Privacy Policy

Last updated: November 14, 2025

Introduction

ThankATech ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform that connects customers with skilled technicians.

Information We Collect

Personal Information

  • Name, email address, and phone number
  • Business information (for technicians)
  • Profile photos and business images
  • Location data (with your permission)
  • Payment information (processed securely)
  • Points and recognition data
  • TOA token transaction history

Usage Information

  • How you interact with our platform
  • Pages visited and features used
  • Device information and IP address
  • Browser type and operating system

How We Use Your Information

  • To provide and maintain our services
  • To facilitate connections between customers and technicians
  • To process payments, tips, and TOA token transactions
  • To calculate and display points for community recognition
  • To manage TOA token purchases, transfers, and payouts
  • To send you important updates and notifications
  • To improve our platform and user experience
  • To ensure platform safety and prevent fraud
  • To comply with legal obligations

Information Sharing

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:

  • With Other Users: Profile information visible to facilitate connections
  • Service Providers: Third-party services that help us operate our platform
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In case of merger, acquisition, or asset sale
  • With Your Consent: Any other sharing with your explicit permission

Data Security

We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.

  • Encryption of data in transit and at rest
  • Regular security assessments and updates
  • Access controls and authentication procedures
  • Employee training on data protection

Your Rights and Choices

You have the following rights regarding your personal information:

  • Access: Request copies of your personal information
  • Rectification: Request correction of inaccurate information
  • Erasure: Request deletion of your personal information
  • Portability: Request transfer of your data to another service
  • Objection: Object to processing of your personal information
  • Restriction: Request restriction of processing

Regional Privacy Rights

European Union (GDPR) Rights

If you are located in the European Union, you have additional rights under the General Data Protection Regulation (GDPR):

  • Lawful Basis: We process your data based on consent, contract performance, or legitimate interests
  • Right to Object: You can object to processing based on legitimate interests
  • Data Protection Officer: Contact us at privacy@thankatech.com for GDPR-related inquiries
  • Supervisory Authority: You have the right to lodge a complaint with your local data protection authority
  • Data Retention: We retain data only as long as necessary for the stated purposes

California (CCPA) Rights

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: Request information about personal information we collect, use, and disclose
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: We do not sell personal information, but you can opt-out if this changes
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
  • Authorized Agent: You may designate an authorized agent to make requests on your behalf

Exercising Your Rights

To exercise any of these rights, please contact us:

  • Email: privacy@thankatech.com
  • Subject Line: Include "Privacy Rights Request" in your email
  • Response Time: We will respond within 30 days of receiving your request
  • Verification: We may need to verify your identity before processing requests

Cookies and Tracking

We use cookies and similar tracking technologies to enhance your experience on our platform:

  • Essential cookies for platform functionality
  • Analytics cookies to understand usage patterns
  • Preference cookies to remember your settings
  • You can control cookie preferences in your browser settings

Mobile Applications (Future Considerations)

If we develop mobile applications in the future, additional data collection and privacy considerations may apply:

Mobile Device Permissions

  • Location Services: With your permission, to help find nearby technicians
  • Camera Access: To upload profile photos and business images
  • Push Notifications: To send important updates and messages
  • Contacts: Only with explicit permission, to facilitate connections
  • Storage: To save app data and preferences locally

Mobile-Specific Data Collection

  • Device identifiers and mobile advertising IDs
  • App usage analytics and crash reports
  • Device type, operating system, and app version
  • Network information and connection status
  • App store interaction data (downloads, updates)

Mobile Privacy Controls

You will always have control over mobile permissions and can modify them through your device settings. We will request permissions only when necessary for specific features and will explain why each permission is needed.

Payment Processing & Stripe Integration

We use Stripe, Inc. ("Stripe") as our payment processor to handle all financial transactions securely. This section explains how your payment information is handled:

Payment Data Security

  • PCI DSS Compliance: Stripe is certified as a PCI Level 1 Service Provider
  • Card Data: We never store your complete credit card information
  • Tokenization: Card details are converted to secure tokens by Stripe
  • Encryption: All payment data is encrypted in transit and at rest
  • 3D Secure: Additional authentication for enhanced security

Information Collected for Payments

  • Billing name and address
  • Credit/debit card information (processed by Stripe)
  • Transaction history and receipt information
  • Device and browser information for fraud prevention
  • IP address and geolocation data for security verification

Payment Data Usage

  • Processing tip payments and TOA token purchases and payouts to technicians
  • Calculating and collecting platform fees
  • Generating receipts and transaction records
  • Managing points calculation and display for community recognition
  • Processing TOA token conversions and monetary payouts
  • Fraud detection and prevention
  • Compliance with financial regulations (AML, KYC)
  • Resolving payment disputes and chargebacks

Stripe's Role and Responsibilities

  • Stripe acts as our payment processor and may collect additional information
  • Stripe's privacy policy governs their handling of your payment data
  • Stripe may use your information for their own fraud prevention and compliance
  • You can review Stripe's privacy policy at stripe.com/privacy

Platform Fee Structure

ThankATech charges a flat platform fee of $0.99 per transaction. This fee covers:

  • Payment processing through Stripe
  • Platform maintenance and security
  • Customer support and dispute resolution
  • Fraud protection and monitoring
  • Compliance with financial regulations

Third-Party Services

Our platform integrates with third-party services to enhance functionality:

  • Google Sign-In: For secure authentication and profile management
  • Firebase: For data storage, authentication, and real-time features
  • Stripe: For secure payment processing (see Payment Processing section above)
  • Analytics services: For platform improvement and usage insights

These services have their own privacy policies, and we encourage you to review them.

Children's Privacy

Our platform is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you become aware that a child has provided us with personal information, please contact us immediately.

International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your personal information in accordance with this privacy policy and applicable laws.

Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this privacy policy, unless a longer retention period is required or permitted by law.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

For material changes, we will provide at least 30 days' notice before the new policy takes effect. You are advised to review this Privacy Policy periodically for any changes.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Note: ThankATech is an online platform. All communications are handled electronically via email or through our website contact form.

Governing Law

This Privacy Policy shall be governed by and construed in accordance with the laws of the State of New York, without regard to its conflict of law provisions. Any disputes arising from this Privacy Policy will be subject to the exclusive jurisdiction of the courts located in New York County, New York.