1. Scope and roles
This Privacy Policy applies to Alltasko websites, accounts, job requests, professional profiles, messages, files, reviews, verification and support. Alltasko controls personal information used to operate the platform. A professional may separately control information collected from a customer outside Alltasko.
For Stripe Identity, Alltasko and Stripe may each act as an independent controller for parts of the personal information they process. Stripe also processes certain verification information as a service provider to Alltasko. Stripe handles information under its own Privacy Policy and the Stripe Identity terms.
2. Information we collect
When a professional chooses identity verification, Stripe Identity collects a government-ID image, live capture, selfie or facial-comparison data, document details, device information and fraud signals under Stripe’s notices and consent flow. Alltasko does not store copies of the government-ID or selfie images. To decide the verification and prevent duplicate professional accounts, Alltasko receives the result and limited verified document fields through Stripe’s protected API, uses those fields briefly to create non-reversible fingerprints, and does not store the raw document number, date of birth or extracted identity fields. Alltasko stores the verification result, Stripe session/report references, the acknowledgement date and policy versions, and the non-reversible fingerprints.
When payment features are enabled, Stripe collects and stores full payment-card details. Alltasko does not store the full card number or security code. Alltasko stores processor identifiers and limited card details—such as brand, last four digits and expiration date—so a professional can recognize a saved payment method and Alltasko can process authorized charges and refunds.
- Account and contact data, including name, email, phone number, role and sign-in identifiers.
- Location data, including ZIP code, service area, city/state and approximate location inferred from an internet address when used for matching.
- Professional profile data, including company name, services, rates, availability, portfolio, credentials, verification status and limited technical verification references.
- Job and transaction data, including descriptions, answers, photos, proposals, agreed pricing, lead charges, refund requests, statuses and reviews.
- Communications, including in-platform messages, protected SMS content, protected-call transcripts, call/text metadata, automated job-outcome signals, attachments, support requests and notification preferences. Audio from protected calls is not recorded by Alltasko.
- Technical and usage data, including internet address, device/browser information, session records, timestamps, security logs and interactions with the service.
3. Sources of information
We receive information directly from users, from platform activity, from devices and browsers, from authentication, hosting, email, storage, payment and identity-verification service providers, and from lawful public or verification sources when a review requires them.
4. How information is used
Private conversations are not public. Access by an authorized administrator is limited to legitimate platform purposes, protected by administrator authentication and recorded in an access log. Protected communication may be automatically classified as contact made, price discussed, appointment scheduled, hired, declined, cancelled or unknown. That signal assists human review and never automatically approves or denies a refund. Alltasko does not use identity-verification data, private messages, protected communication content or precise job addresses for advertising.
- Create and secure accounts.
- Match jobs with relevant professionals by service, location, availability and verification status.
- Operate requests, proposals, private conversations, protected calling and texting, files, notifications, reviews, lead billing and refunds.
- Verify professional identity, prevent duplicate professional accounts and investigate safety, fraud, abuse or policy violations.
- Provide support, maintain records, resolve billing or service disputes, understand whether marketplace leads produce agreements, debug problems and improve platform reliability.
- Comply with law, enforce agreements and protect users, Alltasko and the public.
5. How information is disclosed
Information may be disclosed to the customer or professional involved in a job as needed for the marketplace workflow; to vendors that provide authentication, identity verification, hosting, databases, file storage, email, protected calling and text messaging, transcription, automated analysis, push notifications, mapping, security or payment processing; to professional advisers; to authorities or other parties when required by law or reasonably necessary for safety and rights protection; and in connection with a merger, financing, sale or business transfer.
Alltasko uses Stripe for risk and identity-verification services. Alltasko shares identifying information with Stripe, and Stripe analyzes and uses that information to operate and improve the services it provides to Alltasko, including identity verification, risk evaluation, fraud detection, authentication and analytics. Stripe may also process information for its own legal obligations and purposes described in Stripe’s Privacy Policy.
