This policy explains how Localee Limited ("Localee", "we", "us") collects, uses, stores, and shares personal data when you use the Localee platform. It is incorporated by reference into our Terms of Service and applies to all users — customers and service providers alike.
We process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Irish Data Protection Acts 1988–2018, and the ePrivacy Regulations (S.I. 336/2011).
Contents
- Who we are
- Scope and our roles under GDPR
- What personal data we collect
- How we use it, and our legal bases
- Who we share data with
- International transfers
- How long we keep data
- Your rights
- How we keep data safe
- Cookies and similar technologies
- Automated decisions and profiling
- Notes for customers and providers
- Changes to this policy
- Contact
1. Who we are
Localee Limited is a private company limited by shares, registered in Ireland (CRO No. 805431; registered office: 6 Hunters Hill, Hunters Wood, Dublin 24, Ireland). We are the data controller for the personal data described in this policy, except where stated otherwise.
For privacy queries and to exercise your rights under GDPR, contact us at privacy@localee.ie. For other queries, use info.support@localee.ie.
We have not appointed a Data Protection Officer. Our core activities do not involve large-scale systematic monitoring or large-scale processing of special-category data, so Article 37 GDPR does not require us to. Privacy questions are handled by Localee's designated privacy contact at the email above.
2. Scope and our roles under GDPR
This policy applies to use of the Localee platform in Ireland. We operate only in Ireland.
Personal data flowing through the platform falls into one of three controllership tiers, mirroring §14.2 of our Terms of Service:
Localee as controller. For account data, payment-authorisation data, communications conducted through the platform, uploaded evidence, search and usage analytics, platform telemetry, and verification data submitted to us directly.
Independent controllers. Service providers and customers each act as independent controllers for personal data they exchange directly in connection with a booking — for example, gate codes shared with a cleaner, photographs taken at a service location, vehicle registrations supplied to a detailer, or information about a household, occupants, or premises that a provider needs in order to perform the service. Each party is independently responsible for GDPR compliance over that data.
Localee as processor. Where a service provider asks us to process customer data on its behalf — for example, during dispute escalation, when we handle customer evidence on the provider's instructions — we act as a data processor. A separate Data Processing Agreement governs that processing.
3. What personal data we collect
3.1 Account data
Name, email, phone number, hashed password, profile photo, login activity, and device identifiers. Collected from both customers and service providers.
3.2 Identity and verification data (providers only)
Legal business name, trading name, CRO or business-registration number, Tax Reference Number, PPSN (sole traders only, for tax reporting under DAC7), licence and insurance certificates, photographic ID, proof of address, and any other documentation submitted to satisfy verification under §§3.2, 3.3, and 18.3 of the Terms.
We collect this data to meet our trader-traceability obligation under Article 30 of the Digital Services Act, our DAC7 tax-reporting obligation, and our own safety, security, and trust checks — not to perform payment KYC or anti-money-laundering screening, which is carried out by Stripe as an independent controller (§5.2). We apply data minimisation: we do not duplicate Stripe's identity checks where we can rely on Stripe's verification status, and we do not keep raw identity documents (photographic ID, proof of address) any longer than we need to complete and evidence the check — see the retention table in §7.
3.3 Payment data
Billing name and address, payment-method type, last-four digits of card, bank account details for payouts (providers only), and tokens issued by our payment processor. Full card numbers, CVCs, and bank credentials are processed and stored solely by Stripe Payments Europe Limited — Localee never receives or stores them.
3.4 Booking data
Service-card content (services offered, pricing, availability), booking history, dates and times, service or pickup locations, booking amounts, ratings, reviews, and dispute history.
3.5 Communications
Messages, voice notes, and call records exchanged through the platform, evidence uploads (photographs, documents), and notes added to a booking.
3.6 Usage and device data
IP address, browser type, operating system, referring URL, pages viewed, features used, session duration, crash reports, and similar identifiers stored in your browser. We do not currently use analytics cookies — see §10.
3.7 Inferred data
Service preferences, repeat-booking patterns, geographic search clusters, and fraud-risk signals derived from the data above. We do not profile in a way that produces legal or similarly significant effects on you — see §11.
3.8 Special categories
We do not seek special-category data within the meaning of Article 9 GDPR (health, religion, sexual orientation, biometrics, and so on). The nature of some services may incidentally surface special-category data — a customer disclosing a health condition to a personal trainer or carer, or a provider photographing a service location that captures medical items. Where this happens, we process the data only to the extent necessary for the booking. The legal basis is your explicit consent or, where applicable, establishment, exercise, or defence of legal claims (Article 9(2)(a) and (f)).
