Privacy, in plain English
Gigsorted exists because musicians shouldn't have to hand their TFN and bank details to a different spreadsheet every week. That only works if you can trust us more than the spreadsheet. Here's exactly what we do.
What we collect, and why
Only what's needed to pay you and pay your super: name, contact details, date of birth, address, bank account, super fund details, and — if you choose — your TFN. Super funds require the DOB/address/TFN parts to match contributions to your account; none of it is used for anything else. Purpose limitation means exactly that: your details go into payment and super files for gigs you're attached to, and nowhere else. We don't sell your data, target ads at you, or "share with partners".
Your TFN specifically
TFNs are protected by the Privacy (Tax File Number) Rule 2015, and we treat that as a floor, not a ceiling. Your TFN is requested under superannuation law so it can be passed to your super fund with contributions. Providing it is voluntary and declining is not an offence; without it, your fund may tax contributions at the highest rate or take longer to match them. You choose: store it encrypted, or have us ask you each time — in that mode it's written into the generated file and destroyed, never kept.
No directory, and no search
A bandleader can only ever see musicians who explicitly accepted their invite or shared their personal link with them — or people whose details the bandleader already held and imported themselves (next section). There is no browsing, no lookup, no "find musicians near you". This is permanent product policy, not a v1 limitation.
Details an organiser imports
Some organisations already collect their people's payment details through forms of their own. An organiser can import that information — name, contact details, bank account, super fund, and where they hold them, date of birth, ABN and TFN — so the people on their list can be paid without re-typing anything. If that's you: the organiser entered your details from what you had given them, we didn't collect them from anywhere else, and they are encrypted, masked on screen and access-logged exactly like details you'd typed yourself. Your records state that the organiser supplied them. Sign in with your email address at any time to see everything held, correct it, or delete your account — and once you save anything yourself, the profile is yours and no import can change it again.
One thing to know if you change what an organiser gave us. If you correct the bank account or the super fund they entered for you, they will see that you changed it — only that you changed it, never what it said before. They are the ones about to pay you, and if the account they wrote down is no longer the one we hold, it is better they see a note on their screen than send money to the wrong place. It works the other way too: it means nobody who gets hold of your email can quietly point your fee at their own account without the person paying you noticing. Everything else you change is yours alone — your phone number, your address, your date of birth, your name — and nobody is told.
Encryption
TFNs, bank account numbers, dates of birth and super member numbers are encrypted at the application layer (AES-256-GCM) with keys held outside the database. If the database were ever stolen, those fields are gibberish without the keys. On screen, sensitive values only ever appear masked (like ****4521); the real values exist only inside the payment files generated for your gigs — and those files expire and are deleted after 7 days.
Access logging
Every time your details are decrypted into a payment file, and every download of files containing them, is logged — and the log is shown to you, in the app, with who and when. Not on request. Always.
Real deletion
Delete your account and your personal data — including the encrypted values — is destroyed. The one exception: gig and payment records already baked into a bandleader's generated documents (they're legally required to keep payment records). Those keep your name and the amounts, nothing more.
How you found us
When you first arrive we note where from: the campaign words in the link you followed, if it was one of ours from an ad or a post; the name of the site that sent you; and which page of ours you landed on. That sits in your own browser until you create an account, is attached to the account once, and is erased from the browser as soon as it is. It is how we tell whether an ad was worth what it cost.
What it isn't: no cookie, no advertising network, and nothing that follows you anywhere else. It is our own note, held in your own browser, and no third party is involved in it — the counter described below is separate. We keep the name of the site that sent you and never the full web address, because an address can carry the search somebody typed. None of it identifies you, none of it is shared, and if you arrive with nothing to note, that is what we record.
Counting visits
We count page views using Cloudflare Web Analytics: how many people opened a page, and which site or search sent them, as totals. There is no cookie and nothing that identifies you — that is why it is the one we use. Cloudflare sets out what it collects in its privacy policy.
It runs on the app as well as the public pages, so opening a signed-in page is counted the same way opening the front page is. What that means in practice: the counter sees that somebody opened /app/. It does not see who, it does not see your gigs or your payments, and none of your details go anywhere near it.
The bot check on our forms
Our sign-in, sign-up and contact forms run a bot check by Cloudflare, called Turnstile. You won't see it — there's no puzzle and nothing to click, which is deliberate: a form that hands you your own pay details shouldn't make you prove yourself first.
It isn't nothing, though, so here is what it does. When you submit one of those forms, Cloudflare looks at signals from your browser — your IP address, your browser's user agent, a fingerprint of the connection, and which site the check came from — and decides whether you look like a person. Cloudflare says it cannot identify an individual from those signals. Cloudflare sets out what it collects and what it does with it in its Turnstile Privacy Addendum, which sits alongside its main privacy policy. We're required to point you at that addendum, and we'd rather do it in plain sight than in a footnote.
If something goes wrong
We designed for the Notifiable Data Breaches scheme: if a breach likely to cause serious harm ever occurs, we assess it fast, notify the OAIC, and tell you directly what happened and what to do — no burying it.
Who's asking for your details
Bandleader accounts must verify an ABN against the Australian Business Register before they can send invites, and every invite shows you the verified entity name. If an invite smells wrong, the report button freezes that account's file generation immediately, pending review.
If you send invites, you can add a contact email address and phone number in your organisation settings. Everyone you invite sees whatever you put there, in the invite email and on the screen where they accept, so they can get in touch before handing over their bank details. Leave both blank and nothing is shown — the address you sign in with only appears on an invite if you type it into that field yourself.
Questions, complaints, or a privacy request? Send us a message — choose "Privacy request" and it comes straight to us. This page is a plain-English summary of how Gigsorted works, not legal advice.