tourQ — Privacy Policy
Last updated: August 21, 2026
This policy is maintained by Gigz Technologies Inc., d/b/a tourQ ("tourQ," "we," "us"). It explains what we collect across the tourQ platform, why we collect it, and who it is shared with. It is a description of our practices, not a certification.
This policy covers tourq.co and app.tourq.co. Ticket buyers on our public marketplace should also read the tourQtickets Privacy Policy, which describes the buyer-side practices in more detail.
1. Who this policy is about
tourQ holds information about three different groups of people, and your rights depend on which one you are:
- Account holders — artists, managers, venue staff and event producers who sign up and use the platform.
- Fans and ticket buyers — people who buy a ticket, follow an artist link, or visit a public event page. Most fan data is handled under the tourQtickets policy above.
- Industry contacts — venues, talent buyers and performing artists who appear in our live-music database because that information is publicly available in the industry, even if they have never used tourQ. Section 8 explains this in full, including how to be removed.
2. Information you give us
- Account and profile: name, email address, phone number when provided, password (stored hashed, never in readable form), role, and the artist, venue or production company you represent.
- Professional profile: biography, photos, genres, hometown, links to your streaming and social profiles, technical and hospitality riders, and anything else you choose to publish.
- Business records you enter: shows, offers, proposals, contracts, settlements, guarantees, expenses, capacities and attendance figures.
- Payout details: collected and held by Stripe, not by us. See section 6.
- Banking connections: if you use tourQbooks accounting features and choose to link a bank account, that connection is made through Plaid. We receive transaction and balance records to reconcile your books. We never receive your online banking credentials.
- Support and communications: messages you send us, bug reports, and messages you exchange with other users on the platform.
3. Information we collect automatically
IP address, browser and device type, pages viewed, referring page, and timestamps. We use this for security, fraud prevention, diagnosing errors, and understanding which features are used. We also store cookies and local storage needed to keep you signed in and remember your workspace.
4. Accounts you connect
Connecting a third-party account is always optional, always initiated by you, and can be disconnected at any time from your settings. Disconnecting revokes our stored token and stops all future syncing.
Meta (Facebook and Instagram)
When you choose to connect Meta, we request these permissions:
- instagram_basic — to read your Instagram business profile, follower count and recent media so we can show your audience metrics inside tourQ.
- pages_show_list — to list the Facebook Pages you manage so you can pick which one to connect.
- business_management — to identify the Business account that owns the Page and ad account you select.
- ads_management and ads_read — only used if you run promotion through tourQ, to create and read the performance of ad campaigns for your own shows, in your own ad account.
What we do with it: we store your access token encrypted, and we store the profile and metric values we read (follower counts, post engagement, campaign results) so we can display your growth over time and, where you ask us to, factor audience size into demand estimates for your shows.
What we do not do: we do not post to your accounts without an explicit action from you, we do not read your private messages, we do not access your friends' or followers' personal information, we do not use Meta data to build advertising audiences for anyone other than you, and we do not sell or transfer Meta data to any third party.
Advertising pixels and the Meta Conversions API
If you add your own Meta pixel to a tourQ smart link or event page, visits and link clicks on that page are reported to Meta — both from the visitor's browser and from our servers using Meta's Conversions API. The server-side report includes the visitor's IP address and browser user-agent string, which Meta requires in order to match an event. These events go only to the pixel you configured, in your own ad account. If you do not configure a pixel, no such data is sent.
Other connections
- Spotify — to verify your artist identity, read your public artist profile, follower and listener metrics, and pull your catalog.
- Google — calendar availability and, for venues, business listing details.
- Mailchimp — to sync your own fan mailing list when you connect it.
5. How we use your information
To operate your account and workspace; to publish the profile and event pages you ask us to publish; to route offers, proposals, contracts and settlements between artists, venues and producers; to sell tickets and pay out the proceeds; to produce the demand and market estimates the platform is built around; to send transactional messages such as confirmations, reminders, proposal notifications and settlement statements; to provide support; to detect fraud and abuse; to improve the product; and to meet tax, accounting and legal obligations.
We do not sell your personal information, and we do not share it with advertisers for cross-context behavioral advertising.
