WorkGY — Privacy Policy
1. What we collect
| Category | Examples | Source |
|---|---|---|
| Account info | name, email, role (customer / worker), display name, bio | You |
| Location | task addresses, approximate device coordinate, service radius | You / device GPS |
| Worker details | categories, hourly rate, ratings, city | You |
| Marketplace activity | tasks you post, applications, bookings | You |
| Messages / chat | messages exchanged with your matched customer/worker, conversation metadata (participants, timestamps, last message) | You |
| Reviews | star rating, written comment, reviewer/reviewee link to the booking | You |
| Task media | photos and videos you attach to a task posting (compressed on your device before upload). Visible to all signed-in users browsing tasks — treat them as public within the app. May incidentally contain location detail (e.g. your home's interior); attach only what you're comfortable showing. | You |
| Payment metadata (customers) | Stripe customer id, payment intent ids, payment status, and the per-booking connection-fee amount/currency (the fixed fee you pay WorkGY to connect with your worker — the only payment WorkGY processes; the job payment is arranged directly between you and the worker, off-platform). No card data ever touches WorkGY — you enter it in Stripe's PaymentSheet and Stripe handles it under PCI-DSS. | You → Stripe |
| Credit balance & ledger (customers) | your in-app credit balance and a ledger of credit events (connection fees returned as credit after cancellations, credit redeemed against later fees), plus a review flag if you exceed the cancellation-credit cap — account data with no cash value, stored by WorkGY. | WorkGY (derived from your bookings) |
| Notification tokens | APNs/FCM push registration token, device platform ("ios"), token timestamps — stored under your account to deliver pushes; removed/rotated on reinstall | Your device |
| Identity confirmation (workers only) | Before a worker profile goes live, WorkGY asks the worker to show a government-issued photo ID (national ID, passport, or driver's licence) by email. The document is viewed and then deleted — WorkGY does not store, upload, or keep a copy of any identity document. All that is retained on the worker's record is the fact that identity was confirmed, the type of document shown, its last four characters, and the date. Customers never see any of it. | The worker |
| Support communications | what you write to support support@workgy.gy | You |
| Crash data | Firebase Crashlytics: stack traces, device model, OS version, app version, a Firebase installation id. No names/emails/content attached. | Your device |
| Analytics | Firebase Analytics (no-Ad-ID build — no IDFA, no AdSupport, no cross-app tracking): six high-level milestone events (sign_up_completed, task_created, application_submitted, booking_created, booking_completed, review_submitted) with no parameters — no message content, addresses, amounts, or identifiers beyond the Firebase app-instance id. The full event list lives in code (AnalyticsService.swift); anything not listed there is not logged. | Your device |
2. Why we collect it
- Run the marketplace (matching, bookings, chat, reviews).
- Process the connection-fee payment via Stripe (we share booking id + the fee amount; Stripe holds cards). WorkGY processes no other payments — workers pay and receive nothing through WorkGY, and we collect no worker identity/bank/payout data.
- Maintain your in-app credit balance and ledger (cancellation credits and redemptions).
- Send push and in-app notifications about your bookings, applications, messages, reviews, and payment status.
- Detect abuse and prevent fraud.
- Diagnose crashes (Crashlytics) and measure aggregate funnel health (Analytics) — never advertising or cross-app tracking.
- Comply with legal obligations (tax, law-enforcement requests).
3. Who we share with
- Other WorkGY users, but only what's needed to complete a booking: a customer sees their assigned worker's profile and messages; a worker sees the customer's task and messages. Task postings — including attached photos/videos — are visible to all signed-in users so workers can find and evaluate jobs.
- Official Partner coordinators (Terms §3b): when you book a worker whose profile is labelled “Managed by [Partner]”, that Partner’s coordinator(s) can read and send messages in the booking’s conversation and see the booking’s details — they are how the Partner arranges your job. This applies only to bookings with Partner-managed workers and is visible in the app before you pay the connection fee.
