Privacy Policy
Last updated: November 16, 2025
1. Introduction
This Privacy Policy describes how Abrega, Inc., a Delaware corporation, doing business as Gigpie ("Gigpie," "we," "our," or "us") collects, uses, discloses, and safeguards your information when you visit our website, use our online tutoring and coaching platform, or engage with our services. By using our services, you agree to the collection and use of information in accordance with this policy.
This policy applies to all users of our platform, including administrators, coaches, parents, students, and other authorized users within educational organizations.
2. Information We Collect
2.1 Information You Provide Directly
We collect information you provide when you:
- Create an account or register for our services
- Complete your profile or organizational setup
- Make payments or enter billing information
- Contact customer support or communicate with us
- Participate in surveys, feedback, or promotional activities
This includes personal information such as names, email addresses, phone numbers, payment details, student information, and organizational data.
2.2 Information Collected Automatically
When you use our platform, we automatically collect:
- Usage Data: Pages visited, features used, session duration, and interaction patterns
- Device Information: IP address, browser type, operating system, device identifiers
- Log Data: Access times, pages viewed, and system activity
- Session Replay Data: Mouse movements, clicks, scroll behavior, page content viewed, and form interactions (with sensitive fields masked) captured through Microsoft Clarity, along with associated IP address, device, and browser information
- Cookies and Tracking Technologies: Information about your browsing behavior and preferences
Please avoid entering sensitive personal information into free-text fields unless requested by the Service; session replay tools may briefly capture on-screen content before masking is applied.
2.3 Information from Third-Party Integrations
When you connect third-party services to our platform, we may receive:
- Calendar data from Google Calendar or Microsoft Outlook
- Video conferencing details from Zoom, Google Meet, or Microsoft Teams
- Authentication tokens and integration settings
- Usage data from connected services
We only access the minimum data necessary for platform functionality and store this information securely.
2.4 Information from Educational Organizations
When educational organizations use our platform, they may provide us with student and family information necessary for service delivery, including:
- Student names, ages, and academic information
- Parent/guardian contact details
- Enrollment and progress data
- Session notes and educational records
3. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), our legal basis for collecting and using your personal information depends on the information concerned and the context in which we collect it. We process your personal information generally because:
- It is necessary for the performance of a contract with you
- You have given us permission to do so
- It is necessary for our legitimate business interests and your rights are not overridden
- It is necessary to comply with legal obligations
- It is necessary to protect your vital interests or those of others
4. How We Use Your Information
We use the collected information for the following purposes:
4.1 Service Provision
- Creating and managing user accounts
- Providing access to platform features and services
- Processing payments and managing billing
- Scheduling and managing tutoring sessions
- Facilitating communication between users
4.2 Platform Improvement
- Analyzing usage patterns and user behavior
- Developing new features and services
- Improving user experience and interface design
- Conducting research and analytics
- Reviewing session replays and heatmaps (e.g., via Microsoft Clarity) to diagnose issues and improve usability, using de-identified or aggregated data where possible
4.3 Communication and Support
- Sending service-related notifications and updates
- Providing customer support and technical assistance
- Responding to inquiries and feedback
- Sending marketing communications (with consent)
4.4 Security and Compliance
- Detecting and preventing fraud and abuse
- Ensuring platform security and integrity
- Complying with legal obligations
- Enforcing our terms of service
5. Information Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following limited circumstances:
5.1 Service Providers and Business Partners
We share information with trusted third-party service providers who assist us in operating our platform:
- Payment Processors: Stripe for secure payment processing
- Cloud Infrastructure: Hosting and data storage providers
- Communication Services: Email and messaging platforms
- Analytics and Session Replay: Usage tracking, performance monitoring, and behavioral analytics/heatmaps (e.g., Microsoft Clarity) to improve the Service
- Customer Support: Help desk and ticketing systems
These providers are contractually obligated to maintain the confidentiality and security of your information. Microsoft may also use aggregated and de-identified data to improve its services in accordance with its privacy terms.
5.2 Within Educational Organizations
Within organizations using our platform, information is shared between authorized users based on their roles and permissions:
- Administrators can access organization-wide data
- Coaches can access student and session information
- Parents can access their children's progress and schedules
- Students can access their own learning materials and records
5.3 Legal Requirements and Safety
We may disclose information when required by law or to protect rights and safety:
- In response to legal requests, court orders, or subpoenas
- To investigate potential violations of our terms or policies
- To protect against fraud, security threats, or illegal activity
- To safeguard the rights, property, or safety of our users or the public
5.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, user information may be transferred as part of the transaction. We will notify users of any such change in ownership or control.
