1. Who we are
WeDoIt is the operator of wedoit.work and the WeDoIt iOS and Android apps. We are launching in Metro Manila, Philippines.
WeDoIt is a directory and messaging host. Clients find skilled tradespeople, message them, and settle payment themselves. We do not employ professionals, do not hold escrow, do not take commissions, and do not process payments. We do not impose working hours or exclusivity.
Contact for privacy and data requests: hello@wedoit.work.
2. What this policy covers
It applies when you use the apps, this website, or related operator tools. It does not cover websites or apps we do not control, including Google when you choose Google sign-in.
3. Data we collect
Account
When you sign up we collect an email address and, if you use Google, the name and avatar Google shares with us. Authentication is provided by Clerk. We send email one-time codes after a Cloudflare Turnstile check. We record that you attested you are old enough to use the service. We do not currently collect phone numbers on the sign-up path.
If you join the website waitlist we store the email address and whether you chose Client or Professional, so we can tell you when WeDoIt opens in Metro Manila. That is not an app account.
Profile and jobs
If you publish a professional profile we store display name, trades, bio, avatar, portfolio photos, service area, and whether you are accepting work. If you post a job we store the title, description, optional budget, photos, and a location for matching.
Location
To rank nearby professionals and jobs we store precise coordinates on our servers. Other users never receive those coordinates. They see a neighbourhood-style label and a rounded distance (for example “Quezon City · 2 km”). Display pins on maps are offset from the true point by a fixed per-user amount so a profile cannot be used as a live GPS fix.
Messages and media
Direct messages may include text, photos, and voice memos. Photos have EXIF (including GPS) stripped before they are stored. Voice memos are stored so the other participant can play them back. We may keep a server-side export of a thread for safety and continuity.
Reviews and proof
Reviews, optional replies, and proof photos of completed work (captured in-app from the camera) are stored and may appear on a professional’s public profile.
Identity documents
If a professional submits government ID or trade certifications for a verification badge, those files are stored privately. They are not published. After we approve or reject the submission we schedule the images for deletion within 7 days. Regardless of that decision, identity-document images are not kept longer than 90 days from upload. The decision itself — approved or rejected, and any badge — is kept.
Device, safety, and operations
- Device identifiers and Expo push tokens, so we can send chat, job-match, and verification notifications you enable.
- Reports and blocks you submit, and automated holds when public text matches our safety screener.
- Coarse search logs (city, trade, area cell — not a street address) so we can operate the market.
- Admin audit logs of operator actions (market changes, moderation, verification decisions).
4. Why we use it
- To run the directory, job board, and chat.
- To show trust signals (ratings, badges, proof) without holding anyone’s money.
- To moderate reports, enforce blocks, and review credentials.
- To send notifications and transactional email you have a reason to receive.
- To keep the service secure (rate limits, bot checks, abuse and ban evasion on device and email).
- To understand liquidity in a city at a coarse geographic level — not to track you from street to street.
We do not sell personal data. We do not use your chat contents to train public AI models.
5. Who can see it
Other users see what you publish: professional profiles, open jobs (without the poster’s identity on the public board), reviews, and messages you send to a thread participant. Blocked users cannot contact you.
Operators with a separate admin account and multi-factor authentication can see reports, verification documents, and enough account context to moderate. Those actions are audited.
Processors who help us run the service, under their own terms:
- Clerk — sign-in (email OTP and Google).
- Cloudflare — hosting, database, file storage, CDN, and Turnstile.
- Expo — push notification delivery.
- Resend — transactional email.
- Google — only if you choose Google sign-in.
We may disclose information if required by law or to prevent serious harm. Advertising in the feeds is planned; it is not currently personalised in the shipped app. If that changes, we will update this policy and request consent where the stores require it.
6. Permissions on your device
We ask for location, camera, microphone, and notifications in context — when you search nearby, take a proof photo, record a voice memo, or turn a notification category on — not as a stack of prompts at first launch. You can refuse; some features then cannot run.
7. How long we keep it
- Account, profile, jobs, reviews, and messages: for as long as the account exists. When you ask us to delete the account we remove or anonymise it (messages in a shared thread may be anonymised in place so the other person keeps their history). There is not yet a self-serve deletion form on this website — email us.
- Identity-document images: 7 days after the verification decision, and never more than 90 days from upload.
- Chat photos: up to 365 days. Voice memos: up to 180 days. Or sooner if the account is deleted.
- Push tokens: until the device is unregistered or the account is deleted.
- Coarse search logs and operator audit logs: as long as needed to operate and secure the market.
8. Your choices and rights
You can edit your profile, notification preferences, and blocks in the app. You can request a copy of your data or deletion by emailing hello@wedoit.work from the address on the account. We will complete deletion across our systems (account provider, database, files, and chat storage) within a reasonable period unless we must retain a narrow record (for example a ban, to stop evasion).
If you are in the Philippines, you have rights under the Data Privacy Act of 2012 (Republic Act No. 10173), including access, correction, and erasure, and you may complain to the National Privacy Commission.
9. Children
WeDoIt is not directed at children. You must be 18 or older. We collect a self-attested date of birth at sign-up and do not complete account creation under that age. If you believe we have an underage account, write to hello@wedoit.work.
10. International processing
We and our processors may store or process data outside the Philippines (including on Cloudflare’s global network). We do that to run a single hosted service, not to sell data abroad.
11. Changes
If we change this policy in a material way we will update the date and version on this page. The apps also carry a privacy-policy version from our servers so we can tell a shipped build that a newer text exists.
Questions
Email hello@wedoit.work · Metro Manila, Philippines
This page is the operator’s description of current product behaviour. It is not legal advice. Store listings and in-app links should point here: https://wedoit.work/privacy.html