Legal

Privacy Policy

Effective 16 July 2026 · Version 1.5

How we collect, use, and protect your personal data when you use Localee.

This policy explains how Localee Limited ("Localee", "we", "us") collects, uses, stores, and shares personal data when you use the Localee platform. It is incorporated by reference into our Terms of Service and applies to all users — customers and service providers alike.

We process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Irish Data Protection Acts 1988–2018, and the ePrivacy Regulations (S.I. 336/2011).


Contents

  1. Who we are
  2. Scope and our roles under GDPR
  3. What personal data we collect
  4. How we use it, and our legal bases
  5. Who we share data with
  6. International transfers
  7. How long we keep data
  8. Your rights
  9. How we keep data safe
  10. Cookies and similar technologies
  11. Automated decisions and profiling
  12. Notes for customers and providers
  13. Changes to this policy
  14. Contact

1. Who we are

Localee Limited is a private company limited by shares, registered in Ireland (CRO No. 805431; registered office: 6 Hunters Hill, Hunters Wood, Dublin 24, Ireland). We are the data controller for the personal data described in this policy, except where stated otherwise.

For privacy queries and to exercise your rights under GDPR, contact us at privacy@localee.ie. For other queries, use info.support@localee.ie.

We have not appointed a Data Protection Officer. Our core activities do not involve large-scale systematic monitoring or large-scale processing of special-category data, so Article 37 GDPR does not require us to. Privacy questions are handled by Localee's designated privacy contact at the email above.

2. Scope and our roles under GDPR

This policy applies to use of the Localee platform in Ireland. We operate only in Ireland.

Personal data flowing through the platform falls into one of three controllership tiers, mirroring §14.2 of our Terms of Service:

Localee as controller. For account data, payment-authorisation data, communications conducted through the platform, uploaded evidence, search and usage analytics, platform telemetry, and verification data submitted to us directly.

Independent controllers. Service providers and customers each act as independent controllers for personal data they exchange directly in connection with a booking — for example, gate codes shared with a cleaner, photographs taken at a service location, vehicle registrations supplied to a detailer, or information about a household, occupants, or premises that a provider needs in order to perform the service. Each party is independently responsible for GDPR compliance over that data.

Localee as processor. Where a service provider asks us to process customer data on its behalf — for example, during dispute escalation, when we handle customer evidence on the provider's instructions — we act as a data processor. A separate Data Processing Agreement governs that processing.

3. What personal data we collect

3.1 Account data

Name, email, phone number, hashed password, profile photo, login activity, and device identifiers. Collected from both customers and service providers.

3.2 Identity and verification data (providers only)

Legal business name, trading name, CRO or business-registration number, Tax Reference Number, PPSN (sole traders only, for tax reporting under DAC7), licence and insurance certificates, photographic ID, proof of address, and any other documentation submitted to satisfy verification under §§3.2, 3.3, and 18.3 of the Terms.

We collect this data to meet our trader-traceability obligation under Article 30 of the Digital Services Act, our DAC7 tax-reporting obligation, and our own safety, security, and trust checks — not to perform payment KYC or anti-money-laundering screening, which is carried out by Stripe as an independent controller (§5.2). We apply data minimisation: we do not duplicate Stripe's identity checks where we can rely on Stripe's verification status, and we do not keep raw identity documents (photographic ID, proof of address) any longer than we need to complete and evidence the check — see the retention table in §7.

3.3 Payment data

Billing name and address, payment-method type, last-four digits of card, bank account details for payouts (providers only), and tokens issued by our payment processor. Full card numbers, CVCs, and bank credentials are processed and stored solely by Stripe Payments Europe Limited — Localee never receives or stores them.

3.4 Booking data

Service-card content (services offered, pricing, availability), booking history, dates and times, service or pickup locations, booking amounts, ratings, reviews, and dispute history.

3.5 Communications

Messages, voice notes, and call records exchanged through the platform, evidence uploads (photographs, documents), and notes added to a booking.

3.6 Usage and device data

IP address, browser type, operating system, referring URL, pages viewed, features used, session duration, crash reports, and similar identifiers stored in your browser. We do not currently use analytics cookies — see §10.

3.7 Inferred data

Service preferences, repeat-booking patterns, geographic search clusters, and fraud-risk signals derived from the data above. We do not profile in a way that produces legal or similarly significant effects on you — see §11.

3.8 Special categories

We do not seek special-category data within the meaning of Article 9 GDPR (health, religion, sexual orientation, biometrics, and so on). The nature of some services may incidentally surface special-category data — a customer disclosing a health condition to a personal trainer or carer, or a provider photographing a service location that captures medical items. Where this happens, we process the data only to the extent necessary for the booking. The legal basis is your explicit consent or, where applicable, establishment, exercise, or defence of legal claims (Article 9(2)(a) and (f)).

