Privacy Policy
Manole (also branded “Two Peaks”) is a mobile marketplace that connects customers with local service providers (handymen and businesses). This policy explains what personal data we collect, why, who processes it, and the rights you have — including the deletion and export tools built into the app.
1. Data we collect
Account & profile data (you provide it):
- Email address and password (stored only as a secure hash by our authentication provider; we never see it).
- Display name, account type (customer / handyman / business), and optional profile details: bio, phone number, avatar photo, city/region, map location, service categories and skills, service areas, portfolio photos.
- Provider business details you choose to add: business name, website, registration number, team size, hourly rates.
- Profile visibility preference (public / contacts-only / private) — you control who can see your profile.
Content you create: job posts and service posts (title, description, budget/pricing, photos, optional location); chat messages and chat images; reviews you write and receive; reports you file; identity-verification requests and the documents you upload for them.
Technical data: push-notification device tokens; crash reports via Firebase Crashlytics (device model, OS version, stack traces — production builds only); product analytics via PostHog (screen views and feature-usage events tied to an opaque user id; message contents and other free text are not sent to analytics).
We do not collect: payment or card data (the app has no payments), contacts, or precise background location (location is only what you set on your profile/posts or pick when searching).
2. Why we process it (legal bases)
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Provide the service: accounts, profiles, posts, chat, reviews | account, profile, content | Contract (Art. 6(1)(b)) |
| Show providers/jobs near a location you choose | location fields you set | Contract |
| Chat push notifications | device tokens, message metadata | Contract; disable anytime in Settings → Notification Preferences |
| Trust & safety: reports, blocking, moderation, identity verification | reports, verification documents, block records | Legitimate interest (Art. 6(1)(f)) |
| Crash reporting & product analytics | technical data | Legitimate interest |
| Auth emails (confirmation, password reset) | email address | Contract |
3. Who sees what (visibility inside the app)
- Your profile is visible according to your visibility setting; “public” profiles (the default) are visible to anyone browsing the app, including signed-out visitors.
- Active job/service posts are public to app users.
- Chat messages and images are visible only to conversation participants (and to moderation when investigating a report).
- Reviews are public on the reviewed profile.
- Verification documents are visible only to you and to administrators reviewing your request.
4. Processors we use
| Processor | What it does | Data it touches |
|---|---|---|
| Supabase | database, authentication, file storage, server functions | account / profile / content data |
| Google Firebase — Cloud Messaging | delivers push notifications | device tokens, notification payloads (sender name + message preview) |
| Google Firebase — Crashlytics | crash reporting | device / technical crash data |
| PostHog (EU cloud) | product analytics | opaque-id usage events |
| Google Maps Platform | location search / place picking | the places you search or pick |
| Resend | sends auth emails from manole.live | your email address |
We do not sell personal data and we do not share it with third parties for their own advertising.
5. International transfers
Analytics is pinned to PostHog’s EU cloud. Supabase project region: EU Central (Frankfurt, eu-central-1). Firebase
(Google) and Resend may process data outside the EEA; where that happens, transfers rely on the
EU–US Data Privacy Framework and/or Standard Contractual Clauses as applicable.
6. Retention
Account and content data are kept while your account exists. When you delete your account (Settings → Account → Delete account), your personal data is immediately anonymized: your name, email, phone, photo, bio and location are removed or blanked, your listings are cancelled, your personal files (avatar, portfolio, post images, verification documents) are deleted, and sign-in is permanently blocked. Messages and reviews you exchanged with other people are retained in anonymized form (“Deleted user”) so other users’ conversations and ratings stay intact. For full erasure of those remnants, contact us (Section 8). Crash and analytics data are retained per the processors’ standard rolling windows.
7. Your rights (GDPR)
You can access, rectify, erase, restrict, object, and port your data. In the app: Settings → Account → Export my data (machine-readable JSON copy) and Settings → Account → Delete account. For anything else contact support@manole.live. Under GDPR Art. 77 you may also lodge a complaint with the data-protection supervisory authority of your own EU country — in your place of residence, your place of work, or where the issue occurred. The European Data Protection Board lists every national authority.
8. Contact
Manole — a company registered in the European Union
Email: support@manole.live
9. Children
Manole is not directed at children and requires users to be at least 18 years old (see the Terms of Service). We do not knowingly collect data from minors.
10. Changes to this policy
We will post any changes at this URL and update the effective date. Material changes will be announced in the app.