01 Purpose and Scope
This policy explains how long GigVault keeps each category of personal information, why we keep it for that period, and what happens to it afterwards. It applies to all users of the GigVault platform — artists, promoters/bookers, and business accounts — and works together with our Privacy Policy (which explains what we collect and why) and our Terms and Conditions.
Retention periods are set by two things: what we need to operate the platform for you, and what South African law — in particular the Protection of Personal Information Act (POPIA), the Financial Intelligence Centre Act (FICA), and tax legislation — requires us to keep.
02 Our Approach
Our guiding principle is data minimisation: we keep only what we need, for only as long as we need it. In practice this means:
- Verify and discard. Documents and images used to verify your identity are used for that check and then deleted. We keep a record that verification happened and its outcome — not the raw document or image.
- Store the minimum. Where a partial value is enough, we keep only that — for example, a masked bank account number (the last four digits) and the last four digits of an ID number, never the full values.
- Let the specialist hold it. Full banking details are held by our licensed payment processor (TradeSafe), which is regulated for exactly that purpose — not on GigVault's servers.
- Automate deletion. Deletion is built into the platform and runs automatically — it does not depend on someone remembering to clean up.
03 Retention Schedule
The table below sets out our standard retention periods for each category of information. Where a legal obligation requires a longer period than an operational one, the legal period applies.
| Category | Kept for | Why |
|---|---|---|
| Identity documents (ID or passport copy, bank confirmation letter) |
Deleted immediately once verification succeeds. If verification is never completed, uploads are automatically deleted by a scheduled sweep, and in any event within 180 days. | Verify-and-discard — the document is needed only to perform the check. |
| Release-authorisation selfies | Never stored. The image is checked in memory and discarded immediately. | Used only to confirm a real, present person is authorising a release of funds. |
| Agreement selfie and signature | Kept with the signed booking agreement, for as long as that agreement is kept (see transaction records below). | Forms part of the record of the agreement itself. |
| Verification outcome records (verification method, result, legal name, last four digits of ID) |
At least 5 years after the business relationship ends. | FICA/anti-money-laundering record-keeping and fraud prevention. |
| Banking details | Masked account number (last four digits) kept while your account can receive payouts or refunds. The full account number is held by TradeSafe under its own regulated retention rules and is not stored by GigVault. | To display your payout account to you and route payments correctly. |
| Booking, payment, and escrow records (bookings, fees, escrow movements, withdrawals, invoices/receipts) |
At least 5 years after the transaction or after your account closes. | FICA, tax law, and dispute resolution. |
| Dispute records (dispute messages, evidence records, timelines, outcomes, commissioned affidavits) |
Kept with the related booking's records for the same period as transaction records. Affidavits are retained permanently as the record of what was agreed; ID copies attached to dispute confirmations are deleted automatically when the dispute resolves. | Evidence of how a dispute was resolved. |
| Business & tax documents (CIPC CoR39 certificate, SARS VAT notice) |
Deleted as soon as the document has been processed; only the outcome (registered name, registration number — public registry data) is kept. | Verify-and-discard — the document is needed only to perform the check. |
| Account and profile information (name, email, phone, username, bio, photos) |
While your account is active. Removed or de-identified after account closure, except where needed inside records we must keep (see above). | To operate your account. |
| Messages and reviews | While your account is active; messages that form part of a dispute follow the dispute-record period. | To provide chat and review features and resolve disputes. |
| Device and push notification tokens | While the app is installed and your account is active; removed when they stop working or your account closes. | To deliver booking notifications. |
| Security and audit logs (verification events, payment-system logs — outcomes only, no documents or images) |
At least 5 years. | Fraud prevention, security investigations, and regulatory accountability. |
| Support correspondence | Up to 3 years after the matter is resolved. | To handle follow-ups and recurring issues. |
Note: Where GigVault's payment processor (TradeSafe) or another regulated partner is itself required by law to keep records — for example under FICA — those records are held by that partner under its own retention obligations, which may differ from the periods above.
04 Identity Documents & Facial Images
Because identity documents and facial images are the most sensitive information we handle (a facial image is "special personal information" under POPIA), they get the strictest treatment:
05 Account Closure and Deletion Requests
06 How We Delete
When information reaches the end of its retention period, or is deleted at your request, it is removed from our live systems. Copies held in our infrastructure provider's routine backups are not individually editable and expire on that provider's backup cycle, after which they are gone entirely; backup copies are never restored except to recover from a system failure, and deleted data is re-deleted if a restore ever brings it back.
Deletions of identity documents are themselves logged (the fact of deletion, not the content), so we can demonstrate that verify-and-discard actually happened.
07 Changes to This Policy
We may update this Data Retention Policy from time to time, for example when the law changes or when we improve our data-handling practices. Material changes will be reflected by an updated "Last updated" date at the top of this page.
08 Contact
For questions about this policy, or to exercise your POPIA rights (access, correction, deletion, objection):
Email: support@gigvault.co.za
Website: gigvault.co.za
GigVault is a product of uMncube (Pty) Ltd (Reg No: 2022/772917/07), a private company registered in the Republic of South Africa. You may also lodge a complaint with the Information Regulator of South Africa.
Note: This document is version 1.0 published 3 July 2026 and works together with our Privacy Policy and Terms and Conditions. GigVault recommends that Users retain a copy for their records.