The short version
- Gaffr (for clients) and Gaffr Live (for crew) are in closed testing. No real card payments, no real payouts yet.
- The website sets no cookies. Its analytics count visits without working out who you are.
- Crew hand over a lot: right-to-work documents, a National Insurance number, bank details. The law and the job need them. Clients never see any of it.
- Crew location is used only while the “On my way” or on-shift screen is open, and the client watches it live on a map during that time.
- While a crew member is live, anyone signed in to the Gaffr app sees an unnamed dot for roughly where they live, to about 100 metres. We haven’t decided whether that stays. Details below.
- We don’t sell your data. We don’t run ads.
- Nothing is deleted on a timer yet. Deleting your account is how your data goes today. The detail is in how long we keep it.
Who we are
Gaffr is a trading name of GAFFR LTD LTD, a company registered in England and Wales (company number 17461178), registered office 66 Paul Street, London, England, EC2A 4NA. We decide what personal data is collected through gaffr.uk and the two apps and what it’s used for, which makes us the controller under UK data protection law.
Anything about this policy, including using your rights: hello@gaffr.uk. Post to the registered office works too. We haven’t appointed a data protection officer; a person at Gaffr reads that inbox.
This policy covers gaffr.uk, the Gaffr app and the Gaffr Live app. It replaces the Crew Privacy Notice v1.0 inside Gaffr Live, which is wrong in places (it says we don’t hold bank details, for one). Where the two disagree, this page is right.
Website visitors
The waitlist form
What you give us
- Data
- Whether you book crew or are crew, your name, your email address and, if you want, your company (clients) or discipline (crew). Each answer is cut to 200 characters. A hidden field catches bots; if it’s filled in, we throw the whole thing away.
- Why
- To invite you when Gaffr opens to your side of the job. Nothing else. We don’t pass it on.
- Lawful basis
- Your consent. Take it back any time by emailing hello@gaffr.uk.
Analytics
We count visits with Vercel Web Analytics. For each page view it records the page, the site that sent you, your country, your browser, operating system and type of device. It sets no cookies and stores nothing on your device. Vercel tells visits apart with a code built from your request and throws that code away after 24 hours, so it can’t follow you from one day to the next or across other sites. We see totals, never individuals.
Lawful basis: legitimate interests, in knowing which pages get used so we can make the site better. Don’t want to be counted? A content blocker stops the analytics script and the site works exactly the same without it.
Hosting
Vercel hosts the site. Like any web server, it sees your IP address, your browser details and the pages you ask for, and uses them to deliver the site and protect it from attacks. Pages come from the Vercel data centre nearest you; the waitlist form is handled in Washington DC. Lawful basis: legitimate interests, in running a website that works and stays up.
Everything else
No ad tags, social media pixels, embedded videos or chat widgets. Our fonts are served from gaffr.uk, so your browser never contacts Google to fetch them. The cookies page has the full list of what the site and the apps store on your device.
Emailing us
Email to hello@gaffr.uk lands in our Google Workspace mailbox. We use what you send to answer you. Lawful basis: legitimate interests, or our contract with you if it’s about your account.
Clients: the Gaffr app
Clients are the producers, venues and crew chiefs who book crew through the Gaffr app. This is what the app collects and why. You can’t book without an account and a card on file; everything else is part of making a booking work.
What we collect
Your account
- Data
- Your name, email address, company name and a password. Supabase, our sign-in provider, stores the password scrambled; nobody at Gaffr can read it. You can sign in with a one-time email link instead.
- Why
- To run your account and your bookings.
- Lawful basis
- Contract.
Your postcode
- Data
- The postcode you give at sign-up. If we don’t cover it yet, your email, name, postcode and company go on our app waitlist instead.
- Why
- To check we operate where you do.
- Lawful basis
- Steps you ask us to take before a contract.
Sign-up checks
- Data
- Your IP address and your device’s user agent (the string that names your app or browser version) at sign-up, plus the two halves of your email address.
- Why
- A daily check compares these across accounts to catch duplicates and fakes. A match flags the account for a person at Gaffr to look at. It never blocks anyone on its own.
