GigShield.ai — Privacy Policy

Version 1.0 — Effective 28 July 2026

1. Who We Are

GigShield.ai Ltd, a company registered in England and Wales under company number 17223823, with its registered office at 124-128 City Road, London, England, EC1V 2NX ("GigShield," "we," "us," or "our"), is the data controller for the personal data described in this Policy. You can contact us about privacy matters at privacy@gigshield.ai.

2. Data We Collect

2.1 Account and profile data

Full name, email address, password (stored hashed, never in plain text), country of residence, account type (individual or business), company name (for business accounts), and whether you're acting as a Business or Professional on a given Gig.

2.2 Identity verification (KYC/KYB) data

To meet our legal identity-verification and anti-money-laundering obligations before you can fund or receive funds through a Shield, we collect: date of birth, residential or business address, government-issued ID type, number, issuing country, and expiry date; and, for business accounts, company registration number, country of incorporation, registered company address, and information about beneficial owners.

2.3 Contact verification data

Phone number and phone verification status, collected to confirm you can be reached and to reduce fraud.

2.4 Financial and payout data

Cryptocurrency wallet addresses; for bank payouts, account holder name, bank name, and the account identifiers relevant to your country (account/routing number, IBAN, BIC, or sort code); for card payouts, cardholder name, card brand, and the last four digits and expiry of the card. We do not store full card numbers or CVC codes — those are handled directly by our card processing partner.

2.5 Optional professional profile data

Portfolio or website URL, LinkedIn profile URL, and LinkedIn Verified Partner banner confirmation, if you choose to participate in the 0%-fee partner program.

2.6 Gig and dispute content

Gig titles and descriptions, milestone descriptions, and — if a dispute is raised — any evidence either party submits, which may include written explanations, screenshots, code, or log files.

2.7 Usage and device data

Log-in timestamps, IP address, browser and device information, and security event logs (such as failed login attempts or account status changes), collected to keep your account secure.

2.8 Communications

Emails and in-platform notifications we send you, and any support correspondence you have with us.

3. Where This Data Comes From

  • Directly from you, when you create an account, complete verification, or use the Platform.
  • From our identity-verification provider, as part of processing the KYC/KYB documents you submit.
  • From LinkedIn, limited to the public profile URL you provide for partner-program verification.
  • Automatically, through your use of the Platform (device and log data).

4. How and Why We Use Your Data

  • Provide the Platform. Create and manage your account, create and fund Shields, process Milestone approvals and releases, and send payouts — necessary to perform our contract with you.
  • Verify your identity. Run KYC/KYB checks and sanctions screening before you can transact — required by anti-money-laundering law.
  • Prevent fraud and keep the Platform secure. Monitor for suspicious activity and enforce account security — our legitimate interest in protecting the Platform and its Users.
  • Resolve disputes. Review submitted evidence to mediate Milestone disputes, including through Shield AI's automated proposals — to perform our contract with you.
  • Communicate with you. Send transactional emails and notifications about your Gigs and account; send marketing communications only where you've opted in.

Where UK GDPR or the EU GDPR applies to our processing of your data, the lawful bases above are, respectively: performance of a contract, compliance with a legal obligation, legitimate interests, performance of a contract, and consent.

5. Who We Share Data With

  • Circle Internet Financial — provisions and operates the custodial USDC wallets used to hold and move Shield funds.
  • Our card and bank payment processing partners — process card payments and card/bank payouts.
  • Our identity verification provider — performs KYC/KYB identity checks on our behalf.
  • Twilio — sends SMS codes for phone number verification.
  • Brevo — sends transactional emails (account, Gig, and dispute notifications).
  • Supabase — hosts our database, authentication, and file storage infrastructure.
  • Regulators and law enforcement — where required by law, such as in connection with anti-money-laundering or sanctions obligations.

We do not sell personal data to third parties.

6. International Data Transfers

GigShield serves Users in multiple countries and works with service providers that may process data outside the UK or the European Economic Area. Where we transfer personal data internationally, we do so on the basis of an applicable adequacy decision, or by using Standard Contractual Clauses (or the UK's International Data Transfer Addendum) approved by the relevant authorities, to ensure your data continues to receive an appropriate level of protection.

7. How Long We Keep Your Data

We retain identity-verification (KYC/KYB) records for five years from the end of your relationship with GigShield, in line with the UK Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017. We retain Gig, Milestone, and dispute records for six years from the date of the relevant transaction, in line with standard UK financial record-keeping practice. Where a shorter retention period is appropriate for a particular type of data, we apply that instead.

8. How We Protect Your Data

We use encryption in transit, role-based access controls that separate ordinary application access from administrative access, per-request encryption of the credentials used to authorize wallet operations, and audit logging of financial operations. No system can be guaranteed completely secure; if you believe your account or data has been compromised, contact us immediately at security@gigshield.ai.

9. Your Rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Request deletion of your data, subject to our legal obligation to retain certain records (Section 7).
  • Restrict or object to certain processing.
  • Receive a copy of your data in a portable format.
  • Withdraw consent, where processing is based on consent, without affecting processing carried out before withdrawal.
  • Lodge a complaint with your local data protection authority — in the UK, the Information Commissioner's Office (ico.org.uk).

To exercise any of these rights, contact us at privacy@gigshield.ai.

10. Cookies and Local Storage

The Platform uses only the essential cookies and browser local storage needed to keep you signed in and to remember basic preferences, such as your selected language. We do not currently use third-party advertising or analytics cookies.

11. Children's Privacy

The Platform is not directed at, and we do not knowingly collect personal data from, anyone under 18 years old. If we learn we have collected data from someone under 18, we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-platform notice and update the version and effective date above.

13. Contact Us

GigShield.ai Ltd, 124-128 City Road, London, England, EC1V 2NX, United Kingdom. Email: privacy@gigshield.ai.