3.9 Children
The platform is not directed at people under 18 and we do not knowingly collect personal data from minors. Providers offering services to or involving minors — childcare, tutoring, paediatric services — process minor-related personal data as independent controllers under §2, subject to their own legal obligations including those under the Children First Act 2015 where applicable.
4. How we use it, and our legal bases
We match every processing purpose to a lawful basis under Article 6 GDPR (and Article 9 where special categories are involved).
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and operate your account | Account; verification | Contract (Article 6(1)(b)) |
| Facilitate bookings, payments, and payouts | Booking; payment; communications | Contract (Article 6(1)(b)) |
| Verify provider identity and traceability under DSA Article 30 | Verification (business identity, ID copy) | Legal obligation (Article 6(1)(c)) where Article 30 applies to us; otherwise legitimate interests (Article 6(1)(f)) in trader traceability, applying Article 30 standards voluntarily |
| Vet providers for safety, security, and trust (insurance, licences, reliability) | Verification | Legitimate interests (Article 6(1)(f)) |
| Run our dispute resolution procedure | Booking; communications; evidence | Contract (Article 6(1)(b)) + legitimate interests (Article 6(1)(f)) |
| Prevent fraud, abuse, and unauthorised access | Account; payment; usage; inferred | Legitimate interests (Article 6(1)(f)) + legal obligation (Article 6(1)(c)) |
| Report providers to Revenue under DAC7 (Directive (EU) 2021/514) | Provider name, address, TRN/PPSN, booking totals | Legal obligation (Article 6(1)(c)) |
| Send transactional and critical financial alerts | Account; booking | Contract (Article 6(1)(b)) |
| Send marketing and product news | Account | Consent (Article 6(1)(a)) — withdrawable any time |
| Improve the platform | Usage; inferred (pseudonymised where practicable) | Legitimate interests (Article 6(1)(f)) |
| Meet other legal obligations (court orders, accounting law, regulatory requests) | Any | Legal obligation (Article 6(1)(c)) |
| Establish, exercise, or defend legal claims | Any | Legitimate interests (Article 6(1)(f)); for special categories, Article 9(2)(f) |
Identity KYC and anti-money-laundering checks are carried out by Stripe as an independent controller under its own regulated status (§5.2). Localee is not a regulated financial institution and does not perform separate AML screening. Our own verification is limited to what DSA Article 30 traceability, DAC7 reporting, and safety vetting require, and is held on the retention clocks in §7. While Localee qualifies as a micro or small enterprise, DSA Article 30 may not yet bind us directly (Article 29 DSA); in that case we apply Article 30's traceability standards voluntarily, on the basis of our legitimate interests in a safe, traceable marketplace, and the legal-obligation basis takes over when Article 30 applies to us.
Critical financial alerts override marketing preferences. Notifications such as payment-failure alerts, deposit-authorisation failures, balance-payment retry reminders, and booking cancellations triggered by payment failure are sent whether or not you have turned off informational and marketing notifications. They contain information you need to act on, and they are required for the performance of our contract with you. The notifications setting controls marketing communications only.
5. Who we share data with
We share personal data only to the extent necessary for the purposes set out in §4, and only with the categories of recipient listed below.
- Service providers and customers — the counterparty to a booking receives the data needed to perform or receive the service.
- Professional advisors — lawyers, accountants, auditors, tax advisors, insurers, all bound by confidentiality.
- Public authorities and regulators — where required by law (the Revenue Commissioners, An Garda Síochána, the Data Protection Commission, the courts).
- Successors — in the event of a corporate transaction (merger, acquisition, reorganisation, insolvency), data may be transferred to the successor entity subject to this policy.
5.1 Named subprocessors
We work with the trusted subprocessors below. Each is bound by an Article 28 GDPR data-processing agreement and processes personal data only on our documented instructions, except where the subprocessor is itself an independent controller for the relevant data (Stripe for KYC and payment-card data — see §5.2).
| Subprocessor | Role | Data processed |
|---|---|---|
| Stripe Payments Europe Limited | Payment processing · Stripe Connect provider payouts · KYC and identity verification for providers | Payment-card data, payout bank details, provider identity-verification data |
| Firebase / Google | Authentication and identity management for end-user accounts | Email, hashed password, sign-in metadata, auth tokens |
| Supabase | Primary database · file storage (including data-export archives and uploaded photos) · platform infrastructure | All persisted Account, Booking, Communications, and evidence data |
| Resend | Transactional and broadcast email delivery | Email address, recipient name, message content |
| Sentry | Application error monitoring and performance observability | Diagnostic information — stack traces, request metadata, limited user identifiers such as user ID — transmitted only when an error occurs. Used solely to debug and improve the platform. Sentry does not use cookies or local storage; it transmits diagnostics directly. |
| Vercel | Frontend hosting and edge delivery | Request metadata, IP address |
| Railway | Backend service hosting | Request metadata, IP address |
The table above is the live list of all subprocessors — vendor name, role, and data processed. We update it with at least 14 days' notice of additions.
