HumanRail ("Company," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy describes how we collect, use, share, and protect personal information when you use the HumanRail platform, APIs, SDKs, website, and related services (collectively, the "Service").
This policy applies to two categories of users: Customers (organizations and developers who use the HumanRail API to route tasks) and Workers (individuals who complete tasks on the platform). Where practices differ between these groups, we note the distinction.
We use the data we collect for the following purposes:
| Purpose | Data Used | Legal Basis (GDPR) |
|---|---|---|
| Service delivery — routing tasks, matching workers, delivering results | Task payloads, worker skills, account data | Contract performance |
| Verification — running our multi-stage verification pipeline | Task outputs, worker performance history | Contract performance |
| Payment processing — paying workers and processing customer deposits | Billing info, wallet addresses, payout amounts | Contract performance |
| Fraud prevention — detecting abuse, fake submissions, and payment fraud | Activity data, IP addresses, performance metrics | Legitimate interest |
| Service improvement — improving routing, verification, and platform reliability | Aggregate usage data, error logs | Legitimate interest |
| Customer support — responding to inquiries and resolving issues | Account data, correspondence | Contract performance |
| Legal compliance — responding to lawful requests and meeting regulatory obligations | As required by law | Legal obligation |
3.1 Workers. Workers see only redacted and masked versions of task payloads. The level of redaction is determined by the worker's trust tier and the task type. Workers never see your API keys, account details, or billing information.
3.2 Payment Processors. We share billing information with Stripe (for customer deposits) and Strike (for worker payouts via Lightning Network and fiat). These processors handle data in accordance with their own privacy policies.
3.3 Infrastructure Providers. We use cloud infrastructure providers to host the Service. Data is stored on servers with encryption at rest. Our infrastructure providers process data only on our behalf and under our instructions.
3.4 Legal Requirements. We may disclose data if required by law, regulation, legal process, or governmental request.
3.5 Business Transfers. In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. We will notify you of any such transfer and any changes to this Privacy Policy.
3.6 No Selling of Data. We do not sell personal information to third parties. We do not share data with advertisers or data brokers.
We retain data only as long as necessary for the purposes described in this policy:
| Data Type | Retention Period |
|---|---|
| Task data (payloads, outputs, metadata) | 90 days after task completion |
| Account data (profile, settings) | Duration of account + 1 year |
| Billing and payment records | 7 years (legal/tax requirements) |
| Server logs | 30 days |
| Worker performance data | Duration of worker account + 1 year |
| Identity verification documents | Duration of worker account + 30 days |
After the retention period, data is permanently deleted or anonymized. You may request earlier deletion of your task data at any time (see Section 6).
We implement industry-standard security measures to protect your data:
To report a security vulnerability, contact [email protected].
Depending on your jurisdiction, you may have the following rights regarding your personal data:
To exercise any of these rights, contact us at [email protected]. We will respond to your request within 30 days (or as required by applicable law). We may need to verify your identity before processing your request.
7.1 Session Cookies. Our web applications (customer dashboard and worker app) use session cookies that are essential for authentication and session management. These cookies expire when you close your browser or after a fixed period of inactivity.
7.2 No Tracking Cookies. We do not use third-party tracking cookies, advertising cookies, or cross-site tracking pixels. We do not participate in ad networks or retargeting platforms.
7.3 Analytics. We use privacy-respecting analytics that do not use cookies and do not track individual users across sites.
The Service is operated from the United States. If you are located outside the United States, your data will be transferred to and processed in the United States. We ensure appropriate safeguards are in place for international transfers, including standard contractual clauses where required by GDPR.
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 18, we will delete it promptly. If you believe a child has provided us with personal information, contact us at [email protected].
As a company with fewer than 250 employees, we are not required to appoint a Data Protection Officer under GDPR. However, for any data protection inquiries, you may contact our privacy team at [email protected].
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a prominent notice on our website at least 30 days before the changes take effect. The "Last Updated" date at the top of this page indicates when the policy was last revised.
If you have any questions or concerns about this Privacy Policy or our data practices, contact us: