Skip to content

Legal

Privacy Policy

How GigNode handles personal data in its current product flows.

Last updated: September 8, 2026

Official operator details remain incomplete until the controller's verified company records are supplied.

1. Who is responsible?

GigNode is currently operated prior to the incorporation of its commercial entity. Corporate registration, registered address and jurisdiction details will be published here once incorporation is completed.

Contact: support@getgignode.com

2. Data categories we collect

  • Account and identity data: name, email, authentication and session information, language preference, and account-security records.
  • Marketplace data: client profiles, service requests and attachments, provider profiles and applications, services and portfolios, matches, proposals, change requests, acceptances, engagements, reviews, and reports.
  • GigNode Ops data: workspaces and team membership, clients and projects, deliverable files or links, feedback and revisions, approvals, activity records, and informational payment status.
  • Communications data: support requests and recipient, delivery, and failure records for transactional emails.
  • Technical and security data: IP/network and device-context request data, timestamps, rate-limit and security events, errors and performance records, plus Vercel's anonymized page-view and Web Vitals data.

3. Why we use data

  • Authenticate accounts, maintain sessions, and enforce authorised access.
  • Operate Marketplace matching, proposal, and acceptance flows and the Ops project/client-portal workflow.
  • Store and securely deliver files and send transactional emails.
  • Prevent abuse, enforce rate limits, investigate incidents, and measure reliability.
  • Provide support, administer records, and respond to valid legal requests.

4. Service providers / processors

  • Supabase: authentication, Postgres database, and file storage.
  • Vercel: application hosting and deployment, anonymized Web Analytics, and Speed Insights performance measurements.
  • Resend: delivery of transactional and account emails.
  • Cloudflare Turnstile: bot and abuse checks on protected forms such as signup and login.

5. Cookies and technical storage

Supabase session cookies are necessary to keep accounts signed in and verify authorised requests. The gignode_ops_locale cookie retains the chosen EN/TR language for one year. Turnstile may use technical identifiers or browser storage for security when a protected form loads.

Vercel Web Analytics does not use cookies and anonymizes visitors with a daily-changing hash. Speed Insights collects real-user Web Vitals. The repository contains no advertising, session-replay, or cross-site marketing tracker. A non-essential cookie consent banner is therefore not shown for the current setup.

6. Sharing and visibility

Data is shown to clients, providers, workspace members, or portal users according to product roles and workspace rules. Selected parts of an approved and published provider profile may be public; private contact, application, and internal-review data are not designed for the public directory.

GigNode has no product flow for selling personal data.

7. Retention

Data is retained while needed to provide the account and service, protect security or dispute records, and meet applicable obligations. The period varies by data type, active project or engagement state, security need, and deletion request.

After verification and blocker checks, an account-deletion request is scheduled with a 14-day cancellation period. Active workspace ownership, an open Marketplace request, or an active engagement may need resolution first. Copies in backups or required records may remain through the ordinary deletion cycle or an applicable retention requirement.

8. Your choices and rights requests

You can update account information in the product, change your language, and request deletion from the available account area. Contact support@getgignode.com to request access, correction, deletion, restriction, objection, or portability where such rights apply to you. We may verify identity and authority.

This policy does not assert a specific legal basis or regional rights regime until the company's jurisdiction is verified.

9. International processing and hosting

Supabase, Vercel, Resend, and Cloudflare may use global infrastructure and subprocessors. The repository does not establish the precise production data region or every transfer mechanism; these details must be confirmed before launch from live project settings and provider agreements.

10. Security

GigNode uses access controls, workspace scoping, private storage, signed links, rate limiting, Turnstile, MFA options, and security-event records. No internet service can guarantee absolute security.

11. Contact

Privacy questions and rights requests: support@getgignode.com. The official company address and country will also appear here once the central operator fields are completed.