Privacy Policy
Effective Date: October 5, 2026
Your Privacy Matters
This Privacy Policy explains how Tinkr collects, uses, and protects your personal information in compliance with GDPR and other applicable privacy laws. We are committed to transparency and giving you control over your data.
1. Data Controller and Contact Information
2. Information We Collect
2.1 Personal Information You Provide
| Data Type |
Purpose |
Legal Basis |
Account Information Name, email, phone number, date of birth |
Account creation, identity verification, communications |
Contract performance, legitimate interests |
Profile Information Bio, skills, availability, profile photo |
Marketplace functionality, matching users |
Contract performance |
ID check (everyone) A photo of your passport, ID card or driving licence, checked by Stripe Identity before you can post a task or apply for one |
Making sure everyone on Tinkr is who they say they are, and fraud prevention. Photos of your ID go only to Stripe; Tinkr does not see or keep them. Tinkr keeps whether the check passed. To stop people who were banned from coming back with a new account, Tinkr also keeps a one-way code made from the verified name and date of birth (the details themselves can't be read back from it). It is compared with other accounts and deleted when you delete your account, unless your account was banned, in which case it is kept to enforce the ban. |
Legitimate interests (safety and fraud prevention) |
Payment Information Bank details, transaction history |
Payment processing, financial reporting, service fees from Task Posters only |
Contract performance, legal compliance |
Payout setup (Task Takers) Name, date of birth, home address, bank account (IBAN), the ID check above and, if Stripe asks for it, a proof of address |
Verifying your identity and paying out your earnings. These details are sent from your device directly to our payment partner Stripe, which verifies them as a regulated payment provider (anti-money-laundering rules). Photos of your ID go only to Stripe; Tinkr does not see or keep them. Tinkr keeps the last 4 digits of your IBAN to show you where payouts go, and the verification status. |
Contract performance, legal obligation (Stripe) |
Tax reporting (DAC7, Task Takers) Name, date of birth, home address, IBAN, citizen service number (BSN), and your earnings, number of tasks and the fees Tinkr kept, per quarter |
The yearly report Tinkr must make to the Dutch Tax Administration (Belastingdienst) under EU Directive 2021/514 (DAC7). Tinkr keeps these details encrypted, with access limited to staff who prepare the report. Your BSN is used only for this report, as Dutch law allows. |
Legal obligation |
Location Data Address, GPS coordinates (with consent) |
Task matching, service delivery |
Consent, contract performance |
2.2 Information We Collect Automatically
- Device Information: Device type, operating system, app version
- Usage Data: App interactions, features used, time spent
- Location Data: General location for task matching (with permission)
- Communication Data: In-app messages, ratings, reviews
- Technical Data: IP address, browser type, log files
2.3 Information from Third Parties
- Payment processors for transaction verification
- University partners for student verification
We do not currently use background check providers or social media account linking. If we introduce these in the future, we will update this section accordingly.
