What we collect
At signup — name, email, phone number, password (stored as a bcrypt hash, never plaintext), account type (TALENT / COMPANY / MEMBER), and for talents and companies: discipline, sub-category, location, services offered, and basic profile fields.
KYC documents — passport / Emirates ID / company trade license / selfies, uploaded for identity verification. KYC documents are encrypted at rest, accessed only by the SUPPORT / FULL admin tier for face-match review, and never shipped to public profile responses.
Operational data — bookings, offers, jobs you post or apply to, transactions (Stripe IDs only — we do not store full card numbers), messages between platform users, notifications, reviews, reports, wishlist + saved searches, and cart contents (saved to your account so they follow you between devices).
Push notification data — if you enable push notifications, we store the endpoint your browser issues and its encryption keys against your account, purely to deliver the notification. Disabling notifications deletes it.
Audit + security data — sign-in IP / user agent, failed login counts, token version, account lockout timestamps, rate-limit counters, and an admin audit trail recording which administrator opened which record and when.