Current infrastructure may also include Google for sign-in and account services, Twilio for protected calls, text-message delivery, real-time transcription and communication analysis, Cloudflare and other infrastructure providers for hosting and storage, and device push services operated by Apple, Google or browser providers. Public professional profiles, portfolio items and approved reviews are visible to visitors. Private contact details, messages, transcripts and identity-verification data are not public.
6. Sale, sharing and advertising
Alltasko does not currently sell personal information for money or share it for cross-context behavioral advertising. If those practices change, this policy and any legally required opt-out controls will be updated before the change takes effect.
8. Data retention
Information is kept only as long as reasonably needed for the purposes described here, including active accounts, job history, conversations, dispute handling, fraud prevention, financial records, legal compliance and backup cycles. One-time sign-in code records are normally removed within 24 hours, and email sessions normally expire after 30 days. Anonymous traffic visitor records are normally removed after 30 days and page-view records after 90 days. Protected-call transcript text and the separate protected-SMS analysis copy are normally removed after 90 days; the shorter outcome, confidence, timing and audit record may be retained with the related job or dispute. Alltasko does not retain protected-call audio. Other retention periods vary by record type.
Alltasko may retain the Stripe verification result, acknowledgement record and non-reversible duplicate-prevention fingerprints after an account closes when reasonably necessary to prevent fraud, document compliance or resolve disputes. Alltasko does not retain Stripe’s ID or selfie images. Stripe’s service terms state that verification data stored on Alltasko’s behalf is normally retained for three years after verification unless a different permitted retention setting applies. Stripe may separately retain information for its own lawful purposes.
9. Security
Alltasko uses administrative, technical and access safeguards appropriate to the information handled, including restricted document access, protected account sessions and logged administrator access to private conversations. No internet service can promise absolute security. Users should use secure devices, protect sign-in accounts and promptly report suspected unauthorized access.
10. Privacy choices and rights
Depending on residence and applicable law, a person may have rights to know or access personal information, correct inaccurate information, delete information, obtain a portable copy, limit certain uses of sensitive information, withdraw consent where applicable, opt out of sale or sharing, appeal a privacy-request decision, and receive equal service without unlawful discrimination.
Send a request to notifications@alltasko.com from the account email or use the Delete account page. Alltasko may verify identity, ask for clarification and retain information when an exception applies. An authorized agent may be required to provide proof of authority. For an eligible Stripe Identity deletion request, Alltasko can ask Stripe to redact the verification session and related personal data; Stripe states that redaction may take up to four days. Information Stripe controls for its own purposes may require a separate request to Stripe.
A professional may decline Stripe Identity before starting. When applicable law requires a non-biometric alternative, contact Alltasko before verification so an appropriate alternative review can be assessed. Declining verification means the professional account remains offline and cannot receive paid leads until a permitted verification method is completed.
11. Children
Alltasko is for adults and is not directed to children under 13. Accounts and service agreements require users to be at least 18. If Alltasko learns that a child’s personal information was collected improperly, it will take reasonable steps to delete it.
12. U.S. processing and transfers
Alltasko is operated for the United States. Information may be processed in the United States and other locations where service providers operate, subject to applicable safeguards and legal requirements.
13. Reviews and public content
Alltasko displays reviews connected to genuine platform activity and may use reasonable measures to identify manipulation. Honest negative reviews are not removed merely because they are unfavorable. A review may be removed or restricted when it is fake, unrelated, unlawfully threatening, discriminatory, obscene, infringing, privacy-invasive or otherwise prohibited by the Terms.
Public profile and portfolio content may be indexed by search engines. Deleting an account does not guarantee immediate removal from third-party caches or copies outside Alltasko’s control.
14. Changes, incidents and contact
Material changes will be posted with a revised date and additional notice or consent when required. If a security incident triggers a legal notification duty, Alltasko will provide notices to affected people and authorities as required by applicable law.
Questions, complaints, appeals and privacy-rights requests may be sent to notifications@alltasko.com.
Use the email connected to your Alltasko account so the request can be verified.