Contents

01 Information We Collect

Account information

Name, email address, phone number, and password (handled by our authentication provider — we never see or store your raw password).

Profile information

Username, bio, genre, profile photo, and cover photo.

Identity and verification information

To confirm who you are and to prevent fraud, we collect your full legal name, your date of birth, and your South African ID number or passport, together with supporting documents (a copy of your ID or passport and, for payouts or refunds, a bank account confirmation letter). We read your identity details directly from the document you upload. Where an account is operated by a business, we also collect the registered business name, company registration number, and details of the person responsible for the account. This applies both to artists (who receive payouts) and to promoters/bookers, and helps us meet South African anti-money-laundering (FICA) requirements.

Banking information

Bank name, account holder name, account type, and account number — used to pay artists for completed bookings and to return funds where required (for example, a refund following a dispute). We keep only a masked version of your account number (for example, the last four digits); the full account number is held securely by our licensed payment processor and is not stored on GigVault's servers. We also do not store card numbers or online banking login credentials; card payments are handled directly by our payment processor. Inside the app, you must re-enter your account password to view or change your banking details.

Booking information

Event dates, times, venues, technical and hospitality riders, fees, and payment/escrow records.

Verification media (including facial images)

We capture a selfie in two situations: when you sign a booking agreement, and when you authorise money to be released (for example, releasing escrow, redeeming a release code, or withdrawing funds). A facial image is "special personal information" under POPIA, and we treat it with extra care and use it only to confirm that a real, present person is carrying out the action. The selfie taken to authorise releasing money is used for that check only and is not stored; the selfie and signature captured when you sign an agreement are kept with that signed agreement as a record of it.

Location information

Venue addresses you search for or enter (via a mapping and location search provider), used to help bookers find venues and artists find events. In addition: (a) if you consent to share your live location while travelling to an event, your position is shared with the promoter until check-in and the most recent shared position forms part of the booking record; and (b) we record a GPS position at key booking actions — checking in, checking out, and opening a dispute or cancellation — as part of the booking/dispute record. We record these positions as facts with timestamps; if location sharing is off, no travel location data exists and none can be produced.

What you search for in the Gig Guide

When you search the Gig Guide, we record the search: the town or city you were searching in, the date you were looking for, the artist you filtered by if you chose one, and — importantly — whether we had anything to show you. We use this to find places and dates where people are looking for live music and not finding any, so that artists and promoters can put shows where they are actually wanted.

We do not keep your position. Your device's coordinates are turned into the name of the nearest town on our servers and then discarded in the same step — what is written down is a place name such as "Polokwane", never a location. If your coordinates do not fall near any town we recognise, nothing is recorded at all. Repeat searches for the same thing within a few minutes are stored once, not several times.

Where you have set a home city on your profile, we also note whether the town you searched differs from it — this is how we tell that people in one town are looking for shows in another. This information is never shown to an artist, a promoter or a label as anything about you individually. It is only ever reported as counts of people, and a place-and-date combination searched by fewer than three people is not reported at all. These search records are deleted after 90 days, and all of them are deleted when you delete your account.

Communications

Messages sent between artists and bookers through in-app chat, and reviews/ratings left after a booking.

Content you publish, and who can see it

Photographs, video, captions and comments you post to the Feed, together with the events you list in the Gig Guide. This content is public inside the app — anyone using GigVault can see it, along with your display name and profile photo. Please treat anything you post as public, and do not include personal details you would not want a stranger to read.

We also record who follows whom, and which posts you like, comment on or save. We use this to build your feed, to show follower counts on profiles, and to tell an artist who is following them. Your follower and following lists are visible to other users; the events you save privately are not.

The like button on a post is captioned "Come to my City", and it means what it says: when you press it we also note the home city you set on your profile, so that artists can see which towns are asking for them. We take that city from your own profile — never from your device's location — so if you have not set one, nothing is attached. It is only ever reported to an artist or label as a count of people per town, never as a list naming you.

When you use the share button on a video or photo, we create a copy carrying GigVault branding, your display name, your profile picture and your caption, and place it at a public internet address so that it can be opened outside the app. That copy sits outside GigVault once shared, and we cannot recall it — deleting the original post, or your account, does not delete a copy someone has already shared onward.

How you engage with an artist's content

We record how much of a video you watch, and how often the app has shown you a particular artist. We use this to work out which artists you are genuinely engaged with, and we show each artist an ordered list of the people most invested in them.

What that list shows about you is limited on purpose. An artist sees your display name and profile photo, whether you follow them, whether you have set a ticket alert (and the city you entered when you did), and whether you have marked one of their shows as one you want to go to — in other words, things you deliberately chose to do towards that artist. An artist is never shown how long you watched, how much of a video you finished, how many times you have been shown their posts, or any score.

The detailed viewing records behind this are deleted after 90 days; only the summary is kept, and it fades on its own if you stop engaging. If you would rather not appear on these lists at all, you can opt out in the app, and everything about you is deleted when you delete your account.

