Welcome to Veridome ("we", "us", or "our"). Veridome is a marketplace that connects homeowners and property owners with local repair and home-service professionals. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services.
Information We Collect
Account Information — When you register, we collect your name, email address, phone number, profile photo, and password (stored as a one-way hash).
Professional / Contractor Data — Contractors provide name, service categories, license information, insurance details, service area, and other professional verification documents. This information is collected to verify contractor credibility, ensure a safe and trusted marketplace for homeowners, and maintain service quality on the platform. This data is not shared publicly and is used only for internal verification and operational purposes.
Job & Project Data — Details about jobs you post or bid on: description, location, photos, videos, budget, and status history.
Media Files — Images and videos you upload for AI analysis or job documentation. These are stored securely and processed to generate estimates.
Payment Information — Payment is handled entirely by Stripe. We store only transaction identifiers never raw card numbers or CVV codes.
Communications — Messages exchanged between homeowners and contractors through in-app chat. AI conversation history used to power our estimation assistant.
Device & Usage Data — IP address, device type, operating system, app version, pages visited, and interaction timestamps.
Location Data — Approximate location to match you with nearby service professionals (only when you grant permission).
How We Use Your Data
- Provide the Service — Create and manage accounts, post jobs, match homeowners with contractors, and process bids.
- AI-Powered Estimates — Analyse uploaded images/videos and conversation context using Google Gemini to generate cost and duration estimates.
- Payments — Process contractor unlock-contact payments via Stripe.
- Identity Verification — Verify phone numbers via Twilio OTP to prevent fraud.
- Push Notifications — Send job updates, bid alerts, and chat messages via Firebase Cloud Messaging.
- Email Communications — Transactional emails (password reset, booking confirmations) via SendGrid/Nodemailer.
- Platform Safety — Detect and prevent abuse, fraud, spam, and policy violations.
- Analytics & Improvement — Understand how features are used and improve the platform.
- Legal Compliance — Meet our obligations under applicable laws and respond to lawful requests.
- Analyse user-submitted images, videos, and text queries (provided voluntarily by the user) using Google Gemini to generate cost and duration estimates.
- To verify contractor identity and professional credentials for trust and safety purposes.
AI & Media Processing
Veridome uses Google Gemini (a large language and vision model) to analyse images and videos you upload, and to power our repair estimation assistant. When you voluntarily submit media or queries for AI-based analysis:
- Files are temporarily uploaded to the Google Generative AI File API for processing.
- Files are processed via Google’s AI infrastructure in accordance with their data handling policies. We do not retain unnecessary media beyond what is required for platform functionality and only retain structured outputs such as category and cost estimates.
- AI conversation history is stored to maintain context across your session and improve accuracy.
- We do not use your personal media to train third-party AI models without explicit consent.
- By using AI-powered features within the platform, you acknowledge and agree that any media (images, videos) and text you voluntarily submit may be processed by third-party AI service providers (such as Google Gemini) for the purpose of generating analysis, estimates, and responses.
Sharing & Disclosure
We do not sell your personal information. We may share data only in the following circumstances:
- Between Users — Homeowners see contractor profiles, ratings, and portfolio. Contractors can view job details after unlocking contact information (paid feature).
- Service Providers — Trusted third parties that help operate Veridome (see Section 9). They are contractually bound to protect your data.
- Legal Requirements — When required by law, court order, or government authority.
- Safety — When necessary to protect the safety of any person or to investigate fraud.
- Business Transfers — In the event of a merger, acquisition, or sale of assets, your data may transfer to the new entity under the same privacy protections.
- This includes AI service providers that process user-submitted content strictly to deliver platform functionality such as issue detection, recommendations, and cost estimation.
Data Retention
Security
We implement industry-standard measures to protect your information:
- Passwords hashed with bcryptjs — never stored in plain text.
- All API communication over HTTPS/TLS.
- JWT tokens with expiration for session management.
- MongoDB access restricted by network ACLs and authentication credentials.
- Firebase Admin SDK for secure server-to-device push delivery.
- Stripe handles payment data under PCI-DSS compliance — we never touch raw card data.
No method of transmission over the internet is 100% secure. We cannot guarantee absolute security, but we continuously monitor and improve our defences.
Your Rights
Depending on your jurisdiction, you may have the right to:
- Access — Request a copy of the personal data we hold about you.
- Correction — Ask us to fix inaccurate or incomplete information.
- Deletion — Request erasure of your account and associated data ("right to be forgotten").
- Portability — Receive your data in a structured, machine-readable format.
- Objection — Object to certain types of processing (e.g. marketing).
- Restriction — Request we limit how we use your data while a dispute is resolved.
- Withdraw Consent — Where processing is based on consent, withdraw it at any time.
Cookies & Tracking
Our web interfaces use minimal cookies:
- Essential Cookies — Required for authentication sessions and security (cannot be disabled).
- Analytics Cookies — Help us understand traffic patterns and improve UX. You may opt out via browser settings.
- Preference Cookies — Remember your language and display preferences.
Our mobile applications do not use browser cookies but may use device identifiers for push notification delivery via Firebase.
Third-Party Services
Each provider has their own privacy policy. We encourage you to review them. We only share data necessary for these services to function.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will:
- Update the "Last updated" date at the top of this page.
- Send an in-app notification or email for material changes.
- Require fresh acknowledgement if changes significantly affect how your data is used.
Your continued use of Veridome after changes are posted constitutes acceptance of the revised policy.
Contact Us
If you have any questions about this Privacy Policy or want to exercise your data rights, please reach out:
Have a privacy concern?
Our team is ready to help you understand your data rights and address any concerns promptly.
Contact Privacy Team