5.2 Stripe as independent controller
For the data Stripe collects directly through its Stripe Connect onboarding — legal name, date of birth, residential address, government-issued ID, bank account details — Stripe is the data controller, not Localee's processor. For that KYC data we only see a verification status and a tokenised reference; we do not receive or store the underlying identity documents Stripe collects. Separately, we collect a limited set of verification documents directly from providers for the purposes in §4 (DSA Article 30 traceability, DAC7 reporting, and safety vetting); those documents are held by Localee under the retention rules in §7, and we minimise them by relying on Stripe's verification status where we can. Stripe's own privacy policy applies to the data Stripe collects and is published at https://stripe.com/privacy.
5.3 No sale of personal data
We do not sell personal data and do not share personal data with third parties for cross-context behavioural advertising.
6. International transfers
We prefer to process personal data within the European Economic Area. Most of our infrastructure and subprocessors operate from EEA jurisdictions.
Some subprocessors are headquartered outside the EEA — notably in the United States. Where personal data is transferred outside the EEA, we rely on one of the GDPR-recognised transfer mechanisms:
- an adequacy decision by the European Commission under Article 45 GDPR, including the EU–US Data Privacy Framework where the recipient is certified;
- Standard Contractual Clauses adopted by the European Commission under Article 46(2), supplemented by additional technical and organisational measures (encryption-in-transit and at-rest, pseudonymisation, access controls) where a transfer-impact assessment requires; or
- your explicit, informed consent under Article 49(1)(a), for occasional transfers not covered by the above.
You can request a copy of the safeguards applied to a specific transfer by emailing privacy@localee.ie. We may redact commercially sensitive content.
7. How long we keep data
We retain personal data only for as long as we need it for the purposes in §4, or as required by law.
| Category | Retention |
|---|---|
| Account data | Lifetime of the account, plus the period in the row below |
| Booking, payment, communications, evidence | 6 years from the date of the final booking — to meet Irish tax law and the limitation period under the Statute of Limitations 1957 |
| Completion photos uploaded by providers | 365 days from the booking completion date — kept as evidence in any dispute, then deleted |
| Provider business identity + tax IDs (CRO/registration number, TRN/VAT, PPSN) | Lifetime of the account, plus 6 years — for DAC7 and Irish tax/limitation periods |
| Photographic ID copy | Duration of the account, plus up to 6 months after closure (the DSA Article 30 traceability window), then deleted — or verify-then-delete where identity is confirmed via Stripe |
| Proof of address | Deleted promptly after the verification check is completed (within 30 days); we prefer to rely on Stripe's verification rather than retain a copy |
| Licence + insurance certificates | While relied upon, plus 6 years after the last booking to which the cover or licence applied |
| Verification outcome + audit trail (result, method, date, reviewer, Stripe reference) | Lifetime of the account, plus 6 years — as evidence the checks were performed |
| Usage and device data | 13 months in identifiable form, then aggregated or deleted |
| Marketing consent records | Lifetime of the account, plus 2 years |
| Active disputes or claims | For as long as the matter remains live, plus 6 years from final resolution |
| Data-export archives (§8) | 7 days from generation; deleted thereafter |
| Audit logs | 2 years from the audited event |
When you close your account, we delete or anonymise your account data and usage data within 90 days, and we delete raw identity documents (photographic ID, proof of address) within the short windows in the table above rather than holding them for the full statutory period. We retain booking, payment, communications, tax, and verification-outcome records for the statutory periods stated above. Where law, a regulatory order, or active legal process requires longer retention, we will retain accordingly.
8. Your rights
You have the following rights over the personal data we hold about you.
| Right | What it means | GDPR Article |
|---|---|---|
| Access | Confirm whether we process your data and receive a copy | 15 |
| Rectification | Correct inaccurate or incomplete data | 16 |
| Erasure | Ask us to delete your data, where one of the grounds applies | 17 |
| Restriction | Ask us to restrict processing in the circumstances described | 18 |
| Portability | Receive your data in a structured, machine-readable format | 20 |
| Objection | Object to processing based on legitimate interests, or to direct marketing | 21 |
| Withdraw consent | Withdraw consent at any time where consent is the basis | 7(3) |
8.1 Self-service: download your data
For access and portability, the fastest route is the self-service flow inside Localee. Sign in and go to Settings → Privacy & Data → Download your data. We prepare your export asynchronously and email you when it's ready. The export is delivered as a ZIP archive from your dashboard (not as an email attachment) and stays available for 7 days.
