1. Introduction
Gygnus ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.
This policy complies with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other applicable privacy laws.
2. Information We Collect
2.1 Personal Information
We collect the following types of personal information:
- Account Information: Full name, email address, phone number, password (encrypted)
- Profile Information: Profile photo, bio, skills, experience, certifications
- Location Data: Address, city, state, ZIP code, GPS coordinates (when permissioned)
- Verification Data: Government ID, business licenses (for service providers)
2.2 Payment Information
Financial data is processed securely by Stripe, our payment processor.
- Gygnus does NOT store credit card numbers, CVV codes, or full bank account details
- We store only: last 4 digits of cards, payment method type, and transaction history
- All payment data is encrypted and PCI-DSS compliant
- Stripe's privacy policy also applies: stripe.com/privacy
2.3 Usage Data
We automatically collect:
- IP address, browser type, device information
- Pages visited, time spent on platform, click patterns
- Search queries, job posts viewed, messages sent
- Error logs and performance data
2.4 Communications Data
- Messages exchanged between customers and service providers
- Reviews and ratings
- Customer support inquiries
- Email and SMS communications with Gygnus
3. How We Use Your Information
3.1 Core Services
- Create and manage your account
- Match customers with service providers
- Process payments and manage escrow
- Enable communication between users
- Display your profile to potential customers/providers
3.2 AI Usage
We use Artificial Intelligence (powered by Google Gemini and OpenAI) to enhance your experience:
- Customer Support: AI chatbot helps answer questions and resolve issues
- Job Matching: AI analyzes job descriptions to suggest relevant service providers
- Content Improvement: AI corrects grammar and suggests better phrasing for job posts
- Fraud Detection: AI identifies suspicious patterns to protect users
When you interact with AI features, your messages may be sent to third-party AI providers (Google, OpenAI). These providers have their own privacy policies:
3.3 Platform Improvements
- Analyze usage patterns to improve features
- Conduct A/B testing for better user experience
- Generate anonymized analytics and reports
- Train AI models (with anonymized data only)
3.4 Safety and Security
- Verify user identities and prevent fraud
- Resolve disputes and enforce Terms of Service
- Comply with legal obligations and court orders
- Protect against security threats and abuse
3.5 Marketing and Communications
- Send job opportunities to service providers
- Notify users of platform updates and new features
- Promotional emails (you can opt-out anytime)
- SMS notifications for urgent job updates (opt-in required)
4. How We Share Your Information
4.1 With Other Users
- Public Profile: Name, photo, bio, ratings, and reviews are visible to other users
- Job-Specific: When you apply or post a job, relevant details are shared with the other party
- Location: Approximate location (city/neighborhood) is shown; exact address only shared after hire
4.2 With Service Providers
- Stripe: Payment processing (see Section 2.2)
- AI Providers: Google Gemini, OpenAI (see Section 3.2)
- Cloud Hosting: AWS/Heroku (encrypted data storage)
- Analytics: Google Analytics (anonymized usage data)
- Email Service: SendGrid/Mailgun (transactional emails)
4.3 Legal Requirements
We may disclose information when required by law:
- In response to court orders or subpoenas
- To comply with government investigations
- To protect rights, property, or safety of Gygnus and its users
- In connection with potential fraud or illegal activity
4.4 Business Transfers
If Gygnus is acquired or merged with another company, your information may be transferred to the new owner. We will notify you before this happens.
5. Data Retention
- Active Accounts: Data retained as long as account is active
- Deleted Accounts: Most data deleted within 30 days; financial records kept for 7 years (legal requirement)
- Backup Data: May persist in backups for up to 90 days after deletion
- Legal Hold: Data preserved if subject to legal dispute or investigation
6. Your Privacy Rights
6.1 GDPR Rights (EU Users)
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate information
- Erasure: Request deletion of your data ("right to be forgotten")
- Portability: Export your data in machine-readable format
- Objection: Object to certain types of processing
- Restriction: Limit how we use your data
6.2 CCPA Rights (California Users)
- Know: What personal information we collect, use, and share
- Delete: Request deletion of your personal information
- Opt-Out: Opt-out of sale of personal information (Note: Gygnus does NOT sell user data)
- Non-Discrimination: Equal service regardless of privacy choices
6.3 How to Exercise Rights
Email us at: privacy@gygnus.com
Or visit: Settings → Privacy → Data Requests
We will respond within 30 days for GDPR requests, 45 days for CCPA requests.
7. Cookies and Tracking
We use cookies and similar technologies:
- Essential Cookies: Required for platform functionality (login, security)
- Analytics Cookies: Track usage patterns (Google Analytics)
- Preference Cookies: Remember your settings and language
- Marketing Cookies: Personalize ads (you can opt-out)
Manage cookie preferences in your browser settings or our Cookie Consent banner.
8. Data Security
We protect your data with:
- 256-bit SSL/TLS encryption for data in transit
- AES-256 encryption for data at rest
- Regular security audits and penetration testing
- Access controls and multi-factor authentication for staff
- Automated backup and disaster recovery systems
Note: No system is 100% secure. We cannot guarantee absolute security but use industry-standard practices to protect your information.
9. Children's Privacy
Gygnus is not intended for users under 18 years old. We do not knowingly collect data from children. If we discover a child's account, we will delete it immediately.
10. International Data Transfers
Gygnus is based in the United States. If you access our platform from another country, your data may be transferred to and processed in the U.S. By using Gygnus, you consent to this transfer.
11. Changes to Privacy Policy
We may update this Privacy Policy periodically. We will notify you of significant changes via email or platform notification. Continued use after changes constitutes acceptance.
12. Contact Us
For privacy questions or to exercise your rights:
Email: privacy@gygnus.com
Address: Gygnus Inc., Privacy Team, Newark, NJ 07102
Phone: (555) 123-4567
Your privacy matters to us. If you have any concerns about how your data is handled, please contact us. We're here to help.