If you book artists: what we record about your search for talent

When you browse for artists to book, we record which artists were put in front of you, the position they appeared in, and the town you were booking for — again resolved to a place name on our servers and never stored as a position. We use this for one purpose: to tell an artist or their label how often they were shown to real promoters and how often that led to a booking, so that an artist who is seen often but rarely booked can be told the difference between "nobody sees me" and "people see me and pass".

This is never shown to anyone as a record of what you personally looked at. An artist or label sees counts of promoters, never your name against a browsing history, and never which other artists you considered. We keep one record per artist per day however many times you scroll the same list. These records are deleted after 90 days and all of them are deleted when you delete your account.

Business and tax documents

Where you choose a business payout account we collect your CIPC CoR39 certificate, and where you declare VAT registration we collect your SARS Notice of Registration (VAT). We read the registration details directly off these documents and delete them as soon as they have been processed — only the outcome (for example, the registered name and registration number, which are public registry data) is kept.

Dispute records

When a dispute is opened we compile an evidence record (payment records, the signed agreement, check-in/check-out times, and — where applicable and consented — location facts), which is emailed to both parties from our disputes mailbox and archived as the case file. Resolution proposals include commissioned affidavits and proof of identity from both parties: affidavits are retained permanently as the record of what was agreed; the ID copies are deleted automatically once the dispute resolves. Dispute timelines and outcomes are retained for accountability.

Emergency contact (third-party information)

Artists may provide the name, email address, phone number and relationship of an emergency contact. This is information about someone other than you, so please only enter details of a person who is content to be contacted on your behalf, and tell them you have done so.

We use it for one purpose only: if a promoter reports that your event was cancelled and we cannot reach you for 12 hours, we email this person to establish that you are safe before any conclusion is drawn about your booking or your fee. We do not use emergency contact details for marketing, we do not share them with promoters, other artists or any other user, and we do not use them for any other purpose. They are deleted when you delete your account, and you can change or remove them at any time in the app.

Device and push notification information

A push notification token so we can notify you about booking updates, and basic app performance/usage data.

02 Why We Collect It

We do not sell your personal information, and we do not use it for third-party advertising.

03 Who We Share It With

·TradeSafe (Pty) Ltd — our escrow and payment processor. Banking details and the information needed for FICA/AML checks are shared with TradeSafe to process payments and payouts.
·Identity and bank-account verification services — used to confirm that the identity and banking details provided are valid and belong to you.
·Cloud infrastructure and authentication providers — used to securely host the Platform, manage account sign-in, and carry out automated identity and image checks.
·A mapping and location search provider — used for venue address search and autocomplete.
·Our email provider — used to send booking confirmations, receipts, and account notifications.
·Our app delivery provider — used to deliver push notifications and app updates.
·Travel partners — if you explicitly request help arranging travel (flights, accommodation, transport) for a booking, we share only what's needed to arrange it: your contact number and email, and the relevant booking details (dates, venue, what needs arranging). This only happens when you take that action yourself — it's never shared automatically — and is limited to that specific request. You can withdraw this consent at any time by contacting support@gigvault.co.za, which stops any further sharing for that booking.

We only share what each provider needs to do its job, and we require them to protect your information appropriately. We may also disclose information where required by law, or to protect the rights, safety, or property of GigVault, our users, or the public.

04 Data Retention

We keep your information for as long as your account is active. After account closure, we retain certain records (in particular FICA/banking and transaction records) for as long as South African law requires — typically several years — for tax, anti-money-laundering, and dispute purposes.

Wherever possible we keep only what we need. Identity documents (such as ID or passport copies and bank confirmation letters) are deleted as soon as verification is complete — we do not keep the documents afterwards, only a record that verification took place and its outcome (for example, the verification method and the last four digits of your ID). Selfies used to authorise releasing money are discarded after the check and are not stored at all. For full details, see our Data Retention Policy.

05 Security

We apply reasonable technical and organisational measures to protect your personal information. These include holding sensitive banking details with our licensed payment processor rather than on our own servers (we keep only a masked account number), deleting identity documents as soon as verification is complete, and requiring you to re-enter your account password before viewing or changing your banking details in the app. No system is completely secure, and we cannot guarantee absolute security, particularly against events outside our reasonable control such as third-party cyberattacks.

06 Your Rights

Under POPIA, you have the right to:

To exercise any of these rights, contact us using the details in Section 9.

07 Children

GigVault is not intended for use by anyone under 18. We do not knowingly collect personal information from children.

08 Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date at the top of this page.

09 Contact

For any questions about this Privacy Policy or how we handle your personal information:

Email: support@gigvault.co.za

Website: gigvault.co.za

GigVault is a product of uMncube (Pty) Ltd (Reg No: 2022/772917/07), a private company registered in the Republic of South Africa.

Note: This document is version 1.8 published 1 August 2026 and works together with our Terms and Conditions and Data Retention Policy. GigVault recommends that Users retain a copy for their records.