The archive contains a JSON file for each entity we hold about you — profile, bookings, payments, receipts, reviews, messages, packages, subscriptions, disputes, notifications, audit log — plus a bookings.csv for spreadsheet use, a manifest.json with SHA-256 hashes for integrity verification, and a README.txt explaining the contents.
Customers can export customer-scope data. Provider account owners can additionally export business-scope data, with team-member personal contact data scrubbed — each team member uses their own customer-scope export to retrieve their own data.
You can submit one active export per scope every 24 hours. The request is gated by a recent-reauthentication check (see §9), to mitigate stolen-token data exfiltration.
8.2 By email
For rectification, erasure, restriction, objection, or withdrawing consent, email privacy@localee.ie. We may need to verify your identity before responding. We will respond within one month of receipt; for complex requests we may extend this by a further two months and will tell you why.
8.3 Cost
Requests are free unless manifestly unfounded or excessive — in which case we may charge a reasonable fee or refuse, with reasons.
8.4 Complaining to the DPC
You have the right to complain to the Data Protection Commission of Ireland — 21 Fitzwilliam Square South, Dublin 2, D02 RD28; https://www.dataprotection.ie; info@dataprotection.ie. We would appreciate the chance to address your concerns first.
9. How we keep data safe
We maintain technical and organisational measures appropriate to the risk, including:
- TLS encryption for all platform traffic and at-rest encryption for stored personal data
- Role-based access controls and the principle of least privilege for Localee staff
- Two-factor authentication on administrative systems
- Dependency scanning and runtime error monitoring (via Sentry); third-party penetration testing planned from Year 1 of operations
- Secure software-development practices (code review, secret-handling policy)
- Supplier due diligence and contractual data-protection obligations (Article 28 GDPR)
- Incident response procedures aligned with Articles 33–34 breach-notification obligations
- A reauth-fresh requirement on sensitive account actions: deleting your account or downloading your data requires your identity to have been re-verified by password within the last 5 minutes, mitigating data-exfiltration attacks based on stolen session tokens
- Session revocation on password change and account deletion, closing the legacy-session window
- Signed, short-lived download URLs — sensitive exports use 5-minute signed links minted in the dashboard, so a forwarded email cannot expose the export
If a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission within 72 hours, and you directly without undue delay where the risk is high.
You can help by keeping your login credentials confidential and reporting any suspected unauthorised access to info.support@localee.ie.
10. Cookies and similar technologies
We use a small set of strictly-necessary technologies to operate the platform — primarily a localStorage token to keep you signed in, a small number of first-party items including a UI-preference cookie (sidebar:state), plus Stripe's fraud-prevention cookies on payment pages. We do not use analytics or advertising cookies at launch.
Full details — categories, specific items, retention, third-party providers, and how to manage your preferences — are in our Cookie Policy.
11. Automated decisions and profiling
We do not make decisions producing legal or similarly significant effects on you that are based solely on automated processing within the meaning of Article 22 GDPR.
We do use automated signals to triage potentially fraudulent transactions, abusive accounts, or content that may breach our Terms. Any consequential action — account suspension, payment hold, content removal — is reviewed by a human Localee operator before it is enforced. You can appeal a moderation decision under §11.6 of the Terms or §18.5 (DSA internal complaint handling).
12. Notes for customers and providers
12.1 For customers
Service providers see your name, profile photo, service-location address (where relevant to the booking), the contact details needed to perform the service, your booking history with that provider, and any messages or evidence you upload. Providers act as independent controllers for the data they receive from you (§2) and have their own privacy obligations.
12.2 For providers
Customers see your trading name, profile, service cards, ratings, and reviews, and any data you publish on your provider page. We may share your business identity — CRO number, address, contact details — with public authorities under Article 30 DSA. Under DAC7, we report your booking volumes and identifying data to the Revenue Commissioners.
12.3 Reviews
Reviews you publish are visible to other users and may be visible to non-users on the public web. We do not remove honest reviews on request; see §§4.5 and 10 of the Terms for the limited grounds on which we will.
13. Changes to this policy
We will update this policy whenever our practices change.
- Non-material changes (typographical, formatting, clarifications) take effect on publication.
- Material changes — changes to how we use your data, the legal bases we rely on, the categories of recipient, or your rights — take effect 30 days after we notify you by email and in-app.
Previous versions are archived and available on request at privacy@localee.ie.
14. Contact
Localee Limited
Registered office: 6 Hunters Hill, Hunters Wood, Dublin 24, Ireland
Company registration: 805431
- Privacy:
privacy@localee.ie - General:
info.support@localee.ie - Data Protection Commission of Ireland: https://www.dataprotection.ie
