Skip to content
Legal

Privacy policy

Last updated 08 September 2026 · what Taskvelo collects, why, and what you can do about it

The short version

  • · We collect what an escrowed marketplace needs — no more.
  • · We never sell your data and we do not run advertising trackers.
  • · Your seller profile and reviews are public; your wallet, messages and order files are not.
  • · One session cookie, strictly necessary, expires when you sign out.
  • · Ask for your data or its deletion at support@taskvelo.com.

1. Who we are

Taskvelo operates this marketplace and is the controller of the personal data described below. Questions about this policy, or requests to exercise your rights, should be sent to support@taskvelo.com.

We only collect what is needed to run an escrowed marketplace: enough to identify a member, deliver an order, move money and resolve a dispute.

2. Data we collect

You give us

  • Account details: name, username, email address, country, optional phone number, profile photo, biography and skills.
  • Credentials: a password, stored only as a bcrypt hash. We cannot read it and will never ask for it.
  • Content: gig titles, descriptions, images, packages, FAQs, requirement questions, messages, attachments, deliveries, reviews and dispute explanations.
  • Payments: the amounts, methods and payout destinations you enter. Card details are handled by the payment provider and never stored on our servers.

Collected automatically

  • Technical data: IP address, browser and device characteristics, pages requested, and the date and time of each request.
  • Session data: a strictly necessary session cookie, a CSRF token, and a session fingerprint used to detect hijacking.
  • Marketplace signals: gig views, order timestamps, delivery and completion times, and wallet movements.
  • Security logs: failed sign-in attempts, rate-limit hits, and administrator actions.

From third parties

  • Payment providers confirm whether a charge succeeded, and return a transaction identifier and the captured amount.
  • Mail providers report delivery status for transactional messages.

3. Why we use it

  • To create and operate your account and authenticate you securely.
  • To match clients with sellers, display gigs, and process orders through escrow.
  • To move money: record deposits, lock escrow, release payouts, take commission and process withdrawals.
  • To deliver notifications about orders, messages, offers, reviews and account security.
  • To mediate disputes using the conversation, the requirements and the delivered files.
  • To prevent fraud, abuse, spam and review manipulation, and to enforce our terms.
  • To meet legal, tax and accounting obligations, and to respond to lawful requests.
  • To improve the platform: aggregate statistics, performance measurement and debugging.

We rely on performance of a contract, our legitimate interests in operating a safe marketplace, legal obligation, and — for optional marketing — consent that you may withdraw at any time.

4. What is public

Selling on Taskvelo means part of your profile is visible to anyone:

  • Your display name, username, profile photo, country, biography and skills.
  • Your gigs, packages, prices, delivery times and gallery images.
  • Your rating, review count and the text of reviews left on your completed orders, plus your public responses.
  • Aggregate stats such as completed orders and active gigs.

Your email address, phone number, wallet balance, transaction ledger, order contents and messages are never public. Reviews show only your display name and country.

5. Sharing

We do not sell personal data. We share it only where necessary:

  • With the other party to an order: your name, username, avatar, country, and everything you write in messages, requirements and deliveries.
  • With payment processors to authorise and capture a charge, and with mail providers to send transactional email.
  • With hosting and infrastructure providers who store the data under contract on our behalf.
  • With an administrator mediating a dispute, who sees the relevant conversation, files and ledger entries.
  • Where the law compels us, or to protect the safety, rights or property of our members or the platform.
  • With a successor entity in the event of a merger or asset sale, subject to equivalent protections.

6. Cookies

We use one strictly necessary session cookie that keeps you signed in and protects forms from cross-site request forgery. It expires when you sign out or when your session times out, and it is marked secure and HTTP-only.

We do not run third-party advertising cookies or cross-site tracking. If we add analytics in future, this policy will be updated first and optional cookies will require your consent.

7. Retention

  • Account data is kept while your account is open.
  • Orders, deliveries and the transaction ledger are retained for the period required by tax and accounting law, typically six to ten years, because they are financial records.
  • Messages and attachments are retained while the account is open, then deleted unless they form part of an unresolved dispute or a legal hold.
  • Failed sign-in attempts and rate-limit records are deleted automatically after a short period.
  • Notifications are pruned automatically so only recent ones remain.

8. Security

  • Passwords are hashed with bcrypt and re-hashed automatically when the cost factor is increased.
  • All database access uses prepared statements, and every value echoed into a page is escaped to prevent cross-site scripting.
  • Sessions are regenerated on sign-in and sign-out, are fingerprinted to the browser, and expire after inactivity.
  • State-changing requests require a CSRF token compared in constant time.
  • Uploads are checked against a MIME allow-list and an extension deny-list, stored under random names outside the web-accessible path where possible, and served through an ownership check.
  • Security headers — content-type options, frame options, referrer policy and permissions policy — are sent on every response.

No system is impenetrable. If a breach affects your personal data and the law requires notification, we will tell you and the relevant authority without undue delay.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, port or object to the processing of your personal data, and to withdraw consent.

  • Access and correction: most of it is available to you directly in Account settings.
  • Deletion: ask us at support@taskvelo.com. We delete what we are not legally required to keep; financial records must be retained.
  • Portability: we can export your orders, ledger and messages in a machine-readable format.
  • Objection and restriction: tell us and we will stop the processing unless we have a compelling lawful reason to continue.
  • Complaint: you may complain to your local data protection authority. We would rather hear from you first.

10. Children

The platform is not for anyone under 18 (or the age of majority where they live). We do not knowingly collect data from children. If you believe a child has an account, tell us and we will close it.

11. International transfers

Your data may be processed and stored in countries other than your own, including where our hosting or payment providers operate. Where transfers require safeguards, we rely on standard contractual clauses or an equivalent mechanism.

12. Changes

We may update this policy as the platform changes. Material changes are announced on the site and, where we hold your email address, sent to you. The date at the top of this page always shows the current version.

Exercise a right or raise a concern

Email support@taskvelo.com and we will acknowledge your request within one business day.