Privacy Policy

Last Updated: September 2026

Tool Connect (also referred to as "Tool", "we", or "us") is committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR) and applicable Czech law. This Privacy Policy explains what personal data we collect, why we process it, who we share it with, and what rights you have when you use our platform (the website tool-connect.com and our mobile apps).

1. Who we are

The controller of your personal data is the operator of the Tool Connect platform, with its place of business in Prague, Czech Republic. For privacy matters, contact us at info@tool-connect.com.

  • The platform connects clients with service providers in the Czech Republic (website, iOS, and Android).
  • This Policy applies to all users of the website and the mobile apps.
  • Please read this Policy together with our Terms and Conditions and Cookie Policy.

2. Data We Collect

We collect different types of data depending on how you use the platform:

For All Users:

  • Phone number (used for account verification via one-time password – OTP)
  • First and last name
  • Email address if you provide one (for example on a business profile or the contact form)
  • Profile photos, profile backgrounds, and profile videos
  • Language preferences
  • Location data (city, country, and approximate coordinates for nearby searches)
  • Messages and attachments sent through the platform, including metadata such as send time, edit time (when applicable), and read status
  • Account and session identifiers needed to keep you signed in
  • A device push-notification token in the mobile app if you enable notifications
  • Search queries and related filters (category, location, result count) so we can improve search

For Clients:

  • Preferred service categories and search settings
  • Favorite service providers
  • Work requests (description, budget, photos, and other attachments)
  • Reviews and ratings

For Service Providers:

  • Business details (e.g. company name, IČO if applicable)
  • Services offered, category, and specialization
  • Bio, pricing, and availability
  • Portfolio (images, videos, descriptions)
  • Social media links

Technical and Diagnostic Data (collected automatically):

  • Error reports and crash logs (the error message and the location in the code where it occurred)
  • Device information (device model, operating system or browser version)
  • A history of actions taken in the app or on the website just before an error occurred
  • An opaque user identifier, so we can trace and resolve issues affecting your account

This technical and diagnostic data is processed by Sentry solely to keep the platform secure and functional (on the basis of legitimate interest). The IP address is anonymized (not stored) and no message content or other personal data is sent beyond that identifier.

3. Purposes and legal bases

We process personal data only where we have a legal basis under Article 6 GDPR:

  • Contract (Article 6(1)(b) GDPR) — creating and managing your account, profiles, search, work requests, messaging, storing and displaying media, and delivering notifications you have enabled.
  • Legitimate interest (Article 6(1)(f) GDPR) — platform security, abuse prevention (including SMS fraud and bots), moderation, error diagnostics, improving search, and basic website operation.
  • Consent (Article 6(1)(a) GDPR) — analytics cookies (Google Analytics) and any future marketing cookies. You may withdraw consent at any time.
  • Legal obligation (Article 6(1)(c) GDPR) — where the law requires us to retain or disclose data (for example to a competent authority).

We do not sell your personal data and we do not use it for advertising profiling.

4. Use of Phone Number

Your phone number is used to:

  • verify your account
  • send login codes (OTP)
  • send important service-related notifications (e.g. critical updates)

We do not use your phone number for marketing without your explicit consent. Other users can see your phone number only if you choose to share it.

5. Messaging and Communication

Messages sent through the platform are stored until you delete them individually or until you delete your account. We process messages to:

Message Storage and Processing:

  • ensure proper functionality
  • support user communication
  • maintain platform safety
  • investigate misuse or violations

Access to Messages:

  • moderation and enforcing platform rules
  • user support requests
  • safety and fraud prevention
  • investigation of illegal or inappropriate activity

When you edit a message, only the latest version is kept and the recipient is shown an "edited" indicator. When you delete a message you sent, your own view hides it and the recipient sees a "This message was deleted" placeholder. The original record may still remain stored temporarily in our systems for security, moderation, and legal purposes. Chat attachments are not publicly accessible; they are viewed through time-limited signed links.

6. Photos, videos, and other files

We process files you upload (avatars, backgrounds, portfolio, profile videos, work-request photos, and chat attachments) so we can store them and display them on the platform.

  • New uploads are stored with our object-storage provider Backblaze (B2) in the European Union (Amsterdam).
  • Public media (for example profile photos, backgrounds, portfolio, profile videos, and work-request photos) are delivered through Cloudflare’s CDN at cdn.tool-connect.com so they load quickly over HTTPS.
  • Chat attachments are private. They are not served publicly through the CDN; only conversation participants can open them via a time-limited link.
  • Some older files may still be stored in Supabase Storage until migration is finished. Both locations are protected by access rules and encrypted transport.
  • Public media may be cached briefly at Cloudflare edge locations, including outside the EEA, so they can load quickly. After you delete or replace a file we usually purge that cache; a copy may remain until it expires.
  • Content you publish on a profile or work request is visible to other users of the platform.

