Privacy Policy

How GigSpace collects and uses personal data. Prepared under the GDPR and the Irish Data Protection Act 2018.

Effective date: 1 September 2026 · Version 1.1

1. Who we are

This platform (“GigSpace”, “we”, “us”, “our”) is operated by GIGSPACE LIMITED, a private company limited by shares, registered in Ireland (company number 823892), with its registered office at 37 Silverstream Avenue, Stameen, Drogheda, Co. Louth, A92 V5D0, Ireland.

GigSpace is a booking-management platform for the live-entertainment industry. It is used by booking agencies (our customers), and by the venues and artists those agencies work with. This Policy explains what we do with personal data across the website at gigspace.ie and the application at app.gigspace.ie (together, the “Platform”). This Policy, and our handling of personal data, are governed by both EU law (the GDPR) and Irish law (including the Data Protection Act 2018).

For any privacy question, or to exercise your rights, contact us at privacy@gigspace.ie, or by post at the address above marked “Data Protection”.

2. Our role: controller and processor

GigSpace handles personal data in two capacities, and it matters which applies:

2.1Where we decide why and how data is used, for example account registration, security, billing, and improving the Platform, we are the data controller. This Policy governs that data.

2.2Where a booking agency loads and manages data about its venues and artists to run its own business, that agency is the controller and we act as its data processor, handling the data on its instructions under a separate data-processing agreement. If your data was put on the Platform by an agency you work with, that agency’s own privacy notice governs that use, and you should also contact them to exercise your rights. We will help route your request to them.

3. Who this Policy is for, and the 18+ requirement

The Platform is intended solely for business users aged 18 or over: staff of booking agencies, venue representatives, and artists offering their services in the course of a trade, business or profession. It is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has provided us with personal data, contact us immediately so we can delete it.

4. The personal data we collect

Depending on your role, we may process:

CategoryExamples
Account & identityName, email address, phone number, password (stored hashed), role, and the agency/agencies you are linked to.
Artist profileStage/act name, biography, genres/act type, photos and media you upload, availability, and (where you choose to provide it) insurance details.
Venue detailsVenue name, address, contact person and preferences (where these identify an individual).
Bookings & activityOffers, acceptances, bookings, re-confirmations, cancellations and gig history.
Feedback & ratingsPost-gig feedback and ratings that venues give about acts (data about the act, provided by the venue).
Financial (as applicable)Fees, invoices and payment records. When online card payments are enabled, these are handled by our payment provider (Stripe); we do not store full card details.
Technical & usageIP address, device/browser type, log data, and cookie data (see the Cookie Policy).
CommunicationsMessages, notifications and support correspondence.

Some of this data we collect directly from you. Some we receive from others: most importantly, a booking agency may create a profile for you, and a venue may submit feedback about an act. Where we obtain data about you from someone else, the categories and sources are those described in the table above.

5. Why we use it, and our legal basis

We rely on the following legal bases under Article 6 of the GDPR, the EU General Data Protection Regulation (an EU law statute that applies directly in Ireland):

PurposeLegal basisNotes
Creating and running your account; providing the PlatformContractTo deliver the service you or your agency signed up for.
Operating the booking engine (offers, acceptances, re-confirmations, cancellations)Contract / legitimate interestsTo make the core service work.
Matching, suggested invite lists and feedback-based rankingLegitimate interestsTo help agencies match acts to venues efficiently (see section 6).
Security, fraud prevention, and keeping recordsLegitimate interests / legal obligationTo protect the Platform and meet our legal duties.
Billing, invoicing and tax record-keepingContract / legal obligationFinancial records are retained as required by law.
Service emails and notificationsContract / legitimate interestsOperational messages about your bookings and account.
Marketing emails (if any)ConsentOnly where you have opted in; you can withdraw at any time.
Improving and developing the PlatformLegitimate interestsUsing usage data, generally in aggregated form.

Where we rely on legitimate interests, we have weighed those interests against your rights and are happy to explain that assessment on request. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.

6. Feedback, ranking and automated decisions

GigSpace helps agencies match acts to venues. As part of this, venues can leave feedback about acts, and the Platform can use that feedback to suggest or rank acts (for example, marking an act “preferred” for a venue, or flagging that a venue does not wish to re-book an act).

A person always stays in control. The booking agency’s staff make the actual booking and re-booking decisions; the Platform surfaces suggestions and flags, it does not silently and automatically exclude an act on its own. You have the right to obtain human review of, to express your view on, and to contest any decision that significantly affects you and that you believe was made without meaningful human involvement. To do so, contact us at privacy@gigspace.ie.

7. Who we share data with

We do not sell your personal data. We share it only as needed to run the Platform:

  • Other Platform users, as the service requires: e.g. an agency sees the acts and venues it works with; a venue sees acts proposed for its gigs (never an act’s fee); an act sees offers made to it.
  • Our service providers (sub-processors), who process data on our behalf under contract, including: Supabase (database and hosting, EU region), Vercel (application hosting/CDN), Resend (transactional email), and, when online payments are enabled, Stripe (payment processing).
  • Professional advisers, authorities or successors, where required by law, to protect our rights, or in connection with a business reorganisation or sale.

We keep a current list of sub-processors and will make it available on request.

8. International transfers

We aim to keep personal data within the European Economic Area (EEA); our primary database is hosted in the EU. Some service providers are based outside the EEA (for example in the United States). Where data is transferred outside the EEA, we rely on an appropriate safeguard: an EU adequacy decision (including the EU–US Data Privacy Framework where the provider is certified) and/or the European Commission’s Standard Contractual Clauses. You can ask us for details of the safeguard used for a particular transfer.

9. How long we keep it

We keep personal data only as long as necessary for the purposes above:

  • Account and profile data: for as long as your account is active, and for a reasonable period afterwards.
  • Booking and feedback data: while it remains relevant to the service; we may set a maximum age on feedback used for ranking.
  • Financial and tax records: retained for the period required by Irish law (generally six years).

When we no longer need data that identifies you, we delete it or irreversibly anonymise it. Where we are legally required to keep financial or audit records, we retain those records and restrict their use, even after you close your account. Full detail is held in our internal retention schedule, available on request.

10. Your rights

Under the GDPR you have the right to: access your data; have it corrected; have it erased; restrict or object to processing; data portability; and, where we rely on consent, to withdraw it. You also have rights in relation to automated decisions (section 6).

To exercise any right, contact privacy@gigspace.ie. We will respond within one month (extendable by two further months for complex requests, with notice). There is normally no charge. We may need to verify your identity first. If your data is managed by an agency (where we act as processor), we will forward your request to them.

You also have the right to complain to the Irish Data Protection Commission, www.dataprotection.ie, though we would welcome the chance to resolve your concern first.

11. Cookies

The Platform uses cookies and similar technologies. Please see our Cookie Policy for detail and to manage your choices.

12. Security

We use appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit, and tenant isolation so one agency’s data is not accessible to another. No system is completely secure, but we work to protect your data and to meet our breach-notification duties if something goes wrong.

13. Changes to this Policy

We may update this Policy from time to time. We will post the updated version here with a new effective date and, where changes are significant, take reasonable steps to notify you.