Privacy Policy
Last Updated: January 8, 2025
Manny ("we," "us," "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, share, and protect your information when you use our platform and services.
GDPR/AVG Compliance: This Privacy Policy complies with the General Data Protection Regulation (GDPR) and the Dutch Data Protection Act (Algemene Verordening Gegevensbescherming - AVG). If you are located in the European Union, you have specific rights regarding your personal data.
1. Data Controller
Manny is the data controller for the personal data we process. You can contact us at:
2. Information We Collect
2.1 Information You Provide Directly
When you register as a Customer:
- Full name
- Email address
- Phone number
- Home address (service location)
- Profile photo (optional)
- Payment information (processed by Stripe, not stored by us)
When you register as a Technician:
- Full name
- Email address
- Phone number
- Business name and registration number (KvK number)
- Professional licenses and certifications
- Service areas and specializations
- Bank account information (for payments via Stripe)
- Profile photo and portfolio images
- Insurance information
When you use our services:
- Service requests and job details
- Messages and communications between Customers and Technicians
- Reviews and ratings
- Community posts and interactions
- Support inquiries and correspondence
- Photos and videos uploaded for service requests or showcases
2.2 Information Collected Automatically
When you access our Platform, we automatically collect:
- Device Information: IP address, browser type, operating system, device identifiers
- Usage Data: Pages viewed, features used, time spent on the Platform, click patterns
- Location Data: Approximate location based on IP address (we do not track precise GPS location unless you explicitly enable it for service matching)
- Cookies and Similar Technologies: See our Cookie Policy for details
2.3 Information from Third Parties
We may receive information from:
- Google OAuth: If you register using Google, we receive your name, email, and profile picture
- Stripe: Payment processing information and transaction details
- Public Databases: For Technician verification, we may verify KvK registration numbers
3. How We Use Your Information
3.1 Legal Basis for Processing (GDPR/AVG)
We process your personal data based on the following legal grounds:
- Contract Performance: To provide our services and fulfill our agreement with you
- Legitimate Interests: To improve our Platform, prevent fraud, and ensure security
- Legal Obligations: To comply with tax, accounting, and other legal requirements
- Consent: For marketing communications and optional features (you can withdraw consent anytime)
3.2 Purposes of Data Processing
We use your information to:
Provide and Improve Services:
- Create and manage your account
- Connect Customers with appropriate Technicians
- Facilitate scheduling, communication, and service delivery
- Process payments and send receipts
- Provide customer support
- Improve platform functionality and user experience
Safety and Trust:
- Verify Technician credentials and qualifications
- Monitor and moderate reviews and community content
- Detect and prevent fraud, abuse, and security incidents
- Resolve disputes between users
Communication:
- Send transactional emails (bookings, confirmations, receipts)
- Send service updates and important announcements
- Respond to your inquiries and support requests
- Send marketing communications (only with your consent - you may opt out)
Legal Compliance:
- Comply with tax and financial reporting obligations
- Respond to legal requests and prevent illegal activity
- Enforce our Terms and Conditions
4. How We Share Your Information
4.1 With Other Users
- Customers can see: Technician names, ratings, reviews, service areas, profile photos, and portfolios
- Technicians can see: Customer names, service locations, contact information (after accepting a job), and past reviews left for technicians
- Both parties can see: Messages exchanged through the Platform's messaging system
4.2 With Service Providers
We share data with third-party service providers who help us operate the Platform:
- Stripe: Payment processing (see Stripe's Privacy Policy)
- SendGrid (Twilio): Email delivery (see SendGrid's Privacy Policy)
- MongoDB Atlas: Database hosting (see MongoDB's Privacy Policy)
- Railway: Cloud hosting services (see Railway's Privacy Policy)
4.3 For Legal Reasons
We may disclose your information if required by law or if we believe it's necessary to:
- Comply with legal obligations, court orders, or government requests
- Protect the rights, property, or safety of Manny, our users, or the public
- Detect, prevent, or address fraud, security, or technical issues
- Enforce our Terms and Conditions
4.4 Business Transfers
If Manny is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our Platform before your data is transferred and becomes subject to a different privacy policy.
