GigTracker legal

Privacy Policy

What personal information GigTracker handles, why it is needed, who processes it, and how you can exercise your privacy rights.

Version 1.0Effective July 27, 2026PIPEDA-oriented
Return to GigTrackerTermsRetention
ContentsSummaryAccountabilityInformation collectedWhy we use itService providersPaymentsSafeguardsYour choices and rightsIncidentsBusiness transfersContact and complaints
Plain-language summary. GigTracker uses personal information to create and secure accounts, store the records you choose to enter, process plan access, provide private attachments and exports, communicate with you, and operate the service. We do not sell personal information. We do not run advertising profiles or use visitor analytics at launch.

1. Accountability and scope

GigTracker is operated in Ontario, Canada, by sole proprietor Ruth Salomi Janga and is accountable for personal information under its control. The designated Privacy Officer may be contacted at gigtrackerca@gmail.com. This Policy is designed around Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applies to the GigTracker PWA, support communications, and connected operations.

2. Information we collect

  • Account information: name, email, optional recovery email, authentication identifiers, policy versions accepted, province, and profile defaults.
  • Your record content: earnings, receipts, receipt line items, mileage, vehicles, notes, tax fields you choose to record, attachment metadata, and uploaded JPEG, PNG, WebP, or PDF files.
  • Plan and transaction information: selected plan and calendar year, entitlement, storage usage, promotion result, Stripe Checkout identifiers, amount paid, currency, transaction status, and limited receipt information. We do not receive or store full payment-card numbers.
  • Security and operational information: authentication, CAPTCHA, API, function, storage, email-delivery, webhook, backup, and error logs. These may include timestamps, request identifiers, IP address, browser or device information, and actions needed to detect abuse or troubleshoot.
  • Support information: messages and information you provide when asking for account, privacy, payment, deletion, or technical help.

We collect information directly from you, automatically through service operation and security controls, and from payment or email providers when they report transaction or delivery status.

3. Why we collect, use, and disclose information

We use personal information only for identified and reasonable purposes, including to create and authenticate accounts; provide calendar-year record storage; enforce plan limits; process and reconcile purchases; generate exports; send transactional messages; respond to requests; prevent fraud and unauthorized access; back up and restore the service; comply with law; and improve reliability without behavioural advertising.

If we propose a materially new purpose, we will explain it and obtain consent when required. We limit collection to what is reasonably needed for these purposes.

4. Service providers and processing locations

We use contracted providers to operate GigTracker:

  • Supabase: authentication, PostgreSQL database, server functions, and operational logs.
  • Cloudflare: website delivery, DNS, Turnstile security checks, private R2 attachments, and encrypted database-backup storage.
  • Stripe: Checkout, promotions, payment processing, receipts, fraud controls, and webhook events.
  • Resend: transactional authentication email delivery and related delivery logs.
  • GitHub: source deployment and a scheduled workflow that temporarily processes database exports on an ephemeral runner before encrypting and sending them to private R2 storage; no backup is retained as a GitHub artifact or committed to Git.

These providers process information on our behalf under their own security and legal obligations. Information may be processed in Canada, the United States, or other locations used by a provider, and may be subject to lawful access under those jurisdictions. We remain accountable for personal information transferred for processing.

5. Payments and promotions

Stripe collects payment details directly. GigTracker receives transaction status and identifiers needed to activate and audit calendar-year access. Private promotion codes are validated server-side. A 100% promotion may create a completed no-cost order without a card or PaymentIntent.

6. Safeguards

Safeguards include encrypted HTTPS connections, Supabase row-level access controls, private object storage, short-lived signed file links, least-privilege server credentials, Stripe webhook signatures, Turnstile abuse protection, multi-factor authentication where enabled, encrypted off-site backups, retention limits, and controlled recovery procedures. No system can guarantee absolute security; safeguards are reviewed as risks and technology change.

7. Your choices and privacy rights

  • You may view and correct many profile and record fields in the app.
  • You may request access to personal information under our control, ask how it has been used or disclosed, and request correction.
  • You may download Record Packages and request account or data deletion, subject to identity verification and lawful retention needs.
  • You may withdraw consent, subject to legal or contractual limits and reasonable notice. This may make it impossible to continue providing some or all of the service.

We may need to verify identity before acting on an access, correction, export, or deletion request. We aim to respond within the period required by applicable law.

8. Security incidents

We maintain incident and recovery procedures. If a breach of security safeguards creates a real risk of significant harm, we will investigate, keep required records, notify affected individuals and report to regulators as required by applicable law.

9. Business transfers and succession

Personal information may be reviewed or transferred as part of a genuine incorporation, financing, merger, sale, restructuring, or transfer of the service. Before completion, prospective recipients must use the information only to evaluate the transaction and protect it appropriately. A successor may use transferred information only for the purposes for which it was collected unless another use is permitted by law and supported by required consent. We will provide notice of a material operator change and any choices required by law.

10. Children

GigTracker is intended for people capable of entering a binding service agreement and is not directed to children. Do not create an account for a child or upload a child's personal information unless you have lawful authority and the processing is appropriate.

11. Changes to this Policy

We may update this Policy prospectively. The page shows the current version and effective date. Material changes will be highlighted and, where appropriate, require fresh acceptance before continued use.

12. Contact, access requests, and complaints

Ruth Salomi Janga, GigTracker Privacy Officer
Email: gigtrackerca@gmail.com
Subject line suggestion: Privacy request

Please contact us first so we can investigate and respond. You may also contact the Office of the Privacy Commissioner of Canada about PIPEDA concerns. We will not retaliate against a good-faith privacy inquiry or complaint.

GigTracker Privacy Policy, Version 1.0. See also the Terms of Use and Data Retention Policy.