Legal
Privacy Policy
Last updated: June 1, 2025
ServiceLink ("we", "our", or "us") is committed to protecting your privacy. This policy explains what information we collect, how we use it, with whom we share it, and the rights you have over your data. By using ServiceLink, you agree to the practices described here.
1. Information we collect
We collect information in three ways: directly from you, automatically when you use the platform, and from third parties.
Information you provide:
- Account information — name, email address, phone number, and profile photo when you register.
- Provider information — business name, service descriptions, pricing, availability schedule, service images, and verification documents (government-issued ID, proof of address, certifications).
- Bank details — bank account name, number, and bank name provided when requesting payouts as a provider. This information is encrypted and used only for payout processing.
- Booking information — service details, scheduled dates and times, notes, and price agreed between parties.
- Communications — messages sent through the in-app chat on your booking pages, dispute submissions, and contact form enquiries.
- Reviews — ratings and written reviews you submit after completed bookings.
Information collected automatically:
- Usage data — pages visited, features used, search queries, booking activity, and time spent on the platform.
- Device information — IP address, browser type, operating system, and device identifiers.
- Cookies and session data — authentication tokens, session identifiers, and preference settings. See Section 9 for details.
- Push notification tokens — if you grant permission, we store a device token to deliver booking updates and messages.
Information from third parties:
- Google OAuth — if you sign in with Google, we receive your name, email address, and profile photo from Google.
- Paystack — we receive payment confirmation status, transaction references, and masked card details. We do not store your full card number.
- Cloudinary — we use Cloudinary to store and serve profile photos and service images uploaded to the platform.
2. How we use your information
We use the information we collect to:
- Create and manage your account.
- Process bookings, payments, refunds, and payouts.
- Facilitate communication between customers and providers through in-app chat.
- Send transactional emails — booking confirmations, payment receipts, refund notifications, and dispute updates.
- Deliver push notifications for messages, booking status changes, and quote updates (only if you have granted permission).
- Verify provider identity and calculate badge levels (Basic, Trusted, Elite).
- Resolve disputes and review reports of misconduct.
- Moderate reviews and enforce community standards.
- Improve the platform through analysis of usage patterns and performance metrics.
- Detect and prevent fraud, abuse, and security incidents.
- Comply with legal obligations and respond to lawful requests from authorities.
We do not use your information for automated decision-making that produces legal or similarly significant effects without human oversight.
3. Sharing your information
We share your information only in the following circumstances:
With other users: When a booking is created, the customer's name and the provider's name, profile photo, and contact details are made available to each other within the booking context.
Public profile information: Provider profile details — name, headline, bio, location, services, reviews, and badge level — are publicly visible on the platform. Review author names and photos are also publicly visible.
With service providers: We share data with third-party services that help us operate the platform, including:
- Paystack — for payment processing. Paystack processes card data on our behalf under their PCI-DSS-compliant infrastructure.
- Cloudinary — for image hosting and delivery.
- Resend — for transactional email delivery.
- Railway — for cloud infrastructure and database hosting.
- Redis / Upstash — for session management and rate limiting.
All third-party processors are bound by data processing agreements and may only use your data to provide services to ServiceLink.
For legal compliance: We may disclose information to regulatory authorities, law enforcement, or courts where required by Nigerian law or a valid legal order.
We do not sell your personal data to advertisers or data brokers, and we do not serve third-party advertising on the platform.
4. Payment data
Payment processing is handled entirely by Paystack. ServiceLink does not store or have access to your full credit or debit card number, CVV, or card expiry date. We store only the transaction reference, masked card details (last 4 digits), and payment status returned by Paystack.
Provider bank account details submitted for payout requests are stored encrypted in our database. This information is accessible only to our payment processing systems and authorised admin staff.
Paystack's privacy policy applies to payment data collected during checkout. We encourage you to review it at paystack.com/privacy.
5. Data retention
We retain your personal data for as long as your account is active and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce agreements.
- Account data — retained until you delete your account, after which it is permanently removed within 30 days.
- Booking and payment records — retained for 7 years for financial compliance purposes, even after account deletion.
- Chat messages — retained for 2 years and then automatically purged.
- Verification documents — retained for 1 year after account closure or last verification event, then securely deleted.
- Push notification tokens — deleted when you revoke notification permissions or close your account.
6. Your rights
Under applicable data protection law, you have the following rights:
- Access — request a copy of the personal data we hold about you.
- Correction — update inaccurate or incomplete information from your profile settings.
- Deletion — request deletion of your account and associated personal data from Settings → Danger Zone. Note that booking and payment records may be retained for legal compliance.
- Portability — request your data in a structured, machine-readable format.
- Objection — object to processing of your data for analytics or marketing purposes.
- Withdraw consent — revoke push notification permissions at any time through your device settings.
To exercise any of these rights, contact us at privacy@servicelink.ng. We will respond within 30 days.
7. Security
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, and destruction. These measures include:
- HTTPS encryption for all data in transit.
- Database encryption at rest on Railway's managed PostgreSQL infrastructure.
- Rate limiting on authentication endpoints to prevent brute-force attacks.
- Email verification required before account activation.
- Secure bcrypt hashing of all passwords — we never store passwords in plain text.
- Redis-based session management with short-lived tokens.
No system is completely secure. If you suspect your account has been compromised, contact us immediately at security@servicelink.ng.
8. Children
ServiceLink is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a minor has registered an account, we will suspend that account and delete the associated data promptly. If you believe a minor has registered, please contact us.
9. Cookies
ServiceLink uses the following types of cookies and similar technologies:
- Session cookies — used to authenticate you and maintain your logged-in state. These are deleted when you close your browser.
- Persistent cookies — used to store your theme preference (dark/light mode) and cookie consent status.
- Analytics — we may use anonymised analytics to understand how the platform is used. We do not use third-party advertising cookies.
You can control cookies through your browser settings. Disabling session cookies will prevent you from logging in.
10. Push notifications
If you grant permission, ServiceLink will send push notifications to your device using the Web Push API and VAPID keys. Notifications are sent for: new messages from providers or customers, booking status changes, new quotes, refund confirmations, and announcement messages from ServiceLink.
You can withdraw notification permission at any time through your browser or device settings, or from the Settings page within the app. Revoking permission removes your device token from our database.
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in law, technology, or our practices. When we make material changes, we will notify registered users by email and display a notice on the platform at least 14 days before the changes take effect.
Continued use of ServiceLink after the effective date of an updated policy constitutes your acceptance of the changes.
12. Contact
If you have questions, concerns, or requests relating to this Privacy Policy, contact us at:
Or visit our Help & Contact page for additional support options.