3.9 Children

The platform is not directed at people under 18 and we do not knowingly collect personal data from minors. Providers offering services to or involving minors — childcare, tutoring, paediatric services — process minor-related personal data as independent controllers under §2, subject to their own legal obligations including those under the Children First Act 2015 where applicable.

We match every processing purpose to a lawful basis under Article 6 GDPR (and Article 9 where special categories are involved).

Purpose Data used Legal basis
Create and operate your account Account; verification Contract (Article 6(1)(b))
Facilitate bookings, payments, and payouts Booking; payment; communications Contract (Article 6(1)(b))
Verify provider identity and traceability under DSA Article 30 Verification (business identity, ID copy) Legal obligation (Article 6(1)(c)) where Article 30 applies to us; otherwise legitimate interests (Article 6(1)(f)) in trader traceability, applying Article 30 standards voluntarily
Vet providers for safety, security, and trust (insurance, licences, reliability) Verification Legitimate interests (Article 6(1)(f))
Run our dispute resolution procedure Booking; communications; evidence Contract (Article 6(1)(b)) + legitimate interests (Article 6(1)(f))
Prevent fraud, abuse, and unauthorised access Account; payment; usage; inferred Legitimate interests (Article 6(1)(f)) + legal obligation (Article 6(1)(c))
Report providers to Revenue under DAC7 (Directive (EU) 2021/514) Provider name, address, TRN/PPSN, booking totals Legal obligation (Article 6(1)(c))
Send transactional and critical financial alerts Account; booking Contract (Article 6(1)(b))
Send marketing and product news Account Consent (Article 6(1)(a)) — withdrawable any time
Improve the platform Usage; inferred (pseudonymised where practicable) Legitimate interests (Article 6(1)(f))
Meet other legal obligations (court orders, accounting law, regulatory requests) Any Legal obligation (Article 6(1)(c))
Establish, exercise, or defend legal claims Any Legitimate interests (Article 6(1)(f)); for special categories, Article 9(2)(f)

Identity KYC and anti-money-laundering checks are carried out by Stripe as an independent controller under its own regulated status (§5.2). Localee is not a regulated financial institution and does not perform separate AML screening. Our own verification is limited to what DSA Article 30 traceability, DAC7 reporting, and safety vetting require, and is held on the retention clocks in §7. While Localee qualifies as a micro or small enterprise, DSA Article 30 may not yet bind us directly (Article 29 DSA); in that case we apply Article 30's traceability standards voluntarily, on the basis of our legitimate interests in a safe, traceable marketplace, and the legal-obligation basis takes over when Article 30 applies to us.

Critical financial alerts override marketing preferences. Notifications such as payment-failure alerts, deposit-authorisation failures, balance-payment retry reminders, and booking cancellations triggered by payment failure are sent whether or not you have turned off informational and marketing notifications. They contain information you need to act on, and they are required for the performance of our contract with you. The notifications setting controls marketing communications only.

5. Who we share data with

We share personal data only to the extent necessary for the purposes set out in §4, and only with the categories of recipient listed below.

  • Service providers and customers — the counterparty to a booking receives the data needed to perform or receive the service.
  • Professional advisors — lawyers, accountants, auditors, tax advisors, insurers, all bound by confidentiality.
  • Public authorities and regulators — where required by law (the Revenue Commissioners, An Garda Síochána, the Data Protection Commission, the courts).
  • Successors — in the event of a corporate transaction (merger, acquisition, reorganisation, insolvency), data may be transferred to the successor entity subject to this policy.

5.1 Named subprocessors

We work with the trusted subprocessors below. Each is bound by an Article 28 GDPR data-processing agreement and processes personal data only on our documented instructions, except where the subprocessor is itself an independent controller for the relevant data (Stripe for KYC and payment-card data — see §5.2).

Subprocessor Role Data processed
Stripe Payments Europe Limited Payment processing · Stripe Connect provider payouts · KYC and identity verification for providers Payment-card data, payout bank details, provider identity-verification data
Firebase / Google Authentication and identity management for end-user accounts Email, hashed password, sign-in metadata, auth tokens
Supabase Primary database · file storage (including data-export archives and uploaded photos) · platform infrastructure All persisted Account, Booking, Communications, and evidence data
Resend Transactional and broadcast email delivery Email address, recipient name, message content
Sentry Application error monitoring and performance observability Diagnostic information — stack traces, request metadata, limited user identifiers such as user ID — transmitted only when an error occurs. Used solely to debug and improve the platform. Sentry does not use cookies or local storage; it transmits diagnostics directly.
Vercel Frontend hosting and edge delivery Request metadata, IP address
Railway Backend service hosting Request metadata, IP address

The table above is the live list of all subprocessors — vendor name, role, and data processed. We update it with at least 14 days' notice of additions.

