Privacy Policy
Version 2026-08-01. Last updated: August 1, 2026.
Contents
1. Who we are
Data controller: SC DESTIN ENTREPRISE SRL, in the process of incorporation. Provisional details: Tax ID (CUI): [pending], Trade Registry No.: [pending], Registered office: [pending].
Website: servico.ro
Email: privacy@servico.ro
2. What data we collect
- Account data: name, email, phone, password (stored as a hash).
- Provider profile: the services you check, self-declared qualifications, your base point on the map, travel radius, hourly rate, the description you write.
- Tasks: description, photos, job address, county and city, coordinates, budget and agreed price.
- Technical data: IP address, device type, logs, cookies (see the Cookie Policy).
- Communications: task chat messages, reviews, notifications sent (push, SMS, email).
- The provider's live location, only during the window described in section 5.
- Metadata for masked phone calls, described in section 6.
- Payments: amounts, commission, transaction status and Stripe identifiers. We do not store any card number — card data is entered directly at Stripe and never passes through our servers.
- Consents: which document you accepted, which version, and on what date.
We do not request or store national ID numbers, tax IDs, or IBANs. See also section 8.
3. Legal bases (GDPR)
- Performance of a contract (Art. 6(1)(b)): providing the account and the platform's features.
- Consent (Art. 6(1)(a)): marketing, newsletter, non-essential cookies.
- Legitimate interest (Art. 6(1)(f)): preventing abuse/fraud, improving our services.
- Legal obligation (Art. 6(1)(c)): tax/accounting obligations.
4. Purposes of processing
- Creating and managing your account, publishing tasks/listings.
- Communication between users; operational notifications.
- Analytics, security, abuse detection.
- Marketing (only with consent), Servico Blog updates.
5. Provider's live location
Purpose. Between "I'm on my way" and the doorbell, the client has exactly one question. The map answers it, so three phone calls aren't needed. Nothing else is done with the position: it isn't used to rank providers, it isn't used for pricing, and it isn't sold to anyone.
Who and when. Only the provider assigned to a task, and only while the task is in the "on the way" state — from the moment they tap "I'm heading your way" until they tap "I've arrived". Outside that window the platform records no position at all, even if the browser were to send one. It is seen by exactly one person: the client of that task. Not other providers, not administrators, not the arbitrator of a dispute.
What is recorded. Latitude, longitude, the accuracy reported by the phone, and the time of the reading. Nothing about speed, battery, or open apps.
How long it's kept. A task's trail is automatically deleted 24 hours after the task ends, and any position older than the absolute retention ceiling is deleted regardless, even if the task never ended. There is no archive and no export. A position older than 120 seconds isn't even shown to the client anymore — the map says "location unavailable" instead of showing a stale point.
How to stop it. Three ways, all valid:
- Right now, for this trip: the "Stop sharing" button on the task screen. Nothing is recorded anywhere about you stopping it, and it has no effect on the task.
- Permanently: withdrawing consent from your provider profile. It takes effect immediately — the next ping is refused, the browser stops tracking, and positions already recorded are deleted on the spot. It can be re-enabled at any time, from the same place.
- From your phone: revoking location permission in your browser settings. The platform cannot override it.
The legal basis is consent (Art. 6(1)(a)). Withdrawing it doesn't affect prior processing and has no consequence on your account, your rating, or the tasks you receive.
6. Masked phone calls
When the client and provider call each other through the platform, the call goes through one of our numbers, so neither of you sees the other's number.
We do not record the content of the call. There is no audio file, no transcript, and no listening in — not by administrators, and not during a dispute.
Only metadata is kept: which task the call belongs to, the platform number used, the time, the duration, whether the call connected or was refused, and its cost. Both parties' phone numbers are necessary to connect the call and are shown redacted in the history. The metadata serves two purposes: answering "did you actually talk?" during a dispute, and billing telephony correctly. The legal basis is performance of the contract and legitimate interest.
The telephony provider that routes the call processes, in turn, the calling and called numbers, since the call cannot be technically established without them.
7. In-platform messages
A task's chat is kept for as long as the task exists, as proof of what was agreed. A message cannot be deleted after it's sent — the other party has already read it, and in a dispute it is the only record of what was said.
Phone numbers, email addresses and links to other websites are hidden on display, so the exchange stays on the platform, where payment is protected. The original text remains stored: the mask is applied at read time, not at write time.
An administrator can read the unmasked text of a conversation only while the task is under dispute, and only to resolve it. Every such read is logged in the audit trail, with the administrator's name and the time.
Notifications (push, SMS, email) and their delivery status are kept so we don't send you the same thing twice, and so we can explain why a message didn't arrive.