6. Data Security
We implement comprehensive security measures to protect your personal information:
6.1 Technical Safeguards
- Encryption: Data encrypted in transit (TLS/SSL) and at rest
- Access Controls: Role-based access and multi-factor authentication
- Network Security: Firewalls, intrusion detection, and monitoring
- Data Backup: Regular encrypted backups with secure storage
6.2 Organizational Safeguards
- Employee Training: Regular security awareness training
- Access Management: Least privilege access principles
- Incident Response: Established procedures for security incidents
- Regular Audits: Security assessments and compliance reviews
While we implement robust security measures, no system is completely secure. We cannot guarantee the absolute security of your information.
7. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law.
7.1 Active Accounts
Personal information associated with active accounts is retained while the account is in use and for a reasonable period after account deactivation.
7.2 Educational Records
Student progress data, session notes, and educational records are retained according to applicable education regulations and organizational policies.
7.3 Legal and Regulatory Requirements
Certain information may be retained longer to comply with legal obligations, resolve disputes, or enforce our agreements.
7.4 Data Deletion
When information is no longer needed, we securely delete or anonymize it using industry-standard methods.
8. Your Rights and Choices
You have certain rights regarding your personal information. The availability of these rights depends on your location and applicable law.
8.1 General Rights
- Access: Request a copy of your personal information
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information
- Portability: Request transfer of your data in a structured format
- Restriction: Request limitation of processing in certain circumstances
- Objection: Object to processing based on legitimate interests
8.2 Marketing Communications
You can opt out of marketing communications at any time by following the unsubscribe instructions in our emails or contacting us directly.
8.3 Cookie Controls
You can control cookies through your browser settings. However, disabling certain cookies may affect platform functionality.
8.4 Exercising Your Rights
To exercise your rights, please contact us using the information in Section 13. We will respond to your request within 30 days (or as required by applicable law) and may require verification of your identity.
9. Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience and analyze platform usage.
9.1 Types of Cookies We Use
- Essential Cookies: Required for platform functionality
- Analytics Cookies: Help us understand user behavior and improve services
- Preference Cookies: Remember your settings and preferences
- Security Cookies: Help protect against fraud and abuse
9.2 Managing Cookies
You can control cookie settings through your browser preferences. For more information about our cookie practices, please contact us.
9.3 Session Replay and Heatmaps (Microsoft Clarity)
We use Microsoft Clarity to capture session replays, heatmaps, and related analytics so we can understand how users navigate the Service and address usability issues. Clarity sets cookies and similar identifiers to link page views within a session and records on-screen content, clicks, scrolls, and interactions; sensitive fields are masked where possible.
You can control Clarity cookies through your browser settings or by using tracking-protection tools. If you prefer not to be included in Clarity analytics, you may also contact us using the details in Section 13 so we can help accommodate your request.
10. Third-Party Services and Integrations
Our platform integrates with various third-party services. Each service maintains its own privacy policy:
- Stripe Privacy Policy
- Google Privacy Policy
- Microsoft Privacy Policy
- Microsoft Clarity Terms and Privacy
- Zoom Privacy Policy
We encourage you to review the privacy policies of these third-party services. We are not responsible for their privacy practices.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws than your jurisdiction.
When we transfer personal information internationally, we implement appropriate safeguards such as:
- Standard contractual clauses approved by relevant authorities
- Adequacy decisions by competent data protection authorities
- Your explicit consent where required
- Other legally recognized transfer mechanisms
12. Children's Privacy
Our services are designed for use by educational organizations and are not intended for children under 13 years of age (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children under this age.
If we become aware that we have collected personal information from a child under the applicable age, we will take steps to delete such information promptly. Educational organizations using our platform are responsible for ensuring compliance with applicable children's privacy laws.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
When we make material changes, we will:
- Update the "Last updated" date at the top of this policy
- Post the updated policy on our website
- Send notification via email or platform notification for significant changes
- Provide additional notice for changes affecting user rights
Your continued use of our services after the effective date of changes constitutes acceptance of the updated policy.
14. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Abrega, Inc. (d/b/a Gigpie)
General inquiries: hello@gigpie.com
Address: 651 N Broad St, Suite 201, Middletown, Delaware 19709
We will respond to your inquiries within 30 days. For data protection inquiries under GDPR, you also have the right to lodge a complaint with your local data protection authority.
15. Compliance with Google OAuth
Our use of Google OAuth and Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. We only access and use Google user data as described in this Privacy Policy and in accordance with our published OAuth scopes.
For more information about how Google handles your data, please refer to the Google Privacy Policy.
16. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict of law principles. Any disputes arising from this policy will be resolved in the courts of Delaware.