- Lawful basis
- Legitimate interests: preventing fraud and abuse.
Your card
- Data
- Your card goes straight to Stripe, which stores it. We keep Stripe’s customer reference for you, a reference to your saved card (never the card number) and whether billing is set up. The app uses your camera only if you choose to scan your card.
- Why
- To hold and take payment for bookings. Stripe also uses your card and device details to prevent fraud, as a controller in its own right.
- Lawful basis
- Contract.
What you agreed to
- Data
- Which version of the fee structure and the payment terms you accepted, and when.
- Why
- So both sides can prove what was agreed.
- Lawful basis
- Legitimate interests.
Your bookings
- Data
- Venue address and postcode, the map pin and whether it came from the address or you placed it, access instructions, notes for crew (up to 500 characters), the site contact’s name, phone and email, your health-and-safety answers, times, your maximum rate, card holds, charges, extensions and any cancellation fee owed.
- Why
- To find crew, run the booking and charge for it.
- Lawful basis
- Contract, and legal obligation for the accounting records.
Ratings, reports and disputes
- Data
- Ratings you give and get (stars, comment, would book again), feedback about the app (free text and a 0–10 score), “Problem with this match” reports, “Crew didn’t show” claims, and “Block or report”: the reason and detail you give go to our team, and the block keeps you and that crew member apart for good. Reporting a past conflict with a crew member blocks them the same way. If you dispute a charge with your bank, we keep a copy of Stripe’s record of it.
- Why
- Fairness, safety, and sorting out problems and disputes.
- Lawful basis
- Legitimate interests, and contract.
Notifications
- Data
- A push token from Apple so we can send notifications to your iPhone. Push on Android isn’t set up yet.
- Why
- To tell you when crew accept, arrive or finish.
- Lawful basis
- Contract.
Your location
- Data
- If you allow it, the home map centres on where your phone is and asks our server for live crew nearby. We don’t save your location. Like any request to our server, that one can show up in our host’s short-lived request logs.
- Why
- To show you who’s around before you book.
- Lawful basis
- Legitimate interests.
What crew see about you
- Every crew member offered your booking sees your name, your company name, the venue postcode, the skills needed and your health-and-safety answers. Not the street address.
- The crew member who accepts gets the full booking: venue address, access instructions, notes, the site contact’s name and phone number, and your name and company.
- After the shift you rate each other. Neither of you sees the other’s rating until both are in, or 14 days pass.
Crew: the Gaffr Live app
Crew find and work shifts through Gaffr Live. Sign-up is by invite. We ask crew for far more than clients, because the law and the job demand it: we have to check you can work in the UK, report your earnings to HMRC, and pay you.
You don’t have to give us any of it, but without the required parts (your legal name, date of birth, home address, mobile number, NI number, right to work, photo ID, insurance, bank details and a Stripe payout account) we can’t offer you work.
What we collect
Who you are
- Data
- Your email address (you sign in with it, and it’s the one we invited), display name, legal first and last name, mobile number, date of birth and profile photo.
- Why
- To run your account and show clients who’s coming. Your date of birth is checked on our server to confirm you’re 18 or over, and goes in the HMRC report.
- Lawful basis
- Contract, and legal obligation (HMRC reporting).
Your home address
- Data
- Your home address, the date you confirmed it, and a map point for it, which Mapbox works out from the address or you place by hand.
- Why
- To offer you work within reach, estimate your travel time and when to leave, set up your Stripe payout account, and report to HMRC, which asks us to reconfirm it every 36 months. It also places the approximate dots clients see on the map (below).
- Lawful basis
- Contract, and legal obligation (HMRC reporting).
National Insurance number and UTR
- Data
- Your National Insurance number, which you need to finish sign-up. Your Unique Taxpayer Reference, if you choose to give it.
- Why
- The UK’s digital platform reporting rules make us collect and check your NI number and report it to HMRC each year. We encrypt it before we store it. It appears in full only in the HMRC report, which only Gaffr admins can download, and every download is logged. If you give your UTR, it goes in that report too. It’s stored without the NI number’s extra encryption, and our team can see it.
