TaskForTask Platform
Privacy Policy
This document explains how TaskForTask ("we", "us", "our") collects, processes, stores, and protects your personal information when you use our platform. By using TaskForTask, you agree to the practices described here.
Overview
TaskForTask is a transparent, accountability-first marketplace. We collect only what we need to run the platform and protect our users. We do not sell your data.
TaskForTask is a peer-to-peer task-and-skill exchange platform that allows registered users to post tasks, accept work, manage coin-based payments through a secure escrow system, and build a reputation over time. To deliver these services, we collect and process certain personal and behavioural data, as described in this policy.
This Privacy Policy applies to all users of the TaskForTask website and any associated services. If you do not agree with these terms, please do not use our platform.
We are committed to compliance with applicable data protection laws, including but not limited to the Information Technology Act, 2000 (India), the General Data Protection Regulation (GDPR) where applicable, and other relevant regulations.
Information We Collect
We collect your name, email, profile info, and how you use the platform. You give us most of this directly. Some of it is recorded automatically as you use the site.
A. Information You Provide Directly
- Full name and chosen username (your public platform identity)
- Email address (obtained from your authentication provider and cannot be edited)
- Phone number (optional, provided by you)
- Profile picture (a URL to an image you provide or authorize)
- Date of birth, profession, biography, and self-described interests
- Skills selected from our curated skill catalogue
- Referral code used during registration (if any)
- Task content: headlines, descriptions, file attachments, and work submissions
- Messages sent within the platform
- Dispute statements, revision requests, and review text
B. Information Collected Automatically
- Session and authentication tokens stored in encrypted browser cookies
- IP Address (Captured automatically for network security and fraud prevention)
- Online/offline status and last-seen timestamps (to power the live presence feature)
- Activity logs: tasks posted, tasks completed, bids submitted, reviews given
- Reputation metrics: XP points, rating averages, and Search Result Ranking (SRR)
- Dispute and penalty records associated with your account
- Transaction ledger entries for all coin movements on the platform
C. Information from Third-Party Sign-In
When you sign in via a third-party identity provider (such as a social login service), we receive only the data that provider shares with us — typically your name, email address, and profile picture URL. We do not receive your password or any data beyond what you explicitly authorise that provider to share.
How We Use Your Data
Your data powers the platform: verifying who you are, showing your profile, routing payments through escrow, and keeping the community safe. We do not sell your data.
We use the information we collect for the following purposes:
- Creating and maintaining your account identity on the platform
- Operating the task marketplace: matching, assigning, and completing tasks
- Calculating and updating reputation scores (XP, ratings, SRR) automatically
- Facilitating task-specific messaging between users
- Resolving disputes through our internal resolution systems
- Enforcing our Terms of Service and initiating permanent bans (including IP-based blacklisting) for bad actors
- Improving and personalising the platform security layers
The Limit of Knowledge: We only collect out of necessity, not out of curiosity. If we don't store it, we don't know it. If we don't know it, we can't share it. This is our ultimate security layer to protect our users' privacy while upholding platform safety. However, this does not grant immunity from the law; in cases of suspected illegal activities, we will cooperate with and share necessary information with concerned authorities.
Security & Fraud Prevention Data
To protect our community from account hijacking and abuse, we collect technical device info. This is strictly for security and never used for marketing.
To protect our community from account hijacking, bot attacks, and multiple-account abuse (cloning), we automatically collect certain technical information about your device. This includes:
Hardware Specifications:
- Approximate CPU cores
- Available RAM (memory)
- GPU/graphics renderer information
Browser Environment:
- Browser name and version
- Screen resolution and color depth
Network Identifiers:
- IP address
- General timezone and locale
Our Promise: This data is used strictly for security purposes to ensure a fair environment (e.g., preventing spam or fraudulent coin mining). We do not use this for marketing, we do not build a personal profile of your offline life, and we never sell this data to third parties.
System-Managed Data
Your coin balance, XP, ratings, and penalties are controlled entirely by our backend — not by you. This prevents fraud. You can view this data but cannot manually edit it.
Certain data fields on your account are designated as system-managed and can only be modified by TaskForTask's automated backend processes. This includes, but is not limited to:
- TFT coin balance and escrow holdings
- Experience points (XP) and XP transaction history
- Task completion counts and active task records
- Dispute counts, warnings, and penalty records
- Search Result Ranking (SRR) score
- Account status (active, restricted, or banned)
- Premium membership status
These fields are protected at the database level by server-side rules that prevent unauthorised modification — even by technical users who might attempt to exploit the platform's public-facing interfaces. All changes to these fields are recorded in an immutable audit log.
This design is intentional. It ensures that coin balances and reputation scores reflect genuine activity only and cannot be manipulated by any party outside our automated systems.
