How GigMatch protects employee data
GigMatch is built so employees can use the benefit privately and securely, and so the organizations that offer it can trust where the data lives.
For technical questions, your security team can reach us at security@gigmatch.com.
- Hosting: AWS, United States regions
- Encryption in transit: TLS 1.2 or higher for all connections
- Encryption at rest: database and backups encrypted with managed keys
- Apps: iOS and Android, distributed through the App Store and Google Play
- SOC 2: compliance in progress
Encryption
All traffic between the GigMatch app or admin portal and our backend is encrypted with TLS 1.2 or higher. Data at rest is encrypted in our managed PostgreSQL database using managed keys, with encrypted backups and encrypted object storage for any files.
Authentication and the app
Employees sign in with Apple, Google, or email and password, following current NIST password guidance. The GigMatch app runs on the employee's own iOS or Android device and is distributed through the App Store and Google Play, so each release passes Apple's and Google's review before it reaches anyone. There is nothing to install on company-managed devices and no IT involvement required on the employer's side.
Data minimization
GigMatch collects only what it needs to deliver the product. For each registered employee, that is:
- Authentication identifiers (email, sign-in provider IDs)
- Profile information the employee chooses to provide (name, contact info, zip code)
- The stuff, interests, and skills used to generate gig matches
- App usage and engagement data
We do not collect:
- Government identifiers such as Social Security or driver's license numbers — they are not required to use GigMatch
- Bank account or payment card information from employees — the employer pays the contract and employees pay nothing
- Location data beyond zip code, unless the employee explicitly opts in to a location-based feature
Privacy and data sharing
We do not sell user data. And we do not share an individual employee's data with the employer who sponsors the benefit — employers see only aggregate, anonymized numbers, never anything tied to a specific person. An employee's participation and answers stay private inside GigMatch.
We share data with vendors only as necessary to run the service — cloud hosting, email delivery, identity, analytics, and error reporting — each governed by a Data Processing Agreement. The full vendor list is available on request.
Compliance and audits
SOC 2 compliance is in progress. CCPA disclosures are covered in the GigMatch Privacy Policy. GigMatch does not handle protected health information and is not HIPAA-aligned. We can provide additional documentation — architecture overview and full vendor list — under NDA on request.
Incident response
We monitor production systems for anomalous activity and unusual data access. If we identify a security incident:
- We assess scope and severity within 24 hours
- We notify affected customers within 72 hours where employee data may have been affected
- We implement and verify remediation
- We produce a post-incident report for affected customers within two weeks of resolution
Vulnerability disclosure
If you or your security team identifies a vulnerability in our app or backend, please report it to security@gigmatch.com. We acknowledge legitimate reports within 48 hours, share a remediation timeline within one week of triage, and track the report through resolution. We do not pursue legal action against good-faith security researchers.
Questions
Technical security questions: security@gigmatch.com.
Everything else: hello@gigmatch.com.