Contents

01 Purpose and Scope

This policy explains how long GigVault keeps each category of personal information, why we keep it for that period, and what happens to it afterwards. It applies to all users of the GigVault platform — artists, promoters/bookers, and business accounts — and works together with our Privacy Policy (which explains what we collect and why) and our Terms and Conditions.

Retention periods are set by two things: what we need to operate the platform for you, and what South African law — in particular the Protection of Personal Information Act (POPIA), the Financial Intelligence Centre Act (FICA), and tax legislation — requires us to keep.

02 Our Approach

Our guiding principle is data minimisation: we keep only what we need, for only as long as we need it. In practice this means:

03 Retention Schedule

The table below sets out our standard retention periods for each category of information. Where a legal obligation requires a longer period than an operational one, the legal period applies.

CategoryKept forWhy
Identity documents
(ID or passport copy, bank confirmation letter)
Deleted immediately once verification succeeds. If verification is never completed, uploads are automatically deleted by a scheduled sweep, and in any event within 180 days. Verify-and-discard — the document is needed only to perform the check.
Release-authorisation selfies Never stored. The image is checked in memory and discarded immediately. Used only to confirm a real, present person is authorising a release of funds.
Agreement selfie and signature Kept with the signed booking agreement, for as long as that agreement is kept (see transaction records below). Forms part of the record of the agreement itself.
Verification outcome records
(verification method, result, legal name, last four digits of ID)
At least 5 years after the business relationship ends. FICA/anti-money-laundering record-keeping and fraud prevention.
Banking details Masked account number (last four digits) kept while your account can receive payouts or refunds. The full account number is held by TradeSafe under its own regulated retention rules and is not stored by GigVault. To display your payout account to you and route payments correctly.
Booking, payment, and escrow records
(bookings, fees, escrow movements, withdrawals, invoices/receipts)
At least 5 years after the transaction or after your account closes. FICA, tax law, and dispute resolution.
Dispute records
(dispute messages, evidence records, timelines, outcomes, commissioned affidavits)
Kept with the related booking's records for the same period as transaction records. Affidavits are retained permanently as the record of what was agreed; ID copies attached to dispute confirmations are deleted automatically when the dispute resolves. Evidence of how a dispute was resolved.
Business & tax documents
(CIPC CoR39 certificate, SARS VAT notice)
Deleted as soon as the document has been processed; only the outcome (registered name, registration number — public registry data) is kept. Verify-and-discard — the document is needed only to perform the check.
Account and profile information
(name, email, phone, username, bio, photos)
While your account is active. Removed or de-identified after account closure, except where needed inside records we must keep (see above). To operate your account.
Messages and reviews While your account is active; messages that form part of a dispute follow the dispute-record period. To provide chat and review features and resolve disputes.
Device and push notification tokens While the app is installed and your account is active; removed when they stop working or your account closes. To deliver booking notifications.
Security and audit logs
(verification events, payment-system logs — outcomes only, no documents or images)
At least 5 years. Fraud prevention, security investigations, and regulatory accountability.
Support correspondence Up to 3 years after the matter is resolved. To handle follow-ups and recurring issues.

Note: Where GigVault's payment processor (TradeSafe) or another regulated partner is itself required by law to keep records — for example under FICA — those records are held by that partner under its own retention obligations, which may differ from the periods above.

04 Identity Documents & Facial Images

Because identity documents and facial images are the most sensitive information we handle (a facial image is "special personal information" under POPIA), they get the strictest treatment:

4.1ID and passport copies, and bank confirmation letters are used to perform verification and are deleted from our systems as soon as verification succeeds. We do not keep a copy. What remains is the outcome record: that verification took place, the method used, the result, your legal name, and the last four digits of your ID number.
4.2If verification is not completed — for example, you upload a document but never finish the process — the uploaded documents are deleted automatically by a scheduled cleanup, and in any event within 180 days of upload.
4.3Selfies used to authorise releasing money (releasing escrow, redeeming a release code, withdrawing funds) are checked in memory and are never written to storage. There is nothing to delete because nothing is kept.
4.4The selfie and signature captured when you sign a booking agreement are different: they form part of the signed agreement itself, so they are kept with that agreement as a record of it, for the same period as the related transaction records.
4.5Changing your banking details requires re-verification. Because we do not keep your documents, any change to banking details requires you to re-upload your ID and go through verification again. The newly uploaded documents are again deleted once the check succeeds.

05 Account Closure and Deletion Requests

5.1You may request closure of your account and deletion of your personal information at any time by contacting support@gigvault.co.za from the email address linked to your account.
5.2On closure, we delete or de-identify your profile and account information. However, records we are legally required to keep — in particular FICA verification outcomes, transaction and escrow records, and related dispute records — are retained for the periods in Section 3 even after your account closes. This is a legal obligation under POPIA section 14, which permits retention where another law requires it.
5.3An account cannot be closed while it has an active booking, funds in escrow, an unresolved dispute, or a pending payout. Once these are resolved, closure proceeds.
5.4Retained records are kept only for the legal purposes that require them, are protected in the same way as active data, and are deleted when the retention period ends.

06 How We Delete

When information reaches the end of its retention period, or is deleted at your request, it is removed from our live systems. Copies held in our infrastructure provider's routine backups are not individually editable and expire on that provider's backup cycle, after which they are gone entirely; backup copies are never restored except to recover from a system failure, and deleted data is re-deleted if a restore ever brings it back.

Deletions of identity documents are themselves logged (the fact of deletion, not the content), so we can demonstrate that verify-and-discard actually happened.

07 Changes to This Policy

We may update this Data Retention Policy from time to time, for example when the law changes or when we improve our data-handling practices. Material changes will be reflected by an updated "Last updated" date at the top of this page.

08 Contact

For questions about this policy, or to exercise your POPIA rights (access, correction, deletion, objection):

Email: support@gigvault.co.za

Website: gigvault.co.za

GigVault is a product of uMncube (Pty) Ltd (Reg No: 2022/772917/07), a private company registered in the Republic of South Africa. You may also lodge a complaint with the Information Regulator of South Africa.

Note: This document is version 1.0 published 3 July 2026 and works together with our Privacy Policy and Terms and Conditions. GigVault recommends that Users retain a copy for their records.