Policy draft
Privacy policy
This document explains the directory’s minimal data boundary and the rules that must apply before launch.
Data we collect
A matching profile may contain country of residence, optional city, an 18+ age range, languages, devices, participation formats, employment status, voluntary consumer and professional attributes, available payout methods and notification preferences.
Why the data is needed
Profile fields are compared with known opportunity requirements. We do not receive answers from screeners or studies on provider websites.
Where and how long the profile is stored
The current profile is stored in a signed browser cookie and remains valid for up to 30 days. The signature prevents undetected changes but does not encrypt values. The profile is rejected after expiry.
Data rejected by the schema
We do not accept passport data, identity documents, card or bank account numbers, medical data, an exact address, political views, religion, ethnicity or sexual orientation. Payout readiness records availability only, without account details.
Retention and minimization
The profile cookie has a limited lifetime. Server-record retention will be approved before launch; unnecessary fields are not added, and account deletion must leave only anonymized statistics.
Your GDPR rights
You have rights to access and a copy, rectification, actual deletion, restriction or objection, portability, withdrawal of consent and a complaint to a supervisory authority. A request channel will be specified before launch.
Consent
Service notifications and marketing require separate dated consent. Declining optional messages must not block the basic directory.
Data controller and contacts
Data controller details will be specified before launch.
The address will be specified before launch.
The working email address will be specified before launch.