Gigcult Privacy Policy
Effective date: 2026-10-06
Last updated: 2026-10-06
This Privacy Policy explains how Álvaro Boyadjian, who operates Gigcult ("we", "us"), collects, uses, shares and protects personal information when you use the Gigcult apps for iOS and Android, the website at gigcult.app, and related services (together, the "Service").
If you have questions, contact us at contact@gigcult.app.
1. Who is responsible for your data
Álvaro Boyadjian, an individual, is the controller of the personal data described in this policy.
2. What we collect
2.1 Information you give us
| Data | Examples | Required? |
|---|---|---|
| Account details | Email address, password (stored hashed by our authentication provider), or the name, email and profile photo shared by Google when you sign in with Google | Yes, to create an account |
| Profile | Username, display name, bio, avatar, home city / location you enter | Username required; the rest optional |
| Diary content | Shows you log, dates, ratings, reviews, tags, notes, setlist highlights, lists | Optional |
| Media | Photos and videos you upload to a show | Optional |
| Social activity | Who you follow, likes, comments | Optional |
| Messages to us | Support emails, reports of content or bugs | Optional |
2.2 Information collected automatically
- Usage and analytics events: screens viewed, features used, buttons tapped, approximate session length, app version, device model, OS version, language, and a pseudonymous app instance ID. Collected with Google Firebase Analytics.
- Advertising data: when ads are shown, our ad partners (such as Google AdSense and Google AdMob) collect your device's advertising identifier (IDFA on iOS, Advertising ID on Android) or ad cookies on the web, your IP address, approximate location derived from it, device and app information, and which ads you see and tap. See section 6.
- Marketing and attribution data: when you arrive from one of our ad campaigns, pixels and SDKs from advertising platforms (such as Google Ads, Meta, Apple Ads and TikTok) record that you saw or clicked the ad and whether you then installed the app, signed up, or subscribed. This includes your advertising identifier or cookie ID, IP address, device and browser information, and the event that happened. Where these platforms support it, we may also send a hashed (scrambled, one-way encoded) version of your email address so they can match the event to their own users. See section 6.
- Crash and diagnostic data: crash traces, device state at the time of a crash, and an installation identifier. Collected with Firebase Crashlytics.
- Device location (only if you allow it): used to find your city and suggest concerts near you. We do not track your location in the background and we do not store a location history. If you decline, you can type a city instead.
- Log data: IP address, request time and similar technical data processed by our hosting and backend providers to run and secure the Service.
- Cookies and local storage (website): used to keep you signed in, remember preferences such as language, and run analytics. See section 9.
2.3 Information from third parties
- Google, if you sign in with Google (name, email, profile photo).
- Apple App Store / Google Play, if you buy a subscription: purchase status, product, renewal and expiry dates. We never receive your card details.
- Public music data: concert listings, venues, setlists and artist images from third-party music data sources. This is information about events and artists, not about you.
3. How we use your information
| Purpose | Legal basis (EEA/UK) |
|---|---|
| Create and run your account; store and display your diary, lists, photos and profile | Performance of contract |
| Show your activity to followers and in public feeds according to your visibility settings | Performance of contract |
| Recommend shows and build city agendas; compute stats and year-in-review summaries | Performance of contract / legitimate interests |
| Process subscriptions and check entitlements | Performance of contract |
| Send notifications you enabled (new followers, comments, likes) | Performance of contract / consent where required |
| Understand usage, fix crashes, improve the Service | Legitimate interests / consent where required |
| Show ads that help keep the Service free, measure their performance and prevent ad fraud | Consent (personalized ads) / legitimate interests (non-personalized ads, fraud prevention) |
| Measure our own ad campaigns on other platforms, find people likely to be interested in Gigcult, and avoid showing our ads to existing users | Consent / legitimate interests where consent is not required |
| Keep the Service secure, prevent abuse, spam and fraud, enforce our Terms | Legitimate interests |
| Comply with law and respond to lawful requests | Legal obligation |
We do not sell your personal information for money. Ad and marketing partners may use the data described above for personalized advertising and campaign measurement only where you allow it (see section 6). We do not use your content to train machine-learning models offered to third parties.
4. What other people can see
Gigcult is a social service. Your username, display name, avatar and bio are public. Each diary entry, list and media item has a visibility setting (for example public, followers-only, or private). Public content may be shown on gigcult.app, appear in search engines, and be shared via links and share cards. Content you make private is visible only to you. Comments you post on someone else's entry are visible to anyone who can see that entry.
Think before posting personal details. Once content has been seen or copied by others, we cannot fully withdraw it.
5. How we share information
We share personal data only with:
- Service providers that process data on our behalf under contract:
- Google Firebase / Google Cloud (authentication, database, file storage, cloud functions, hosting, analytics, crash reporting, remote configuration, push messaging)
- Apple and Google (app distribution, in-app purchases, push notifications)
- Advertising and marketing partners, such as Google (AdSense, AdMob, Google Ads), Meta (Facebook, Instagram), Apple (Apple Ads) and TikTok, [and attribution providers such as AppsFlyer or Adjust,] which receive the advertising, marketing and attribution data described in section 2.2. They act as independent controllers for some of their own purposes; see how Google uses data from sites and apps that use its services.
- Other users, as described in section 4.
- Legal and safety: when required by law, or to protect the rights, safety or property of users, the public or us.
- Business transfers: in a merger, acquisition or sale of assets, subject to this policy.
When we look up concert or setlist data from music data providers, we send only search terms (such as an artist or city), not your identity.
6. Advertising and marketing
The free version of Gigcult may show ads from third-party ad networks such as Google AdSense (website) and Google AdMob (apps). This section describes how ads and marketing work when they are active. Ads are never placed inside other people's diary entries or reviews, and your diary content is never shared with advertisers.
