Overview
GigOrganizer ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our contract generation and e-signature services.
Information We Collect
Contract Information
When you create a contract, we collect the information you provide including names, email addresses, event details, and payment terms. This information is used primarily to provide, maintain, secure, and improve the Service, including contract generation and e-signature workflows.
Payment Information
Payment processing is handled by Stripe. We do not store your credit card information. We store transaction details necessary for order fulfillment and entitlement tracking, including: transaction amount, date, customer email, Stripe session and payment intent identifiers, payment status, and associated entitlements (e.g., GigPack credits).
Account Information
If you create an account, we store your email address and any profile information you provide. This enables you to access your contract history and manage your purchases.
E-Signature Data
Notice at Collection for Signers
If you are signing a document through GigOrganizer, this section serves as your notice at the point of collection. We collect the categories of information listed below for the purposes described. For retention periods, see Data Retention. We do not sell or share your personal information.
When you use GigOrganizer's electronic signature features, either as the organizer sending a contract or as a signer receiving one, we collect the following:
Signer Identity Information
- Name and email address provided by the contract creator
- Typed legal name entered during the signing ceremony
Signature Data
- Typed name signature (required for all signers)
- Drawn signature image, if the signer chooses to draw a signature (stored as a PNG image)
- Signature stroke coordinate data for drawn signatures (used solely to preserve signing evidence)
Technical and Network Information
- IP address at each step of the signing process (document review, disclosure acceptance, and signature)
- Browser type and version (user agent string)
- Timestamps for each action taken during signing
Audit Trail Data
A chronological, append-only record of all events in the signing transaction, including: envelope creation, email delivery, link access, document review, disclosure acceptance, signature adoption, and document finalization. Each event records the timestamp, actor email, IP address, and browser information. The audit trail is designed to be append-only and tamper-evident in ordinary application operation. Routine application paths do not permit modification or deletion of audit events.
Document Integrity Data
SHA-256 cryptographic hashes of documents, computed at generation and verified at signing. Frozen PDF snapshots (contract versions) that preserve the exact document presented to each signer.
How We Use E-Signature Data
We use e-signature data solely to: facilitate the electronic signing of contracts between parties; verify signer identity and demonstrate intent to sign; maintain legally sufficient evidence of signing transactions; generate Certificates of Completion appended to signed documents; detect and prevent unauthorized access or tampering; and comply with applicable electronic signature laws (ESIGN, UETA, CUETA). We do not use signature images, typed names, or signing behavior data for marketing, advertising, or profiling.
E-Signature Data Sharing
E-signature data is shared only with: the parties to the transaction (organizer and client), who receive the signed document and Certificate of Completion; our infrastructure providers (Supabase for database and storage, Vercel for hosting) acting as data processors; and law enforcement or regulatory authorities when required by valid legal process. We do not sell e-signature data or share it with third parties for marketing purposes.
How We Use Your Information
- Generate performance contracts based on your input
- Facilitate e-signature collection between parties
- Send contract-related emails (signing requests, completion notifications)
- Process payments and provide purchase confirmations
- Provide customer support when you contact us
- Improve our services based on usage patterns (anonymized)
Third-Party Services
We use the following third-party services:
- Stripe - Payment processing
- Resend - Transactional email delivery
- Twilio - SMS message delivery
- Google - OAuth sign-in (if you choose Google login)
- Apple - OAuth sign-in (if you choose Apple login)
- Supabase - Database, authentication, and file storage
- Vercel - Hosting and infrastructure
Each of these services has their own privacy policy governing their use of your data.
Cookies & Session Technologies
GigOrganizer uses essential cookies and similar technologies to operate the Service. We do not use advertising or tracking cookies.
- Authentication cookies: Used to maintain your login session across pages. Set on the
.gigorganizer.comdomain to enable seamless access between gigorganizer.com and contracts.gigorganizer.com. - Guest access tokens: Used to grant temporary dashboard access to guest purchasers (without an account) for 24 hours. These tokens are cryptographically signed and expire automatically.
- Security cookies: Used for CSRF protection and session integrity during authentication flows (e.g., OAuth PKCE code verifiers).
