Privacy notice
Last updated 8 October 2026
HelpFinder is a locally operated marketplace. The Owner of the installation controls its database, uploaded files, and backups. Find the configured privacy contact on Help & Support before you provide personal information.
Information the marketplace stores
- Account name, email, email verification status, role, a password hash, and account activity. Provider profiles can include a business name, biography, skills, and service areas.
- Customer problem descriptions, location details, service area, budget, preferred time, and any photos the Customer adds.
- Offers, job status history, messages, completion evidence photos and notes, reviews, disputes, notifications, and records of externally verified payment outcomes.
- Security and audit records, including login attempt information and source IP addresses. Session and CSRF tokens are stored as hashes in the database.
How information is used and shared
The app uses account details to sign people in and apply role permissions. It uses problem, skill, and service area details to show matching work to Providers and support offers and jobs. Matching is based on saved skills and area names. Admins and the Owner can review operational and security records to manage the marketplace.
Before hiring, eligible matching Providers can see the problem description, photos, category and skill, service area, budget, urgency, and preferred schedule. They cannot see the separately entered exact job address or account contact fields through the opportunity view. A Provider assigned to the job can see the exact job address. Unrelated Providers cannot access the problem photos or job location. Please check descriptions and photos for addresses, phone numbers, entry codes, IDs, and other details you do not want matching Providers to see before hiring.
Customers can see Provider offer and profile details. Customer and assigned Provider can see their job history and messages. Completion evidence is available to job participants and authorized staff.
The current app serves its own pages and does not include advertising or third-party analytics scripts. If an operator deploys the app through another hosting or network service, that operator must explain any additional providers or data transfers separately.
Cookies and security
After sign-in, the app sets a session cookie and a CSRF cookie so it can keep you signed in and protect write requests. The session cookie is HttpOnly. Sessions expire after seven days unless revoked earlier. Privileged accounts use multi-factor authentication. Passwords and reset tokens are not stored in plaintext; uploaded photos are kept outside the public web directory and served through permission checks.
Storage and deletion
The current local version keeps account and marketplace records in a SQLite database and photos in a private uploads folder. It has no automatic account deletion or general retention schedule. Records remain until the Owner handles them, and copies may remain in backups. The Owner should define a retention and deletion process before using the app with real people.
Your requests
To ask about, correct, or request removal of your information, use the privacy contact on Help & Support. The operator should verify the request and explain what can be changed or retained under the rules that apply where the service operates.
See the Terms of use for how the marketplace works.