01 Information We Collect
Account information
Name, email address, phone number, and password (handled by our authentication provider — we never see or store your raw password).
Profile information
Username, bio, genre, profile photo, and cover photo.
Identity and verification information
To confirm who you are and to prevent fraud, we collect your full legal name, your date of birth, and your South African ID number or passport, together with supporting documents (a copy of your ID or passport and, for payouts or refunds, a bank account confirmation letter). We read your identity details directly from the document you upload. Where an account is operated by a business, we also collect the registered business name, company registration number, and details of the person responsible for the account. This applies both to artists (who receive payouts) and to promoters/bookers, and helps us meet South African anti-money-laundering (FICA) requirements.
Banking information
Bank name, account holder name, account type, and account number — used to pay artists for completed bookings and to return funds where required (for example, a refund following a dispute). We keep only a masked version of your account number (for example, the last four digits); the full account number is held securely by our licensed payment processor and is not stored on GigVault's servers. We also do not store card numbers or online banking login credentials; card payments are handled directly by our payment processor. Inside the app, you must re-enter your account password to view or change your banking details.
Booking information
Event dates, times, venues, technical and hospitality riders, fees, and payment/escrow records.
Verification media (including facial images)
We capture a selfie in two situations: when you sign a booking agreement, and when you authorise money to be released (for example, releasing escrow, redeeming a release code, or withdrawing funds). A facial image is "special personal information" under POPIA, and we treat it with extra care and use it only to confirm that a real, present person is carrying out the action. The selfie taken to authorise releasing money is used for that check only and is not stored; the selfie and signature captured when you sign an agreement are kept with that signed agreement as a record of it.
Location information
Venue addresses you search for or enter (via a mapping and location search provider), used to help bookers find venues and artists find events. In addition: (a) if you consent to share your live location while travelling to an event, your position is shared with the promoter until check-in and the most recent shared position forms part of the booking record; and (b) we record a GPS position at key booking actions — checking in, checking out, and opening a dispute or cancellation — as part of the booking/dispute record. We record these positions as facts with timestamps; if location sharing is off, no travel location data exists and none can be produced.
What you search for in the Gig Guide
When you search the Gig Guide, we record the search: the town or city you were searching in, the date you were looking for, the artist you filtered by if you chose one, and — importantly — whether we had anything to show you. We use this to find places and dates where people are looking for live music and not finding any, so that artists and promoters can put shows where they are actually wanted.
We do not keep your position. Your device's coordinates are turned into the name of the nearest town on our servers and then discarded in the same step — what is written down is a place name such as "Polokwane", never a location. If your coordinates do not fall near any town we recognise, nothing is recorded at all. Repeat searches for the same thing within a few minutes are stored once, not several times.
Where you have set a home city on your profile, we also note whether the town you searched differs from it — this is how we tell that people in one town are looking for shows in another. This information is never shown to an artist, a promoter or a label as anything about you individually. It is only ever reported as counts of people, and a place-and-date combination searched by fewer than three people is not reported at all. These search records are deleted after 90 days, and all of them are deleted when you delete your account.
Communications
Messages sent between artists and bookers through in-app chat, and reviews/ratings left after a booking.
Content you publish, and who can see it
Photographs, video, captions and comments you post to the Feed, together with the events you list in the Gig Guide. This content is public inside the app — anyone using GigVault can see it, along with your display name and profile photo. Please treat anything you post as public, and do not include personal details you would not want a stranger to read.
We also record who follows whom, and which posts you like, comment on or save. We use this to build your feed, to show follower counts on profiles, and to tell an artist who is following them. Your follower and following lists are visible to other users; the events you save privately are not.
The like button on a post is captioned "Come to my City", and it means what it says: when you press it we also note the home city you set on your profile, so that artists can see which towns are asking for them. We take that city from your own profile — never from your device's location — so if you have not set one, nothing is attached. It is only ever reported to an artist or label as a count of people per town, never as a list naming you.
When you use the share button on a video or photo, we create a copy carrying GigVault branding, your display name, your profile picture and your caption, and place it at a public internet address so that it can be opened outside the app. That copy sits outside GigVault once shared, and we cannot recall it — deleting the original post, or your account, does not delete a copy someone has already shared onward.
How you engage with an artist's content
We record how much of a video you watch, and how often the app has shown you a particular artist. We use this to work out which artists you are genuinely engaged with, and we show each artist an ordered list of the people most invested in them.
What that list shows about you is limited on purpose. An artist sees your display name and profile photo, whether you follow them, whether you have set a ticket alert (and the city you entered when you did), and whether you have marked one of their shows as one you want to go to — in other words, things you deliberately chose to do towards that artist. An artist is never shown how long you watched, how much of a video you finished, how many times you have been shown their posts, or any score.