- Lawful basis
- Legal obligation.
Bank details
- Data
- Account holder name, sort code and account number. We encrypt them before storing them and keep the last four digits readable so you can recognise the account. Each payout keeps its own copy: the payee name and last four digits readable, the rest encrypted.
- Why
- To pay you. Paying crew through Stripe isn’t finished yet. Until it is, and as a fallback afterwards, a person at Gaffr pays you by bank transfer from our account at Tide, using these details. A second person has to approve each payment, and every time someone at Gaffr views your full account number, it’s logged.
- Lawful basis
- Contract.
Your Stripe payout account
- Data
- Crew payouts are moving to Stripe, and you need a Stripe account before you can go live or accept work. To set it up we send Stripe your legal name, date of birth, address, phone number, email, bank account and a short description of your work. You confirm them and accept Stripe’s terms on Stripe’s own pages. We keep Stripe’s status for your account: what it still needs from you, and whether payouts are on.
- Why
- To pay you. Stripe runs its own identity and anti-money-laundering checks as a controller in its own right, and may ask you directly for ID.
- Lawful basis
- Contract.
Your work profile
- Data
- Your skills, your hourly rate and its history, your default availability, whether you take scheduled work, and your crew code, which you give a colleague who wants you to cover a booking for them.
- Why
- To match you with work you can do, at your rate.
- Lawful basis
- Contract.
Your documents
- Data
- Right to work (a screenshot of your share code from gov.uk or, for British and Irish citizens, the photo page of your passport), photo ID, public liability insurance and any licences, such as PASMA or IPAF. Plus expiry dates, whether each was approved or declined and why, and the reference from the government’s online right-to-work check. Right-to-work documents show your nationality or immigration status.
- Why
- To confirm you can work in the UK, that you are who you say, and that you’re insured and qualified for the work you take.
- Lawful basis
- Right to work: legal obligation where the law puts the check on Gaffr (how far it does isn’t settled yet), and otherwise legitimate interests in keeping illegal working off Gaffr. The rest: contract and legitimate interests (safety).
Terms and legal pages
- Data
- Which version of the crew terms you accepted, when, and whether you scrolled to the end; when you opened the legal pages.
- Why
- So both sides can prove what was agreed.
- Lawful basis
- Legitimate interests.
Going live
- Data
- Whether you’re live and until when, when the app last checked in, and, on iPhone, whether the app detects that the phone has been jailbroken.
- Why
- To offer work only to crew who are available, and to protect accounts.
- Lawful basis
- Contract, and legitimate interests (security).
Location on a shift
- Data
- Your position, its accuracy, your speed and heading, and the time, while the “On my way” or on-shift screen is open. Also whether your phone reports a faked location, and a flag if you seem to move impossibly fast.
- Why
- The client’s live map and ETA, the arrival check, spotting faked locations, and settling “Crew didn’t show” claims. More in Location.
- Lawful basis
- Contract, and legitimate interests (fraud and safety).
Offers, bookings and releases
- Data
- Offers sent to you and what happened to them, bookings you accepted, and bookings you released, with the reason you picked (Ill or injured, Family emergency, Travel disruption, Clash with other work, Something else), whether you marked it as an emergency or out of your hands, and an optional note of up to 300 characters. Only Gaffr sees the reason and the note. If you name a colleague to cover a booking, we keep that too.
- Why
- To run bookings, reopen a released one to other crew, and look at releases in context. Declining an offer is free and isn’t held against you.
- Lawful basis
- Contract, and legitimate interests (reliability).
Attendance
- Data
- Your estimated travel time from home, the time you need to leave by, signals that you’re at risk of being late, “Crew didn’t show” claims and how they ended, and notes our team writes about them.
- Why
- To warn early when a shift is at risk, and to settle claims.
- Lawful basis
- Legitimate interests.
Incidents
- Data
- Incident reports (how serious, what kind, what happened, photos), your reply and photos if a client says you didn’t show, and “Block or report” on a client: the reason and detail go to our team, and the block keeps you and that client apart for good.
