Privacy Policy

Last updated: September 2026

This Privacy Policy explains how GigsLo Oy ("GigsLo", "we", "us") collects, uses and protects your personal information when you use our website and services.

1. Controller

The controller of your personal data is GigsLo Oy, Finland. Our registered address, business ID (Y-tunnus) and VAT number are shown in the footer of every page. For any privacy matter, email contact@gigslo.com. We have not appointed a data protection officer, as we are not required to.

2. Information we collect

We collect information you provide directly — name, email address, phone number, location, task details, profile photo, and for helpers also identity and tax details — and information collected automatically, including device information, IP address, browser type and approximate location based on your IP.

3. How we use your information

We use your information to operate the GigsLo platform, match you with helpers or customers nearby, process payments, communicate with you, prevent fraud, meet our legal obligations and improve our services.

4. Legal bases

Performance of our contract with you: accounts, tasks, offers, messaging, payments and support. Legal obligation: identity and tax data collected for DAC7 reporting to the Finnish Tax Administration, bookkeeping, and responses to authorities. Legitimate interest: fraud prevention, platform safety, service statistics and security logging. Consent: precise location, marketing emails, non-essential cookies and push notifications — you can withdraw consent at any time.

5. Sharing of information

We share information with other users only to the extent necessary to complete a task (for example, your first name and approximate location). We use processors for payments (Stripe), hosting and database (Supabase infrastructure), email delivery, error monitoring and push delivery, each under a data processing agreement. We report helper earnings and identity data to the Finnish Tax Administration under DAC7. We do not sell personal data.

6. Transfers outside the EU/EEA

Our services are hosted in the EU where possible. Some processors (for example payment and infrastructure providers) may process data outside the EU/EEA. In those cases the transfer is based on the European Commission's Standard Contractual Clauses together with additional technical safeguards. You can ask us for details.

7. Location data

With your permission, we use your device's location to show tasks and helpers near you. You can disable location sharing in your browser or device settings at any time.

8. Cookies

We use strictly necessary cookies to keep you signed in and secure. Analytics and other non-essential cookies are only set after you consent in the cookie banner, and refusing is as easy as accepting. You can change your choice at any time via Cookie settings in the footer.

9. Data retention

Account and profile data: while your account is active and 12 months after closure. Task, message and review data: 3 years after the task, for dispute handling. Payment and accounting data: 6 years from the end of the accounting year, as required by the Finnish Accounting Act. Identity verification data: while the helper account is active, or until you delete it yourself. Tax identity and DAC7 records: at least 5 years, as required by tax law. Support emails: 2 years.

10. Your rights

Under the GDPR you have the right to access your data, correct it, have it deleted, restrict or object to processing, withdraw consent, and receive your data in a portable format. Contact contact@gigslo.com and we reply within one month. If you are not satisfied, you can lodge a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, tietosuoja.fi). Note that data we must keep for tax or accounting reasons cannot be deleted on request.

11. Security

Data is encrypted in transit and at rest, access is restricted by row-level security so users can only reach their own records, and identity documents live in a private bucket scoped to each account. No method of transmission over the internet is 100% secure.

12. Personal identity codes and tax data

Helpers must give either a Finnish personal identity code (henkilötunnus) or a business ID (Y-tunnus) before they can be paid. We collect it solely because the EU DAC7 rules and Finnish tax law require platforms to report seller identity and earnings to the Finnish Tax Administration; this is a legal obligation and processing an identity code for it is permitted under section 29 of the Finnish Data Protection Act. It is stored in a separate restricted table, is never shown to customers or other helpers, never appears in search, directory or public profile data, and is accessible only to the compliance staff who prepare the annual report. Each helper receives a copy of the information reported about them.

13. Verification and background checks

Identity verification is described in the next section. Beyond that we check the information a helper gives us against public registers — the Finnish Business Information System (YTJ) and the prepayment register for business status. We do not obtain criminal record extracts; where the law requires one for work with children, the customer arranges it directly with the helper.

14. Identity verification (KYC)

Helpers must verify their identity before earning. We support two paths and record only what each one returns:

  • Suomi.fi e-Identification (recommended for residents of Finland). You authenticate with your Finnish bank credentials or Mobile Certificate via DVV's Suomi.fi service. GigsLo receives only a hashed pseudonymous subject identifier and the eIDAS assurance level — we never see or store your bank credentials, and Suomi.fi never passes us your personal identity code. (Your identity code is collected separately, and only for DAC7 tax reporting, as described in section 12.)
  • Manual upload (fallback). If neither Finnish service is available to you, you can upload a photo of a government ID and a verification selfie. These files travel over TLS and are stored encrypted at rest in a private storage bucket scoped to your account by row-level security.

Lawful basis: performance of our service contract with you and our legitimate interest in fraud prevention and trust & safety on the platform.

Who can access it: only you. Access is enforced by row-level security on the database and by per-user paths on the private storage bucket. We do not share verification data with task posters, other helpers, or any third party.

Retention & deletion: we keep verification data while your helper account is active. You can delete your verification data at any time from the Identity verification section of your Profile. Full account deletion can be requested via the Contact page.

15. Children

GigsLo is for adults only. You must be at least 18 to create an account, and we do not knowingly collect personal data from minors.

16. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified through the service or by email.

17. Contact

Questions about this policy? Email us at contact@gigslo.com.