The detailed viewing records behind this are deleted after 90 days; only the summary is kept, and it fades on its own if you stop engaging. If you would rather not appear on these lists at all, you can opt out in the app, and everything about you is deleted when you delete your account.
If you book artists: what we record about your search for talent
When you browse for artists to book, we record which artists were put in front of you, the position they appeared in, and the town you were booking for — again resolved to a place name on our servers and never stored as a position. We use this for one purpose: to tell an artist or their label how often they were shown to real promoters and how often that led to a booking, so that an artist who is seen often but rarely booked can be told the difference between "nobody sees me" and "people see me and pass".
This is never shown to anyone as a record of what you personally looked at. An artist or label sees counts of promoters, never your name against a browsing history, and never which other artists you considered. We keep one record per artist per day however many times you scroll the same list. These records are deleted after 90 days and all of them are deleted when you delete your account.
Business and tax documents
Where you choose a business payout account we collect your CIPC CoR39 certificate, and where you declare VAT registration we collect your SARS Notice of Registration (VAT). We read the registration details directly off these documents and delete them as soon as they have been processed — only the outcome (for example, the registered name and registration number, which are public registry data) is kept.
Dispute records
When a dispute is opened we compile an evidence record (payment records, the signed agreement, check-in/check-out times, and — where applicable and consented — location facts), which is emailed to both parties from our disputes mailbox and archived as the case file. Resolution proposals include commissioned affidavits and proof of identity from both parties: affidavits are retained permanently as the record of what was agreed; the ID copies are deleted automatically once the dispute resolves. Dispute timelines and outcomes are retained for accountability.
Emergency contact (third-party information)
Artists may provide the name, email address, phone number and relationship of an emergency contact. This is information about someone other than you, so please only enter details of a person who is content to be contacted on your behalf, and tell them you have done so.
We use it for one purpose only: if a promoter reports that your event was cancelled and we cannot reach you for 12 hours, we email this person to establish that you are safe before any conclusion is drawn about your booking or your fee. We do not use emergency contact details for marketing, we do not share them with promoters, other artists or any other user, and we do not use them for any other purpose. They are deleted when you delete your account, and you can change or remove them at any time in the app.
Device and push notification information
A push notification token so we can notify you about booking updates, and basic app performance/usage data.
02 Why We Collect It
- To create and run your account and match artists with bookers
- To verify your identity and confirm that payout or refund accounts belong to you, and to detect and prevent fraud
- To process payments and hold funds in escrow until a booking is completed
- To pay artists their booking fees, and to meet FICA/AML legal requirements
- To let artists and bookers communicate and confirm agreements
- To resolve disputes, provide support, and keep the platform secure
- To send booking-related notifications and emails
- To show artists which of their audience is most engaged with them, in the limited form described above
We do not sell your personal information, and we do not use it for third-party advertising.
03 Who We Share It With
We only share what each provider needs to do its job, and we require them to protect your information appropriately. We may also disclose information where required by law, or to protect the rights, safety, or property of GigVault, our users, or the public.
04 Data Retention
We keep your information for as long as your account is active. After account closure, we retain certain records (in particular FICA/banking and transaction records) for as long as South African law requires — typically several years — for tax, anti-money-laundering, and dispute purposes.
Wherever possible we keep only what we need. Identity documents (such as ID or passport copies and bank confirmation letters) are deleted as soon as verification is complete — we do not keep the documents afterwards, only a record that verification took place and its outcome (for example, the verification method and the last four digits of your ID). Selfies used to authorise releasing money are discarded after the check and are not stored at all. For full details, see our Data Retention Policy.
05 Security
We apply reasonable technical and organisational measures to protect your personal information. These include holding sensitive banking details with our licensed payment processor rather than on our own servers (we keep only a masked account number), deleting identity documents as soon as verification is complete, and requiring you to re-enter your account password before viewing or changing your banking details in the app. No system is completely secure, and we cannot guarantee absolute security, particularly against events outside our reasonable control such as third-party cyberattacks.
06 Your Rights
Under POPIA, you have the right to:
- Access the personal information we hold about you
- Ask us to correct inaccurate or outdated information
- Ask us to delete your information, subject to our legal retention obligations (see Section 4)
- Object to certain processing of your information
- Lodge a complaint with the Information Regulator of South Africa
To exercise any of these rights, contact us using the details in Section 9.
07 Children
GigVault is not intended for use by anyone under 18. We do not knowingly collect personal information from children.
08 Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date at the top of this page.
09 Contact
For any questions about this Privacy Policy or how we handle your personal information:
Email: support@gigvault.co.za
Website: gigvault.co.za
GigVault is a product of uMncube (Pty) Ltd (Reg No: 2022/772917/07), a private company registered in the Republic of South Africa.
Note: This document is version 1.8 published 1 August 2026 and works together with our Terms and Conditions and Data Retention Policy. GigVault recommends that Users retain a copy for their records.