1. Who we are and what this covers
OfficePassport (“we,” “us”) operates https://officepassport2.theodorecacciola.com. For users in the EU, EEA, or UK, we are the data controller for the personal data described here.
This policy covers the website, your account, orders, messaging, the job board, seller tools, and the AI features. It does not cover third-party sites we link to, or what a buyer or seller does with information you give them directly — when you send another user your files or details, that user handles them under their own practices.
Our Terms of Use govern your use of the Platform.
2. Personal data we collect
2.1 Data you give us
| Category | Examples |
|---|---|
| Account | First and last name, email address, password (stored only as a bcrypt hash, never in readable form), account role (buyer, seller, enterprise), country, profile photo, bio. |
| Seller profile | Tagline, skills, experience, education, languages, social links, portfolio items, cover image, availability, seller level. |
| Seller application | Your introduction, work samples, and materials submitted for review, plus our reviewer's screening notes and score. |
| Listings & jobs | Service listings and images, job posts, bids, and bid portfolios. |
| Order content | Requirements and briefs, uploaded files, delivered files, revision requests, reviews and ratings. |
| Messages | Messages you exchange with other users through the Platform, and their attachments. |
| Support | Support tickets and dispute submissions, including the subject, description, any order reference, and our replies. |
| AI prompts | Text you submit to the AI tools and the output returned (see Section 5). |
Please do not send sensitive personal data — health information, government ID numbers, financial account numbers, biometric data, or details about racial or ethnic origin, religion, politics, sex life, or criminal history — through messages, briefs, support tickets, or the AI tools. We do not need it and do not ask for it. Identity documents go directly to Stripe, not to us (Section 3).
2.2 Data we collect automatically
- Session and authentication data — a session cookie, a CSRF token, and your last sign-in time, so you stay signed in securely.
- Server logs — IP address, browser and device type, pages requested, referring page, timestamps, and error records.
- Usage data — searches, listings viewed, saved gigs, notifications, and other in-product activity.
- Administrative logs — a record of moderation and administrative actions taken on accounts and orders.
2.3 Data we receive from others
- Stripe — payment status, the last four digits and brand of a card, payout status, a customer or connected-account identifier, and identity verification results.
- Email delivery providers — bounce and delivery status for messages we send you.
- Other users — reviews, dispute submissions, and reports about you.
3. Identity verification
Sellers may be asked to verify their identity. This is handled by Stripe Identity. You submit your government-issued document and any selfie directly to Stripe — those images do not pass through, and are not stored on, our servers.
From Stripe we receive and store only the verification outcome and limited metadata: a session identifier, the status (pending, verified, failed), the verified name, the document type, the issuing country, any failure code and reason, and the time of the check. Our administrators may add review notes.
Stripe's processing of your document is governed by Stripe's Privacy Policy. Depending on your jurisdiction, the images may constitute biometric data processed by Stripe under its own retention rules. We use verification results only to decide whether to approve a seller, to prevent fraud and impersonation, and to meet our legal obligations.
4. Payment and payout data
Payments are processed by Stripe. We never receive or store your full card number, CVC, or bank account credentials. Those go directly to Stripe.
We store, for each transaction: the order it relates to, a Stripe payment identifier, the gross amount, the platform fee, the seller payout amount, and the status. For sellers we store a Stripe connected-account identifier, transfer identifiers, payout amounts, and cumulative earnings.
Stripe acts as an independent controller for the payment data it collects, under its own privacy policy. We keep transaction records as long as tax, accounting, and anti-fraud law requires.
5. AI tools
When you use an AI feature, the text you submit is sent to our AI provider (Anthropic) to generate a response. We log the feature used, the input, the output, the cost, and the timestamp, linked to your account.
We use these logs to operate and bill the feature, to investigate abuse, and to improve quality. We do not use your prompts, outputs, messages, or files to train AI models, and our AI provider is contractually restricted from training on data we send through the API.
Because prompts are logged and sent to a third party, do not put confidential information or other people's personal data into the AI tools. You can avoid this processing entirely by not using the AI features.
6. Cookies and similar technologies
We keep our use of cookies deliberately narrow.
| Cookie | Type | Purpose |
|---|---|---|
PHPSESSID | Strictly necessary | Keeps you signed in and links your requests to your session. Set
HttpOnly, SameSite=Lax, and Secure over
HTTPS. Expires when your session ends. |
| CSRF token | Strictly necessary | Protects forms against cross-site request forgery. Session-scoped. |
op_cookie_notice | Preference | Remembers that you dismissed the cookie notice, so we do not show it again. Stored in your browser for 12 months. |
| Stripe cookies | Strictly necessary / fraud prevention | Set by Stripe on checkout and verification pages to process payments and detect fraud. |
Strictly necessary cookies do not require consent because the Platform cannot function without them. We do not use advertising cookies, cross-site tracking pixels, or third-party ad networks. If we ever add analytics or advertising technology, we will update this policy and ask for consent where the law requires it.