6. Automated processing and AI features
Parts of the platform generate text and estimates automatically — artist briefs, market predictions, outreach drafts, contract summaries and similar. To do this we send the relevant content to AI processing providers under contract to us, currently the Lovable AI Gateway and OpenAI. These providers act on our instructions and are not permitted to use your content to train their own models. We do not send payout details, banking data or passwords to any AI provider.
Predictions, scores and estimates produced this way are informational. They are not decisions about you, and they are not guarantees of ticket sales or income.
7. Who we share information with
- Other users, by design. The platform exists to connect people. A venue you send a proposal to sees your profile, your draw history and your terms. An artist you book sees your venue details and your offer. Attendance and settlement figures are shared with the counterparties to that show. What you publish on a public profile or event page is public.
- Service providers that run parts of the platform for us: Supabase (hosting, database and authentication), Stripe (payments, subscriptions and payouts), Plaid (bank connections, if you use them), Resend (transactional email), Creatomate (video rendering), and the AI providers named in section 6. They may only use the data to perform their service for us.
- Payments and payouts. Stripe collects and holds the identity and bank details required to pay you, including information required by law for identity verification. We receive confirmation of account status and the amounts moved. We never receive or store full card numbers or CVC codes.
- Legal and corporate: where required by law, subpoena or lawful request, to protect rights and safety, or in connection with a merger, acquisition or sale of assets.
8. Our live-music industry database
tourQ maintains a database of venues, talent buyers and performing artists so the platform can suggest realistic routing and matches. Much of it describes businesses rather than individuals, but some records contain a booking contact's name, work email address or work phone number.
This information comes from publicly available industry sources — venue websites and public business listings, public event and box-office listings, and licensed data providers including Soundcharts, Bandsintown, Pollstar, Setlist.fm, Ticketmaster and Google Places. We use it only for business-to-business booking purposes.
If you are a booking contact and you do not want to be listed, email us at the address in section 13 and we will remove your contact details from the database. You do not need a tourQ account to make that request.
9. Cookies
We use cookies and local storage that are strictly necessary to keep you signed in, remember which workspace you are in, and protect checkout against fraud. We use privacy-respecting analytics to count page views and understand which features are used. You can block cookies in your browser, but sign-in will not work without the necessary ones.
10. How long we keep it
Account and workspace records are kept while your account is active. Show, settlement and payout records are kept afterwards for as long as needed to resolve disputes and satisfy tax and accounting requirements. Support correspondence is kept for a limited period after resolution. Technical logs are kept for a short period for security purposes. Tokens for connected accounts are deleted when you disconnect the account.
11. How we protect it
Traffic is encrypted in transit with TLS. Data is stored on managed infrastructure with row-level access controls, and internal access is limited to people who need it to operate the service. Access tokens for connected accounts are stored encrypted and are never exposed to the browser. Card data is handled by Stripe, a PCI DSS Level 1 service provider, and never touches our servers. No online service can promise perfect security. If a breach affects your personal information, we will notify you and the relevant authorities as required by law.
12. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. Residents of California, Colorado and similar jurisdictions also have the right not to be discriminated against for exercising these rights.
- Update your details in your account settings at any time.
- Disconnect a linked account — including Meta, Instagram, Spotify, Google and Mailchimp — from your settings. This revokes our stored token immediately and stops all future syncing.
- Delete your account from your account settings, or by emailing us. We will verify your identity before acting.
- Delete data obtained from Meta. You can remove tourQ from the Apps and Websites section of your Facebook settings, which sends us an automated deletion request. We honour these requests and delete the Meta profile data and tokens we hold for you. You can also email us to make the same request directly.
- Unsubscribe from marketing email at any time using the link in the footer. Transactional messages about an active booking, ticket or payout cannot be turned off while it is live.
We cannot delete records we are required to keep for a completed transaction, and requests about data already shared with a counterparty on a booking may also need to be sent to them.
13. Children
tourQ is a professional tool and is not directed at children under 13. We do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it.
14. International visitors
The platform is operated from the United States and your information is processed there. If you access tourQ from another country, you understand that your information will be transferred to and processed in the United States, which may have different data protection rules than your home country.
15. Changes to this policy
We will post updates here with a new "last updated" date. If a change materially affects how we use your information, we will make that clear.
16. Contact us
For privacy questions, deletion requests, or to exercise any right described above:
Gigz Technologies Inc., d/b/a tourQ
Email: privacy@tourq.co