Privacy
How we look after your data, in plain English.
Last updated: 9 June 2026
Who we are
Get Set Gig is built by Get Set Gig Ltd — a UK company (registration number 17248614), registered office 45 Crossway, Welwyn Garden City, Herts. AL8 7ED. We’re the data controller for personal data processed through this site and the Get Set Gig app. Get Set Gig Ltd is registered with the UK Information Commissioner’s Office under reference ZC160073 — you can verify the entry on the ICO’s public register.
We don’t have a Data Protection Officer because we’re not required to appoint one under UK GDPR (we don’t process large-scale special-category data and we’re not a public authority). Privacy questions go to Rob Wilson, the company director, at rob.wilson@getsetgig.com.
What we collect
- Account information — the email address you sign up with, an optional display name, optional address (used as your origin for drive-time on gig setup), optional phone number. If you sign in with Google or Microsoft, we also receive your verified email and display name from them.
- Band data you create — songs, setlists, gigs, rehearsals, contacts, venues, and the like. This is your band’s data. You own it. We hold it so the app works.
- Contacts you enter about other people — when you save a venue contact, promoter, or substitute musician (a “dep”), you’re entering some personal data about a third party (typically name, role, email, phone). You’re responsible for telling those people you’ve recorded their details for the band’s logistics use. We rely on legitimate interests (Art. 6(1)(f) UK GDPR) — the band needs to record who their promoter is.
- Brand assets you upload — logos, photos, audio files you upload via the brand-assets feature. Held in private Supabase Storage; only band members can read.
- Service usage — basic logs (timestamp, route, response code) so we can diagnose issues and keep the app fast. We strip personal data from error reports before they reach Sentry.
- Analytics — inside the app (app.getsetgig.com), PostHog collects anonymised behaviour only if you opt in on the Account page. On the landing site (getsetgig.com), PostHog also runs in a cookieless, memory-only mode — page views and CTA clicks are recorded in aggregate, but no cookies are set, no user profiles are built, and we can’t tell if the same visitor came twice. Same privacy footprint as the Vercel Web Analytics that’s also on the landing.
- Waitlist email — if you signed up on the landing page, just the email and a timestamp. We use it once, when paying customers can join.
We don’t deliberately collect special category data (health, racial or ethnic origin, political opinions, religious beliefs, biometric data, etc.). The one place a user might voluntarily share something close — the dietary requirements field on their profile — is treated as a free-text preference the user chose to enter (eg. for promoter riders, hotel breakfasts). We don’t infer health or religious status from it. The field is optional, editable by the user at any time, and visible to other members of their band only. The service is intended for adults: by signing up you confirm you are 18 or over.
Why we collect it (legal basis under UK GDPR Article 6)
- Performance of a contract (Art. 6(1)(b)) — to provide the service you signed up for: storing your band’s data, letting you collaborate with band members, processing payments when subscriptions launch.
- Legitimate interests (Art. 6(1)(f)) — third-party contact records you enter, security monitoring and abuse prevention, basic service logs to keep the app fast and stable. Our legitimate interests are balanced against the rights of those individuals; you can object at any time.
- Consent (Art. 6(1)(a)) — product analytics via PostHog, the waitlist email opt-in. Withdrawable at any time from the Account page or by emailing us.
- Legal obligation (Art. 6(1)(c)) — keeping billing records under UK tax law once subscriptions are live.
Who we share it with
We use third-party processors to deliver specific parts of the service. Each is bound by a data processing agreement.
- Supabase — database, authentication, file storage (region
eu-west-2/ London) - Vercel — application hosting (EU + UK regions)
- Resend — transactional email delivery (sign-in links, band invites)
- Sentry — error monitoring (EU region; we strip PII before sending)
- PostHog — product analytics (EU region). Opt-in and identified inside the app. On the landing site, cookieless and aggregate-only.
- Google — OAuth sign-in (for users who choose Google), Maps Distance Matrix for drive-time, Places autocomplete for venue lookup
- Microsoft — OAuth sign-in (for users who choose Microsoft)
- IONOS — domain DNS
- Vercel Web Analytics — landing-page traffic counts. Cookieless, aggregate only — no individual tracking.
We do not sell your data. We do not share it with advertisers or data brokers.
International transfers
Your data is processed and stored within the UK and the European Economic Area. Specifically: Supabase is configured to use the eu-west-2 (London) region, Vercel runs in EU regions, Sentry and PostHog use their EU clusters. Where any small amount of data may transfer to Google or Microsoft systems outside the UK/EEA (during OAuth sign-in), it’s covered by the UK’s adequacy decision for the EU and by the UK Addendum to the EU Standard Contractual Clauses for any onward transfers.
How long we keep it
We keep account and band data while your account is active. If you delete your account, your personal data is removed immediately from our application database, with full deletion from backups within 30 days. We retain anonymised analytics data and aggregated logs for up to 12 months. Where law requires us to keep records longer — for example UK tax law requires billing records for six years — we keep those minimum records for the legally required period and nothing more.
How we protect it
Data is encrypted in transit (TLS) and at rest (Supabase’s storage encryption). Authentication uses magic links or OAuth via Google/Microsoft — no passwords to leak. All administrator accounts on our sub-processors require multi-factor authentication. The application uses Postgres row-level security so a band’s data is database-level isolated from every other band. We add basic security headers (CSP, HSTS, X-Frame-Options) and rate-limit public endpoints. No system is invulnerable, but we’re honest about that and we don’t process anything more sensitive than what’s needed for the band-management service.
Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data — you can fix most of it yourself in the app.
- Erase your data — delete your account on the Your data page in the app.
- Restrict or object to processing based on legitimate interests.
- Port your data — download a full ZIP export on the same Your data page.
- Withdraw consent — analytics, waitlist, future marketing.
To exercise any of these, the in-app controls are the fastest route. If you’d rather email, we’re at rob.wilson@getsetgig.com — we aim to respond within 30 days. If you’re not satisfied with our response you can complain to the UK Information Commissioner’s Office at ico.org.uk.
Automated decision-making
We don’t do any automated decision-making or profiling that produces legal effects on you. No AI is used to make decisions about your account.
Cookies
What we set and why is listed separately on the cookies page.
Changes to this notice
We may update this notice from time to time. Material changes will be notified by email or in the app at least 14 days before they take effect. The “Last updated” date at the top of the page always reflects the current version.
Contact
Privacy questions, data requests, or complaints — rob.wilson@getsetgig.com.