Plain-language summary
GigMigo does not sell personal information and does not use third-party behavioral advertising. Profiles and calendar details are public only to the extent you publish or share them. Service providers process limited data to operate login, email, AI, maps, payments, hosting, and owner alerts.
1. Scope
This Privacy Policy applies to GigMigo websites, accounts, public profiles and calendars, scheduling tools, messaging, gig posts, referrals, payment-related features, and AI-assisted calendar tools (collectively, the “Service”). “GigMigo,” “we,” “us,” and “our” refer to the operator of the Service.
This policy does not govern a third-party website or service you choose to visit, including a payment provider, map provider, blockchain explorer, or a link posted by another user.
2. Information we collect
Account and profile information
- Phone number, display name, public handle, account and profile type, and account timestamps.
- Optional email address, password hash, profile photo, profile summary, and verification-status fields.
- Your acceptance of the Terms of Service and acknowledgment of this Privacy Policy.
Calendar and marketplace content
- Calendar events, availability, dates, times, locations, company names, notes, categories, recurring schedules, privacy roles, share links, invite claims, and change history.
- Time requests, including requester name, contact information, proposed time, title, and message.
- Private messages, gig posts, offers, agreements, work locations, pay descriptions, referrals, gig credits, and related account activity.
- Payment-claim information such as amount, network, token, transaction hash or signature, processor session identifiers, status, and the private listing draft awaiting publication. GigMigo does not receive complete card numbers from Stripe.
AI inputs and outputs
If you use the AI Assistant, we process the instructions, images, calendar context, tool actions, responses, and operational logs needed to perform and audit the requested calendar work.
Device and usage information
Our servers and service providers may receive IP address, request time, requested URL, browser or device information, referring page, error information, and security or rate-limit events. First-party visit analytics also record a pseudonymous visitor identifier, a 30-minute visit-session identifier, pages viewed, referral or campaign source, device category, and an approximate city, region, and country derived from the network address. The analytics dashboard stores a one-way keyed hash instead of the raw IP address; ordinary infrastructure logs may separately contain IP addresses for a limited operational period. We also use cookies and server-signed tokens described below.
Information from other sources
We may receive verification status from SMS, email, identity, or payment providers; public transaction information from blockchain networks or explorers; and geocoding results for addresses.
3. How we use information
- Create and secure accounts; send and verify one-time login codes; maintain sessions; and prevent abuse.
- Display profiles and calendars according to the visibility settings, roles, and links selected by the calendar owner.
- Process time requests, messages, gigs, offers, agreements, referrals, credits, payments, and transaction verification.
- Run the AI Assistant, apply requested edits, preserve change history, troubleshoot failures, and enforce daily usage limits.
- Geocode gig addresses and display maps.
- Send service messages, verification emails, signup alerts to the Service operator, security notices, and support replies.
- Maintain, debug, secure, measure, and improve the Service; understand traffic sources and approximate visitor geography; send real-time visitor alerts to the Service operator; enforce our Terms; and comply with law.
4. Public and shared information
Your handle, display name, profile type, profile photo, profile summary, public calendar view, public gigs, and other content you intentionally publish may be visible to anyone and may be copied or shared by others.
Calendar privacy controls can show full event details, selected fields, a “Booked” block, or nothing, depending on event type and viewer role. Share or invite links can grant additional access. Anyone who receives a link may forward it, so use limits and revocation controls when appropriate.
Time requests and direct messages are not public, but they are visible to the people participating in that request or conversation and to authorized Service administrators when reasonably necessary for support, safety, enforcement, or legal compliance.
5. How we disclose information
We disclose information only as needed for the purposes described in this policy:
- Other users and the public: information you publish, send, or share through profiles, calendars, links, requests, messages, gigs, offers, and agreements.
- Twilio: phone number and verification activity for SMS login codes.
- SignalWire: private alerts to the Service operator for new accounts and new site visits. Visitor alerts can include approximate city/region/country, referral source, first page, device category, and visit time, but not the visitor’s raw IP address.
- IPWhois: a visitor’s network address for conversion into approximate city, region, country, timezone, and network-provider information used in private first-party analytics and owner alerts.
- Email delivery providers: email address and verification or service-message content.
- Google Gemini: AI instructions, attached images, relevant calendar context, and generated responses when you use the AI Assistant. Do not submit information you do not want processed by an AI provider.
- OpenStreetMap, Nominatim, map-tile, and software-CDN providers: addresses submitted for geocoding and ordinary connection information such as IP address when map or library resources load.
- Stripe, if card checkout is enabled: checkout and transaction information. Stripe collects card information directly under its own privacy policy.
- Hosting, infrastructure, security, and professional providers: information reasonably necessary to operate, protect, audit, or support the Service.
- Legal and safety disclosures: when we reasonably believe disclosure is required by law or necessary to protect rights, safety, users, or the Service.
- Business transfer: as part of a financing, merger, acquisition, reorganization, or sale, subject to appropriate confidentiality and notice where required.
No sale or behavioral advertising: GigMigo does not sell personal information and does not share personal information for cross-context behavioral advertising.
7. Retention
We retain account, profile, calendar, message, listing, agreement, referral, credit, payment, change-history, and security records for as long as reasonably necessary to provide the Service, maintain continuity and backups, resolve disputes, prevent fraud, meet accounting or legal obligations, and enforce agreements. Pseudonymous visit and pageview analytics are ordinarily retained for up to 365 days; the coarse network-location cache is refreshed or removed after approximately 30 days.
Data approved for deletion may remain for a period in backups, logs, fraud-prevention records, or records we are legally required to keep. Public blockchain transactions cannot be deleted by GigMigo.
8. Security
We use measures designed to protect information, including encrypted HTTPS transport, one-time-code and password authentication, server-signed and HttpOnly session cookies, rate limits, password hashing, access controls, and restricted credential storage. No internet service can guarantee absolute security. Protect your login methods, review public visibility settings, and report suspected unauthorized access promptly.
9. Your choices and privacy rights
You can edit many profile and calendar fields, remove your profile image, change privacy roles and invite links, decline requests, and choose whether to use optional AI, email, password, messaging, map, and marketplace features.
You may request access, correction, portability, or deletion of personal information, or object to or restrict certain processing, by emailing privacy@gigmigo.com. We may need to verify your identity and authority before acting. We will not discriminate against you for exercising a privacy right. Some information may be retained or excluded where permitted by law.
If you live in a jurisdiction with additional rights, you may also have the right to appeal a denied request or contact your local privacy regulator. An authorized agent may submit a request where permitted by law, subject to verification.
10. Age requirement
GigMigo is for adults age 18 and older and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided information, contact us so we can investigate and take appropriate action.
11. United States processing
GigMigo is operated from the United States. If you access the Service from another country, information may be transferred to and processed in the United States and other places where our providers operate, which may have different data-protection laws.
12. Changes to this policy
We may update this policy as the Service or law changes. The revised page will show a new effective date. If a change materially affects how we use previously collected information, we will provide additional notice where required.
13. Contact
Privacy requests and questions: privacy@gigmigo.com
General support: support@gigmigo.com