You can block or delete cookies in your browser settings, but blocking the session cookie will prevent you from signing in.
7. How we use personal data
- Create and administer your account, and authenticate you.
- Operate the marketplace: publish listings, run the job board, process orders, deliver files, and route messages and notifications.
- Process payments, hold and release escrow, calculate fees, and pay sellers.
- Verify seller identity, review seller applications, and enforce eligibility.
- Provide support and resolve disputes.
- Detect, investigate, and prevent fraud, abuse, spam, and security incidents.
- Send service messages — email verification, password resets, order updates, dispute notices, and material changes to these documents.
- Send marketing email, only where you have opted in or where it is permitted by law; you can unsubscribe at any time from any such email.
- Analyse and improve the Platform, generally using aggregated or de-identified data.
- Comply with legal, tax, and accounting obligations, and establish or defend legal claims.
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Seller approvals and dispute outcomes involve human review.
8. Legal bases for processing (EU / EEA / UK)
| Legal basis | We rely on it for |
|---|---|
| Performance of a contract Art. 6(1)(b) |
Running your account, processing orders and escrow, delivering messages, paying sellers, and providing support. |
| Legal obligation Art. 6(1)(c) |
Tax and accounting records, sanctions screening, responding to lawful requests, and retaining transaction records. |
| Legitimate interests Art. 6(1)(f) |
Fraud prevention and platform security, moderation and enforcement, service improvement, aggregate analytics, and direct marketing to existing customers. We balance these against your rights and you may object (Section 14). |
| Consent Art. 6(1)(a) |
Optional marketing email where consent is required, and any non-essential cookies we may introduce. You may withdraw consent at any time, without affecting processing already carried out. |
9. When we share personal data
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We disclose it only as follows:
| Recipient | What and why |
|---|---|
| Other users | The counterparty to an order sees your name, profile, messages, briefs, and files — that is how the transaction works. |
| Stripe | Payment processing, payouts, and identity verification. |
| Anthropic | AI feature prompts and generated output. |
| Hosting & email providers | Storing site data and sending transactional email on our behalf, under contract. |
| Professional advisers | Lawyers, accountants, and auditors, bound by confidentiality. |
| Authorities | Where required by law, subpoena, or court order, or where necessary to protect rights, safety, or property, or to investigate fraud. We will notify you where we are permitted to. |
| A successor | In a merger, acquisition, financing, or sale of assets, subject to this policy continuing to apply. |
Service providers act as processors on our documented instructions and may not use your data for their own purposes. Stripe also acts as an independent controller for its own compliance and fraud-prevention purposes.
10. Information that is public
Some information is visible to anyone by design: your public display name, profile photo and cover image, tagline and bio, skills, portfolio items, seller level, country, listings, job posts, ratings, and the reviews you write. Search engines may index it.
Your email address, password hash, payment details, identity verification results, private messages, order files, and support tickets are not public. Think before you put personal details in a field that appears on your public profile.
11. How long we keep data
| Data | Retention |
|---|---|
| Account and profile | While your account is open. On deletion the account is marked deleted and personal fields are removed or anonymised, generally within 30 days. |
| Orders, transactions, payouts, invoices | Up to 7 years after the transaction, for tax, accounting, and dispute purposes. |
| Messages and delivered files | While the account is open and for a reasonable period after, so disputes and chargebacks can be resolved. |
| Identity verification results | While you are an approved seller and for a period after, as required for anti-fraud and compliance. Document images are held by Stripe, not us. |
| AI usage logs | Up to 12 months, then deleted or aggregated. |
| Support tickets | Up to 3 years after closure. |
| Server and security logs | Typically 90 days, longer where an investigation requires. |
| Records of bans and fraud | Retained as long as needed to keep a banned user from returning. |
Public content such as reviews may remain visible in de-identified form after an account closes, so the marketplace record stays accurate.
12. Security
We take reasonable technical and organisational measures to protect personal data, including HTTPS in transit, bcrypt password hashing, CSRF protection, HttpOnly and Secure session cookies with strict session mode, parameterised database queries, role-based administrative access, upload restrictions, and logging of administrative actions.
No system is perfectly secure. You are responsible for using a strong, unique password and keeping it private. If a breach affects your personal data and the law requires it, we will notify you and the relevant supervisory authority without undue delay.
