Privacy policy
Last updated: September 2026
This page states what we actually collect — not what policies usually say.
What we collect
The company data you enter: name, description, services, contact details, photos.
Your mobile number for login (no password).
IP address and browser user-agent for each login session, and the latest address and agent per account — for security and investigation (we store the raw value, not only a hash, and automatically clear it from sessions older than 90 days; the last-login record keeps only the latest value).
Enquiry data: the sender's name, mobile number and message.
The trade licence image when you request verification.
Aggregated statistics: daily profile view counts with no visitor identifier.
What we do not collect
No tracking cookies, no ads and no visitor profiles, and we do not sell any data.
We do not store your card details: payment happens directly with Stripe.
How we use it
To run the profile and search, send your login code, notify you of enquiries, review verification, and protect the service from abuse.
Security
Login is by a one-time code, sessions are stored hashed, IP addresses are hashed with a secret in security logs, and uploaded images are re-encoded.
Who we share with
The SMS provider (login code), the email provider (enquiry notification), Stripe (subscription), and the hosting and database provider. We never share your data for marketing.
When geographic blocking is enabled: the visitor's IP address is sent to the verification provider (ip-api.com) to determine the connection country and network type (VPN/proxy) — we do not store it ourselves.
Location search in the profile editor goes through our server to OpenStreetMap (Nominatim), sending only the query and no visitor identifier.
Retention and rights
We keep data while your account exists. You can ask us to correct or delete it, and we will respond within a reasonable time.
Changes
Any material change is posted here with the Last updated date.