Legal
Privacy Policy
Effective date: 1 July 2025
1. Who We Are
LocalsOnDemand("we", "our", "us") operates the LocalsOnDemand.me platform — a marketplace connecting visitors with verified local professionals in Montenegro. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our Platform.
We process personal data in accordance with applicable Montenegrin data protection law and, where relevant, the EU General Data Protection Regulation (GDPR) as applied to users based in the European Economic Area.
2. Data We Collect
Account information: Name, email address, phone number, and profile photo when you create an account or provider profile.
Identity verification data (Providers only): Government-issued identity document images (passport or national ID), a live selfie photograph, and the result of biometric facial comparison. This data is processed to verify Provider identity before any bookings are accepted.
Booking data: Service type, date and time, address of service delivery, number of guests, payment method, and booking status.
Payment data: Payment is processed entirely by Stripe. We do not store full card numbers, CVVs, or bank account details. We receive confirmation tokens, payment IDs, and transaction metadata from Stripe.
Communication data: Messages exchanged between Clients and Providers through the in-Platform messaging system.
Review data: Ratings and written reviews submitted after completed bookings.
Usage data: IP address, browser type, pages visited, and timestamps of interactions with the Platform, collected automatically for security and analytics purposes.
3. How We Use Your Data
We use your personal data to:
- Create and manage your account and Provider profile.
- Facilitate bookings and communicate booking details to both parties.
- Process payments and manage payouts to Providers via Stripe Connect.
- Verify Provider identity using automated facial recognition (AWS Rekognition).
- Send transactional emails (booking confirmations, reminders, receipts) via Resend.
- Send SMS notifications via Twilio when relevant (e.g. booking reminders).
- Detect and prevent fraud, abuse, and policy violations.
- Provide customer support and resolve disputes.
- Improve the Platform through aggregated analytics.
Legal basis (GDPR): We rely on contractual necessity (Art. 6(1)(b)) for account management and booking processing; legitimate interests (Art. 6(1)(f)) for security and fraud prevention; and consent (Art. 6(1)(a)) for optional marketing communications. Biometric processing for identity verification is carried out under Art. 9(2)(a) (explicit consent).
4. Identity Verification and Biometric Data
Providers are required to submit an identity document and selfie for verification. This information is transmitted to Amazon Web Services (AWS Rekognition) for automated face-matching. The comparison result (match percentage) is stored in our database. Facial images themselves are stored in Cloudflare R2 object storage with restricted access.
Identity document images and selfies are retained for 90 days after account closure or verification completion, after which they are permanently deleted. Verification results (pass/fail, score) are retained for the lifetime of the Provider's account for audit purposes.
We do not sell or share biometric data with third parties other than AWS for the sole purpose of the verification process described above.
5. Third-Party Services
We share data with the following third-party processors:
- Clerk (authentication): Manages sign-in, sign-up, and session management. Your email address and name are stored with Clerk. Privacy policy: clerk.com/privacy
- Stripe (payments):Processes all card payments and Provider payouts. Subject to Stripe's Privacy Policy at stripe.com/privacy.
- AWS Rekognition (identity verification): Used solely for biometric face comparison during Provider onboarding. Data is not used for any other AWS purpose.
- Cloudflare R2 (file storage): Stores profile photos, identity documents, and selfies in encrypted object storage.
- Resend (email): Sends transactional emails on our behalf. Recipient email addresses and email content are shared.
- Twilio (SMS): Sends optional SMS notifications. Your phone number and message content are shared where SMS is enabled.
- Neon (database):Our PostgreSQL database is hosted on Neon's serverless infrastructure in the EU. Data at rest is encrypted.
6. Data Retention
We retain your data for as long as your account is active. Upon account deletion:
- Profile information is deleted within 30 days.
- Booking and payment records are retained for 7 years for legal and financial audit purposes.
- Biometric images are deleted within 90 days.
- Reviews are anonymised but retained to preserve platform integrity.
- Chat messages are deleted within 30 days.
7. Cookies
We use essential cookies to maintain your session and authentication state. We do not use third-party advertising cookies or tracking pixels. Strictly necessary cookies cannot be disabled without breaking core Platform functionality.
We may use anonymised analytics cookies (without cross-site tracking) to understand how users interact with the Platform. You may opt out of analytics cookies at any time in your account settings.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of all data we hold about you.
- Rectification: Correct inaccurate or incomplete data.
- Erasure:Request deletion of your data ("right to be forgotten"), subject to legal retention requirements.
- Portability: Receive your data in a machine-readable format.
- Restriction: Ask us to limit processing of your data in certain circumstances.
- Objection: Object to processing based on legitimate interests.
- Withdraw consent: For processing based on consent (e.g. biometric verification), you may withdraw at any time — this will end your Provider access.
To exercise any of these rights, contact us at privacy@localsondemand.me. We will respond within 30 days. If you are unsatisfied with our response, you may lodge a complaint with the competent data protection authority in Montenegro (Agency for Personal Data Protection and Free Access to Information — AZLP).
9. Data Security
We implement industry-standard security measures including TLS encryption in transit, AES-256 encryption at rest (via Neon and Cloudflare R2), access control policies, and regular security audits. Stripe handles all payment data and is PCI-DSS Level 1 certified.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected users and the competent authority within 72 hours of becoming aware, as required by law.
10. International Transfers
Some of our third-party processors are based outside the EU/EEA (notably AWS, Stripe, Twilio, Cloudflare). Where data is transferred internationally, we rely on Standard Contractual Clauses (SCCs) or other adequacy mechanisms approved under GDPR to safeguard your data.
11. Children
The Platform is not directed at individuals under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with data, please contact us and we will delete it promptly.
12. Changes to this Policy
We may update this Privacy Policy from time to time. We will notify you by email at least 14 days before material changes take effect. The current version is always available at localsondemand.me/privacy.
13. GDPR — Summary of Your Rights and Our Obligations
This section consolidates your key rights under the EU General Data Protection Regulation (GDPR) and equivalent Montenegrin data protection law in one place for ease of reference.
Data we collect:
- Identity data: name, email, phone number, profile photo.
- Verification data (Providers): identity document images, selfie, biometric comparison score.
- Booking and transaction data: service details, dates, addresses, payment confirmation tokens.
- Usage data: IP address, browser, pages visited, session timestamps.
Retention periods:
- Account and profile data: deleted within 30 days of account closure.
- Booking and payment records: retained for 7 years for legal and financial compliance.
- Biometric images (identity document, selfie): deleted within 90 days of verification.
- Chat messages: deleted within 30 days of account closure.
- Reviews: anonymised but retained indefinitely to preserve platform integrity.
Right to deletion (erasure):
You may request deletion of your personal data at any time by contacting us at privacy@localsondemand.me. We will action your request within 30 days. Certain data categories (booking records, payment history) are exempt from deletion where retention is required by law. We will inform you of any such exemptions when responding to your request.
Sub-processors (data processors acting on our behalf):
- Stripe— payment processing and Provider payouts. Processes cardholder data and payout recipient data. Subject to Stripe's Data Processing Agreement and PCI-DSS Level 1 certification.
- Clerk— authentication and session management. Stores your email address, name, and authentication credentials. Subject to Clerk's Data Processing Agreement.
- Resend — transactional email delivery. Receives recipient email addresses and email content for the purpose of sending booking confirmations, reminders, and receipts.
Each sub-processor is bound by a Data Processing Agreement and is prohibited from using your data for any purpose other than providing the specified service to LocalsOnDemand.
14. Contact
For privacy-related enquiries, requests, or concerns, contact us at: privacy@localsondemand.me