8. Payments and data sent to Stripe
Payments are processed by Stripe Payments Europe, Ltd., which is an independent controller for payment data, not merely our processor. Their policy applies in addition to ours: stripe.com/privacy.
What Stripe receives from us:
- From the client, when paying for a task: the amount, currency, the task's internal identifier, and the email address. Card details are entered directly into the Stripe form embedded on the page — they never reach our servers and we cannot see them.
- From the provider, when verifying a payout account (Stripe Connect): name, email and country, as the form's starting point. Everything else — ID document, date of birth, address, IBAN, company details — is entered directly with Stripe, in a form they host. The platform does not receive or store it. From the verification we only keep the account identifier, whether it can charge, whether it can receive payouts, and the list of documents still missing.
What does not happen: we do not send chat messages, task photos, live location, or reviews to Stripe.
Stripe may transfer data outside the EEA, based on the European Commission's standard contractual clauses.
Tax reporting. As a digital platform, we are required (EU Directive 2021/514, "DAC7") to report annually to the tax authority the income providers earn through the platform: the provider's identifier, number of tasks, gross income, commission withheld and net income, by quarter. The figures come from our internal ledger, and the provider sees the same figures in their wallet before the filing. The legal basis is a legal obligation (Art. 6(1)(c)) and does not depend on consent.
9. Retention periods
| What | How long |
|---|---|
| Provider's live location | 24 hours after the task ends; in any case, no longer than the absolute retention ceiling |
| Call metadata | for as long as the task exists, plus the telephony billing period |
| Chat messages | for as long as the task exists |
| Reviews | indefinitely — they are a provider's public reputation |
| Payments, commissions, earnings ledger | 10 years, the legal accounting period |
| Consents given | for as long as the account exists, plus the statute-of-limitations period — they are proof of what you accepted |
| Account data | until the account is deleted (see section 12) |
10. Disclosure to third parties
We may share data with service providers, only under adequate agreements (DPAs), and only what is necessary:
- Stripe — payments and payout account verification (section 8).
- Our telephony provider — establishing masked calls (section 6).
- Our SMS and email providers — sending notifications and verification codes.
- The browser's push notification service (Google, Apple, Mozilla) — receives an encrypted message only your phone can read.
- Anthropic — automated analysis of a task's photos and automated verification of completion evidence. Receives the task's photos and text, not your identity.
- Our hosting and mapping providers.
Transfers outside the EU are made with legal safeguards (standard contractual clauses). We do not sell data to anyone and we do not run behavioral advertising.
11. Your rights
- Access, rectification, erasure ("the right to be forgotten").
- Restriction, portability, objection.
- Withdrawing consent at any time (does not affect processing already carried out).
- Filing a complaint with ANSPDCP (Romania's data protection authority): dataprotection.ro.
If you're a provider, the annual summary we report about you to the tax authority is always visible in your wallet — it's exactly the figures filed, not a recalculation.
12. Account deletion
Deleting your account anonymizes your data rather than destroying all of it — and it's worth explaining why, since it is a genuine limitation of the right under Art. 17.
A payment has two participants. If we fully deleted one participant's account, the other's payment would be left unexplained: the books wouldn't close, last year's tax filing would come out differently from one month to the next, and the provider who worked for you could no longer prove where the money came from. The earnings ledger is, by design, a ledger where nothing can be deleted.
What disappears: your name, email address, phone numbers, mailing address, avatar, password, profile description, your base point on the map, the address and photos of your tasks, every position ever recorded, all notification subscriptions, and the numbers in your call history. From the texts you wrote — messages, review comments — contact details are stripped out.
What remains: the amounts, commissions, payments and ledger lines, without your name; the ratings you gave (a number about someone else); and proof that you accepted the terms, which is exactly what needs to be kept after your identity is gone.
What we cannot delete: the data you entered directly with Stripe. Your connected account is closed at our request, but Stripe has its own legal retention obligations, and those don't depend on us.
The request cannot be carried out while you still have a task in progress, an unresolved dispute, an unwithdrawn balance, or a withdrawal in progress — all of these resolve on their own or through a step you can take today, and you're told exactly what it is. Send your request to privacy@servico.ro; we respond within 30 days at most.
13. Security
We apply appropriate technical and organizational measures (encryption in transit, access controls, logging). No method offers absolute security.
15. Contact & DPO
Controller: SC DESTIN ENTREPRISE SRL (in the process of incorporation)
Privacy email: privacy@servico.ro
Data Protection Officer (DPO): [if one is appointed, fill in here]
This document is for informational purposes and does not constitute legal advice.