Privacy Policy
Last Updated: August 22, 2026 β’ Official Privacy Policy & Telemetry Disclosure for @YourService
1. Information We Collect
At @YourService, we collect minimal personal data required to provide a safe, high-quality freelance marketplace, digital file exchange, and recruitment platform:
- Account & Profile Data: Full Name / Display Name, Email Address, Salted Bcrypt Password hashes, profile images, and two-factor authentication (2FA) recovery states.
- Social OAuth Data: Profile metadata (email, display name, avatar) provided when registering or signing in via Google, LinkedIn, or Facebook.
- Transaction, Escrow & Subscription Data: Service orders, custom OfferMe requests, milestone statuses, escrow balances, seller subscriptions (PRO / VIP Master), payout requests, and bank details.
- CopyPortal Digital Vault Data: Source code files, design assets, documents, and deliverables uploaded or exchanged between Buyers and Sellers during order fulfillment.
- Recruitment & Job Placement Data: Employer branding details, candidate PRO verified credentials, resume links, screening questionnaire responses, and job application histories.
- Website Telemetry & Analytics Data: Anonymous visitor IDs, session tokens, HTTP Referrer URLs, channel attribution (Search Engines, Social Media, Paid Ads, Direct Links, Referrals), page load speed (ms), page dwell duration, 404 missing page errors, and interaction events (CopyPortal downloads, sign-ups, purchases, offerme requests, job posts).
2. How We Use Your Data & Telemetry
We process your personal information strictly for legitimate operational, security, and performance purposes:
- To facilitate service ordering, custom OfferMe job requests, milestone tracking, and instant escrow settlement.
- To deliver files securely via the CopyPortal digital vault and enforce system storage capacity quotas.
- To send real-time notification alerts (π) regarding order updates, deliverables, and direct messages.
- To analyze website traffic, measure page load performance, calculate conversion funnel drop-offs, and fix broken 404 links.
- To enforce platform governance rules, prevent fraud, execute real-time AI moderation, and maintain administrative audit trails.
3. Data Protection, Encryption & 2FA Security
Your data security is paramount. We employ industry-standard security measures, including 256-bit SSL encryption for all web transit, salted bcrypt password hashing, Multi-Factor Authentication (2FA), and isolation of private payment/bank credentials. Database records are secured on encrypted infrastructure behind Nginx reverse proxies.
4. Cookies, Local Storage & Telemetry Attribution Tokens
We use secure HTTP-only cookies and browser storage tokens strictly for essential functionality and telemetry attribution:
- Authentication Cookies: Secure HTTP-only JWT cookies to maintain user session state across NextAuth authentication cycles.
- Telemetry Attribution Tokens: Anonymous
localStorage(ays_visitor_id) andsessionStorage(ays_session_token) used strictly to measure visitor traffic channels, page dwell times, and conversion funnels. - No Third-Party Ad Networks: We do NOT sell user data or share telemetry tokens with invasive third-party advertising networks.
5. Media Files, Image EXIF Metadata & Stock Library Privacy
To protect seller privacy and maintain intellectual property compliance across all uploaded media and stock imagery:
- Automatic EXIF Metadata Stripping: When sellers upload custom cover photos or portfolio images, embedded EXIF metadata (such as GPS location coordinates, camera serial numbers, and device capture timestamps) is automatically sanitized and stripped during processing to protect seller location privacy.
- Secure Media Storage & CDN Distribution: Uploaded images and portfolio deliverables are stored on encrypted CDN infrastructure with access controls enforcing safe delivery.
- Stock Library Usage Telemetry: When users select pre-approved royalty-free cover photos from our category stock library, selection preferences are measured in aggregate (e.g. tracking popular stock cover styles per category domain) without linking image choices to personal identity or external advertising profiles.
6. Data Sharing & Storage Quota Infrastructure
We do not sell, rent, or trade your personal data. Limited data is shared strictly with essential service providers (e.g. NextAuth OAuth providers like Google, LinkedIn, Facebook, and encrypted database infrastructure) solely for executing platform operations, CopyPortal file exchanges under system storage quotas, and payment processing.
7. Personal Data Deletion & Right to be Forgotten (GDPR / CCPA)
In accordance with international privacy laws (GDPR Article 17 & CCPA), you have the absolute right to request the deletion or anonymization of your personal data.
