Privacy Policy
Last updated: 5 August 2026
1. Who we are
GearHub is a product of Kingstone Consultancy Ltd. Kingstone Consultancy Ltd is the data controller for personal data processed through the GearHub mobile apps, website, and API (together, the "Service"). Our registered address is No1 Parkside Court, Greenhough Road, Lichfield, Staffordshire, United Kingdom, WS13 7FE. You can contact us about privacy matters at serious-stuff@gearhub.tech.
This policy explains what personal data we collect, why, how long we keep it, who we share it with, and the rights you have over it under UK GDPR.
2. Data we collect
We collect the following categories of personal data, generally provided directly by you as you use the Service, or generated automatically by your use of it:
- Identity & profile: username, display name, avatar, bio, contact email, contact phone, Instagram handle, music link, band name, genre/role, personal website, date of birth, privacy setting (public/private profile), verification status/role, your invite code, admin flag, preferred display currency, account creation date, and the timestamp of when you accepted these Terms.
- Location data: your typed hometown (name and coordinates) and, only if you opt in, a live current-location snapshot. These are used to power nearby-stolen-gear alerts and to match recovery-case claimants by area. This location data is coarse, and current-location sharing can be turned off at any time (which also deletes the stored snapshot); hometown location is used in the same way whenever it's set. One exception is precise by design: when you report your own gear stolen, you can choose to capture the exact last-known location on that report. That precise point is visible only to you and to GearHub administrators, and to verified law enforcement if the case reaches them.
- Contact discovery (opt-in, off by default): only once you turn discoverability on do we generate a one-way cryptographic hash of your account email, so that friends who already have it in their contacts can find you on GearHub; if you also add a phone number to be findable, we store that number (so you can see and change it) and a one-way hash of it for the same matching. Turning discoverability off removes these hashes immediately. If you use “find friends from your contacts”, your device creates one-way hashes of your contacts’ phone numbers and email addresses and sends only those hashes to us to check for matches — we never receive or store your address book, and hashes that don’t match an existing user are used only for that lookup and then discarded. Invitations you send to contacts who aren’t on GearHub are composed and sent from your own device; we don’t receive those recipients.
- Gear records: category, type, brand, model, series, year, serial number (and its format-verification status), finish, condition, freeform spec fields, purchase price, purchase date, estimated value, currency, notes, "story" text, photos, public/private and per-field visibility settings, a unique identifying code, status (active/stolen/recovered), and any stolen-report notes.
- Gear history & sub-records: ownership transfer history; component/part records (slot, brand, model, serial, source, install/removal dates); modification history; name-change history; timeline contributions (photos/captions and their approval status); service records (technician/shop name, cost, dates, and shared vs. private notes); appearance history (tours/shows/studio sessions); and, for manufacturer/dealer accounts, company records, gear templates, and brand submissions/change requests.
- QR & possession verification: persistent QR credentials for your gear and their scan logs (who scanned, the result, and any suspicious-activity flags), plus single-use rotating possession tokens (issued/consumed/expiry).
- Recovery & theft data: recovery case records linking a reporter and a claimant, including the claimant's location snapshot at the time of a match, the claimant's recorded stance on making contact (pending, agreed, or declined), and whether the case has been escalated. If a claimant who registered gear matching an active theft report declines contact with the owner or does not respond, the case may be escalated: the claimant's identity (name, username, email, and phone number if provided) and best-known location are compiled into a report intended for law enforcement. This report is accessible only to GearHub administrators.
- Theft-report details: for gear you report stolen, where and when it was taken, a police crime reference number, and an investigating-officer contact email if you provide them. These are visible only to you and to GearHub administrators. If another member spots gear that matches a stolen listing, their sighting report (note, photos, and approximate area) is stored and shown to the owner; the sighter's account is linked internally so abuse can be policed, but is never shown to the owner.
- Vault data (zero-knowledge): a key-derivation salt, your wrapped master key material, a verifier value, and — if you enable it — a TOTP secret and failed-attempt/lockout state. We never have access to, and cannot derive, your plaintext passphrase, recovery key, or file contents. Encrypted attachment metadata (encrypted filename, wrapped per-file key, size, and kind) is stored on our servers, but the actual file bytes are stored encrypted in Cloudflare R2 and never pass through our API server unencrypted.