4.5 With Your Consent
We may share your information with other third parties when you give us explicit permission to do so.
5. International Data Transfers
Your information may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States, where our service providers (Stripe, MongoDB Atlas, SendGrid) operate servers.
We ensure adequate protection through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Selecting service providers certified under EU-US Data Privacy Framework or equivalent safeguards
- Ensuring our partners comply with GDPR requirements
6. Data Retention
We retain your personal data for as long as necessary to:
- Provide our services and maintain your account
- Comply with legal, tax, and accounting obligations (typically 7 years for financial records)
- Resolve disputes and enforce our agreements
Specific retention periods:
- Active accounts: Data retained while your account is active
- Closed accounts: Most data deleted within 90 days, except data we must retain for legal reasons
- Transaction records: Retained for 7 years for tax and accounting purposes
- Marketing data: Retained until you unsubscribe or 3 years of inactivity
- Logs and analytics: Retained for up to 2 years
7. Your Rights Under GDPR/AVG
If you are located in the EU/EEA, you have the following rights:
7.1 Right to Access
You can request a copy of all personal data we hold about you. We will provide this within 30 days in a commonly used electronic format.
7.2 Right to Rectification
You can correct inaccurate or incomplete personal data through your account settings or by contacting us.
7.3 Right to Erasure ("Right to be Forgotten")
You can request deletion of your personal data. We will comply unless we have a legal obligation to retain it (e.g., for tax purposes, ongoing disputes, or fraud prevention).
7.4 Right to Restriction of Processing
You can request that we limit how we use your data in certain circumstances (e.g., while we verify data accuracy).
7.5 Right to Data Portability
You can request a copy of your data in a structured, machine-readable format to transfer to another service.
7.6 Right to Object
You can object to processing based on legitimate interests or for direct marketing purposes.
7.7 Right to Withdraw Consent
Where we process data based on consent, you can withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
7.8 Right to Lodge a Complaint
You have the right to file a complaint with your local data protection authority. In the Netherlands, this is:
7.9 How to Exercise Your Rights
To exercise any of these rights, please contact us at privacy@mannyfix.com. We will respond within 30 days.
8. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption: Data in transit is encrypted using TLS/SSL. Sensitive data at rest is encrypted.
- Access Controls: Access to personal data is restricted to authorized personnel only
- Authentication: We use secure authentication methods (OAuth 2.0, JWT tokens)
- Payment Security: We use Stripe for payment processing and do not store full credit card details
- Regular Security Audits: We regularly review and update our security practices
- Secure Infrastructure: Data is hosted on secure cloud platforms with industry-standard protections
However, no method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. You are responsible for keeping your account credentials secure.
9. Children's Privacy
Manny is not intended for users under 18 years old. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 18, we will delete it promptly.
10. Cookies and Tracking Technologies
We use cookies and similar technologies to improve your experience, analyze usage, and provide personalized content. For detailed information, please see our Cookie Policy.
Types of cookies we use:
- Essential Cookies: Required for the Platform to function (authentication, security)
- Functional Cookies: Remember your preferences and settings
- Analytics Cookies: Help us understand how you use the Platform
- Marketing Cookies: Used to deliver relevant ads (only with your consent)
11. Marketing Communications
We may send you marketing emails about new features, promotions, or updates. You can opt out at any time by:
- Clicking "Unsubscribe" in any marketing email
- Adjusting your email preferences in account settings
- Contacting us at support@mannyfix.com
Note: You cannot opt out of transactional emails (booking confirmations, receipts, security alerts) as these are essential to the service.
12. Third-Party Links
Our Platform may contain links to third-party websites or services (e.g., Technician business websites). We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Sending an email to your registered email address
- Displaying a prominent notice on the Platform
- Updating the "Last Updated" date at the top of this page
Changes take effect 14 days after notification. Your continued use of the Platform after this period constitutes acceptance of the updated policy.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Data Protection Contact:
Email: privacy@mannyfix.com
General Support: support@mannyfix.com
Website: https://mannyfix.com
Your privacy matters to us. We are committed to protecting your personal data and being transparent about how we use it. If you have any concerns, please don't hesitate to reach out.