5.2 Stripe as independent controller

For the data Stripe collects directly through its Stripe Connect onboarding — legal name, date of birth, residential address, government-issued ID, bank account details — Stripe is the data controller, not Localee's processor. For that KYC data we only see a verification status and a tokenised reference; we do not receive or store the underlying identity documents Stripe collects. Separately, we collect a limited set of verification documents directly from providers for the purposes in §4 (DSA Article 30 traceability, DAC7 reporting, and safety vetting); those documents are held by Localee under the retention rules in §7, and we minimise them by relying on Stripe's verification status where we can. Stripe's own privacy policy applies to the data Stripe collects and is published at https://stripe.com/privacy.

5.3 No sale of personal data

We do not sell personal data and do not share personal data with third parties for cross-context behavioural advertising.

6. International transfers

We prefer to process personal data within the European Economic Area. Most of our infrastructure and subprocessors operate from EEA jurisdictions.

Some subprocessors are headquartered outside the EEA — notably in the United States. Where personal data is transferred outside the EEA, we rely on one of the GDPR-recognised transfer mechanisms:

  • an adequacy decision by the European Commission under Article 45 GDPR, including the EU–US Data Privacy Framework where the recipient is certified;
  • Standard Contractual Clauses adopted by the European Commission under Article 46(2), supplemented by additional technical and organisational measures (encryption-in-transit and at-rest, pseudonymisation, access controls) where a transfer-impact assessment requires; or
  • your explicit, informed consent under Article 49(1)(a), for occasional transfers not covered by the above.

You can request a copy of the safeguards applied to a specific transfer by emailing privacy@localee.ie. We may redact commercially sensitive content.

7. How long we keep data

We retain personal data only for as long as we need it for the purposes in §4, or as required by law.

Category Retention
Account data Lifetime of the account, plus the period in the row below
Booking, payment, communications, evidence 6 years from the date of the final booking — to meet Irish tax law and the limitation period under the Statute of Limitations 1957
Completion photos uploaded by providers 365 days from the booking completion date — kept as evidence in any dispute, then deleted
Provider business identity + tax IDs (CRO/registration number, TRN/VAT, PPSN) Lifetime of the account, plus 6 years — for DAC7 and Irish tax/limitation periods
Photographic ID copy Duration of the account, plus up to 6 months after closure (the DSA Article 30 traceability window), then deleted — or verify-then-delete where identity is confirmed via Stripe
Proof of address Deleted promptly after the verification check is completed (within 30 days); we prefer to rely on Stripe's verification rather than retain a copy
Licence + insurance certificates While relied upon, plus 6 years after the last booking to which the cover or licence applied
Verification outcome + audit trail (result, method, date, reviewer, Stripe reference) Lifetime of the account, plus 6 years — as evidence the checks were performed
Usage and device data 13 months in identifiable form, then aggregated or deleted
Marketing consent records Lifetime of the account, plus 2 years
Active disputes or claims For as long as the matter remains live, plus 6 years from final resolution
Data-export archives (§8) 7 days from generation; deleted thereafter
Audit logs 2 years from the audited event

When you close your account, we delete or anonymise your account data and usage data within 90 days, and we delete raw identity documents (photographic ID, proof of address) within the short windows in the table above rather than holding them for the full statutory period. We retain booking, payment, communications, tax, and verification-outcome records for the statutory periods stated above. Where law, a regulatory order, or active legal process requires longer retention, we will retain accordingly.

8. Your rights

You have the following rights over the personal data we hold about you.

Right What it means GDPR Article
Access Confirm whether we process your data and receive a copy 15
Rectification Correct inaccurate or incomplete data 16
Erasure Ask us to delete your data, where one of the grounds applies 17
Restriction Ask us to restrict processing in the circumstances described 18
Portability Receive your data in a structured, machine-readable format 20
Objection Object to processing based on legitimate interests, or to direct marketing 21
Withdraw consent Withdraw consent at any time where consent is the basis 7(3)

8.1 Self-service: download your data

For access and portability, the fastest route is the self-service flow inside Localee. Sign in and go to Settings → Privacy & Data → Download your data. We prepare your export asynchronously and email you when it's ready. The export is delivered as a ZIP archive from your dashboard (not as an email attachment) and stays available for 7 days.