- Social graph & activity: friendships (requester, addressee, and status), asymmetric follows, blocks, feed activity events and their visibility level, reactions, notifications, and referral relationships (who referred whom).
- Financial data: an encrypted purchase-price/valuation blob, stored separately from the main gear record.
- Access-control records: per-item service-permission grants (an owner granting another user access to a specific gear item) and their revocation state.
- Administrative/audit data: an audit log of admin/owner actions, recording the actor, action, target, and a human-readable summary and field-level diff. This log never includes vault secrets or other raw sensitive payloads.
- Device & technical data: push notification tokens (Expo push tokens and Apple Push Notification service tokens, with platform), IP addresses captured for rate-limiting and abuse prevention (not for tracking or profiling you), and crash reports from the web app (the error message, the page it happened on, your browser's user-agent string, and your account id if you were signed in) used solely to find and fix bugs.
- Organisation records: if you use the backline, loan, flight-case, or household features, we store the room, case, and assignment structure you create, plus any names you type in freeform fields (for example a borrower's name on a loan record or a family member's name on a household record). Only type someone's name there with their knowledge.
- Donation offers: if you offer an instrument to the donation programme, we store the offer, your note, and its status. GearHub administrators can see your contact email and phone number on the offer so they can coordinate collection with you.
3. Cookies and similar technologies
We keep cookies to a minimum, and we never set optional cookies without your consent. Cookies on GearHub fall into two groups: essential cookies, which the Service cannot work without and which UK law (PECR) lets us set without consent, and optional cookies, which are only ever set after you choose "Allow cookies" in our cookie banner. You can change your choice at any time in Settings, or via "Cookie preferences" in the site footer if you're not signed in, and withdrawing consent also removes Google's cookies and Webrec's identifiers from your browser. Separately from cookies, we measure how the Service is used, and how our ads perform, with cookie-free signals to Google Analytics and Google Ads; these do not identify you and store nothing on your device. Webrec (session recording, see "Who we share data with") has no equivalent cookie-free mode: it only ever runs after you allow cookies, and never runs at all while your vault is unlocked, regardless of that choice.
The cookies you may see while using GearHub are:
- __session and __client_uat (set by Clerk, our sign-in provider, on gearhub.tech and clerk.gearhub.tech; lifetimes from your session up to about 1 year): keep you signed in and record whether you are signed in. Essential.
- __cf_bm (about 30 minutes) and _cfuvid (session), set on clerk.gearhub.tech by Cloudflare: bot protection and security for the sign-in service, so automated attacks can be told apart from real people. Essential.
- sidebar_state (gearhub.tech, 7 days): remembers whether you collapsed the sidebar. Only set if you change the sidebar, and only used to keep your choice.
- _ga and _ga_* (gearhub.tech, up to about 13 months), set by Google Analytics: help us understand which features get used. Only set with your consent, and removed if you withdraw it in Settings.
- _gcl_au (gearhub.tech, about 90 days), set by Google Ads: links an ad click to what happens afterwards, so we can tell which ads are worth running. Only set with your consent, and removed if you withdraw it in Settings.
- Webrec does not use cookies as such, but stores a session identifier in your browser's session storage and a device identifier in local storage, both sent to Webrec as part of session recording. Only set with your consent, and removed if you withdraw it in Settings.
- We also use your browser's local storage (which is not sent to our servers with requests) for device-level preferences: your theme, your cookie-consent choice itself, and your progress through the welcome tour.
4. How we use your data
We use your data to: provide and operate the Service (accounts, gear records, sharing, verification, QR/possession features); power stolen-gear alerts and recovery-case matching; secure the vault feature while preserving its zero-knowledge guarantees; prevent abuse and enforce rate limits; match your contacts to help you find friends (see Section 2); provide customer support; and enforce these Terms, including the minimum age requirement.
