Back home
GIGSTACKSOCIAL

Privacy Policy

Beta draft — have this reviewed by counsel before public launch.

1. What we collect

  • Account info: the email address and password you sign up with (password is stored as a one-way hash, never in plain text).
  • Brand & venue data: the business names, venues, and account labels you create.
  • Connected social account tokens: once live platform connections are enabled, an OAuth access token per connected account — not your platform password.
  • Content you create: captions, uploaded images/flyers, and scheduling details for posts you compose.
  • Basic usage analytics: which features you use, to improve the product.

2. What we don't collect

We never ask for or store your social platform passwords, payment card numbers (billing is handled by a PCI-compliant processor), or any data from your connected accounts beyond what's needed to publish and report on the posts you create through GigStackSocial.

3. How your data is used

Your data is used only to operate the product: publishing/scheduling your posts to the platforms you connect, showing you analytics on your own content, and improving GigStackSocial's features. We do not sell your data to third parties.

4. Third parties involved

To actually publish posts, GigStackSocial relies on each social network's official publishing API (Meta Graph API, TikTok Content Posting API, X API, YouTube Data API, Google Business Profile API).

5. Data retention & deletion

You can request full account and data deletion at any time. Deleting a connected account immediately revokes its access token.

6. Security

Access tokens are encrypted at rest. Sessions use signed, HTTP-only cookies. This beta environment uses a simplified auth implementation for demo purposes.

7. Your rights

You may request a copy of your data, correction of inaccurate data, or full deletion at any time. GDPR and CCPA/CPRA rights apply where applicable.