscribe button), and you can remove alerts yourself at any time.
-
Location (optional)
We may request your location via browser geolocation to show gigs near you. This is optional—you can browse by typing a town or postcode instead. For everyday browsing, your location stays only on your device (in your browser) and is never sent to our servers. If you set up a gig alert, we save an approximate location (coordinates rounded so they can’t identify your address) and/or the postcode you entered, so we can email you matching gigs. We never store house-level precise coordinates, and you can delete any alert at any time.
-
Voice (optional)
If you add gigs by speaking them, we capture audio only while the recording is running. The clip goes to our server and straight on to OpenAI to be turned into text, then it is discarded — we never store your recording. The transcript is returned to your screen so you can check it and is not saved either; only the gig details you choose to publish are kept. Typing your gigs in instead does exactly the same job.
-
Messages & bookings
Direct messages between users, gig requests posted by venues, and the applications artists send in reply. Visible to the people in that conversation, and to us where we need to investigate a report or enforce our Terms.
-
Contact preferences
Which channels you want to hear on (email, push), and — if you switch push on — the notification address your browser issues for that device.
-
Activity
Gigs you save, artists and venues you follow, and your progress level on the Platform.
-
Comms
Reminder emails to artists/venues; optional newsletters to gig-goers (opt-out anytime).
-
Subscriptions
If you take a paid plan, we store the customer reference Stripe issues for you and whether your plan is currently active. We never see or store your card details — the card fields on our checkout are Stripe’s own, and the card goes straight to them.
-
Feedback
Anything you send us through the feedback form, so we can act on it and reply.
-
Technical
Essential session and security information needed for login and platform integrity, plus a daily count of how often you use AI-backed features so we can apply fair-use limits.
We do not sell personal data.
- Directly from you (account creation, profile setup, event listings, messages).
- Speech you choose to record when adding gigs by voice.
- Essential session/security logs generated by the Platform.
- Public place information from Google Places, used to fill in venue names, locations and photos on venue pages.
- Third-party embeds you choose (e.g., Spotify) governed by their own policies.
No analytics or advertising cookies, and no tracking across other websites. We only store what the site needs to work:
- Session & security — keeps you logged in and protects forms from being submitted by someone else. Cleared when you log out.
- Your location — once you pick a town, postcode or share your location, we save that choice in a cookie for up to a year so the app opens on your gigs instead of asking every visit. It holds the place name and its approximate coordinates, nothing else, and it is only ever set because you chose a location. Clearing the location in the app deletes it.
- Browser storage — your saved location, small preferences, and the fact you’ve dismissed the notice banner. This stays on your device and is never sent to us.
If we ever add analytics or advertising, we’ll ask for your consent first and give you controls to change your mind.
-
Hosting & Storage
Our hosting provider stores site and account data. We use appropriate contractual safeguards with processors; infrastructure locations depend on the provider’s services.
-
Email Delivery
Used for reminders and notifications. Emails may load fonts from Google Fonts, which is subject to Google's Privacy Policy.
-
Payments
Stripe is used for subscriptions. Stripe may act as processor and/or independent controller for some data.
-
Maps & Location
Mapping and location features (provided by Google) are used for venue search and related tools, subject to Google’s Privacy Policy.
-
AI Processing
When you add gigs by voice, the recording and the text taken from it are processed by OpenAI acting as our processor, under their privacy policy and API terms. We send only the audio and the text — never your name, email or account details. OpenAI states that data sent through its API is not used to train its models and is held only briefly for abuse monitoring.
-
Push Notifications
If you switch push on, notifications are delivered through your browser vendor’s push service (e.g. Google, Apple, Mozilla). Only the notification itself and your device’s push address are sent. Turning push off in your browser or settings ends this.
-
Public Content
Artist/venue pages and event listings are public by design.
-
Legal & Safety
We may disclose information to comply with law, enforce terms, or protect rights and safety.
We do not sell personal data.
If data is transferred outside the UK by our providers (e.g., hosting, email, payments, AI processing — OpenAI processes voice and text in the United States), we use appropriate safeguards such as the UK IDTA/Addendum or adequacy decisions.
- Accounts: kept until you delete yours. There’s a delete button in your settings — it runs immediately, you don’t have to email anyone and wait.
- Public pages & events: kept while relevant; past events may be archived.
- Voice recordings: not retained. The clip is deleted as soon as it has been turned into text, and the transcript is never written to our database.
- Messages: kept while your account is open, so both sides keep their thread.
- Billing records: Stripe keeps the payment and invoice records it is legally required to keep. On our side only the customer reference and your plan status remain, and those go when your account does.
What deleting your account removes.
Your profile and login, any pictures you uploaded, gigs you posted, gigs you saved, artists and venues you follow, your gig alerts, the devices you’d turned push notifications on for, and your messages — including from the other person’s copy of the conversation. Sign-up and password-reset records keyed to your email go too.
The one thing that stays.
If you run a venue account and your venue has been named and has gigs against it, the venue listing itself is not deleted — it is unlinked from you. Your account, your email and your ownership of it are gone, but the venue stays on the site as a public listing so the artists who played there don’t lose their gigs, and so someone at that venue can claim it later. A venue you never finished setting up has no listing and no gigs, so it is deleted with the account.
You may request access, correction, deletion, or restriction/objection to certain processing. Where we rely on consent (e.g., newsletters), you can withdraw it anytime.
Two of these you can do yourself, right now: download everything we hold on you with the button below, and delete your account from your profile settings — no email, no waiting on us.
Contact: support@gigiddy.co.uk. If unresolved, you can complain to the UK Information Commissioner’s Office (ICO).
Users under 18 may sign up. Parents/guardians can contact us to remove an account.
- We apply appropriate technical and organisational measures to protect account data, including login credentials, consistent with industry practice.
- Access to our systems is limited to authorised personnel for operating and securing the service.
- Data is encrypted in transit (HTTPS); our providers apply further safeguards.
If we make material changes, we’ll notify you (e.g., email or in-app) and update the date at the top of this page.