Automated suggestion features: importing a gear listing from a URL and identifying an item from a photo each send that content (the fetched page, or the photo) to a third-party processing provider (Anthropic, with OpenAI as a fallback) to generate the result — this is a distinct data flow from our own storage, and treat it as sharing that content with that provider for the purpose of generating the result. An identification photo is used only for that one request and is never written to our storage. Reading a serial number from a photo and spec suggestions don't involve a third party: the serial reader runs local text recognition on our own servers (the photo is, again, never stored), suggesting specs for a brand/model looks at other members' own entries for that exact model already in our database, and extracting specs from an item's own notes pattern-matches the notes text. Either way, nothing is written back to your record until you review and approve it; approved specs then become visible on the item's public Details card, even though the source notes themselves stay private.
Public images are screened automatically before publication, including a check for generated imagery under our no generative AI policy: this currently covers profile pictures, brand/manufacturer company logos, gear photos, platform posts, and Voice content. Screening sends the image to a third-party model provider for classification only; images that fail are refused or held for human review. Business-page logos (tech/retailer/studio/producer/promoter/agency pages) and job-post photos are not yet covered by this automated screening — we're working to close that gap; in the meantime they remain subject to manual removal if reported.
Platform emails: because most members don't check the app every day, we send an occasional email covering platform news and a personalised suggestion for getting more out of GearHub (for example, if you haven't registered any gear yet). These are on by default, the same way most of our other member communication is, but you can turn them off at any time in Settings or with the unsubscribe link in any such email. Turning them off never affects the transactional emails you get about your own gear (a recall, a recovery match, or a comp).
5. Who we share data with
We do not sell your personal data.
Law enforcement & legal disclosure: where a recovery case is escalated (see "Recovery & theft data" above), we compile the relevant claimant and theft-report details into a report to help recover stolen gear. Such a report is only ever provided to verified law enforcement, and before it is sent a GearHub administrator checks the police contact details supplied. Separately, accounts we have verified as belonging to serving officers can use in-app tools to check serial numbers against the public stolen register and the counterfeit registry, and to look up a recovery case by its police crime reference number. Every one of those checks is recorded in our audit log (who searched, and for what). We may also disclose data where we are legally required to, or where it is necessary to protect the rights, property, or safety of our users or others.
We share data with the following third-party processors, each engaged to help us run the Service:
- Clerk — authentication and identity (account credentials, session management, sign-in).
- Cloudflare — our web/API infrastructure runs on Cloudflare Workers, so Cloudflare sees the IP address of every request to the Service; Cloudflare R2 also stores encrypted vault attachment file bytes and, unencrypted, most other image/file uploads (profile pictures, business/company logos, gear photos, sighting-report evidence, grain prints, gig files, and audio).
- Neon — hosting of our production database.
- Anthropic — processing for the automated gear-listing import and photo-based item identification features (primary provider).
- OpenAI — fallback processing for the automated features above, and automated image screening/classification before public images are published.
- BigDataCloud — resolves a coordinate to a coarse, human-readable area (reverse geocoding) for shared/hometown locations and stolen-report coordinates.
- Open-Meteo — resolves a place name you type (e.g. a hometown or business location) to coordinates (forward geocoding).
- Google Analytics — usage analytics. Every visit sends Google a small measurement signal that works without cookies and does not identify you; analytics cookies, which make that measurement more accurate, are only set after you allow them (see "Cookies and similar technologies").
- Google Ads — conversion measurement for our own advertising (which ads led to a sign-up), on the same cookie-free-by-default, cookies-only-with-consent basis as Google Analytics above. Consenting also lets Google build remarketing audiences from your visit, which we may use to show GearHub ads elsewhere in future; declining or withdrawing consent stops this the same way it stops analytics.
- Webrec — session recording, heatmaps, and product-usage analytics, to help us understand how the Service is used and find rough edges. Unlike Google Analytics and Google Ads above, Webrec has no cookie-free mode: nothing is recorded until you allow cookies, and withdrawing consent stops it and removes its identifiers from your browser. If you're signed in, your recorded sessions are also linked to your account name and email, rather than staying anonymous, so we can review a specific report of a problem you've told us about. Form input values are masked by default, and recording is switched off entirely, on every page, for as long as your vault is unlocked, regardless of your cookie choice, so vault contents are never captured.
- GitHub — hosts our source code and CI/CD pipeline, which runs with production database access to deploy the Service.