- Why
- Safety, and hearing your side of a dispute.
- Lawful basis
- Legitimate interests.
Money
- Data
- Your payouts, anything we’ve invoiced you to recover, and the charges your fee was part of.
- Why
- To pay you and keep the books.
- Lawful basis
- Contract, and legal obligation (tax and HMRC).
Sign-up checks, waitlist and notifications
- Data
- The same sign-up checks as clients (IP address, user agent, the two halves of your email). If we don’t cover your area yet, your email, name, postcode and phone go on our app waitlist. A push token from Apple for notifications on iPhone.
- Why
- Catching duplicate accounts, inviting you when we reach you, and sending you offers.
- Lawful basis
- Legitimate interests, and contract.
Health information
Picking “Ill or injured” when you release a booking, or describing an injury in an incident report, tells us something about your health. The law treats health data as a special category, which needs a legal condition on top of a lawful basis. We haven’t settled which one applies to us yet. We use it only to handle that release or incident, and it never goes to clients. You don’t have to give a health reason: “Something else” works, and the note is optional.
What clients see about you
- Before anyone books: while you’re live, anyone signed in to the Gaffr app sees, on its home map, a dot for each live crew member nearby. The dot is your home point, rounded to roughly 100 metres. No name, no photo, nothing else.
- From confirmation to the end of the shift: your first name, photo, mobile number (so the client can call you), the skill booked, the fixed labels “Right to work verified”, “ID checked” and “Insurance on file”, how many jobs you’ve completed, and your average rating once you have at least three.
- While you’re on the way and on shift: your live position on a map, and your ETA.
- After the shift: your first name and photo.
- Never: your date of birth, age, nationality, which right-to-work document you used, immigration status, email address, legal name, home address, tax or bank details.
The booking’s site contact can mark you as arrived. A colleague you give your crew code to can name you to cover a booking for them.
Site contacts
When a client books, they can name a site contact: a name, phone number and email address. They come from the client, not from you. We email the site contact a sign-in link, sent through MailerSend. Opening it creates a sign-in record for that email address with Supabase, our sign-in provider, and lets them mark the crew member as arrived for that booking and nothing else. The crew member who accepts sees their name and phone number so they can find them on the day (their app also receives the email address; see the note under clients). The details stay with the booking.
Lawful basis: legitimate interests, the client’s and ours, in getting crew onto site. Don’t want to be a site contact? Tell the client, or email hello@gaffr.uk. The rights further down this page are yours too.
Google and Apple sign-in
What we receive
- Google: your name, email address, Google account ID and a link to your Google profile picture.
- Apple: an ID for your Apple account, your email address and, the first time only and only if you choose to share it, your name. If you pick Hide My Email, Apple gives us a private relay address that forwards to your real inbox, and we never see the real one.
- We don’t get your Google or Apple password, your contacts, calendar, files or anything else in those accounts.
What we do with it
- We use your email address to sign you in and match you to your Gaffr account. We don’t use your profile picture.
- Crew accounts are by invite, tied to the address we invited. If the address Google or Apple gives us doesn’t match it, sign in with an email link to your invited address instead.
- It’s stored with your sign-in record at Supabase, our sign-in provider, and deleted when your Gaffr account is deleted.
- We don’t share it with anyone else, sell it, or use it for ads. Gaffr’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- With a relay address, our emails go through Apple. Turn forwarding off and you’ll miss sign-in links and booking emails.
- To disconnect, remove Gaffr in your Google Account’s security settings or under Sign in with Apple in your Apple Account settings. That stops that way of signing in; it doesn’t delete your Gaffr account. Do that in the app.
Biometric unlock
Also coming, and also not built yet: an optional Face ID, Touch ID or fingerprint lock on the apps. Your phone does the check. Your face or fingerprint never leaves the phone and Gaffr never receives it.
Location
Crew: foreground only
Gaffr Live uses your location only while the “On my way” or on-shift screen is open, and our server rejects location from any booking that isn’t under way. We never ask for background location, so nothing is tracked between shifts or with the app closed. “I’m here” takes a single reading when you tap it.
