Privacy Policy
Version 2026-06-19 · Applies to the BlessGig website and the BlessGig Android application (package com.blessgig.app).
BlessGig is a digital marketplace and gig platform. This policy explains exactly what data the app collects, why, who it is shared with, how long it is kept, and how you can delete it. We do not sell your personal data and we do not use it for third-party advertising.
1. Data we collect
Account information
Email address and password (stored only as a secure hash by our authentication provider), or, if you sign in with Google, your Google account email and basic profile details. We also store your selected role, account status and sign-in security events.
Profile information
Display name, headline, bio, country, hourly rate, skills, preferred currency, preferred language and time zone, plus any profile photo or cover photo you upload.
Messages and user-generated content
Chat messages, voice messages, attachments, job posts, proposals, gigs, product listings, product and gig images, reviews, support requests, task proof screenshots and reports you submit. Messages are readable only by the participants of that conversation and by staff acting on an abuse report or dispute.
Camera and photos
The app requests camera and photo access only when you choose to take or select a picture — for a profile photo, a listing image, a chat attachment or an identity document. We do not access your camera or gallery in the background and we do not scan your photo library.
Microphone and calls
Audio and video calls between users are powered by ZEGOCLOUD. Microphone and camera are used only for the duration of a call you start or accept. BlessGig does not record or store call audio or video; we store only call metadata (participants, type, time, duration) so calls appear in your history.
Identity verification (KYC)
If you request verification, we collect the government-issued identity document you upload. These files are stored in a private bucket, are never publicly accessible, and are visible only to reviewing staff.
Payment and wallet information
We store transaction records: deposits, withdrawals, escrow movements, commissions, subscription status, payout destination (your PayPal email or bank details you enter for a withdrawal), amounts, currencies and exchange-rate snapshots. Card details are never collected or stored by BlessGig — payments are handled entirely by PayPal.
Marketplace and order information
Orders, delivery method, delivery or pickup address details you supply, order status, disputes and reviews.
Device and technical information
IP address, user agent, device/browser type, app version, language, and security events such as failed sign-ins and rate-limit hits. This is used for security, fraud prevention and debugging.
Notification tokens
If you enable notifications, we store the push token issued by Firebase Cloud Messaging for your device, along with your notification preferences. The token is used only to deliver BlessGig notifications and is deleted when you disable notifications or delete your account.
2. How we use your data
- To create and operate your account and profile.
- To match buyers, sellers, clients and freelancers, and to run listings and orders.
- To process payments, escrow, commissions, subscriptions and withdrawals.
- To deliver messages, calls and notifications you have opted into.
- To verify identity where required and to prevent fraud, abuse and money laundering.
- To provide customer support and resolve disputes.
- To meet legal, tax and accounting obligations.
3. Third-party services
- Supabase — database, authentication and file storage.
- Cloudflare — hosting, delivery and abuse protection.
- PayPal — deposits, subscription payments and payouts.
- Firebase Cloud Messaging (Google) — push notification delivery.
- Google Sign-In — optional authentication provider.
- ZEGOCLOUD — real-time audio and video calling.
- AI translation and assistance providers — used to translate interface and user-submitted content on request, and to power the in-app support assistant.
We share only the data each provider needs to perform its function, and we disclose data to authorities where legally required.
4. Security
All traffic uses HTTPS. Data is protected by row-level security so users can only read their own records and the records they are party to. Identity documents, chat attachments and task proofs are stored in private buckets served through short-lived signed URLs. Wallet withdrawals require re-authentication and an optional wallet PIN, and are always verified on our servers — never by the app on your phone. Payment secrets and service keys exist only on our servers and are never shipped inside the Android application.
5. Data retention
- Profile and account data: kept while your account is open.
- Messages and listings: kept while your account is open, or until you delete them.
- Identity documents: deleted when your account is deleted.
- Push tokens: deleted when you disable notifications or delete your account.
- Financial records (orders, escrow, payouts, commissions, invoices): retained in anonymised form for the period required by accounting and anti-fraud law, even after deletion.
6. Deleting your account
You can delete your BlessGig account at any time from inside the app: open Settings → Delete account, confirm your password and type DELETE. Deletion removes your profile details, photos, saved carts and wishlists, skills, identity documents, wallet PIN, notification devices and role assignments, and signs you out. Deletion is blocked only while a withdrawal is in progress or money is held in escrow, so no funds are lost mid-transaction. If you cannot access the app, email us via the Contact page and we will process the deletion for you.
7. Your rights
You may access, correct, export or delete your personal data. Profile data can be edited in the app; deletion is available in Settings; for access or export requests, contact us and we will respond within 30 days.
8. Children
BlessGig is not intended for anyone under 18. We do not knowingly collect data from children, and we remove such accounts when identified.
9. Cookies and local storage
We use strictly necessary cookies and local storage for authentication, session persistence, your language choice and cached translations. We do not use advertising cookies.
10. Changes
If this policy changes materially, we update the version above and ask you to re-accept it the next time you sign in.
11. Contact
For privacy questions or data requests, reach us through the Contact page. See also our Terms of Service and Trust & Security pages.