Third-Party Services
We use trusted external partners for authentication, cloud storage, and payment processing. Each has their own privacy policy. We share only the minimum data they need.
To deliver the TaskForTask experience, we integrate with carefully selected third-party service providers. We do not disclose the specific identities of these providers in this public document to protect our infrastructure. Each provider is bound by their own privacy policy and, where applicable, a data processing agreement with us.
Authentication & Identity: We use a cloud-based authentication provider to handle secure sign-in, session management, and identity verification. Data shared includes your email and authentication token.
Database & Backend Infrastructure: Your profile, tasks, messages, and transaction records are stored on a secure, enterprise-grade cloud database provider with end-to-end encryption in transit and at rest.
File & Media Storage: Files, images, and work submissions uploaded to the platform are stored with a cloud storage provider. URLs to these assets may be shared with other users as part of the platform's functionality (e.g., task work delivery).
Payment Processing (Future): When real-money top-up or withdrawal features are enabled, transactions will be processed by a licensed, regulated payment gateway. TaskForTask will never store your raw financial credentials (card numbers, bank account details). All such data is handled exclusively by the payment processor under their own PCI-DSS compliance.
Security & Storage
Your data is encrypted, access-controlled, and protected by layers of security. We never expose your data to other users beyond what's necessary for the platform to work.
We implement multiple layers of security to protect your personal data:
- All data is encrypted in transit using industry-standard secure protocols
- Data at rest is encrypted by our cloud infrastructure provider
- Access controls ensure users can only access their authorised data
- Sensitive server-side operations are exclusively accessible to our authenticated backend services, never to the public-facing client
- Authentication tokens are securely managed with short expiry windows and automatic rotation
- Administrative access to raw data is restricted to authorised personnel only
- Platform chats are generally not monitored by the TaskForTask backend team. Chats are only accessed in the event of a report from participants, an active dispute, a revision request, suspicions of illegal activity, or multiple reports against a user.
Despite our best efforts, no system is 100% secure. If you discover a security vulnerability, please report it to us immediately at our contact address below. We will investigate and respond promptly.
Data Retention
We keep your data as long as your account is active. If you delete your account, most data is removed. Some records (like transaction logs) are kept for legal and fraud-prevention reasons.
We retain your personal data for as long as your account is active or as needed to provide you with our services. Specific retention policies:
- Account profile data: retained until you request account deletion
- Messages: retained for the lifetime of their associated chat room and for a period after, to support dispute resolution
- Transaction records and escrow logs: retained for a minimum of 7 years, as required by financial and legal compliance obligations
- XP and coin audit logs: retained indefinitely as immutable records of platform activity
- Dispute records: retained for a minimum of 3 years after resolution
- Blacklisted IP addresses: retained indefinitely to ensure account-security and platform integrity
- Deleted messages: the message content is replaced with a deletion notice, but the message record is retained for evidentiary purposes in the event of an active dispute
To request deletion of your account and associated data, please contact us at the address below. Note that some data may be retained beyond account deletion where required by law or for the protection of other users.
Your Rights
You have the right to see, correct, or delete your data. You can also ask us to stop processing it. Some data we are legally required to keep even if you ask us to delete it.
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate personal data (editable fields only — system-managed fields cannot be manually altered)
- Right to Erasure: Request deletion of your account and personal data, subject to legal retention obligations
- Right to Restriction: Request that we limit how we process your data in certain circumstances
- Right to Data Portability: Request your personal data in a structured, machine-readable format
- Right to Object: Object to processing of your data for specific purposes
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, contact us using the details in the "Contact Us" section. We will respond within 30 days. In some cases, we may need to verify your identity before fulfilling a request.
Age & Parental Consent
TaskForTask is open to users aged 16 and above. Users under 18 should obtain parental consent before registering. By creating an account, you self-certify your eligibility.
Minimum Age: TaskForTask is available to users aged 16 and above. By creating an account, you self-certify that you meet this minimum age requirement. We do not independently verify age. If you provide false information about your age, responsibility for any resulting consequences rests solely with you.
Users aged 16–17: Parental or guardian consent is mandatory for users under 18. During the registration process, users aged 16 or 17 must check a declaration confirming that their parent or legal guardian has consented to their use of this platform. By completing registration, you confirm that this consent has been obtained. The legal burden of obtaining and maintaining this consent rests entirely with the user and their guardian, not with TaskForTask.
We do not knowingly collect personal data from users under 16. If we become aware that a user is under 16, we will immediately suspend and permanently delete their account and all associated data.
Future paid features: When paid features are introduced on the platform (such as premium subscriptions, badges, or profile boosts), applicable age restrictions and consent requirements will be clearly communicated at the time. We will not introduce paid features without updating these terms accordingly.
