01 Information We Collect
Account information
Name, email address, phone number, and password (handled by our authentication provider — we never see or store your raw password).
Profile information
Username, bio, genre, profile photo, and cover photo.
Identity and verification information
To confirm who you are and to prevent fraud, we collect your full legal name, your date of birth, and your South African ID number or passport, together with supporting documents (a copy of your ID or passport and, for payouts or refunds, a bank account confirmation letter). We read your identity details directly from the document you upload. Where an account is operated by a business, we also collect the registered business name, company registration number, and details of the person responsible for the account. This applies both to artists (who receive payouts) and to promoters/bookers, and helps us meet South African anti-money-laundering (FICA) requirements.
Banking information
Bank name, account holder name, account type, and account number — used to pay artists for completed bookings and to return funds where required (for example, a refund following a dispute). We keep only a masked version of your account number (for example, the last four digits); the full account number is held securely by our licensed payment processor and is not stored on GigVault's servers. We also do not store card numbers or online banking login credentials; card payments are handled directly by our payment processor. Inside the app, you must re-enter your account password to view or change your banking details.
Booking information
Event dates, times, venues, technical and hospitality riders, fees, and payment/escrow records.
Verification media (including facial images)
We capture a selfie in two situations: when you sign a booking agreement, and when you authorise money to be released (for example, releasing escrow, redeeming a release code, or withdrawing funds). A facial image is "special personal information" under POPIA, and we treat it with extra care and use it only to confirm that a real, present person is carrying out the action. The selfie taken to authorise releasing money is used for that check only and is not stored; the selfie and signature captured when you sign an agreement are kept with that signed agreement as a record of it.
Location information
Venue addresses you search for or enter (via a mapping and location search provider), used to help bookers find venues and artists find events. In addition: (a) if you consent to share your live location while travelling to an event, your position is shared with the promoter until check-in and the most recent shared position forms part of the booking record; and (b) we record a GPS position at key booking actions — checking in, checking out, and opening a dispute or cancellation — as part of the booking/dispute record. We record these positions as facts with timestamps; if location sharing is off, no travel location data exists and none can be produced.
Communications
Messages sent between artists and bookers through in-app chat, and reviews/ratings left after a booking.
Business and tax documents
Where you choose a business payout account we collect your CIPC CoR39 certificate, and where you declare VAT registration we collect your SARS Notice of Registration (VAT). We read the registration details directly off these documents and delete them as soon as they have been processed — only the outcome (for example, the registered name and registration number, which are public registry data) is kept.
Dispute records
When a dispute is opened we compile an evidence record (payment records, the signed agreement, check-in/check-out times, and — where applicable and consented — location facts), which is emailed to both parties from our disputes mailbox and archived as the case file. Resolution proposals include commissioned affidavits and proof of identity from both parties: affidavits are retained permanently as the record of what was agreed; the ID copies are deleted automatically once the dispute resolves. Dispute timelines and outcomes are retained for accountability.
Device and push notification information
A push notification token so we can notify you about booking updates, and basic app performance/usage data.
02 Why We Collect It
- To create and run your account and match artists with bookers
- To verify your identity and confirm that payout or refund accounts belong to you, and to detect and prevent fraud
- To process payments and hold funds in escrow until a booking is completed
- To pay artists their booking fees, and to meet FICA/AML legal requirements
- To let artists and bookers communicate and confirm agreements
- To resolve disputes, provide support, and keep the platform secure
- To send booking-related notifications and emails
We do not sell your personal information, and we do not use it for third-party advertising.
03 Who We Share It With
We only share what each provider needs to do its job, and we require them to protect your information appropriately. We may also disclose information where required by law, or to protect the rights, safety, or property of GigVault, our users, or the public.
04 Data Retention
We keep your information for as long as your account is active. After account closure, we retain certain records (in particular FICA/banking and transaction records) for as long as South African law requires — typically several years — for tax, anti-money-laundering, and dispute purposes.
Wherever possible we keep only what we need. Identity documents (such as ID or passport copies and bank confirmation letters) are deleted as soon as verification is complete — we do not keep the documents afterwards, only a record that verification took place and its outcome (for example, the verification method and the last four digits of your ID). Selfies used to authorise releasing money are discarded after the check and are not stored at all. For full details, see our Data Retention Policy.
05 Security
We apply reasonable technical and organisational measures to protect your personal information. These include holding sensitive banking details with our licensed payment processor rather than on our own servers (we keep only a masked account number), deleting identity documents as soon as verification is complete, and requiring you to re-enter your account password before viewing or changing your banking details in the app. No system is completely secure, and we cannot guarantee absolute security, particularly against events outside our reasonable control such as third-party cyberattacks.
06 Your Rights
Under POPIA, you have the right to:
- Access the personal information we hold about you
- Ask us to correct inaccurate or outdated information
- Ask us to delete your information, subject to our legal retention obligations (see Section 4)
- Object to certain processing of your information
- Lodge a complaint with the Information Regulator of South Africa
To exercise any of these rights, contact us using the details in Section 9.
07 Children
GigVault is not intended for use by anyone under 18. We do not knowingly collect personal information from children.
08 Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date at the top of this page.
09 Contact
For any questions about this Privacy Policy or how we handle your personal information:
Email: support@gigvault.co.za
Website: gigvault.co.za
GigVault is a product of uMncube (Pty) Ltd (Reg No: 2022/772917/07), a private company registered in the Republic of South Africa.
Note: This document is version 1.4 published 4 July 2026 and works together with our Terms and Conditions and Data Retention Policy. GigVault recommends that Users retain a copy for their records.