- Stripe, for payment processing. See Stripe's privacy policy.
- Firebase / Google Cloud, our backend infrastructure (data stored in Canada, processed in the United States — see §4; Google's standard data-processing terms apply).
- Apple, for push delivery via APNs (token only, no message bodies in delivery infra).
- Law enforcement, when compelled by a valid legal request.
We do not sell personal information to third parties.
4. Where we store it
Your data lives in two places, both Google Cloud:
- Account, booking, chat, and review data —
northamerica-northeast2(Toronto, Canada). - Files you upload — task photos and videos, profile photos, and CVs —
us-central1(Iowa, United States).
The Cloud Functions that process all of it also run in us-central1 (Iowa, United States). Your data may therefore be stored and processed in countries other than your own.
5. How long we keep it
- Account + worker profiles: while the account exists.
- Bookings + reviews: 7 years (tax / payment-audit / dispute window).
- Chat messages: deleted 90 days after the booking closes (completed or cancelled), by an automated daily job. Two exceptions, both to protect you: messages in a disputed booking are kept until the dispute is resolved — they are the evidence — and messages that are the subject of an open safety report are kept until moderation closes it.
- Identity documents (workers): not kept at all. The image is viewed once during approval and deleted immediately. The confirmation record (that ID was seen, its type, last four characters, and date) is kept for as long as the worker account exists, because it is what lets us show a worker was checked.
- Push tokens: rotated when the device reinstalls or signs out.
- Crash logs (Crashlytics): 90 days (Firebase default retention).
- Analytics events: 2 months — the shortest Google Analytics retention setting, chosen to match WorkGY's data-minimizing, no-tracking posture.
6. Your rights
- Access: request a copy of your data via privacy@workgy.gy.
- Correct: edit profile / worker fields in-app.
- Delete: open the app → Settings (gear icon) → Delete account. The action is irreversible and runs server-side via our
deleteUserAccountCloud Function. You can also email privacy@workgy.gy if you prefer.What gets deleted immediately:
- your user profile (
users/{uid}) and, if applicable, your worker profile (workers/{uid}); - your push notification tokens (
users/{uid}/fcmTokens); - your in-app notification inbox (
notificationsrows targeting your uid); - any tasks you posted that are still
open(no commitments made); - any pending applications you submitted;
- your Firebase Authentication record (frees the email for re-signup).
What gets anonymized (kept for the other party's history + legal/payment audit):
- past bookings you participated in — your uid is rewritten to a one-way hash (
deleted:<hash>), so the booking, money trail, and timestamps remain for tax + dispute compliance, but no one can re-identify you from them; - reviews you wrote or received — same hash; rating + comment preserved so the counter-party's rating average stays honest;
- tasks you posted that already moved past
open— anonymized so the assigned worker still sees the booking.
Retention of anonymized records is up to 7 years to satisfy payment-audit and tax obligations (Privacy §5). After that window, an audit row in
accountDeletions/{uid}is purged and is then deleted automatically. - your user profile (
- Object / restrict / port: GDPR / CCPA requests are honored — contact us.
- Withdraw push consent: iOS Settings → Notifications → WorkGY → Allow Notifications → off.
- Withdraw location consent: iOS Settings → Privacy → Location Services → WorkGY → Never.
7. Children
WorkGY is intended only for adults. You must be at least 18 years old to create an account or use the service (see Terms of Service §2) — WorkGY is a marketplace for paid, in-person work and is not directed to, or intended for, anyone under 18. We do not knowingly collect personal information from anyone under 18; if we learn we have, we delete it.
8. Security
We use TLS in transit, Firestore security rules for access control, and Stripe for PCI-DSS-compliant payment handling. No system is perfect; you are responsible for keeping your account credentials safe.
9. Changes
We will post any material change at this URL with a new effective date. Significant changes may trigger an in-app notice.
10. Contact
support@workgy.gy · 476 Republic Park, Peter's Hall, Guyana