- Marketing pixels and SDKs. We advertise Gigcult on other platforms. To know which campaigns work, our website contains pixels or tags (such as the Meta Pixel, Google Ads tag and TikTok Pixel) and our apps contain the SDKs of those networks. They tell the platform when someone who saw or clicked our ad visits the site, installs the app, signs up or subscribes. The platforms may combine this with what they already know about you to measure results, build audiences (for example, people similar to our users, or people who visited our site), and show you our ads elsewhere. On iOS, apps attribute installs through Apple's privacy-preserving SKAdNetwork / AdAttributionKit and AdServices frameworks unless you allow tracking.
- Personalized ads use your advertising identifier or ad cookies to show ads based on your interests across apps and websites. In the EEA, UK and Switzerland we ask for your consent first through a consent message (built on the IAB Transparency & Consent Framework), and you can change your choice at any time from the privacy choices in the app or on the website. Marketing pixels and SDKs follow the same choice. On iOS, personalized ads and cross-app marketing measurement happen only if you allow tracking in Apple's App Tracking Transparency prompt.
- Non-personalized ads are based on context, such as the page you are on and your approximate location, and still use cookies or identifiers for frequency capping, aggregated reporting and fraud prevention.
- Your other choices: reset or limit your advertising identifier in your device settings (iOS: Settings → Privacy & Security → Tracking; Android: Settings → Privacy → Ads); manage Google's ad personalization at adssettings.google.com; or use industry opt-outs such as youronlinechoices.eu and optout.aboutads.info. Subscribers do not see ads.
- Do Not Track: we honour Global Privacy Control signals as an opt-out of personalized ads where the law requires it. We do not respond to other "Do Not Track" browser signals.
7. International transfers
Our providers may process data in the United States and other countries outside your own. Where required, we rely on safeguards such as the European Commission's Standard Contractual Clauses or adequacy decisions.
8. How long we keep data
- Account and content: for as long as your account exists.
- After you delete your account: profile, diary entries, lists, comments, follows and uploaded media are deleted from production systems promptly, normally within 30 days; any backups roll off within 90 days.
- Advertising and marketing data: kept by our ad and marketing partners according to their own retention policies (see the privacy policies of Google, Meta, Apple and TikTok).
- Analytics: retained by Firebase Analytics for up to 14 months.
- Crash reports: up to 90 days.
- Purchase records: as long as required by tax and accounting law.
9. Cookies and similar technologies
The website uses:
- Essential storage to keep you signed in and remember settings. These cannot be disabled.
- Analytics cookies / identifiers (Firebase / Google Analytics) to measure usage.
- Advertising and marketing cookies and pixels set by our ad and marketing partners (see section 6).
Where the law requires it (for example in the EEA and UK), non-essential cookies are set only after you consent, and you can change your choice at any time.
The apps use equivalent device identifiers for analytics, crash reporting, ads and campaign measurement. On iOS we access the advertising identifier only if you allow it in the App Tracking Transparency prompt.
10. Your choices and rights
In the app you can at any time:
- edit or delete your profile, entries, lists, comments and media;
- change the visibility of each entry;
- turn off location access and notifications in your device settings;
- delete your account from Settings → Delete account (this also works on the web).
Depending on where you live (for example the EEA, UK, Switzerland, Brazil (LGPD), Argentina (Law 25.326), California (CCPA/CPRA) and other US states), you may have the right to:
- access the personal data we hold about you and get a copy (portability);
- correct inaccurate data;
- delete your data;
- object to or restrict certain processing, including processing based on legitimate interests;
- withdraw consent at any time, without affecting earlier processing;
- not be discriminated against for exercising your rights.
To exercise these rights, email contact@gigcult.app from the address linked to your account. We will respond within the time required by law (usually 30 days). You may also complain to your local data protection authority. In Argentina, that is the Agencia de Acceso a la Información Pública (AAIP).
Argentina: El titular de los datos personales tiene la facultad de ejercer el derecho de acceso a los mismos en forma gratuita a intervalos no inferiores a seis meses, salvo que se acredite un interés legítimo al efecto conforme lo establecido en el artículo 14, inciso 3 de la Ley N° 25.326. La AGENCIA DE ACCESO A LA INFORMACIÓN PÚBLICA, en su carácter de Órgano de Control de la Ley N° 25.326, tiene la atribución de atender las denuncias y reclamos que interpongan quienes resulten afectados en sus derechos por incumplimiento de las normas vigentes en materia de protección de datos personales.
California residents: in the past 12 months we collected the categories identifiers, internet/network activity, geolocation (approximate, with permission), audio/visual content (uploaded photos) and inferences (show recommendations). We do not sell personal information for money. Allowing ad and marketing partners to show personalized ads and to measure our campaigns through pixels and SDKs may count as "sharing" for cross-context behavioral advertising, or a "sale", under California and other US state laws. You can opt out through the privacy choices in the app or the "Your privacy choices" link on the website, by sending a Global Privacy Control signal, or by emailing us. We do not knowingly sell or share data of users under 16.
11. Security
We use encryption in transit (HTTPS/TLS), access controls enforced by database security rules, and restricted administrative access. No system is perfectly secure; if a breach affects you, we will notify you and authorities as the law requires.
12. Children
The Service is not intended for children under 13 (or the higher minimum age in your country, such as 16 in some EU countries). We do not knowingly collect data from them, and we do not show personalized ads to users we know are under 16 (or the age of digital consent in their country). If you believe a child has given us data, contact us and we will delete it.
13. Changes to this policy
We may update this policy. If changes are material, we will notify you in the app or by email before they take effect. The "Last updated" date shows the latest version.
14. Contact
Álvaro Boyadjian
contact@gigcult.app