Privacy

AppConsult — appconsult.net

This notice describes how AppConsult processes personal data for the marketplace (web/PWA). It is a starter template for your legal review and should be customised before production launch.

Data we process

  • Account data from Supabase Auth (e.g. email).
  • Profile, booking, payment metadata, and messages you submit in-app.
  • Verification documents you upload (stored in Supabase Storage).
  • Assistant queries logged for product analytics (see Insights).
  • Optional in-app notifications and booking chat messages between client and professional for a confirmed booking.
  • Payment data handled by Paystack (South Africa) and Stripe (UK); we do not store full card numbers.

Purposes & legal bases (UK GDPR)

We process data to provide the service (contract), improve safety and fraud prevention (legitimate interests), and comply with law. Where required, we will rely on consent (e.g. marketing — not enabled in this MVP).

South Africa (POPIA)

We process personal information lawfully, minimise collection, and aim to keep data accurate. You may request access or correction subject to operational limits.

Retention

Bookings and financial records may be retained for a period required by tax and accounting rules. Chatbot logs may be retained for analytics; configure deletion jobs to match your policy.

Processors

We use Vercel (hosting), Supabase (database, auth, storage), Paystack and Stripe (payments), Twilio/Resend (optional messaging), and OpenRouter and/or OpenAI (optional assistant). Sub-processor agreements should be reviewed with counsel.

Terms of service