Privacy Policy
Last updated: 18 August 2026
This policy explains how GigJar ("we", "us") handles personal data when you visit gigjar.co.uk, join the GigJar beta/waiting list, use the GigJar app, connect an optional account or HMRC feature where enabled, or buy the GigJar Desktop Tax Workbook. GigJar is operated in the UK by Keith McKinney as a sole trader and data controller.
1. Contact
For privacy questions or requests, email hello@gigjar.co.uk.
2. Your core app records stay on your phone
The shifts, earnings, mileage and expenses you log in the current GigJar beta are stored on your device. They are not uploaded to GigJar as ordinary app records, and we cannot see or recover them. The app therefore provides export/backup tools so you can save a copy outside the app. Cloud sync is a later feature and this policy will be updated before ordinary records are uploaded for that purpose.
Closed beta: In the current closed beta version of GigJar, crash reporting and user accounts are not enabled. Your GigJar records remain on your device and GigJar does not transmit them to our servers.
If you are taking part in the closed beta cohort study, read the GigJar Closed Beta Cohort Privacy Notice for the additional information about recruitment, feedback and the participant-initiated measurement export.
Optional account, HMRC-connection and crash-diagnostic features are separate from those core records and are described below.
3. What we collect and why
| Data | When | Why | Lawful basis |
|---|---|---|---|
| Beta/waiting-list email | When you choose to join the GigJar beta or launch list | To contact you about the beta, launch and closely related GigJar updates | Consent |
| Workbook order/contact details | When you buy the Desktop Tax Workbook or contact us about an order | To fulfil and support the purchase | Contract |
| Historical filing-reservation record | If you submitted a filing reservation before that standalone offer was retired | To preserve an accurate record of the prior request and respond to withdrawal, access or deletion requests. GigJar no longer accepts new standalone filing reservations. | Legitimate interests in administering the historical request |
| Account sign-in data, such as email and account identifier | When you choose to create or use an optional GigJar account | To authenticate you and provide account-dependent features | Contract |
| National Insurance number and HMRC authorisation data | Only when you choose an HMRC-connected feature in a build where it is enabled | To request the HMRC information you asked GigJar to retrieve. HMRC access tokens are kept server-side; Government Gateway credentials are entered on HMRC's service, not into GigJar. | Contract |
| Limited technical crash/session diagnostics | In configured non-development app builds if an error occurs or a technical session is recorded for reliability monitoring | To diagnose crashes and improve app reliability. GigJar disables default PII collection, screenshots, view hierarchy, performance tracing and session replay in its Sentry configuration. | Legitimate interests in security and reliable service |
| Server/technical logs, which can include IP address | When you visit the website or use an online service | Security and reliable service delivery | Legitimate interests |
4. Analytics and cookies
GigJar currently runs no product analytics or advertising script and does not use advertising or behavioural-tracking cookies. We do not show a cookie banner because we do not currently set non-essential tracking cookies. Limited crash diagnostics, where configured, are used for reliability rather than product-usage analytics. If our analytics or cookie use changes, this policy will be updated before the relevant tooling is enabled.
5. Providers and recipients
We do not sell personal data. Services used to operate GigJar can include:
- Netlify - website hosting and beta/waiting-list form handling.
- Gumroad - Desktop Tax Workbook sales, payment and file delivery.
- Supabase - optional account/authentication, HMRC connection data and related server-side service data where enabled. Current ordinary shifts, trips and expenses are not cloud-synced there.
- Sentry - limited privacy-sanitised crash diagnostics in configured non-development app builds.
- Resend - service emails where used.
- Google Fonts - web fonts; loading fonts can disclose your IP address to Google.
- HM Revenue & Customs (HMRC) - when you explicitly authorise an HMRC-connected feature.
Where a provider processes personal data outside the UK, we use an appropriate transfer mechanism or safeguard required by UK data-protection law. Contact hello@gigjar.co.uk if you want more information about the safeguards used for a particular provider.
6. HMRC-connected features
The current beta does not provide live HMRC filing. In beta builds where the optional HMRC connection is enabled, a signed-in user may choose to authorise read-only HMRC access so GigJar can retrieve supported business/obligation information. Government Gateway credentials are entered on HMRC's own service, not into GigJar. HMRC authorisation tokens are held server-side rather than in the app, and the National Insurance number used for those requests is stored against the signed-in GigJar account in Supabase. GigJar will update this notice before introducing materially different HMRC processing such as live submission.
7. Marketing
We send beta/launch or marketing email where you have consented or where the law otherwise permits communication about our own similar products and services. You can unsubscribe at any time. Where processing relies on consent, you can withdraw that consent at any time.
8. Retention and your rights
We keep personal data only as long as needed for the purpose it was collected and for applicable legal, accounting, security or dispute-resolution obligations. Where we do not set a fixed period, we review whether the data is still needed for the purpose described above.
Depending on the processing, UK data-protection rights can include access, correction, erasure, restriction, objection, portability and withdrawal of consent. Where we rely on legitimate interests, you have the right to object to that processing. Email hello@gigjar.co.uk to exercise a right. You may also complain to the Information Commissioner's Office.
9. Desktop Tax Workbook data
The GigJar Desktop Tax Workbook runs in Excel or Google Sheets under your control. GigJar does not receive the earnings, mileage, expenses or tax figures you type into the workbook merely because you use it.
10. Tax information
GigJar provides organised records, tax information and estimates. It is not regulated personal tax advice. For complex or personal tax circumstances, use a qualified accountant or tax adviser.
11. Changes
We may update this policy as GigJar develops. The date above shows the latest revision; material changes will be highlighted where appropriate.