- Submitting a Deletion Request: Users can request data erasure directly from their account portal under Profile β π‘οΈ Data Privacy & Erasure.
- Compliance Restricted Fulfillment: To safeguard financial records and prevent fraud, data deletion requests are reviewed and executed exclusively by authorized Compliance Governance Officers within 30 days.
- Anonymization vs. Hard Delete: Compliance officers may choose between:
(a) Anonymization & Archival: Redacting all Personally Identifiable Information (PII) including full name, email address, password hash, bio, and bank details, while preserving anonymized transactional order totals for legal tax compliance.
(b) Full Hard Delete: Completely purging the user profile and credentials from the database. - Right to Retract Request: Users have the right to cancel or retract a pending data erasure request at any time prior to governance fulfillment directly from their account portal (Profile β π‘οΈ Data Privacy & Erasure).
- Re-Authentication Protection: Administrative data deletion actions require mandatory password re-verification and generate immutable, timestamped entries in the platform's administrative audit log.
8. Candidate Qualification Data & AI Audio Assessment Privacy
@YourService processes professional credentials and audio screening data with strict security controls:
- Diploma & License Verification Data: User-submitted academic degree certificates, diplomas, and license registration IDs (such as PRC, CPA, or AWS validation IDs) are processed strictly for credential verification. Verification evidence is stored in encrypted transient storage with access restricted to SuperAdmin and platform verification systems.
- AI Voice Audio & Written Screening Privacy: In-browser audio recordings generated during AI Language Screening challenges are processed in real-time solely to compute phonetic fluency and grammar scores. @YourService does not store permanent biometric voice templates, nor do we sell or share raw voice recordings with third parties. Audio samples are automatically purged after evaluation scores are generated.
9. Automated Email Communications, Unsubscription Rights & Opt-Out Governance
To facilitate essential platform operations, security, and marketplace opportunities, @YourService dispatches automated email notifications subject to strict user privacy rights:
- Official Sender Identity: All system transaction emails are dispatched from
@YourService Governance & Notification Systemusing official addressno-reply@atyourservice.website. - Automated System Dispatch Notice: Transaction emails are generated automatically by platform microservices. Because these addresses are automated notification endpoints, direct email replies are not monitored. Users requiring support are directed to https://atyourservice.website/how-it-works or support channels.
- Right to Unsubscribe & Opt-Out (CAN-SPAM / GDPR / CCPA): Users hold the absolute right to manage email subscription preferences or unsubscribe from non-essential emails at any time:
(a) In-App Notification Preferences: Manage granular toggles for Marketing, AI Skill-Match invites, and Job Digests directly from Profile β π Email & Notification Preferences.
(b) 1-Click Unsubscribe Links: All marketing, promotional, and AI match digest emails contain a 1-click tokenized unsubscribe link in the footer (https://atyourservice.website/unsubscribe?email=...) permitting instant opt-out without requiring portal login. - Essential Security Mandate (Non-Unsubscribable): Essential security and transactional emails (2FA security verification codes, password resets, escrow order funding receipts, CopyPortal deliverable ready notices, Stripe payout clearance, and 5-year inactivity warnings) remain active for security governance and legal compliance.
10. 5-Year Inactivity Retention & Automated Account Purge Policy
Under our 5-Year Privacy & Data Retention Governance Policy, inactive accounts are automatically scheduled for permanent data deletion five (5) years after the last recorded account login:
- Advance Email Warning Dispatches: To prevent unexpected data loss, inactive accounts receive advance notification alerts at 4.5 Years (6 Months prior to purge), 4.9 Years (30 Days prior to purge), and 4.97 Years (10 Days prior to purge).
- Automatic Timer Reset: Logging into your account at any time automatically resets the 5-year inactivity retention timer back to zero.
- Data Deletion Scope: Upon reaching the 5-year purge date, user profile metadata, credentials, and uploaded files are permanently deleted or anonymized in compliance with GDPR/CCPA data minimization principles.
