HumanRail
Home Docs Terms Privacy

Privacy Policy

Effective Date: March 1, 2026 · Last Updated: February 28, 2026 · Contact: [email protected]

HumanRail ("Company," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy describes how we collect, use, share, and protect personal information when you use the HumanRail platform, APIs, SDKs, website, and related services (collectively, the "Service").

This policy applies to two categories of users: Customers (organizations and developers who use the HumanRail API to route tasks) and Workers (individuals who complete tasks on the platform). Where practices differ between these groups, we note the distinction.

1. What Data We Collect

1.1 Customer Data

  • Account information: Organization name, email address, billing contact, and account administrator details provided during registration
  • Billing information: Payment method details (processed and stored by Stripe; we do not store full credit card numbers)
  • API usage data: API requests, response codes, timestamps, IP addresses, user agent strings, and API key identifiers
  • Task payloads: The input data you submit with each task and the verified output data returned to you
  • Webhook configuration: Endpoint URLs, event subscriptions, and delivery logs

1.2 Worker Data

  • Identity information: Name, email address, profile photo, and identity verification documents (where required by trust tier)
  • Skills and qualifications: Self-reported skills, assessment scores, and certifications
  • Payment information: Lightning Network wallet address or bank account details for fiat payouts (processed via Strike)
  • Performance data: Task completion rates, quality scores, verification outcomes, and reputation metrics
  • Activity data: Login timestamps, IP addresses, task acceptance and submission times

1.3 Automatically Collected Data

  • Device and browser information: Browser type, operating system, screen resolution, and device identifiers
  • Log data: Server logs including IP addresses, request timestamps, and error reports
  • Usage analytics: Page views, feature usage, and interaction patterns (collected via privacy-respecting analytics)

2. How We Use Your Data

We use the data we collect for the following purposes:

Purpose Data Used Legal Basis (GDPR)
Service delivery — routing tasks, matching workers, delivering results Task payloads, worker skills, account data Contract performance
Verification — running our multi-stage verification pipeline Task outputs, worker performance history Contract performance
Payment processing — paying workers and processing customer deposits Billing info, wallet addresses, payout amounts Contract performance
Fraud prevention — detecting abuse, fake submissions, and payment fraud Activity data, IP addresses, performance metrics Legitimate interest
Service improvement — improving routing, verification, and platform reliability Aggregate usage data, error logs Legitimate interest
Customer support — responding to inquiries and resolving issues Account data, correspondence Contract performance
Legal compliance — responding to lawful requests and meeting regulatory obligations As required by law Legal obligation

3. Data Sharing

3.1 Workers. Workers see only redacted and masked versions of task payloads. The level of redaction is determined by the worker's trust tier and the task type. Workers never see your API keys, account details, or billing information.

3.2 Payment Processors. We share billing information with Stripe (for customer deposits) and Strike (for worker payouts via Lightning Network and fiat). These processors handle data in accordance with their own privacy policies.

3.3 Infrastructure Providers. We use cloud infrastructure providers to host the Service. Data is stored on servers with encryption at rest. Our infrastructure providers process data only on our behalf and under our instructions.

3.4 Legal Requirements. We may disclose data if required by law, regulation, legal process, or governmental request.

3.5 Business Transfers. In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. We will notify you of any such transfer and any changes to this Privacy Policy.

3.6 No Selling of Data. We do not sell personal information to third parties. We do not share data with advertisers or data brokers.

4. Data Retention

We retain data only as long as necessary for the purposes described in this policy:

Data Type Retention Period
Task data (payloads, outputs, metadata) 90 days after task completion
Account data (profile, settings) Duration of account + 1 year
Billing and payment records 7 years (legal/tax requirements)
Server logs 30 days
Worker performance data Duration of worker account + 1 year
Identity verification documents Duration of worker account + 30 days

After the retention period, data is permanently deleted or anonymized. You may request earlier deletion of your task data at any time (see Section 6).

5. Security Measures

We implement industry-standard security measures to protect your data:

  • Encryption at rest: All data stored in our databases and object storage is encrypted using AES-256
  • Encryption in transit: All connections to the Service use TLS 1.2 or higher. API keys and webhook secrets are transmitted only over HTTPS
  • Access controls: Internal access to production data is restricted to authorized personnel on a need-to-know basis, with multi-factor authentication required
  • API key security: API keys are hashed before storage. Webhook signing secrets are encrypted at rest
  • Monitoring: We use OpenTelemetry-based observability (traces, metrics, logs) to detect and respond to security incidents
  • Vulnerability management: We perform regular security reviews and maintain a responsible disclosure policy

To report a security vulnerability, contact [email protected].

6. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

6.1 Rights Under GDPR (EEA/UK Residents)

  • Right of access: Request a copy of the personal data we hold about you
  • Right to rectification: Request correction of inaccurate or incomplete data
  • Right to erasure: Request deletion of your personal data (subject to legal retention requirements)
  • Right to restrict processing: Request that we limit how we use your data
  • Right to data portability: Request your data in a structured, machine-readable format
  • Right to object: Object to processing based on legitimate interests
  • Right to withdraw consent: Where processing is based on consent, withdraw it at any time

6.2 Rights Under CCPA (California Residents)

  • Right to know: Request disclosure of the categories and specific pieces of personal information we collect, use, and share
  • Right to delete: Request deletion of personal information
  • Right to opt-out: Opt out of the sale of personal information (note: we do not sell personal information)
  • Right to non-discrimination: Exercise your rights without receiving discriminatory treatment

To exercise any of these rights, contact us at [email protected]. We will respond to your request within 30 days (or as required by applicable law). We may need to verify your identity before processing your request.

7. Cookies

7.1 Session Cookies. Our web applications (customer dashboard and worker app) use session cookies that are essential for authentication and session management. These cookies expire when you close your browser or after a fixed period of inactivity.

7.2 No Tracking Cookies. We do not use third-party tracking cookies, advertising cookies, or cross-site tracking pixels. We do not participate in ad networks or retargeting platforms.

7.3 Analytics. We use privacy-respecting analytics that do not use cookies and do not track individual users across sites.

8. International Data Transfers

The Service is operated from the United States. If you are located outside the United States, your data will be transferred to and processed in the United States. We ensure appropriate safeguards are in place for international transfers, including standard contractual clauses where required by GDPR.

9. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 18, we will delete it promptly. If you believe a child has provided us with personal information, contact us at [email protected].

10. Data Protection Officer

As a company with fewer than 250 employees, we are not required to appoint a Data Protection Officer under GDPR. However, for any data protection inquiries, you may contact our privacy team at [email protected].

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a prominent notice on our website at least 30 days before the changes take effect. The "Last Updated" date at the top of this page indicates when the policy was last revised.

12. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, contact us:

  • Privacy inquiries: [email protected]
  • Security issues: [email protected]
  • General inquiries: [email protected]

© 2026 HumanRail. All rights reserved. · humanrail.dev · Terms · Privacy

Built by Erik Anderson — Author | Prime Automation Solutions | InkEngine.ai