Template notice. This document is sample content supplied with the platform. It has not been reviewed by a lawyer and is not tailored to any jurisdiction. The marketplace operator must have it reviewed and adapted before relying on it.
What we collect
You give us: name, email address, password (stored only as a salted hash), profile details, listing content, messages, booking details, and — optionally, and only where we have enabled it — a phone number and identity verification.
We generate: booking and payment records, reviews, moderation records, and audit logs.
We collect automatically: approximate location derived from a place you search for, device and browser information, and a hashed form of your IP address. We do not store raw IP addresses.
What we do not collect
We never store payment card numbers, CVV codes or bank credentials. Those go directly to our payment processor.
Why we use it
| Purpose | Lawful basis |
|---|---|
| Operating your account and bookings | Performance of a contract |
| Taking payment and paying providers | Performance of a contract |
| Preventing fraud and abuse | Legitimate interests |
| Meeting tax and accounting obligations | Legal obligation |
| Product updates and marketing | Consent (opt-in only) |
Location privacy
Exact addresses and coordinates are stored separately from listings and are never included in public listing data. What appears on a public map is a deterministically offset point within roughly 1200 metres of the real location. The exact address is released only to the two parties of a booking, and only once that booking is confirmed.
Photographs are re-encoded on upload, which strips EXIF metadata including GPS coordinates.
Sharing
We share data with: our payment processor (to take payment and pay out), our email provider (to send transactional email), our hosting and storage providers, and — where a booking is confirmed — the necessary contact and location details with your counterparty. We do not sell personal data.
Retention
- Account and profile: while your account is open.
- Bookings, payments and invoices: 7 years, for tax and accounting.
- Messages: 3 years after the related booking.
- Moderation and audit records: 3 years.
- Login attempt records: 90 days.
- If an account is permanently banned: a one-way cryptographic digest of the email address, kept until the ban is lifted. It cannot be reversed into an address and is used for one purpose only — recognising the same address if it is used to register again.
Your rights
You can access, correct, export or delete your data from Settings → Privacy. Because bookings and payments are shared financial records, account deletion anonymises your personal data rather than erasing transaction rows that another member and our accountants rely on.
These rights do not depend on your account being in good standing. If you are suspended, or banned and unable to sign in, request a link at https://lendify.now/data-request and you can download your data or ask for deletion without signing in.
Where an account was banned, honouring a deletion request still leaves the digest described above. We consider retaining it a legitimate interest in enforcing our terms; without it, deletion would simply undo the ban. Nothing else about the account is kept.
Contact
Data protection enquiries: legal@lendify.now