Privacy Policy
Last updated: 10 August 2026
1. Who we are
Gigdoor is operated by Felix Commerell, PickPost PK700509, Bahnhofquai 12, 4600 Olten, Switzerland (“Gigdoor”, “we”, “us”).
For any data protection question, write to info@gigdoor.app.
This policy explains how we handle personal data when you visit gigdoor.app, when you use Gigdoor as a venue, and when you submit a booking request to a venue through a Gigdoor form.
2. Our two roles
Please read this section first, because it determines who you should contact about your data.
We are the controller for:
- visitors to our website
- venue accounts and the people who use them
- people who contact us or request a pilot
We are a processor, not the controller, for:
- booking requests that artists and bands submit through a venue’s Gigdoor form
In that second case, the venue decides why and how that data is used. We store and process it only on the venue’s instructions, under a data processing agreement. If you are an artist and you want your submission corrected or deleted, contact the venue you applied to. You can also write to us at info@gigdoor.app and we will forward your request to the venue and support them in handling it.
3. Applicable law
We are based in Switzerland and apply the Swiss Federal Act on Data Protection (FADP / revDSG). Where we offer our services to people in the European Economic Area, the GDPR also applies. Where this policy refers to a legal basis, this refers to Art. 6 GDPR; under Swiss law we rely on the corresponding justification.
4. What we process, why, and on what basis
4.1 Visiting the website
When you open gigdoor.app, our hosting provider automatically records technical data: IP address, browser type and version, operating system, the page requested, referrer, and the time of the request.
- Purpose: delivering the site, security, detecting and defending against attacks and abuse.
- Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in operating a secure and functioning service.
- Retention: short-term server logs held by our hosting provider; we do not build long-term profiles from them.
4.2 Error monitoring
We use Sentry to detect technical errors in the application. When an error occurs, Sentry receives technical data about the request and the state of the application.
- We configure Sentry so that it does not send user identifiers or IP addresses (
sendDefaultPii: false, IP scrubbing enabled). - Purpose: finding and fixing faults.
- Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in a stable and secure service.
- Retention: deleted according to Sentry’s retention period, by default 90 days.
4.3 Venue accounts
To use Gigdoor as a venue you provide an email address and a venue name. We also store your settings, reply templates, and records of sign-ins.
We use passwordless sign-in: we send a one-time sign-in link to your email address.
- Purpose: providing the service, authentication, account security, support.
- Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Retention: for the duration of the contract, then deleted within 30 days of account closure, subject to statutory retention periods for accounting records.
4.4 Pilot requests and contact
If you request a pilot or contact us through a form or by email, we process the details you give us: name, email address, venue name, and the content of your message.
- Purpose: replying to you, arranging setup, pre-contractual steps.
- Legal basis: pre-contractual measures and performance of a contract (Art. 6(1)(b) GDPR), otherwise legitimate interest (Art. 6(1)(f) GDPR) in responding to enquiries.
- Retention: 12 months after the last contact if no contract results, unless correspondence obligations require longer.
4.5 Booking requests submitted by artists
When an artist submits a booking request through a venue’s Gigdoor form, we process, on behalf of that venue: band or artist name, contact email address, optionally a phone number, expected audience size, genres, proposed dates, a description of the act, links to profiles and music, and a free-text message. We also process the status, internal notes and reply emails that the venue adds afterwards.
- Controller: the venue that owns the form.
- Our role: processor, acting only on the venue’s instructions under a data processing agreement.
- Retention: determined by the venue. The venue can delete a request at any time. When a venue account is closed, we delete the associated booking requests within 30 days.
4.6 Emails we send
We use Resend to send transactional email: sign-in links, submission confirmations to artists, and the accept or decline replies that venues send from Gigdoor. Resend processes the recipient address and the content of the message in order to deliver it.
5. Cookies and similar technologies
We use only what is strictly necessary:
- a session cookie to keep venue users signed in
- a language preference stored in your browser
We do not use analytics, advertising, tracking pixels, or third-party marketing cookies. Because we set no non-essential cookies, we do not ask for cookie consent. If we introduce analytics in future, we will ask for your consent first and update this policy.
6. Who we share data with
We do not sell personal data and we do not share it for advertising.
We use the following processors, each bound by a data processing agreement:
| Provider | Purpose | Location |
|---|---|---|
| Vercel Inc. | Website and application hosting | USA, with edge delivery in Europe |
| Neon Inc. | Database hosting | Germany (Frankfurt, eu-central-1) |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | USA |
| Functional Software, Inc. (Sentry) | Error monitoring | European Union |
Beyond this, we disclose data only where we are legally required to, or where it is necessary to establish, exercise or defend legal claims.
7. Transfers outside Switzerland and the EEA
Some of our providers are based in the United States. Where data is transferred there, we rely on the European Commission’s Standard Contractual Clauses together with the Swiss addendum recognised by the Federal Data Protection and Information Commissioner, and, where the provider is certified, on the EU-US Data Privacy Framework and its Swiss extension. You can request a copy of the relevant safeguards at info@gigdoor.app.
8. Security
We use TLS encryption for all data in transit, encryption at rest for our database, passwordless authentication with expiring one-time links, strict separation of data between venues, access controls limiting access to what is necessary, and automated backups. No system is completely secure, but we treat unauthorised access to venue and artist data as the most serious failure this service could have.
9. Your rights
You have the right to access your data, to have inaccurate data corrected, to have data deleted, to restrict processing, to object to processing based on legitimate interest, and to receive your data in a portable format. Where processing is based on consent, you may withdraw it at any time with effect for the future.
To exercise these rights, write to info@gigdoor.app. We may need to verify your identity.
If you submitted a booking request to a venue, contact the venue first, since they are the controller for that data. If you cannot reach them, write to us and we will help.
You also have the right to lodge a complaint with a supervisory authority:
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch
- EEA: the supervisory authority of your country of residence
10. Automated decision-making
We do not use automated decision-making or profiling that produces legal effects for you. Filtering and sorting inside a venue’s dashboard is performed by the venue, not by us, and does not automatically decide anything.
11. Children
Gigdoor is intended for professional use by venues and by artists who are able to enter into agreements. It is not directed at children.
12. Changes to this policy
We may update this policy as the service develops. The current version is always available at gigdoor.app/en/privacy. Where a change materially affects you, we will notify venue account holders by email.