These cookies are strictly necessary for the Service to function and cannot be disabled while using GigOrganizer.
SMS / Text Messaging
GigOrganizer offers optional SMS text message reminders as part of our team management features. By opting in to receive SMS messages from GigOrganizer, you agree to the following:
- Opt-In: You will only receive SMS messages if you explicitly opt in via the GigOrganizer gig confirmation page. The opt-in checkbox is unchecked by default and requires your active consent.
- Message Types: SMS messages are limited to gig reminders containing event details such as venue, arrival time, and point-of-contact information.
- Message Frequency: Message frequency varies. You will typically receive 1-2 messages per gig you are confirmed for.
- Message and Data Rates: Message and data rates may apply. Check with your mobile carrier for details.
- Opt-Out: You can opt out at any time by replying STOP to any message, or by unchecking the SMS opt-in toggle on your gig confirmation page. Reply HELP for assistance.
- No Third-Party Sharing: Your mobile phone number and SMS opt-in data will never be shared with or sold to third parties or lead generators for marketing or promotional purposes.
For questions about SMS messaging, contact us at support@gigorganizer.com.
Data Retention
Account Data: Contract data, profile information, and purchase history are retained for the duration of your account. When you delete your account, this data is permanently removed (subject to the e-signature exception below).
Guest Access: Guest purchases (without an account) have full dashboard access for 24 hours. After 24 hours, access is limited to e-signature status and signed PDF downloads (this limited access does not expire). Guest session cookies expire with the access token (24 hours). The underlying purchase and contract records are retained as described in the Account Data and E-Signature Records sections.
Completed E-Signature Records: Signed documents, audit trails, signature images, and stroke data are retained for 7 years from the date of completion, or for the duration of the organizer's account, whichever is longer. This retention period supports the legal enforceability of signed contracts. If the organizer deletes their account, completed e-signature records are retained for the remainder of the 7-year period to preserve the legal record.
Incomplete Signing Transactions: Envelopes where not all parties have signed are retained for 90 days after the signing link expires, then permanently deleted.
Delete Your Data
You can permanently delete your account and all associated data at any time using our self-service deletion tool:
Delete My AccountThis action is permanent and cannot be undone. All contracts, purchases, and account data will be permanently removed. Completed e-signature records (signed documents and audit trails) may be retained for up to 7 years as described in the Data Retention section above.
Your Rights
- Access your personal data
- Request correction of inaccurate data
- Request deletion of your data
- Export your contract data
To exercise these rights, contact us at support@gigorganizer.com.
California Residents
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to Know: You may request the categories and specific pieces of personal information we have collected about you, including e-signature data.
- Right to Delete: You may request deletion of your personal information. E-signature audit trail data associated with completed transactions may be retained as necessary to comply with legal obligations and preserve the enforceability of signed contracts.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
Categories of Personal Information
- Identifiers: Name, email address, typed legal name. Sources: directly from you or from the organizer who creates the contract.
- Internet/Network Activity: IP address, browser type/version, timestamps. Sources: automatically collected during signing and Service use.
- Signature Data: Typed name, drawn signature images, stroke coordinate data. Sources: directly from the signer during the signing ceremony.
- Commercial Information: Transaction amounts, purchase history. Sources: from Stripe payment metadata.
- Authentication Data: Authentication session data from Google or Apple OAuth (if used). We do not persist provider OAuth access tokens. Sources: from the authentication provider you choose.
- Audit Records: Chronological signing event logs. Sources: generated by the Service during e-signature transactions.
Business Purpose: Providing, maintaining, securing, and improving the Service, including contract generation, e-signature facilitation, payment processing, customer support, and maintaining legally sufficient signing evidence.
Service Providers: Stripe (payments), Resend (email), Twilio (SMS), Google/Apple (authentication), Supabase (database/storage), Vercel (hosting).
Sale/Sharing: We do not sell or share personal information for cross-context behavioral advertising.
To exercise these rights, contact support@gigorganizer.com.
Contact
For privacy-related questions or concerns, contact us at: support@gigorganizer.com