Perfection Dynamics — Privacy Policy
Effective date: 2026-07-18 Version: v1.2-2026-07-18
This Privacy Policy explains what data Perfection Dynamics ("the Platform", "we", "us") collects about you, what we do with it, and what choices you have. It applies to your use of the Platform at perfectiondynamics.com and our transactional emails.
By using the Platform, you agree to the data practices described here. If you do not agree, do not use the Platform.
1. What we collect
Account information
- Email address
- Password (stored as a cryptographic hash; we never see the plaintext)
- Full legal name
- Phone number
- ZIP code and service address (Homeowners) or service-radius ZIP (Tradesmen)
- Whether you have a Homeowner capability, a Tradesman capability, or both (we run a single dual-capability account model)
Tradesman-specific
- Business name (optional)
- Service radius (miles) and trades description (free-text list of work you accept)
- General-liability insurance policy number (if you carry one; we record it but do not verify it)
- Stripe Connect account identifier and capability flags (
charges_enabled,payouts_enabled,transfers) - If you opt in to the Starter Kit Program (Terms Section 21), the payment method you provide is stored with Stripe for off-session use, so the card-charge backstop can run at the deadline without you being present. The Platform does not store card numbers; Stripe does.
Job-related
- Job postings: title, description, task list, materials specification, address, postal code, ZIP, bounty, scheduling preferences
- Photos and video you attach to jobs at posting time
- Work-completion documentation: photos and notes the Tradesman uploads at mark-complete
- Dispute submissions: written reasons + photos from each party, stored in segregated evidence pools so the opposing party never sees your dispute documentation. Only the Platform reviewer sees both pools.
- Structured-coordination state: arrival window, running-late pulse
- Notification records (which transactional message we sent you when, and what payload was assembled)
- Ratings you submit: a 1-to-5 star score, an optional written note, and context recorded at the moment of rating (your prior rating activity, account age, the job's value, the counterparty's prior rating volume, and a coarse advisory device signal). See Section 10A.
Support tickets
- Subject, body, optional Stripe / opaque-error reference number
- Up to 3 screenshots per ticket
- The page URL you were on when you opened the support widget (auto-captured)
- Your IP address at submission time (for rate-limiting and abuse detection)
Behavioral analytics
- Product analytics events captured via Posthog (page views you opt into, button clicks, funnel progression). We use explicit-only capture — no autocapture, no auto-pageview. The event taxonomy is published at
/admin/funnel.
Operational signals (used for security, fraud prevention, and ban-evasion detection)
- IP addresses seen at signup and in recent use
- An active device fingerprint: a SHA-256 digest computed in your browser from your canvas rendering, audio-compressor characteristics, screen geometry, navigator features, and timezone. This is more specific than a user-agent string and is designed to be stable across sessions on the same device.
- The fingerprint of the payment card on file (a stable, non-reversible identifier Stripe derives from a card; not the card number)
- A hash of the billing address
- Your normalized phone number and name, used as linkage signals
- Geographic centroid derived from your ZIP code
- Stripe Connect identity-verification status
These signals are combined under a weighting model (strong signals link accounts on their own; weaker signals such as a shared IP or a shared name link accounts only in combination) to detect duplicate or evasive accounts. Stripe Connect identity verification gates whether a Tradesman can claim work; it is not itself an account-matching signal. These signals are not used for advertising and are not shared with third parties for marketing.
2. Third-party services that hold your data
Each of the following services holds a slice of your data per its own privacy policy. We choose vendors that comply with industry-standard security practices.
| Service | What they hold | Their privacy notice |
|---|---|---|
| Supabase | Database, authentication, file storage (Job + dispute + support attachments). U.S.-hosted. | supabase.com/privacy |
| Stripe Connect | Tradesman identity verification (legal name, DOB, SSN/EIN, ID-document images, bank routing/account). We never see bank or ID-document information. | stripe.com/privacy |
| SendGrid (Twilio) | Email addresses + assembled transactional message bodies. | twilio.com/en-us/legal/privacy |
| PostHog | Behavioral event names, timestamps, anonymized distinct IDs, page paths, explicit event properties. We do not send PostHog passwords, payment data, or party-to-party content. | posthog.com/privacy |
| Vercel | Hosting, edge routing, server logs (IP, user-agent, route). Logs retained per Vercel defaults. | vercel.com/legal/privacy-policy |
| Cloudflare (DNS) | DNS resolution. We do not run Cloudflare's WAF/proxy on the application by default. | cloudflare.com/privacypolicy/ |
3. What we use it for
- Operate the Platform: route jobs, hold and capture escrow, dispatch notifications, process payouts.
- Enforce the dispute process: surface both parties' submissions to the Platform reviewer (each party never sees the other's submission).
- Detect fraud and ban evasion: identify duplicate accounts, sanction-list users, and circumvention attempts.