3. How We Use Your Information
We use your personal information to:
- Provide and improve our marketplace services
- Match Task Posters with suitable Task Takers
- Process payments and maintain transaction records
- Verify user identity and prevent fraud
- Facilitate communication between users
- Provide customer support and resolve disputes
- Send important updates about your account or our services
- Comply with legal obligations and enforce our Terms
- Improve platform safety and security
- Analyze usage patterns to enhance user experience
4. Legal Basis for Processing (GDPR)
| Processing Purpose |
Legal Basis |
| Platform services, task matching, payments |
Contract performance |
| Marketing communications (optional) |
Consent |
| Fraud prevention, platform security |
Legitimate interests |
| Financial reporting, tax compliance |
Legal obligation |
| Emergency safety features |
Vital interests |
5. Information Sharing and Disclosure
5.1 With Other Users
- Profile information (name, photo, ratings, bio) visible to other users
- Task-related communications and ratings
- Verification status (if you choose to display it)
- General location area for task matching
5.2 With Service Providers
- Payment Processor: Stripe for secure payment processing and fraud prevention, and for verifying Task Takers' identity and bank details and holding their earnings (Stripe acts as a separate controller for this under its own privacy policy)
- Tax authority: the Dutch Tax Administration (Belastingdienst) receives the yearly DAC7 report about Task Takers' earnings, which it may share with other EU tax authorities as the directive requires
- Backend Infrastructure: Supabase for database hosting, authentication, and data storage
- Communication: Email and SMS service providers
- Error reporting: Sentry receives technical details when the app runs into an error (what went wrong, the page, browser and device type, and your account number), so we can fix it. It does not receive your name, email address, IP address, messages or payment details
- Analytics: Anonymized usage data for platform improvement
- Customer Support: Third-party support platforms
5.3 For Legal Reasons
We may disclose your information when required to:
- Comply with legal obligations or court orders
- Protect the rights, property, or safety of Tinkr, users, or the public
- Investigate and prevent fraud or security issues
- Enforce our Terms of Service
6. Data Retention
We retain your personal information for as long as necessary to provide our services and comply with legal obligations:
- Active accounts: Data retained while account is active
- Closed accounts: Most data deleted within 90 days
- Transaction records: Retained for 7 years for tax/legal compliance
- DAC7 tax details (Task Takers): Kept while your account is open. If you close your account after earning through Tinkr, they are kept until the end of the 7th year after the last report and then deleted; if you never earned anything, they are deleted when you close your account
- Safety records: Incidents and reports retained for 5 years
- Marketing consent: Removed immediately upon withdrawal
7. Your Rights Under GDPR
You have the following rights regarding your personal data:
7.1 Right of Access
Request a copy of all personal data we hold about you. Currently handled by request to our privacy team (see below).
7.2 Right to Rectification
Correct any inaccurate or incomplete personal data. Many profile fields can be edited directly in the app; anything else can be corrected by request.
7.3 Right to Erasure ("Right to be Forgotten")
Request deletion of your personal data in certain circumstances. You can delete your account directly from Account Settings in the app — this immediately anonymizes your profile and removes your saved payment methods (any released earnings are first paid out to your bank account; they are never forfeited), subject to the retention exceptions in Section 6 (e.g. transaction records we must keep for tax purposes).
7.4 Right to Restrict Processing
Limit how we use your data in certain situations. Currently handled by request to our privacy team.
7.5 Right to Data Portability
Receive your data in a structured, machine-readable format. Transaction history can be exported as a CSV file directly from the app; a full data export is currently handled by request to our privacy team.
7.6 Right to Object
Object to processing based on legitimate interests or for marketing purposes. Marketing preferences can be changed directly in the app; other objections can be made by request.
7.7 Right to Withdraw Consent
Withdraw consent at any time where processing is based on consent, such as marketing communications or location access, either directly in the app's settings or by request.
Exercising Your Rights
To exercise any of these rights, contact us at privacy@tinkr.care. We will respond within 30 days and may require identity verification.
8. Data Security
We protect your data through:
- End-to-end encryption for sensitive communications
- SSL/TLS encryption for data transmission
- Secure cloud storage with access controls
- Regular security audits and penetration testing
- Employee training on data protection practices
- Multi-factor authentication for admin access
- Regular data backups with encryption
- Incident response procedures for data breaches
Data Breach Notification
In the unlikely event of a data breach affecting your personal information, we will notify you and relevant authorities within 72 hours as required by GDPR.