What your location on a shift is used for:
- the client’s live map and your ETA; Mapbox calculates the ETA from your position while you’re on the way;
- our team’s live map of shifts under way;
- checking you’ve arrived at the venue;
- spotting faked locations and impossible speeds, which raise an incident for a person to review;
- settling “Crew didn’t show” claims.
Your home point sets which offers are within reach, places the approximate dots on the client map, and goes to Mapbox to estimate your travel time and leave-by time. Mapbox also turns your typed address into that point.
Clients
The Gaffr app uses your phone’s location only to centre the home map and look for crew nearby. We don’t store it.
Mapbox
Our maps come from Mapbox. When a map loads, your phone fetches map images from Mapbox, so Mapbox sees your IP address and the area you’re looking at. Mapbox’s map software in the apps also sends Mapbox its own usage data, which can include your phone’s location if you’ve let the app use it, under Mapbox’s privacy policy. We don’t switch that off for you, because Mapbox’s terms leave that choice to you: tap the ⓘ in the corner of a map for Mapbox’s options, including turning its usage data off.
Decisions the system makes
Some decisions are made by software, with no person looking at your individual case. You have the right to ask for a person to look at any of them again, to give your side, and to challenge the result. Email hello@gaffr.uk.
Who gets offered work
Dispatch picks which crew get each offer. You’re in the running if your account is active, not paused and not being deleted, you’ve accepted the current crew terms, home is within range, you have the skill, your documents are verified, Stripe can pay you, your NI number is on file, your rate is at or under the client’s maximum, you have no clashing booking, you haven’t already turned down, released or been stood down from that booking, and neither you nor the client has blocked the other. For a booking a few hours away or less you also have to be live; for one further ahead, you have to take scheduled work and be reachable by notification.
Offers go out in batches. Crew who haven’t had an offer for that booking come first, then crew whose app has checked in recently (or, for bookings further ahead, who can get a notification), then whoever lives closest, then whoever joined Gaffr first. It never ranks you on ratings, declines, your rate, releases or problem reports. Saying no to an offer costs you nothing. Because this decides who gets paid work, we treat it as a decision that significantly affects you.
“Crew didn’t show”
When a client says their crew member didn’t turn up, the system checks the booking’s record. If the crew member never tapped “On my way”, never arrived, and sent no location from inside the venue’s arrival zone, the claim is accepted automatically: the client pays nothing, the crew member isn’t paid for that booking, and it’s recorded as a no-show. Anything else goes to a person before anything is charged or paid. Crew: if an automatic no-show is wrong (your phone died, say), email us and a person will look at it.
Expired documents
If your right-to-work document or your insurance expires, your account pauses automatically and you can’t go live. We warn you 30 days before. The pause lifts itself once an approved, in-date replacement is on file.
Running late
If you haven’t tapped “On my way” by your leave-by time, or your ETA is after the call time, the app warns you, then tells Gaffr and the client, and offers the client a replacement search. The client decides. If they take it, you’re stood down from that booking and aren’t offered it again. It never affects which other offers you get.
Flagged for a person, never decided by the system
The duplicate-account check and faked-location detection only flag things for our team. Invites and document approvals are made by people.
Where it’s stored
Our database and file storage are in Frankfurt, Germany. UK law treats the EU as giving adequate protection, so no extra safeguard is needed for that. We’ve set up a database in London for launch; it isn’t in use yet.
Some of the companies above are in the USA or can reach the data from there: Vercel, Stripe, Mapbox, MailerSend, Google, Apple, Expo and Supabase. For those transfers we rely on the company being certified under the UK Extension to the EU–US Data Privacy Framework (the “UK–US data bridge”), or on the UK’s International Data Transfer Addendum to the EU standard contractual clauses in that company’s data processing terms. Email hello@gaffr.uk for a copy of the safeguard that applies.
How long we keep it
While your account is open
We keep everything, including location history, documents you’ve replaced, past bookings and the record of what our team has done on your account.