7. Processors and third-party services

We use trusted processors to operate the platform. They process data only on our instructions and only as needed for their service:

  • Supabase — database, authentication (including OTP sessions), and Edge Functions. The database runs in the EU (Stockholm). Some older files may still be in Supabase Storage.
  • Backblaze (B2) — storage of photos, videos, and attachments in the EU (Amsterdam).
  • Cloudflare — CDN for public media (cdn.tool-connect.com), DNS, and login protection (Turnstile) against bots and SMS abuse.
  • Netlify — hosting of the tool-connect.com website.
  • Twilio — sending SMS verification codes (OTP).
  • Google Places API — location autocomplete.
  • Google Translate API — content translation (text may be processed by Google).
  • Google Analytics — aggregated website usage, only if you consent to analytics cookies.
  • Formspree — handling the website contact form.
  • Sentry — error monitoring and crash reporting. Sentry receives only technical error details, device information, the history of actions leading up to an error, and a user identifier. The IP address is anonymized. Sentry has no access to message content.
  • Expo — delivering push notifications in the mobile app if you enable them. Delivery on the device may go through Apple or Google services.

These providers process data in accordance with GDPR and applicable data-protection standards. Where required, we use data-processing agreements and approved safeguards for international transfers.

8. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encrypted transport (HTTPS/TLS) between your device, our website, the CDN, and our storage providers
  • Private media storage; public files are delivered only through our controlled CDN address
  • Private chat attachments via time-limited links, not public URLs
  • Secure authentication using OTP; internal administrator accounts may require additional verification (MFA)
  • Cloudflare Turnstile on login to reduce automated abuse
  • Access restricted to authorized personnel only
  • Use of secure tokens for session management

9. Sharing of Data

  • Profile information (name, photos, videos, services, location) is visible to other users
  • Phone numbers are only visible if you choose to share them
  • Verified platform administrators may proactively contact you for support, moderation, or operational purposes. Such messages are clearly marked with a "Tool Admin" badge
  • Data may be shared with authorities if legally required
  • Aggregated, anonymized data may be used for analytics
  • The processors listed in section 7 receive only the data needed to provide their service

10. User Rights (GDPR)

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your account and personal data (the “right to be forgotten”)
  • Restrict processing
  • Object to processing based on legitimate interest
  • Request data portability
  • Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal

To exercise your rights, contact info@tool-connect.com. You also have the right to lodge a complaint with the supervisory authority: the Czech Office for Personal Data Protection (ÚOOÚ), www.uoou.cz.

11. Data Retention

  • Account data is stored while your account is active
  • When you delete your account we remove personal data from active systems and delete related files from storage (Backblaze and any remaining Supabase Storage)
  • Messages are stored until you delete them individually or delete your account; after deletion they may remain temporarily for security and moderation
  • Public media may remain briefly in the CDN cache until we purge it or it expires
  • Support requests (including contact-form messages) may be retained for up to 2 years
  • Search logs are kept for a limited period to improve the service and are then deleted or aggregated
  • Error reports are retained by Sentry for up to 90 days and then automatically deleted
  • Some anonymized data may be retained for analytics and service improvement

12. Cookies and Local Storage

  • We use browser local storage and essential cookies for sign-in, language, and consent preferences
  • We load analytics tools (Google Analytics) only with your consent
  • We do not use advertising tracking cookies
  • Cloudflare may set essential security cookies related to login protection (Turnstile)

For full details on our cookie usage, please see our Cookie Policy.

13. International Data Transfers

Our database and media storage run in the European Union (Supabase in Stockholm, Backblaze in Amsterdam). Some processors (for example Google, Twilio, Sentry, Formspree, Netlify, Cloudflare, and Expo) may also process data outside the EEA. Public media may be cached temporarily at Cloudflare edge servers worldwide so they load quickly. These providers use GDPR-approved safeguards, in particular Standard Contractual Clauses, where relevant.

14. Children and minors

The platform is for people aged 18 or over. We do not knowingly collect personal data from children. If you believe a minor has created an account, contact us at info@tool-connect.com and we will delete it.

15. Updates to This Privacy Policy

We may update this Policy from time to time, for example when we change storage, CDN, or other processors. The “Last updated” date is always at the top of this page. We will notify you of significant changes in the app or by email. Continued use of the platform after we publish changes means you accept the updated policy, unless the law requires a new consent.

For any questions regarding this Privacy Policy: info@tool-connect.com