9. International Data Transfers
As a Netherlands-based company, we primarily process data within the European Economic Area (EEA). When we transfer data outside the EEA, we ensure adequate protection through:
- European Commission adequacy decisions
- Standard Contractual Clauses (SCCs)
- Certified providers under the EU-U.S. Data Privacy Framework (DPF) or equivalent successor frameworks
- Binding Corporate Rules where applicable
10. App Storage and Tracking Technologies
Tinkr is a mobile and web application rather than a traditional browser-based website, so we don't use browser cookies in the way a marketing website would. Instead, we use the following technologies:
10.1 Technologies We Use
| Technology |
Purpose |
Duration |
| Session Tokens |
Keeping you securely logged in |
Until you log out or the session expires |
| Local App Storage |
Saving your preferences (e.g. language, notification settings) on your device |
Until you change the setting or delete the app |
| Analytics SDKs |
Understanding app usage and improving reliability, using anonymized/aggregated data where possible |
Varies by provider |
If Tinkr operates a separate marketing website that uses browser cookies, that website will present its own cookie notice describing the specific cookies used there.
10.2 Managing These Settings
You can manage notification and marketing preferences directly in the app's account settings, and control device-level permissions (such as location access) through your device's operating system settings.
11. Children's Privacy
Age Restrictions:
- Tinkr is intended solely for individuals 18 years of age or older
- We do not knowingly collect personal data from anyone under 18
- If we become aware that we have collected data from someone under 18, we will delete it promptly
- Parents or guardians who believe a minor has provided us with personal data can contact us to request its removal
12. Marketing Communications
12.1 Types of Communications
- Transactional: Task updates, payment confirmations, account changes
- Service-related: Platform updates, safety notifications, policy changes
- Marketing: Promotional offers, new features, community updates (opt-in only)
12.2 Opting Out
You can unsubscribe from marketing communications at any time through:
- Unsubscribe links in emails
- Account settings in the app
- Contacting customer support
- Emailing privacy@tinkr.care
13. Third-Party Services and Links
Our platform may contain links to third-party websites or integrate with external services:
- Payment Processor: Stripe (subject to their privacy policy)
- Maps Services: Google Maps for location services
- Analytics: Anonymized data sharing with analytics providers
Accounts are currently created using email and password only; we do not offer social media login at this time.
We are not responsible for the privacy practices of third-party services. Please review their privacy policies before using these services.
14. Student-Specific Privacy Protections
Special Protections for Student Users:
- Student status verification data is encrypted and access-restricted
- Educational institutions cannot access individual student activity
- Student discount eligibility is processed separately from personal profiles
- Partnership data with universities is anonymized and aggregated
- Students can request removal of academic affiliations at any time
15. Automated Decision Making and Profiling
15.1 Automated Processes
We use automated systems for:
- Task Matching: Algorithm-based matching of tasks to suitable users
- Fraud Detection: Automated screening for suspicious activity
- Risk Assessment: Safety scoring based on user behavior patterns
- Pricing Suggestions: Market-based pricing recommendations
15.2 Your Rights
You have the right to:
- Request human review of automated decisions
- Challenge automated decisions that significantly affect you
- Understand the logic behind automated processing
- Opt out of certain automated processing where possible
16. Data Subject Complaints
If you believe we have not handled your personal data properly, you have the right to:
- Contact us directly: privacy@tinkr.care
- File a complaint with your local supervisory authority: In the Netherlands, this is the Autoriteit Persoonsgegevens (AP)
- Seek legal remedies: Through competent courts in the EU
17. Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal information may be transferred to the new entity. We will notify you of any such transfer and ensure the receiving party maintains equivalent privacy protections.
18. Updates to This Privacy Policy
Policy Updates:
- We may update this Privacy Policy to reflect changes in our practices or legal requirements
- Significant changes will be communicated via email and in-app notifications
- Continued use of our services after updates constitutes acceptance
- You can access previous versions by contacting our support team
19. Specific Regional Considerations
19.1 Netherlands and EU Users
- Full GDPR compliance and rights
- Data processed according to Dutch data protection laws
- Right to file complaints with Autoriteit Persoonsgegevens
19.2 California Residents (if applicable)
- Rights under California Consumer Privacy Act (CCPA)
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of sale of personal information (we do not sell data)
20. Contact Information and Data Requests