getsetgig

Privacy

How we look after your data, in plain English.

Last updated: 9 June 2026

Who we are

Get Set Gig is built by Get Set Gig Ltd — a UK company (registration number 17248614), registered office 45 Crossway, Welwyn Garden City, Herts. AL8 7ED. We’re the data controller for personal data processed through this site and the Get Set Gig app. Get Set Gig Ltd is registered with the UK Information Commissioner’s Office under reference ZC160073 — you can verify the entry on the ICO’s public register.

We don’t have a Data Protection Officer because we’re not required to appoint one under UK GDPR (we don’t process large-scale special-category data and we’re not a public authority). Privacy questions go to Rob Wilson, the company director, at rob.wilson@getsetgig.com.

What we collect

We don’t deliberately collect special category data (health, racial or ethnic origin, political opinions, religious beliefs, biometric data, etc.). The one place a user might voluntarily share something close — the dietary requirements field on their profile — is treated as a free-text preference the user chose to enter (eg. for promoter riders, hotel breakfasts). We don’t infer health or religious status from it. The field is optional, editable by the user at any time, and visible to other members of their band only. The service is intended for adults: by signing up you confirm you are 18 or over.

Why we collect it (legal basis under UK GDPR Article 6)

Who we share it with

We use third-party processors to deliver specific parts of the service. Each is bound by a data processing agreement.

We do not sell your data. We do not share it with advertisers or data brokers.

International transfers

Your data is processed and stored within the UK and the European Economic Area. Specifically: Supabase is configured to use the eu-west-2 (London) region, Vercel runs in EU regions, Sentry and PostHog use their EU clusters. Where any small amount of data may transfer to Google or Microsoft systems outside the UK/EEA (during OAuth sign-in), it’s covered by the UK’s adequacy decision for the EU and by the UK Addendum to the EU Standard Contractual Clauses for any onward transfers.

How long we keep it

We keep account and band data while your account is active. If you delete your account, your personal data is removed immediately from our application database, with full deletion from backups within 30 days. We retain anonymised analytics data and aggregated logs for up to 12 months. Where law requires us to keep records longer — for example UK tax law requires billing records for six years — we keep those minimum records for the legally required period and nothing more.

How we protect it

Data is encrypted in transit (TLS) and at rest (Supabase’s storage encryption). Authentication uses magic links or OAuth via Google/Microsoft — no passwords to leak. All administrator accounts on our sub-processors require multi-factor authentication. The application uses Postgres row-level security so a band’s data is database-level isolated from every other band. We add basic security headers (CSP, HSTS, X-Frame-Options) and rate-limit public endpoints. No system is invulnerable, but we’re honest about that and we don’t process anything more sensitive than what’s needed for the band-management service.

Your rights

Under UK GDPR you have the right to:

To exercise any of these, the in-app controls are the fastest route. If you’d rather email, we’re at rob.wilson@getsetgig.com — we aim to respond within 30 days. If you’re not satisfied with our response you can complain to the UK Information Commissioner’s Office at ico.org.uk.

Automated decision-making

We don’t do any automated decision-making or profiling that produces legal effects on you. No AI is used to make decisions about your account.

Cookies

What we set and why is listed separately on the cookies page.

Changes to this notice

We may update this notice from time to time. Material changes will be notified by email or in the app at least 14 days before they take effect. The “Last updated” date at the top of the page always reflects the current version.

Contact

Privacy questions, data requests, or complaints — rob.wilson@getsetgig.com.