13. International data transfers
We operate from the United States, and our providers may process data in the U.S. and elsewhere. If you are in the EEA, UK, or Switzerland, your data will be transferred outside your country, where privacy laws may differ.
Where we make such transfers, we rely on appropriate safeguards — ordinarily the European Commission's Standard Contractual Clauses (and the UK Addendum), together with supplementary technical measures. You may request a copy of the relevant safeguards by emailing privacy@officepassport.com.
14. Your rights (EU / EEA / UK)
Subject to conditions in the applicable law, you have the right to:
- Access the personal data we hold about you, and receive a copy.
- Rectify data that is inaccurate or incomplete.
- Erase your data (“right to be forgotten”), where we do not have an overriding legal reason to keep it.
- Restrict processing in certain circumstances.
- Object to processing based on legitimate interests, and to direct marketing at any time.
- Portability — receive data you gave us in a structured, machine-readable format, and have it transmitted to another controller where technically feasible.
- Withdraw consent at any time where processing is based on consent.
- Complain to your local supervisory authority (in the UK, the Information Commissioner's Office). We would appreciate the chance to address your concern first.
To exercise a right, email privacy@officepassport.com from the address on your account, or use your account settings. We respond within 30 days (extendable by two months for complex requests, with notice). We may need to verify your identity first, and we will not charge you unless a request is manifestly unfounded or excessive.
Some data must be retained despite an erasure request — for example transaction records we are legally required to keep, and records that prevent a banned user from returning.
15. California privacy rights (CCPA / CPRA)
If you are a California resident, you have the right to know, delete, correct, and to opt out of sale or sharing, and the right not to be discriminated against for exercising them.
We have not sold or shared personal information for cross-context behavioural advertising in the preceding 12 months, and we do not sell the personal information of minors under 16. We do not use or disclose sensitive personal information for purposes beyond those permitted under the CPRA.
Categories collected in the preceding 12 months, using CCPA labels:
| Category | Examples | Disclosed for a business purpose to |
|---|---|---|
| Identifiers | Name, email, account ID, IP address | Hosting, email, payment providers |
| Customer records (Cal. Civ. Code § 1798.80) | Name, contact details, payment status | Payment provider |
| Commercial information | Orders, purchase history, bids | Payment provider, hosting |
| Internet activity | Pages viewed, searches, session logs | Hosting |
| Geolocation (coarse) | Country, IP-derived region | Hosting, fraud tools |
| Professional information | Skills, experience, education, portfolio | Public on your profile |
| Audio/visual | Profile and portfolio images, uploaded files | Hosting |
| Sensitive personal information | Account credentials; identity verification results for sellers | Payment/identity provider. Used only to provide the service, verify identity, and prevent fraud. |
| Inferences | None used to build a profile about you | — |
To exercise a right, email privacy@officepassport.com with “California Privacy Request” in the subject. We confirm receipt within 10 business days and respond within 45 days (extendable once by 45 days). An authorised agent may submit a request with written proof of authorisation. We may deny a request where a legal exemption applies, and we will tell you why.
16. Other U.S. state privacy rights
Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana — have comparable rights to access, correct, delete, obtain a copy of, and opt out of targeted advertising, sale, or certain profiling. We do not conduct targeted advertising, sell personal data, or engage in profiling with legal effects.
Use the same contact address, and where your state provides an appeal process, you may appeal a denial by replying to our response; we will explain the outcome in writing and tell you how to contact your state attorney general.
17. Children's privacy
The Platform is for adults. You must be at least 18 to hold an account, and we do not knowingly collect personal data from anyone under that age.
If you believe a child has given us personal data, email privacy@officepassport.com and we will delete the account and the data promptly.
18. Do Not Track and Global Privacy Control
We do not track users across third-party websites, so there is no cross-site behaviour to suppress. Because there is no consistent industry standard for Do Not Track, we do not respond to DNT headers. Where the law treats a Global Privacy Control signal as a valid opt-out of sale or sharing, we honour it — though we do not sell or share personal information in the first place.
19. Changes to this policy
We may update this policy. We will change the “Last updated” date above, and for material changes we will give notice by email or an in-product notice before they take effect. If a change requires your consent, we will ask for it. Please review this page periodically.
20. Contact us
For privacy questions or to exercise a right:
OfficePassport
Privacy: privacy@officepassport.com
Legal: legal@officepassport.com
Support: Help Center
We do not currently have an EU or UK representative under Article 27 GDPR. If our processing later requires one, we will name them here.
See also our Terms of Use and Trust & Safety.