The archive contains a JSON file for each entity we hold about you — profile, bookings, payments, receipts, reviews, messages, packages, subscriptions, disputes, notifications, audit log — plus a bookings.csv for spreadsheet use, a manifest.json with SHA-256 hashes for integrity verification, and a README.txt explaining the contents.

Customers can export customer-scope data. Provider account owners can additionally export business-scope data, with team-member personal contact data scrubbed — each team member uses their own customer-scope export to retrieve their own data.

You can submit one active export per scope every 24 hours. The request is gated by a recent-reauthentication check (see §9), to mitigate stolen-token data exfiltration.

8.2 By email

For rectification, erasure, restriction, objection, or withdrawing consent, email privacy@localee.ie. We may need to verify your identity before responding. We will respond within one month of receipt; for complex requests we may extend this by a further two months and will tell you why.

8.3 Cost

Requests are free unless manifestly unfounded or excessive — in which case we may charge a reasonable fee or refuse, with reasons.

8.4 Complaining to the DPC

You have the right to complain to the Data Protection Commission of Ireland — 21 Fitzwilliam Square South, Dublin 2, D02 RD28; https://www.dataprotection.ie; info@dataprotection.ie. We would appreciate the chance to address your concerns first.

9. How we keep data safe

We maintain technical and organisational measures appropriate to the risk, including:

  • TLS encryption for all platform traffic and at-rest encryption for stored personal data
  • Role-based access controls and the principle of least privilege for Localee staff
  • Two-factor authentication on administrative systems
  • Dependency scanning and runtime error monitoring (via Sentry); third-party penetration testing planned from Year 1 of operations
  • Secure software-development practices (code review, secret-handling policy)
  • Supplier due diligence and contractual data-protection obligations (Article 28 GDPR)
  • Incident response procedures aligned with Articles 33–34 breach-notification obligations
  • A reauth-fresh requirement on sensitive account actions: deleting your account or downloading your data requires your identity to have been re-verified by password within the last 5 minutes, mitigating data-exfiltration attacks based on stolen session tokens
  • Session revocation on password change and account deletion, closing the legacy-session window
  • Signed, short-lived download URLs — sensitive exports use 5-minute signed links minted in the dashboard, so a forwarded email cannot expose the export

If a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission within 72 hours, and you directly without undue delay where the risk is high.

You can help by keeping your login credentials confidential and reporting any suspected unauthorised access to info.support@localee.ie.

10. Cookies and similar technologies

We use a small set of strictly-necessary technologies to operate the platform — primarily a localStorage token to keep you signed in, a small number of first-party items including a UI-preference cookie (sidebar:state), plus Stripe's fraud-prevention cookies on payment pages. We do not use analytics or advertising cookies at launch.

Full details — categories, specific items, retention, third-party providers, and how to manage your preferences — are in our Cookie Policy.

11. Automated decisions and profiling

We do not make decisions producing legal or similarly significant effects on you that are based solely on automated processing within the meaning of Article 22 GDPR.

We do use automated signals to triage potentially fraudulent transactions, abusive accounts, or content that may breach our Terms. Any consequential action — account suspension, payment hold, content removal — is reviewed by a human Localee operator before it is enforced. You can appeal a moderation decision under §11.6 of the Terms or §18.5 (DSA internal complaint handling).

12. Notes for customers and providers

12.1 For customers

Service providers see your name, profile photo, service-location address (where relevant to the booking), the contact details needed to perform the service, your booking history with that provider, and any messages or evidence you upload. Providers act as independent controllers for the data they receive from you (§2) and have their own privacy obligations.

12.2 For providers

Customers see your trading name, profile, service cards, ratings, and reviews, and any data you publish on your provider page. We may share your business identity — CRO number, address, contact details — with public authorities under Article 30 DSA. Under DAC7, we report your booking volumes and identifying data to the Revenue Commissioners.

12.3 Reviews

Reviews you publish are visible to other users and may be visible to non-users on the public web. We do not remove honest reviews on request; see §§4.5 and 10 of the Terms for the limited grounds on which we will.

13. Changes to this policy

We will update this policy whenever our practices change.

  • Non-material changes (typographical, formatting, clarifications) take effect on publication.
  • Material changes — changes to how we use your data, the legal bases we rely on, the categories of recipient, or your rights — take effect 30 days after we notify you by email and in-app.

Previous versions are archived and available on request at privacy@localee.ie.

14. Contact

Localee Limited Registered office: 6 Hunters Hill, Hunters Wood, Dublin 24, Ireland Company registration: 805431