Maplelirium Inc. ("we", "us", "our") operates the Proz4u platform. This Privacy Policy explains how we handle your data. Questions? Email support@proz4u.com
1. Scope and Applicable Law
Maplelirium Inc. is headquartered in Canada and is subject to the Personal Information Protection and Electronic Documents Act (PIPEDA). We also comply with the EU General Data Protection Regulation (GDPR) for EEA users and the California Consumer Privacy Act (CCPA/CPRA) for California residents.
This Policy applies to all personal information collected through proz4u.com, the Proz4u iOS app, Android app, and any related services.
2. Information We Collect
2.1 Information You Provide
- Account registration: full name, email address, date of birth (age verification only), role (Worker or Hirer), password
- Profile information: headline, biography, profile photo, portfolio photos, work history, trade categories, skill tags, rate ranges
- Location: city and region (text only). Precise GPS is never stored permanently — see Section 2.3
- Job listings: title, description, trade requirements, suggested rate range, city/region
- Communications: messages, posts, comments sent through the Platform
- Marketplace listings: title, description, photos, price, city
- Team profiles: team name, description, member list, trade categories
- Verification documents: government ID, trade certificates, insurance documents (private encrypted storage)
- Consent records: your responses to each consent request, stored with timestamp and policy version
2.2 Information Collected Automatically
- Device information: device type, operating system, app version
- Usage data: features accessed, screens viewed, search queries, session duration
- FCM token: device identifier for push notifications — deregistered on logout
- Authentication logs: login timestamps and methods (email, Google, Apple)
2.3 Location Data — Special Handling
Your precise GPS coordinates are only collected when you explicitly enable "Appear on map". They are stored transiently and automatically expire after 4 hours. They are never copied to your permanent profile. Disabling "Appear on map" immediately deletes your location from our systems.
2.4 Payment Information
Proz4u uses Stripe Connect. We do not store credit card numbers, CVV codes, or bank account details. Card details are transmitted directly to Stripe and tokenised. We store only Stripe-issued identifiers and transaction records. See Stripe's Privacy Policy.
3. How We Use Your Information
- To create and manage your account and verify your identity
- To enable connections between Workers and Hirers
- To display your public profile to authenticated users
- To facilitate job applications, messaging, and team collaboration
- To process payments via Stripe Connect (Direct Charge)
- To send push notifications about your account activity
- To provide map-based discovery when you opt in
- To verify credentials and display verified badges
- To enforce our Terms of Service and respond to content reports
- To comply with legal obligations under PIPEDA, GDPR, and CCPA
- To improve the Platform through anonymised analytics
4. Legal Basis for Processing (GDPR)
- Contractual necessity (Art. 6(1)(b)): Account data, profile, listings, messages, payments
- Legitimate interests (Art. 6(1)(f)): Analytics, fraud prevention, platform security
- Consent (Art. 6(1)(a)): Location sharing, marketing emails, optional analytics
- Legal obligation (Art. 6(1)(c)): Consent records, data subject requests, applicable law
5. Information We Share
We do not sell your personal information to third parties.
5.1 With Other Users
Your public profile (name, headline, trade, skills, city/region, portfolio, reviews, verified badges, availability) is visible to authenticated users. Your email, date of birth, and precise location are never shown publicly.
5.2 With Service Providers
- Supabase Inc.: database hosting, authentication, file storage, real-time messaging
- Stripe Inc.: payment processing and identity verification (PCI DSS Level 1 certified)
- Google LLC (Firebase): push notifications and crash reporting
- Google LLC (Maps): map display and proximity search
- Apple Inc. (APNs): iOS push notification delivery
- OpenAI Inc.: content safety moderation — user-generated text (posts, messages, listings) may be sent to OpenAI's Moderation API to detect harmful content. Personally identifiable information is stripped before transmission
- Google LLC (Perspective API): content safety moderation — text may be processed by Google's Perspective API for toxicity detection. Personally identifiable information is stripped before transmission
We use third-party AI services to detect harmful content. Text you submit (posts, messages, job listings, skill tags) may be processed by OpenAI and Google for safety purposes. Personal identifiers (emails, phone numbers) are removed before any text is sent to these services.
5.3 Legal Requirements
We may disclose information if required by law, court order, or governmental authority, or to protect our rights or your safety.
6. Data Retention
- Account data: retained while account is active + 30 days after deletion
- Consent records: retained permanently as required by privacy law
- Messages: retained for 2 years then permanently deleted
- GPS location: automatically expires after 4 hours
- Payment records: retained for 7 years (Canadian Income Tax Act)
- Verification documents: retained for 2 years after expiry or account deletion
- Audit logs: retained for 5 years for regulatory compliance
7. Your Rights
All Users (PIPEDA)
- Right to access your personal information
- Right to correction of inaccurate information
- Right to withdraw consent for optional processing
- Right to complain to the Office of the Privacy Commissioner at priv.gc.ca
EEA Users (GDPR)
- Right to erasure ("right to be forgotten")
- Right to restriction and portability
- Right to object to legitimate interest processing
- Right to lodge a complaint with your local supervisory authority
California Residents (CCPA/CPRA)
- Right to know what data is collected and how it is used
- Right to delete your personal information
- Right to opt out of sale (we do not sell personal information)
- Right to correct inaccurate information
- Right to non-discrimination for exercising privacy rights
To exercise any right: email support@proz4u.com or use the "Delete Account" function in the app. We respond within 30 days.
8. Account Deletion
Delete your account via Settings → Account → Delete Account. Upon deletion: your profile is deactivated immediately, personal data is permanently deleted within 30 days, messages are deleted, consent records are retained as required by law, payment records are retained 7 years for tax purposes, and reviews are anonymised.
9. Security
- All data transmitted over HTTPS/TLS encryption
- Database encryption at rest (Supabase on AWS)
- Row-Level Security policies — users can only access their own data
- Verification documents in private storage with short-expiry signed URLs
- Payment processing delegated entirely to Stripe
10. Children's Privacy
The Platform is not intended for anyone under 18. We require date of birth at registration. If we discover a user is under 18 we will immediately deactivate their account and delete their data. Contact support@proz4u.com if you believe a minor has created an account.
11. International Data Transfers
Maplelirium Inc. is based in Canada, which the European Commission recognises as providing adequate data protection. Service providers in the United States (Supabase, Stripe, Google/Firebase) operate under Standard Contractual Clauses.
12. Changes to This Policy
We will notify you of material changes via the Platform and at proz4u.com/privacy at least 30 days before changes take effect. Continued use after the effective date constitutes acceptance.
13. Contact Us
Email: support@proz4u.com
Website: proz4u.com/privacy
Company: Maplelirium Inc., Canada
For GDPR requests, include "GDPR Request" in the subject. For CCPA requests, include "CCPA Request". We respond within 30 days.
Last updated: March 1, 2026