How Gigpie protects your data
You're trusting us with family contact information, session history, and payment activity. Here's exactly how we handle it.
Encryption in transit
All traffic to and from Gigpie is encrypted over TLS. Nothing is sent between your browser and our servers in plain text.
Hashed passwords, encrypted credentials
Passwords are hashed with argon2, a modern, memory-hard hashing algorithm. Connected account tokens (like calendar and email integrations) are encrypted at rest with AES-256-GCM before they ever touch the database.
Tenant-isolated data
Every company's data is scoped by company ID at the data-access layer. One coaching agency's families, sessions, and financials are never visible to another tenant.
Payments handled by Stripe
Gigpie never stores full card numbers or bank account details. All payment processing runs through Stripe, and card data never touches our servers.
Account access and sessions
Sessions are managed with secure, HTTP-only cookies and can be revoked server-side. Access to a company's data is controlled by role-based membership, so front-desk staff, educators, and admins only see what their role permits.
Have a specific security or compliance question we haven't answered here? Reach out and we'll get you a straight answer.
Ready to get started?
See the platform for yourself with a free trial.