Wakazi — Privacy Policy
Last updated: [TODO: confirm — publish date]
Privacy contact: [TODO: privacy contact]
Wakazi ("Wakazi", "we") is a worldwide, location-based marketplace that connects customers who need work done with nearby skilled workers through mutual, swipe-based matching. This policy explains, in plain language, what we collect, why we collect it, and exactly who can see it.
1. What we collect
Account and sign-in
- Email address. Sign-in is passwordless: we send a one-time 6-digit code by email to verify your address. Your email address is stored on your account and is never shown to other users.
- Codes and transactional emails are delivered by our email provider, Resend.
Profile information
- Your role (customer or worker), your name (workers may use a display name), and your area details: county, town, estate.
- Workers additionally provide: occupation, skills, bio, years of experience, expected rate and rate type, travel radius, languages, and availability.
- Ratings and completed-job counts accumulated from platform activity.
Location
- Precise GPS location you provide for your profile and for each job you post, stored as a geographic point.
- We use it to compute distances and rank nearby jobs and workers for matching. How much of it other users can see is described in section 3.
Jobs
- Title, description, budget and payment type, category and skills, photos, schedule, urgency, and both an approximate and an exact location point.
Activity
- Swipes (likes, passes, saves), matches, and reviews (a 1–5 rating and comment, one review per participant per match).
- In-app notifications generated for you (new matches, messages, unlocks).
Messages
- Chat text and any photos you send, stored on our servers so both participants can read the conversation history.
Purchases
- When a customer unlocks a match, the payment is processed entirely by
Apple (App Store) or Google (Play Billing). No card or bank details
ever touch Wakazi. We store only: the store (Apple/Google), the store
transaction id, the product id (
match_unlock), the amount, the currency, and the resulting payment status. We need this to unlock the match and to make double charging impossible (each store transaction id can be redeemed exactly once).
Reports and moderation data
- When you file a report we store: who reported, which user or job was reported, the reason (for example scam, no-show, inappropriate behavior, or other), your details, and the report's status.
Push notifications
- A device push token, used only to deliver notifications to your device via Firebase Cloud Messaging (Google). [TODO: confirm — device-token storage in our database; the FCM delivery pipeline exists, but device-token registration is not yet implemented at the time of writing.]
Security and audit logs
- Records of account and payment events used for security, fraud prevention, and debugging.
2. How we use your information
- Create and secure your account via one-time email codes.
- Show you nearby jobs or workers and rank them by distance and other matching signals.
- Create a match when both sides like each other, and unlock chat, contact details, and exact location after the customer's purchase.
- Deliver in-app and push notifications about matches and messages.
- Keep the platform safe: investigate reports and prevent payment fraud. Purchase receipts are verified server-side with Apple/Google before any unlock, and the app itself is never trusted.
- Maintain security and reliability through audit logs.
We do not sell your personal data, and we do not use it for advertising profiles.
3. Location: who sees what
- Before a match is unlocked, no user ever sees your exact location.
- Worker cards shown to customers display only the worker's area (estate, town, county) and a location snapped to a grid of roughly 1 km — never the exact point.
- Job feeds show the job's approximate area. The exact job location is revealed to the matched worker only after the customer unlocks the match.
- These rules are enforced at the database level (row-level security and restricted views), not merely hidden in the app.
4. Phone numbers and contact details
- Phone numbers are hidden from other users until a match is unlocked.
- After an unlock, the two participants can see each other's contact details so they can arrange the work.
5. Payments
- All purchases are processed by Apple or Google under their own privacy policies; Wakazi never sees, processes, or stores your card data.
- Receipts are verified server-side (Apple App Store Server API / Google Play Developer API) before a match is unlocked. Failed or unverified purchases never unlock anything.
- Payment status is written only by our server-side verification function — never by the app.
- Refunds are handled through the store refund flows (Apple / Google).
6. Chat
- Messages are stored on our servers and are visible only to the two participants of an unlocked match, enforced by database row-level security.
- Messages are not end-to-end encrypted. We may review message content where needed to investigate a report or safety issue. [TODO: confirm — moderation review workflow]
7. Who we share data with
We share data only with:
- Other users, strictly limited by the visibility rules in sections 3, 4 and 6.
- Apple and Google, for payment processing; Google (Firebase Cloud Messaging) additionally for push-notification delivery.
- Our backend provider (Supabase), which hosts the database and server functions. [TODO: confirm — production hosting region]
- An email delivery provider (Resend), to deliver one-time sign-in codes and transactional emails (receipts, match alerts). [TODO: confirm — provider identity]
8. Data retention
- We keep your data while your account is active.
- Retention periods after account deletion for messages, reports, payment records, and logs: [TODO: confirm].
- Payment records (store transaction ids, amounts, currencies) are kept as needed for accounting and fraud prevention. [TODO: confirm — exact retention period]
9. Account deletion
- You can request deletion of your account and personal data at any time by emailing [TODO: privacy contact].
- Deleting your auth account cascades by design to your profile and related personal rows in our database. Some records — for example payment transactions and audit logs — may be retained where required for legal, accounting, or fraud-prevention purposes.
- Self-serve in-app account deletion: [TODO: confirm — not present in the app at the time of writing].
10. Security
- Sensitive fields (phone numbers, exact locations, messages) are readable only under the database row-level-security rules described in this policy.
- All traffic between the app and our backend uses encrypted connections. [TODO: confirm — production TLS configuration details]
11. Age requirement (18+)
Wakazi is for adults only. You must be 18 or older to create an account or use the service. We do not knowingly collect data from anyone under 18; if you believe a minor has an account, contact [TODO: privacy contact] and we will remove it.
12. International use
Wakazi operates worldwide. Your information may be processed in countries other than your own. [TODO: confirm — hosting regions and cross-border transfer safeguards]
13. Changes to this policy
We will update this policy as the product evolves and post the new version with a revised "last updated" date. Material changes will be flagged inside the app. [TODO: confirm — in-app change notification]
14. Contact
Privacy questions, data-access or deletion requests, and report follow-ups: [TODO: privacy contact]