If we discover that an account belongs to a user under the applicable age for a given feature, or that an account was created in violation of these age requirements, we reserve the right to restrict, suspend, or permanently delete that account without notice or refund.
Data We Store & What We Don't
We store your name, email, and phone (if you give it). We don't store your card details, passwords, or anything we don't need. We don't sell your data or share it for ads.
What we store: We limit personal data collection to what is strictly necessary to operate the platform and ensure a smooth experience. The personal identifiers we store are: your name, email address, profile picture URL, and phone number (if provided by you). Beyond this, we store behavioural and platform-activity data described earlier in this policy.
What we do not store: We do not store payment card details, bank account numbers, government ID, or any raw financial credentials. These are handled entirely by licensed third-party payment processors and never pass through or reside on our systems. TaskForTask does not sell your data to any third party.
Sharing with partners: We may share your phone number or email address with carefully selected third-party partners solely for the purpose of providing platform features, such as phone number verification, one-time password (OTP) delivery, and security notifications. We do not share your contact details with any third party for promotional, advertising, or marketing purposes.
Usage notifications: We may contact you by email or phone number to notify you of important account events — such as logins, password changes, transaction confirmations, or policy updates. These communications are service-related and are not marketing.
TFT Coins & Real-World Value
TFT Coins exist solely within the TaskForTask ecosystem and carry no real-world monetary value. Exchanging them for real money — on or off the platform — is a violation of our Terms and grounds for account termination.
TFT Coins are a proprietary digital utility token that exist exclusively within the TaskForTask ecosystem. They carry no real-world monetary value and cannot be exchanged for cash, transferred to external wallets, or redeemed outside the platform.
TaskForTask does not currently buy or sell TFT Coins for real-world currency—though this may change in the future as the platform evolves. Any listing, offer, or agreement to exchange TFT Coins for real money — whether made on or off the platform — is strictly prohibited and constitutes a violation of these Terms.
Users found attempting to trade, sell, or purchase TFT Coins for real-world currency, or facilitating such exchanges in any form, may be permanently banned without warning or refund.
System Failures & Coin Restoration: In the event of a documented system failure, server outage, or database corruption, TaskForTask's sole obligation is to attempt restoration of coin balances and transaction records based on the most recent available automated backup. We are not liable for coins, XP, or progress records that cannot be recovered due to incomplete backup coverage, data corruption beyond recovery, or any losses incurred during the period of the outage. We will make reasonable efforts to restore affected accounts and will communicate transparently with impacted users.
Off-platform transactions: Any payment, agreement, or exchange that takes place outside of the TaskForTask platform — including through third-party payment apps, bank transfers, or physical cash — is entirely outside our jurisdiction. TaskForTask provides zero protection, dispute resolution, or recovery assistance for any fraud, loss, or disagreement arising from off-platform dealings. All tasks must be paid exclusively using TFT Coins through the platform's escrow system.
User Responsibility for Shared Content
TaskForTask facilitates task exchanges between independent users. You are responsible for the content and information you choose to share with other users. We take enforcement action against bad actors, but cannot reverse a data leak once it has occurred.
TaskForTask facilitates the exchange of work, files, and communications between independent users. When you choose to share assets, intellectual property, personal information, or any files with another user as part of a task, you do so at your own risk.
We strongly recommend:
- Not sharing sensitive personal information directly with other users through the chat system
- Using watermarked or low-resolution previews of creative work before final delivery
- Ensuring you have the legal right to share any files or content you upload to the platform
In the event of a privacy breach, content theft, or unauthorised copying of your work by another user: TaskForTask will investigate and take enforcement action against the offending account, up to and including permanent termination and reporting to relevant authorities. However, TaskForTask is not liable for any financial, reputational, or legal damages you may suffer as a result. The platform cannot guarantee the confidentiality of content once it has been shared with another user.
Each user is fully responsible for their own conduct, communications, and decisions on the platform. We are an intermediary — not a guarantor of other users' behaviour.
Policy Changes
We may update this policy. We'll notify you of major changes. Continuing to use the platform after changes means you accept the new policy.
We reserve the right to update this Privacy Policy at any time. When we make significant changes, we will notify you by posting a notice on the platform and, where appropriate, sending a notification to your registered email address.
The date at the top of this page reflects when the policy was last revised. We encourage you to review this policy periodically. Your continued use of TaskForTask after any changes constitutes your acceptance of the updated policy.
Contact Us
Questions? Reach out through the platform or at our official contact email. We'll get back to you.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
TaskForTask Privacy Team
Email: admin@taskfortask.com
Please title your email: "Privacy Request — [Your Username]"
We aim to respond to all privacy-related enquiries within 5 business days.