1. Who controls your data
The organisation operating RentHuman will be the controller for marketplace account and operational data. Its final legal identity and contact details will be inserted here before commercial launch. Google, Stripe, Wise and other providers may separately act as controllers for information they collect under their own notices.
2. Information we collect
Account and identity information
We process your name, email address, authentication-provider identifiers, session information, account roles, verification status and security events. Workers currently authenticate with Google. Posters may use Google or a verified password account when transactional email is enabled.
Worker profile and eligibility
Workers may provide country, city, languages, age range, gender category, social platforms, digital-work abilities, devices, availability and marketplace confirmations. Exact private profile answers are used for eligibility matching. Posters receive only a matching or non-matching result and safe campaign summaries, not a Worker's email or complete private profile.
Campaign and work information
We process public summaries, confidential instructions, targeting rules, invitations, reservations, submissions, correction and rejection reasons, appeal statements, moderation decisions, safety reports and audit events.
Proof files
Submitted images and videos are stored privately. Files may be quarantined for administrator safety review. A Poster can access approved proof only for its own campaign. Public APIs do not return private storage keys.
Payment and payout information
We process campaign funding amounts, provider transaction identifiers, ledger entries, Worker balances, payout requests and reconciliation results. For the reviewed Wise payout flow, Workers provide the email associated with their Wise account. Workers see a masked reference; authorised administrators can access the complete destination for verification and batch processing. RentHuman does not collect Wise passwords or online-banking credentials.
Technical information
Cloudflare and the application may process IP address, request time, user agent, approximate request geography, security signals, rate-limit keys, logs, traces and error information. Rate-limit keys are hashed before they reach the limiter.
3. Why we use information
We use personal information to:
- create and secure accounts and sessions;
- match eligible Workers to campaigns without exposing unnecessary profile details;
- operate reservations, proof review, approvals, appeals and payouts;
- prevent fraud, spam, prohibited campaigns and unsafe uploads;
- send transactional authentication and marketplace notices;
- maintain financial, moderation and security records;
- respond to support, access, export and account-closure requests;
- comply with legal, tax, sanctions and payment-provider obligations; and
- measure reliability and improve the service.
Depending on the person and jurisdiction, these activities rely on performing the marketplace contract, complying with legal duties, protecting legitimate interests in a secure marketplace, and consent where the law specifically requires it. The final jurisdiction-specific lawful-basis table will be approved with the controller details before launch.
4. When information is shared
Information is shared only where needed with:
- Cloudflare, for Worker hosting, D1 database storage, private R2 proof storage, security, rate limiting, logs and email delivery infrastructure;
- Google, when you choose Google authentication;
- Stripe, for card-based campaign funding and webhook settlement;
- Wise or a manual payment provider, for reviewed Worker payouts or bank-transfer reconciliation;
- professional advisers, auditors and service providers bound by confidentiality; and
- courts, regulators, law enforcement or other parties where legally required or necessary to protect rights and safety.
Workers and Posters receive only the information necessary for their shared campaign. Confidential instructions unlock only to the Worker holding the reservation. A Poster does not receive the Worker's login email, exact demographic answers or payout destination. Public visitors do not receive private proof, appeal evidence or administrator reasons.
We do not sell personal information or use it for third-party behavioural advertising.
5. International transfers
Service providers may process information outside your country. Before commercial launch, the operator will document the transfer locations and safeguards applicable to its establishment and users, such as adequacy decisions or approved contractual clauses where required.
6. Retention
We keep active account data while the account is used and for as long as necessary to operate unresolved work, payments, disputes and safety reviews.
An account-closure request first checks for open assignments, appeals, payouts, Worker balances, unsettled campaigns, funding reconciliation and proof objects. Eligible deletion jobs remove private proof and authentication, profile, payout-destination, invitation, notification and access data in bounded retry-safe stages.
Historical campaign, submission, appeal, payout, ledger and moderation records may retain a stable pseudonymous internal identifier where required for financial reconciliation, fraud prevention, legal claims or compliance. The exact production retention periods and approved retention-policy version must be published before launch.
7. Security
RentHuman uses encrypted HTTPS transport, signed and secure session cookies, server-side authorisation, role and ownership checks, restricted private-object access, content and authentication rate limits, signed Stripe webhooks, idempotent financial operations, private proof quarantine, audit records and separate development and production resources.
No service can guarantee absolute security. If a breach creates a legal notification obligation, affected people and authorities will be notified as required.
8. Cookies and local browser storage
Authentication uses cookies necessary to keep you signed in and protect account actions. The Worker profile editor may temporarily keep an unfinished form in session storage for up to 24 hours, scoped to an opaque account-derived value. It is removed after successful save or sign-out and is not used for advertising.
9. Your choices and rights
The account area allows you to update supported profile fields, export account information and request closure. Depending on your location, you may also have rights to access, correct, erase, restrict or object to processing, receive portable data, withdraw consent and complain to a data-protection authority.
Some requests cannot be completed immediately where information is needed for an open assignment, payment, dispute, safety investigation or legal retention duty. The account-closure workflow records the blockers and completes erasure after they are resolved.
10. Children
RentHuman is for adults aged 18 or older. We do not knowingly permit minors to create marketplace accounts or participate in tasks. Contact the privacy address once published if you believe a minor supplied personal information.
11. Changes and contact
Material changes receive a new Privacy Notice version and may require renewed acknowledgement before new marketplace activity. The final privacy email, controller postal address and relevant supervisory-authority information must be added here before public launch.