11. GDPR Article 28 Authorized 3rd-Party Data Sub-Processors
Under GDPR Article 28 transparency rules, @YourService engages verified 3rd-party sub-processors under strict Data Processing Agreements (DPAs) to deliver core payments, storage, AI, and email capabilities:
| Sub-Processor | Purpose / Processing Activity | Data Transferred | Data Location |
|---|---|---|---|
| Stripe Inc. | Payment Processing & Express KYC Payout Verification | Email, Identity, Bank Account Tokens | USA / EU (DPF Covered) |
| DigitalOcean LLC | Server Cloud Hosting & CopyPortal Encrypted Storage | App Database & Uploaded Assets | USA / SGP / EU Datacenters |
| OpenAI LLC | AI Headhunting, OfferMe Decomposition & Support AI | Prompt Inputs & Support Queries | USA (Zero-Data-Retention API) |
| Resend / SMTP | Automated Transactional Email Dispatches | Recipient Email & Notification Body | Global Encrypted Nodes |
12. GDPR Article 20 Data Portability & Article 22 AI Decision Safeguards
- Right to Data Portability (Article 20): Users have the right to request a machine-readable JSON copy of all personal data held by @YourService. Self-service exports can be generated anytime via Profile β π‘οΈ Data Privacy β π₯ Download My Personal Data (.JSON).
- Automated Profiling & AI Human Safeguards (Article 22): While @YourService utilizes AI models to provide OfferMe task decomposition, candidate match scores (β‘ Match Score%), and search ranking algorithms, all binding commercial decisions (order placement, candidate hiring, escrow releases, and dispute awards) are governed exclusively by human users or human admin moderators.
13. Infrastructure Build Transparency & Database Backup Security
To ensure system reliability, continuous disaster recovery, and protection against data loss:
- Staff Version Transparency: Application releases carry subtle build identifiers (e.g.
v4.9.2) accessible solely to authenticated Staff and Admin accounts for diagnostic tracing. Public users see a clean UI without internal version clutter. - Encrypted Triple-Node Snapshots: Pre-deployment database snapshots and CopyPortal ephemeral file assets are generated automatically and replicated asynchronously across Node 1 (@YourService_1 Primary), Node 2 (@YourService_2 Offsite Secondary Vault), and Node 3 (@YourService_3 Cold Tertiary Vault) under 256-bit AES encryption. SuperAdmin controls govern individual server storage limits (in GB) per node, with all storage add-on revenue and financial statistics displayed under clean currency formatting (e.g.
$269.75). - Zero-Data-Loss Rollback Architecture: Version rollback procedures restore application execution files without reverting live user database states, guaranteeing that user accounts, funded escrows, and messages created during release windows are permanently preserved.
14. Technical Developer Roles & Visual GUI Editor Access Governance
Access to real-time visual interface tools and layout manipulation controls is strictly governed:
- Developer Authorization: Technical developer roles (Senior Developer and Junior Developer) and accounts with explicit
canDevelopcapability are granted access to developer workbenches. - GUI Editor Public Concealment: The Visual GUI Editor tool is completely disabled for public users in live production releases to prevent UI tampering and maintain visual layout integrity. All component hooks run unconditionally to ensure strict React Rules of Hooks compliance.
15. Control Panel Gateway (/cp) Short URL Routing Security
The short URL route /cp serves as an operational portal gateway for webmail, notification controls, and administrative services:
- Short-URL Resolution: Accessing
atyourservice.website/cpprovides direct entry to Webmail, CopyPortal file exchange, and account settings without displaying 404 errors. - Transport Encryption: All traffic routed through
/cpis enforced under TLS/SSL 256-bit encryption.
16. Mobile Device Responsiveness & Touch Security Standards
The platform implements responsive design standards to optimize security and usability on mobile devices:
- Dedicated Mobile Form Views: Registration and login interfaces on small viewports conceal ambient hero graphics, ensuring zero form squeezing and optimal input visibility.
17. Promotional Voucher Processing & Launch Special Transparency
Data processing associated with Grand Opening launch banners and promotional voucher redemption:
- Promotional Navigation Transparency: Announcement banners linking to /vouchers-guide clearly outline 0% fee structures, voucher codes, and discount calculations prior to payment authorization. Theme-aware color variables adapt dynamically to prevent text drowning across Light and Dark mode viewports.
18. Your Privacy Rights & Contact
You have the right to access, update, export, or request the full deletion of your personal account data at any time. For privacy inquiries or data erasure requests under GDPR/CCPA, please visit our Data Privacy portal or contact privacy@atyourservice.website.