- Improve the Platform: behavioral analytics inform what we build next.
- Triage support tickets: we may use AI tooling to classify, summarize, or pre-route incoming tickets. AI classification is not the basis of any binding decision; a human reviews any action that affects your account or balance.
- Anonymized featured-work display ("Hall of Fame"): completed-job titles, descriptions, photos, and rounded prices may appear on
/feedand in marketing materials with no party identifiers. - Comply with legal obligations: tax reporting on Stripe's side, lawful subpoenas, court orders.
We do not sell your data. We do not share your data with advertisers. We do not profile you for purposes outside the Platform's operation.
4. Who sees what
- Other Homeowners never see your data.
- Other Tradesmen browsing open postings see them across the Platform's service area (postings are no longer filtered to a Tradesman's own service radius; distance is shown as information, not a gate). Before claiming, a Tradesman sees the neighborhood only: city and ZIP, plus distance, the job title, description, task list, and bounty. A Tradesman does not see the Homeowner's street address, name, or phone number until they claim the job. On claim, the full street address and the coordination details needed to perform the work are released to the claiming Tradesman.
- The Tradesman who claims your job sees, after claim: your full street address, your first name, your phone number (released by the Platform for arrival coordination), the job posting and the photos you attached at posting time, and your work-completion confirmation. If you open a dispute, the Tradesman is shown your written dispute reason, but not your dispute photos or video (photographs and video are segregated by side; see the Terms of Service, Section 7).
- The Homeowner who posted a job sees the Tradesman's business name (or full name), trades description, Stripe-verified status, and, once enough ratings exist, the Tradesman's average star rating. The Homeowner does not see the Tradesman's work-completion photos at any point (they inspect the work in person), and does not see the Tradesman's dispute response or response photos.
- The Platform principal has administrative read access for support, dispute resolution, and analytics. Administrative reveals of personally identifying fields are logged for audit.
- The public web sees only the anonymized neighborhood-activity feed and Hall of Fame content (no names, no addresses, no exact prices).
5. Cookies and tracking
The Platform uses:
- Authentication cookies (Supabase Auth). These are essential; you cannot use the Platform without them.
- PostHog analytics cookies (anonymous distinct ID). You can opt out by clearing site data or by using a browser-level Do Not Track signal.
- Support widget context capture: when you open the support widget, the page URL you are on is captured and attached to your ticket so we can reproduce the issue. No additional cookies are set for this.
No third-party advertising cookies. No cross-site tracking pixels. No data brokers.
6. Your rights
You may at any time:
- Access the information we hold about you using the in-Platform support widget.
- Correct inaccurate information by editing your profile or by request.
- Delete your account and associated data. Records required for legal, regulatory, dispute-resolution, or anti-fraud purposes are retained for the period required. The anti-fraud and ban-evasion signals specifically retained despite a deletion request are: the payment-card fingerprint, the billing-address hash, the device fingerprint, the normalized phone and name, and the signup and recent IP addresses, together with any cluster-sanction evidence snapshot. These are load-bearing platform-safety mechanisms and are NOT removed by a delete request; see Section 7 (Data retention) and Section 9.
- Export your account data in a portable JSON format on request.
Stripe Connect–held data is governed by Stripe's privacy practices; account closure with Stripe must be initiated through Stripe directly.
7. Data retention
- Account data: retained while your account is active; deletable on request subject to legal-retention obligations.
- Job postings, completion records, and dispute submissions: retained for at least 24 months after capture for dispute, chargeback, audit, and regulatory purposes.
- Notifications log: retained indefinitely as an audit trail of platform-to-user communication.
- Support tickets and attachments: retained for at least 24 months after resolution.
- Fraud and ban-evasion signals (payment-card fingerprint, billing-address hash, device fingerprint, normalized phone and name, signup and recent IP): retained indefinitely for the accounts they were derived from; cluster-sanction evidence snapshots are retained for at least 7 years.
- Ratings, notes, and rating context: retained for as long as needed for reputation, safety, dispute-resolution, and legal purposes.
- Behavioral analytics: per PostHog's retention defaults.
- Server logs (Vercel, Supabase): per the providers' retention defaults (Vercel: short-lived; Supabase Pro: 7 days).
8. Security
- All Platform traffic is HTTPS (TLS terminated by Vercel).
- Authentication cookies are HTTP-only and secure.
- Sensitive credentials (database service role keys, Stripe secret, SendGrid API key, PostHog personal API key) are server-side only and never exposed to the browser.
- Dispute evidence and support-ticket attachments are stored in private Supabase Storage buckets; access requires server-mediated signed URLs.
- We use industry-standard practices (row-level security policies in the database, MFA-elevated access for admin surfaces, principle-of-least-privilege on third-party scopes).
No system is perfectly secure. If you suspect your account has been compromised, contact support immediately.
