Privacy Policy
Last updated 15 July 2026
1. What we collect
Only what the platform needs to work:
- Account — name, email, phone (optional), password (hashed with bcrypt, never stored or recoverable in plain text).
- Money — your wallet balance and every transaction: what moved, when, between whom, and against which order.
- Activity — orders, bookings, tickets, posts, messages, ride and tutoring records.
- Security — sign-in attempts (successful and failed) with IP and browser, and an audit log of significant actions.
- Usage — page and feature events, to see what is used.
- Uploads — files you attach, with their real detected type and size.
2. Why
- To run your account and process payments through escrow.
- To show you your own history and prove where money went.
- To detect abuse — failed sign-ins, referral farming, spam.
- To answer your support tickets.
- To understand which parts of the platform are used, in aggregate.
3. Who can see what
This is the part most policies are vague about, so plainly:
- Private messages and their attachments are visible to the people in the conversation. Attachments are stored outside the public web root and served only after a membership check — there is no guessable link.
- Support tickets are visible to you and to support staff. They are not public.
- Admins can see account details, status, roles, wallet balance and your audit trail. They cannot see your password (nobody can) or your message contents through the admin console.
- Anonymous posts hide your name from other students, but your identity is still recorded so moderators can act on abuse. Anonymity here means "your name is hidden", not "nobody knows".
- Other students see your name and what you deliberately publish.
4. What we do not do
- We do not sell your data.
- We do not share it with advertisers. Advertisers on the platform get counts — impressions and clicks — never who you are.
- We do not read your private messages for advertising.
5. Retention
Account data is kept while your account exists. Deleting an account removes your personal records; some things survive deliberately:
- Financial records, because the ledger must reconcile and the other side of a transaction has a right to their own record.
- Audit and analytics counts, anonymised — the event stays, the link to you does not.
6. Your rights
You can view and correct your details in Settings, see your sign-in history under Security, and revoke API tokens. For a copy of your data or a deletion request, raise a ticket.
7. Security
Passwords are bcrypt-hashed. Uploads are validated by content and stored outside the web root. Forms are CSRF-protected. Sign-in is rate-limited.
Being straight with you: this build runs over plain HTTP in development. A real deployment must use HTTPS. No system is perfectly secure.
8. Contact
Contact us with any privacy question.