Version 2026-09-27 · In effect from 27 September 2026
Privacy Policy
In short
We collect what we need to run a marketplace that holds money safely: your account details, identity verification, and the record of what you buy and sell. We do not sell your data, show you ads, or use tracking cookies. Your identity-card and bank details are encrypted. You can download everything we hold about you, or delete your account, from Settings → Privacy & data. We follow the EU General Data Protection Regulation (GDPR) for every user, wherever they live.
1. Who we are
SkilRize (skilrize.com) is operated by the business below, which is the controller of your personal data — the party responsible for deciding how it is used.
NEXOLV.TECH
Sole proprietorship registered with the Federal Board of Revenue, Pakistan. Proprietor: Ibad Ahmed.
House 1037, Street 21, Phase 5, Bahria Town, Rawalpindi, Punjab, Pakistan
Email: nexolv.tech@gmail.com · Phone: +92 332 3285685
For anything about your personal data, write to nexolv.tech@gmail.com with “Privacy” in the subject.
2. What we collect
Information you give us
- Account details: your name, email address and password. Passwords are stored only as a one-way hash (Argon2id) — nobody, including us, can read them.
- Verification: your phone number, a photo of your national identity card (CNIC), and — if you verify as a student — your university email address and a photo of your student ID card.
- Payout details (freelancers only): bank name, account title, account number, CNIC number and mobile-wallet number, so we can send you what you earn.
- Profile: photo, headline, bio, skills, languages, city and country, and the portfolio images you upload.
- Marketplace activity: the services you list, briefs you post, proposals, orders, contracts, files you deliver, time you log, messages, reviews and community posts.
- Payments: the amount, the date, the method type (card, wallet or 1Bill) and Swich's transaction reference. You enter card and wallet details on Swich's page, so we never receive your card number, CVV or wallet PIN.
- Messages to us, if you contact support.
Information collected automatically
- Security data: your IP address, browser and device type, and when you sign in. We keep a keyed fingerprint of each device you use so we can alert you to, and briefly hold payments from, a device you have not used before.
- Search terms typed into our search, stored without any link to who searched.
- Cookies needed to keep you signed in — see the Cookie Policy. We use no analytics or advertising cookies.
Information from services you connect
If you choose to connect Zoom, Google Meet, GitHub, Figma or Notion to a contract, we store an encrypted access token and the limited activity that service shares (for example, commits to a repository you linked). You can disconnect at any time from Settings → Integrations. With the mobile app, we store a notification token for your device if you allow notifications.
3. Why we use it, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating your account, running orders and contracts, holding and releasing payments, paying freelancers, messaging | Performing our contract with you |
| Verifying identity (email, phone, CNIC) before anyone moves money | Legitimate interest in preventing fraud, and our contract with you |
| Keeping financial and transaction records | Legal obligation (tax and accounting law) |
| Security: sign-in protection, new-device checks, rate limits, virus-scanning uploads, audit logs | Legitimate interest in keeping accounts and money safe |
| Search ranking, seller levels and review-integrity checks | Legitimate interest in a fair, trustworthy marketplace |
| Connecting optional integrations, mobile push notifications | Your consent, which you can withdraw at any time |
| Service emails (order updates, security alerts) | Performing our contract; announcement emails can be turned off in Settings → Notifications |
We do not use your data for advertising and we do not sell it to anyone.
4. Automated decisions
Some decisions on SkilRize are made by software. None of them has legal effect on you without a person being able to review it:
- Search ranking combines how well a listing matches your search, the seller's reputation, how recent the listing is, and paid promotion. Promoted listings are always labelled.
- Job Success Score and seller levels are calculated from completed contracts, ratings, on-time delivery and repeat clients.
- Review integrity checks look for signs of manipulated reviews (for example, two accounts reviewing each other repeatedly). A review with enough signals is hidden from scoring — never deleted.
If you think one of these has treated you unfairly, contact us and a person will review it.
5. Who we share it with
- Other users see your public profile, listings and reviews, and the people you work with see what an order or contract needs (your name, messages and delivered work). Your identity card, bank details and phone number are never shown to other users.
- Service providers who process data on our behalf, under contract: Oracle Cloud Infrastructure (hosting), Google (email delivery), and Backblaze (off-site backup storage).
- Swich (a licensed Pakistani payment gateway) processes payments by card, Easypaisa, JazzCash and 1Bill, and refunds. We pass it the amount, a reference for the order, and your name, email and phone number for the payment page. Banks and wallet providers receive the details needed to send payouts and refunds.
- Services you connect yourself (see section 2).
- Authorities, when Pakistani law requires it, or to protect someone from fraud or harm.
- A buyer of the business, if SkilRize is ever sold or merged — under this same policy.
6. Where it is stored
Our servers run on Oracle Cloud in its Mumbai, India region. Email passes through Google, which may process it in other countries. Where your data leaves Pakistan or the European Economic Area, we rely on our providers' contractual data-protection commitments (including the EU Standard Contractual Clauses where they apply).
7. How long we keep it
| Data | Kept for |
|---|---|
| Your account and profile | Until you delete your account |
| Identity-card and student-ID images, payout details, devices, sessions, notifications | Deleted when you delete your account |
| Orders, contracts, payments, payouts and refunds | Six years, as Pakistani tax law requires — attributed to “Deleted user” once your account is deleted |
| Reviews, messages and community posts | Kept as part of other people's history, attributed to “Deleted user” |
| Security audit log | As long as needed to investigate fraud and abuse |
| Sign-in codes and password-reset links | Minutes; they expire automatically |
8. Your rights
Wherever you live, you can:
- Get a copy of your data (access and portability) — download it instantly as a JSON file from Settings → Privacy & data.
- Correct it — edit your profile in Settings, or ask us.
- Delete it — delete your account from the same page. Some records are kept for the reasons in section 7, and the page tells you what before you confirm.
- Object or restrict — ask us to stop or limit a use based on legitimate interest.
- Withdraw consent — disconnect an integration or turn off notifications at any time.
- Complain to a data-protection authority. If you are in the EU, that is your country's supervisory authority. We would appreciate the chance to put it right first.
We answer requests sent by email within one month, and may ask you to confirm your identity first so we never hand your data to someone else.
9. How we protect it
- All traffic is encrypted with HTTPS, and browsers are told never to connect without it.
- Identity-card numbers, bank account numbers, two-factor secrets and connected-service tokens are encrypted in our database (AES-256-GCM).
- Uploaded files are checked, re-encoded to strip hidden data, scanned for viruses, and only ever served through links that expire within minutes.
- Two-factor authentication is available to everyone and required before money moves.
- Staff access is limited by role, requires two-factor authentication, and every sensitive action is written to an audit log that cannot be edited.
If a breach ever puts your data at risk, we will tell you and — where the law requires — the relevant authority, without undue delay (within 72 hours for authorities under the GDPR).
10. Age limit
SkilRize is for people aged 18 and over. We do not knowingly collect data from anyone younger; if we learn we have, we delete it.
11. Cookies
We use only the cookies needed to keep you signed in and protect your forms. The full list is in our Cookie Policy.
12. Changes to this policy
Every version of this policy is dated. If we change it in a way that matters, we will tell you by email or in the app before the change takes effect.
13. Contact
NEXOLV.TECH
Sole proprietorship registered with the Federal Board of Revenue, Pakistan. Proprietor: Ibad Ahmed.
House 1037, Street 21, Phase 5, Bahria Town, Rawalpindi, Punjab, Pakistan
Email: nexolv.tech@gmail.com · Phone: +92 332 3285685