9. Fraud and ban-evasion
We retain operational signals (Section 1) for the explicit purpose of detecting duplicate accounts, sanction-list users, and circumvention of bans. These signals include the payment-card fingerprint, the billing-address hash, an active device fingerprint, the normalized phone number and name, and IP addresses, combined under a strong / weak weighting model so that ordinary shared infrastructure does not link unrelated people. We do not publish our detection thresholds.
If we determine that an account is a ban-evasion attempt, we will terminate that account and any related accounts and retain the underlying signals indefinitely for future detection. This is a foundational part of how the Platform maintains a trustworthy marketplace; it is not negotiable.
10. AI-assisted operations
We may use AI tooling (currently the Anthropic Claude API) for internal operations:
- Triaging incoming support tickets (classification + summary)
- Surfacing patterns across notifications and logs
- Drafting templated communications for human review
AI tooling is not the basis of any binding decision affecting your account, balance, dispute outcome, or eligibility. A human reviews any action that affects you materially.
We do not send the following to AI tooling: passwords, payment card data, Stripe Connect identity-verification data, or any field whose value is not appropriate for a third-party LLM provider.
10A. Ratings data
What we collect. When you submit a rating we collect the 1-to-5 score, your optional written note, and context recorded at the moment of rating that helps us weigh reliability and detect manipulation: your prior rating activity, your account age, the job's value, the counterparty's prior rating volume, and a coarse advisory device signal. This context is captured at the time of rating because it cannot be reconstructed later.
How we use it. Ratings and their context are used to (i) compute and display a Tradesman's aggregate star average, and (ii) support Platform quality, safety, and anti-manipulation analysis. We may in the future apply automated or machine-learning analysis to written notes for these purposes. If that processing involves a third-party AI service, that service will be a disclosed sub-processor under a data-processing agreement, and this Policy will name it before such processing begins. (Our current AI sub-processor for internal operations is named in Section 10.)
Who can see what. The other party never sees your raw score or your written note. Only a Tradesman's aggregate star average is shown, and only above the display threshold. Written notes are stored on our servers only, are scanned so that contact information is redacted for any internal review, and are accessible only to authorized Platform personnel, never to the counterparty.
Retention and your choices. We retain ratings, notes, and context for as long as needed for reputation, safety, dispute-resolution, and legal purposes (Section 7). You may request review or deletion consistent with those obligations and the integrity of the rating system.
11. Children
The Platform is not directed to anyone under 18, and we do not knowingly collect data from minors. If you believe a minor has provided us data, contact support and we will remove it.
12. Geographic scope
The Platform is operated from South Carolina and serves the United States with the exception of states whose legal frameworks structurally prevent the marketplace-facilitator model from operating efficiently. As of the effective date, the excluded states are California, Massachusetts, New Jersey, New York, and Vermont (see Terms §2 for the operative list). Data is processed and stored in U.S.-based facilities operated by our infrastructure providers. The Platform is not designed for users in jurisdictions whose data-protection law requires explicit transfer mechanisms (e.g., GDPR's standard contractual clauses); users outside the United States should not register accounts.
13. Neighborhood Activity and Hall of Fame
The /feed surface has two distinct columns with two distinct privacy postures.
Neighborhood Activity — a text-only listing of recent completed work in your area. Job title, anonymized homeowner-written description, "what got done" task summary, category, city, rounded price, and time-since-completion. No photos are shown. Even though we round prices and strip names and addresses from the projection, photos themselves can incidentally reveal identifying details (house numbers in the background, license plates, neighbors visible, papers on a counter). Anonymization-by-projection cannot reach what's inside an image. So we never show photos on this surface.
Hall of Fame — a curated editorial column highlighting specific completed jobs. Includes the job title, anonymized description, the editor's note, the rounded price, and the work-completion photos. The photo display is the differentiator. This is strictly opt-in: we do not feature your work without first contacting you (the Homeowner and the Tradesman) at the email address on file, describing the proposed display, and obtaining your permission. Declining is consequence-free; we may offer an account credit as recognition for participation.
If you previously consented and wish a specific Hall of Fame entry removed, request removal through the in-Platform support widget and we will remove it within a reasonable period.
14. Changes to this policy
We may revise this Policy at any time. When we do, we post the revised Policy on this page and update the effective date and version marker at the top of this document. That posting is the notice. The version shown here, with the effective date above, is always the current one, and a changed effective date is how you can tell the Policy has been revised. We do not separately announce a revision through any other channel, so check this page for the latest version. Revisions take effect immediately upon posting, as reflected by the updated effective date, so that we can correct errors and close data-handling or security gaps promptly. Continued use of the Platform after a revision's effective date constitutes acceptance of the revised Policy. If you do not agree with a revision, your recourse is to stop using the Platform and, if you wish, delete your account (Section 6).
15. Contact
Privacy questions or data-rights requests: reach us through the in-Platform support widget.
Perfection Dynamics · Upstate South Carolina