- Apple Push Notification service (APNs) — delivering push notifications to the native iOS app.
- Expo Push Service — delivering push notifications to the Expo mobile app.
- Stripe — card payment processing for purchases made on the web.
- RevenueCat — management of subscriptions and in-app purchases and their entitlements across platforms.
- Apple — in-app purchase processing for purchases made in the iOS app. Payment card details are entered with Apple or Stripe and are never received or stored by us.
6. Lawful basis for processing
For each purpose we process your data for, UK GDPR requires us to have a lawful basis. Here is ours:
- Providing the Service itself (accounts, gear records, sharing, verification, QR/possession features, billing) — performance of our contract with you (Article 6(1)(b)).
- Stolen-gear alerts, recovery-case matching, and the public stolen register — our legitimate interests, and those of instrument owners generally, in deterring theft and recovering stolen property (Article 6(1)(f)), balanced against the rights of anyone a report or match concerns. Where this involves data about an alleged criminal offence, we additionally rely on the Data Protection Act 2018's Schedule 1 condition for preventing or detecting unlawful acts; see our Appropriate Policy Document for the fuller basis (available on request).
- Location sharing (current-location toggle) and optional analytics cookies — your consent (Article 6(1)(a)), which you can withdraw at any time.
- Contact discovery (finding friends from your contacts) — your consent (Article 6(1)(a)); off by default, and only active once you turn it on.
- Preventing abuse, enforcing rate limits, and content moderation — our legitimate interests in keeping the Service safe and usable (Article 6(1)(f)).
- Audit logging of admin/owner/enforcement actions — our legitimate interests in security and accountability (Article 6(1)(f)).
- Automated suggestion features and image screening (see "How we use your data") — our legitimate interests in offering useful tooling and keeping the Service free of prohibited content (Article 6(1)(f)), with the actual data sent kept to what those features need.
- Enforcing the minimum age requirement — our legal obligation and legitimate interest in only serving users old enough to use the Service (Article 6(1)(c)/(f)).
- Platform-news and "get involved" emails — our legitimate interests in keeping members informed about, and engaged with, a service they've already joined (Article 6(1)(f)), balanced by an account-level opt-out in Settings and an unsubscribe link on every email.
7. Information about people without accounts
Some data we hold is about people who have never created a GearHub account: a verified tech's own record of their off-platform clients, gig contacts and guest lists a band adds to their own gig sheet (a venue contact, crew, or the friend a band is staying with), household members and loan borrowers a user records for their own gear management, and the contact details a stolen-gear sighting reporter or theft reporter provides. This data is entered by our user for their own record-keeping or to report something to us; the person it describes has not signed up and has no GearHub account of their own.
For most of this data, contacting every such person individually would be disproportionate to the limited, private way it's used (Article 14(5)(b)) — it exists only within the entering user's own account and is not published or shared beyond what's needed for the specific feature it supports (for example, a gig's venue contact is shared with a linked promoter because they need it to run the show; a band's crew and accommodation contacts are not). If you are such a person and want to know what we hold about you, or want it removed, contact us at serious-stuff@gearhub.tech and we will handle your request even though you don't hold a GearHub account.
8. Internal (admin/owner) access
GearHub administrators and the app owner can access user data through internal moderation and support tooling — for example, to review reported content, resolve disputes, or provide support. This is a separate, internal access path from the third-party sharing described above, and internal actions of this kind are recorded in an audit log (see "Data we collect").
9. The vault: what it protects, and its limits
The vault is designed so that we cannot read its contents: your passphrase and recovery key are never sent to or stored by our servers in usable form, and file bytes are encrypted client-side before being uploaded. We only ever hold the pieces described in "Data we collect" above (salt, wrapped keys, a verifier, optional TOTP state, and encrypted attachment metadata).
The direct consequence of this design is that we cannot recover your vault contents for you. If you lose both your passphrase and your recovery key, that data is permanently unrecoverable — not just by us, but by anyone. TOTP, where enabled, is the only vault-related check we can perform server-side; it does not let us decrypt or verify the plaintext contents of your vault.
10. Data retention
We retain your account and gear data for as long as your account is active, and for a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce our agreements. You can request deletion of your account and associated data at any time (see "Your rights" below).