When you delete your account
In either app: Settings → Delete account. You get 14 days to change your mind: sign back in and the app offers to cancel it. After that, a nightly job deletes your account, your documents and their files, bank details, NI number, rates, ratings you wrote, incident reports, offers, location history, any copy of your data we prepared for you, your invite, and your Stripe customer record or payout account. It also strips your ID and email address out of our internal message logs.
Financial records stay, with your name taken off them: payouts (with the payee details wiped), charges, and the bookings they belong to.
Also left behind, with no timer on them yet: our team’s audit log of changes they made to your account, which can repeat details from it; copies of the payment notifications Stripe sends us; and any duplicate-account flag raised about you.
When deletion waits
- While you’re still owed pay, or a cancellation fee owed to you is still being collected.
- While an invoice we sent you to recover money is still open.
- While Stripe won’t close your payout account, usually because it holds a balance or has an open dispute.
- Clients: if a crew member ever accepted one of your bookings, or it reached your card, your whole account is held back, not just those bookings. Our team sees every held deletion, but nothing in our system finishes one yet, so it waits until we deal with it by hand. If it’s been a month, chase us at hello@gaffr.uk.
What the law makes us keep
- Records for HMRC’s platform reporting: five years from the end of the year they’re about.
- Tax and accounting records: six years.
- Stripe keeps its own records for its own legal duties.
Everything else
- Website waitlist sign-ups: in Vercel’s logs for one day (see above).
- The app waitlist, for people outside our area: kept until you ask us to remove you. Deleting an account doesn’t touch it.
- Site contacts’ details: kept with the booking they were given for, for as long as the booking is kept.
- Emails to us: no automatic deletion.
Data we get from others
Most of what we hold comes from you. The rest comes from:
- Clients: ratings of crew, “Problem with this match” reports, “Crew didn’t show” claims, reports and blocks, and site contacts’ details.
- Crew: ratings of clients, incident reports, reports and blocks, and the colleague they name to cover a booking.
- Our team: crew invites (we invite you by email), decisions on documents, and notes.
- Stripe: your payout account’s status; payment, refund and dispute details.
- The Home Office: the result of an online right-to-work check.
- Mapbox: map points for addresses, and travel times.
- Your phone: push tokens, a jailbreak check on iPhone, and whether it reports a faked location.
- Google or Apple, once sign-in with them is switched on.
Your rights
UK data protection law gives you these rights. Using them is free. We answer within one month; if a request is complicated we can take up to two more months, and we’ll tell you if we need to. We may ask you to prove who you are first.
- See your data. In either app: Settings → Request my data. A person at Gaffr prepares a copy and emails it to you. The app says 14 days; the legal limit is one month. The export doesn’t cover everything yet: location history, your home map point, documents, skills, rates, offers, bank details, your Stripe status, push tokens, which legal pages you opened and our internal records are missing. Ask and we’ll send those too. Website visitors: email us.
- Correct it. Change what the app lets you change; email us for the rest.
- Delete it. Settings → Delete account. See how long we keep it for what stays.
- Object to anything we do on the basis of legitimate interests, and restrict what we do while a complaint is sorted.
- Take it with you in a machine-readable format.
- Withdraw consent for the website waitlist.
- Ask a person to review a decision the system made about you.
For anything the app doesn’t do, email hello@gaffr.uk.
You can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We’d like the chance to put it right first, but you don’t have to come to us before you go to them.
Keeping it safe
- NI numbers and bank details are encrypted (AES-256-GCM) before they reach the database.
- Documents sit in private storage. Only Gaffr admins can open them, through links that expire.
- Our team signs in with Google Workspace accounts that require two-step verification, and every admin action is written to an audit log.
- Everything travels encrypted over HTTPS.
- On your phone, the app keeps you signed in using the app’s own private storage. The cookies page has the detail.
If a breach puts you at risk, we’ll tell you, and the ICO, as the law requires.
Age limits
Crew must be 18 or over; our server checks your date of birth before you can go any further. Clients book as producers, venues and crew chiefs; we don’t ask their age. This website isn’t aimed at children.
Changes to this policy
When this policy changes, so does the date at the top. If a change affects how we use data you’ve already given us, we’ll email you about it.