Privacy Notice
Last updated: July 2026
This Privacy Notice explains how Sam Horton ("we", "us", "our"), operating the service GigSniper, collects and uses personal data when you use our website and app.
1. Who is the data controller
Sam Horton, sole trader, is the data controller for personal data processed through GigSniper. For any privacy-related enquiries or to exercise your rights, contact us via the support channels listed in-app.
2. Data we collect
- Account data — name, email, hashed login credentials, and profile information you enter (e.g. artist name, genre, city, links).
- Content data — venues you save, notes, email drafts and sent history, follow-up schedules, and other information you enter into the app.
- Support data — messages you send us and information you share when reporting an issue.
- Usage & device data — pages visited, features used, approximate location derived from IP, device and browser type, timestamps, and diagnostic logs.
- Cookies and similar — see the Cookies section below.
Payment card details are collected and processed by Stripe, not by us. See "Sharing" below.
3. Purposes and legal bases
- Provide the Service (create your account, authenticate you, run venue search, generate emails, store your pipeline) — legal basis: performance of a contract with you.
- Bill and take payment (via Stripe) — legal basis: performance of a contract with you; compliance with legal obligations (tax, accounting).
- Support and communication (respond to enquiries, send service-related updates) — legal basis: performance of a contract; legitimate interests in supporting customers.
- Security and fraud prevention (rate-limiting, abuse detection, audit logs) — legal basis: legitimate interests in keeping the Service safe; legal obligations.
- Product improvement and analytics (understand how features are used, fix bugs) — legal basis: legitimate interests; or consent where required by law.
- Marketing communications (only if you opt in) — legal basis: consent, which you can withdraw at any time.
4. AI processing
When you generate an outreach email, we send the venue information and the context you provide to an AI model provider so it can draft the message. We do not use your prompts or outputs to train third-party models. AI outputs may be inaccurate — you are responsible for reviewing before sending.
5. Sharing your data
We share personal data only with the following categories of recipients:
- Payment processor — Stripe, for handling checkout, payment processing, tax calculation, invoicing, subscription management, and refund processing. See Stripe's privacy notice.
- Infrastructure and subprocessors — cloud hosting, database, email delivery, error logging, analytics, and AI model providers necessary to run the Service.
- Professional advisers — accountants and legal advisers, as needed.
- Authorities — where we are required to do so by law, or to protect our rights or the safety of others.
We do not sell your personal data.
6. International transfers
Some of our subprocessors are based outside the UK/EEA (for example in the United States). When we transfer personal data internationally, we rely on appropriate safeguards such as UK/EU Standard Contractual Clauses or adequacy decisions.
7. Retention
We keep your personal data for as long as your account is active. After you delete your account, we retain data only as long as needed for legitimate purposes (e.g. billing records, fraud prevention, complying with legal obligations), typically up to 7 years for financial records. Usage logs are retained for a shorter period. When retention ends, data is deleted or anonymised.
8. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you;
- correct inaccurate data;
- request deletion ("right to erasure");
- restrict or object to certain processing;
- data portability;
- withdraw consent at any time (where processing is based on consent);
- lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ICO).
We aim to respond to rights requests within one month.
9. Security
We use appropriate technical and organisational measures to protect personal data, including transport encryption (HTTPS/TLS), encryption at rest for our database, access controls, and audit logging. No system is perfectly secure, but we work to keep risks low.
10. Cookies
We use essential cookies and similar technologies to keep you signed in and to run the Service. We may also use analytics cookies to understand aggregate usage and improve the product. Where required by law, we ask for your consent before setting non-essential cookies, and you can manage preferences in your browser at any time.
11. Children
GigSniper is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes to this notice
We may update this Privacy Notice from time to time. Material changes will be posted on this page with a new "last updated" date, or notified by email.
13. Contact
To exercise your rights or ask a privacy question, contact us via the support channels in-app.
GigSniper