You can delete your account yourself at any time from Settings. Deletion removes your account, gear records, photos, documents, and bands only you are in; content that must keep functioning without you (for example reports you submitted) is anonymised rather than retained under your name. Cloud files are queued for removal immediately and deleted by an automated sweep.
Beyond that, we delete or anonymise the specific categories below automatically once they no longer serve a purpose, on a daily automated schedule:
- Stolen-gear sighting tips you dismiss as not useful — deleted 90 days after dismissal; any tip at all, regardless of status, is deleted after 24 months.
- Verification applications (tech, brand, retailer, and similar roles) — deleted 12 months after a decision is made. Applications awaiting a decision are kept until then.
- Push notification tokens — deleted after 180 days with no activity (for example, an app that's been uninstalled).
- In-app notifications — deleted after 18 months.
- Gear transfer requests to a specific person — deleted 12 months after they're accepted, declined, or cancelled.
- One-time gear transfer claim links (for in-person handoffs) — deleted 30 days after they're claimed, cancelled, or expire.
- Recovery cases (see "How we use your data" and "Lawful basis for processing") — the claimant's location snapshot is deleted 7 days after the case is resolved; the case record itself is deleted 24 months after resolution.
- Records of which platform-news/get-involved emails were sent to you (used only to avoid sending the same one twice) — deleted after 12 months.
- Theft reports and a gear item's public stolen status are kept for as long as the item record exists on GearHub, so the public stolen-gear register stays meaningful, as is audit logging of admin/owner/enforcement actions, kept indefinitely for accountability and security. Both are explained further in our Appropriate Policy Document (available on request).
11. Your rights (UK GDPR)
Subject to applicable law, you have the right to: access the personal data we hold about you; request correction of inaccurate data; request deletion of your data; request a portable export of your data; object to or restrict certain processing; and withdraw consent where processing is based on consent (for example, current-location sharing).
Some data is required to use the Service at all: without a sign-in identity, a username, and a date of birth (to enforce our minimum age), we cannot create or operate your account. Other features require your active consent before they turn on, such as current-location sharing and contact discovery; declining that consent simply leaves the feature off, with no other consequence to your account or your ability to use the rest of the Service.
We use one automated process that can affect what gets published: images are screened automatically before publication (see "How we use your data"). An image that fails is refused or held for a GearHub administrator to review, never rejected by the automated check alone with no human involved. We do not otherwise make decisions about your account based solely on automated processing.
To exercise any of these rights, contact us at serious-stuff@gearhub.tech. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) if you believe we have not handled your data properly.
12. Children's privacy and minimum age
The Service is not directed at, and we do not knowingly collect personal data from, anyone under 16. We collect date of birth at signup specifically to enforce this minimum age. If we become aware that we have collected personal data from someone under 16, we will take steps to delete that data and close the account. We do not offer a parental-consent pathway; the minimum age is a hard requirement rather than a feature we adapt for younger users.
13. Security
We use reasonable technical and organizational measures to protect your data, including encryption in transit, encrypted storage for vault attachments, rate limiting on sensitive endpoints, and audit logging of privileged actions. No system is perfectly secure, and the vault's zero-knowledge design specifically means that even we cannot help you recover lost vault credentials — see "The vault" above.
14. International transfers
Most of our third-party processors (listed in Section 5) are US-headquartered technology providers, including Clerk, Cloudflare, Neon, Anthropic, OpenAI, Google, GitHub, Apple, Expo, Stripe, and RevenueCat, so personal data is likely to be processed or stored in the United States as well as the UK/EU. Where a transfer to a country without a UK adequacy decision occurs, we rely on the safeguards UK data protection law requires — such as standard contractual clauses with the recipient — rather than transferring on our own authority alone.
15. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will take reasonable steps to notify active users (for example, in-app). The "last updated" date at the top of this page reflects the most recent revision.
16. Contact us
Questions about this Privacy Policy, or requests relating to your data, can be sent to serious-stuff@gearhub.tech, or by post to Kingstone Consultancy Ltd, No1 Parkside Court, Greenhough Road, Lichfield, Staffordshire, United Kingdom, WS13 7FE.