Legal
RubberDuck Privacy Policy
Version: 1.0 (draft — not yet published) Effective date: [EFFECTIVE DATE] Last updated: [LAST UPDATED DATE]
This Privacy Policy explains what personal data we collect when you use RubberDuck, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It is written to meet the transparency requirements of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
Capitalised terms — Platform, User, Maker, Engineer, Tokens, Challenge, Call (or Session), Content, and Sub-processor — have the meanings given in our Terms and Conditions and are used the same way here. In short:
- "RubberDuck", "we", "us", "our" — PixelBeard Limited, the operator of the Platform.
- "Platform" — the RubberDuck website, web app, and services.
- "User", "you" — any registered user (Maker or Engineer).
- "Maker" — a User who purchases and spends Tokens to book Calls.
- "Engineer" — an independent professional who provides advice via Calls.
- "Tokens" — prepaid platform credit; 100 Tokens = £1.
- "Challenge" — the problem summary (up to 200 words) a Maker submits.
- "Call" / "Session" — a metered 1:1 video consultation between a Maker and an Engineer.
- "Content" — anything a User submits (Challenges, profiles, ratings, messages).
- "Sub-processor" — a third party that processes personal data on our behalf.
1. Who we are and how to contact us
RubberDuck is operated by PixelBeard Limited, a company registered in England and Wales.
| Company registration number | [COMPANY REGISTRATION NUMBER] |
| Registered office | [REGISTERED OFFICE ADDRESS] |
| ICO registration number | [ICO REGISTRATION NUMBER] |
| Privacy contact | [PRIVACY CONTACT EMAIL] |
We are the data controller for the personal data described in this policy, except where we say otherwise (for example, Stripe acts as an independent controller for payment processing and Engineer identity verification — see Section 6).
Questions or concerns? Email us at [PRIVACY CONTACT EMAIL]. We aim to respond to all privacy queries within one month.
How to complain to the ICO. You have the right to complain to the UK's supervisory authority, the Information Commissioner's Office (ICO), at any time:
- Website: https://ico.org.uk/make-a-complaint/
- Phone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would appreciate the chance to address your concern first, but you are not required to contact us before going to the ICO.
2. The personal data we collect
We aim to collect the minimum data needed to run a paid marketplace for 1:1 video consultations. The full list, by category:
2.1 Account data (all Users)
- Name
- Email address (unique per account)
- Password — stored only as a one-way cryptographic hash (bcrypt/argon2); we cannot read your password
- Role (Maker or Engineer)
- Optional location details you choose to give at registration: city, region, country code, timezone
- Email verification timestamp
2.2 Technical and authentication data
- IP address and browser user-agent, recorded against web session records
- API access tokens (Laravel Sanctum) — stored hashed, expiring after 14 days
- Password-reset tokens (short-lived)
2.3 Maker profile
- Free-text bio
- Free-text project summary
2.4 Engineer profile
- Free-text bio
- Years of experience
- Specialties (tags)
- Work examples (links to external portfolios/images — we do not host uploads)
- Rate band
- Vetting/approval status and internal admin review notes written during vetting
- Average rating (derived from Maker ratings)
- Stripe Connect account ID (a reference to your Stripe payout account — see Section 6)
2.5 Financial data (immutable ledger)
- Token wallet balance
- Wallet transactions: signed Token amounts and GBP pence values, Stripe payment reference, idempotency key, description, and the ID of any admin who acted on the entry
- Engineer earnings records: gross amount in GBP pence, hold-until date, payout status, Stripe payout reference
We never store card numbers or bank details. Payments and payouts are handled by Stripe on Stripe-hosted pages (see Sections 6 and 7). Our financial ledger is append-only: entries are corrected by reversing entries, not edited, so a complete audit trail exists. For how Tokens, billing, and refunds work, see our Terms and Conditions.
2.6 Challenges
- The free-text Challenge body (up to 200 words), category, tags, attachment links (external URLs only — no file uploads), and your preferred time windows
Important: the Challenge body is free text. Anything you type in it — including any personal data about yourself or others — will be stored, shown to matched Engineers and our staff, and (if you use the AI challenge assist) sent to Anthropic (see Section 13). Please do not include personal data in a Challenge unless it is genuinely needed to describe your problem.
2.7 Bookings and availability
- Links between Maker, Engineer, and Challenge; scheduled times; the Engineer rate snapshotted at booking
- Engineer weekly availability rules and blocked slots
2.8 Call session data
- Daily.co room reference, actual start and end times, billed seconds, Token and commission breakdown
- Reconnection and network telemetry for the Call
- Per-user "last seen" presence heartbeat timestamps — behavioural/activity data we use to apply the "both-present" billing rule (you are only billed while both parties are present; see our Terms and Conditions)
2.9 Ratings
- A 1–5 score plus a free-text comment about a specific individual's conduct on a Call
- Maker→Engineer ratings are public on the Engineer's profile; Engineer→Maker ratings are internal-only and visible to our staff
2.10 Call transcripts (feature OFF by default)
The Platform includes a transcription feature which is switched off by default at launch. When it is enabled for a Call:
- Daily.co processes the Call's audio to produce a transcript
- We store the transcript as structured segments (speaker user ID, role, name, text, timestamps) plus a flattened text body
- Raw audio and video are never stored by RubberDuck — only the text transcript
- Default retention is 90 days, after which a daily job deletes the transcript; a transcript may be held longer where needed for an active dispute; our admins can also erase a transcript manually
We will not enable transcription for a Call without appropriate notice and consent from both participants.
2.11 Notifications
- Per-user notification records (booking and session reminders) held in your account.
2.12 What we do NOT collect
We do not collect: date of birth, national identity numbers, postal address, phone number, profile photo uploads, or biometric data. (Stripe may collect identity information directly from Engineers for its own verification purposes — see Section 6.) We do not intentionally collect any special category data (health, ethnicity, beliefs, etc.); please do not include such data in free-text fields.
3. How we collect your data
| Source | What we get |
|---|---|
| Directly from you | Registration details, profile information, Challenges, bookings, availability, ratings, and anything you type into the Platform |
| Automatically, from your use of the Platform | Session records (IP address, user-agent), API tokens, presence heartbeats, Call telemetry, billed seconds, notification records |
| From Stripe | Payment confirmations and references for Token purchases; payout account status and payout references for Engineers (we receive references and statuses, not card or bank details) |
| From Daily.co | Call events (join/leave, start/end) via webhooks, which echo the user ID and role we place in the meeting token; the text transcript, if transcription is enabled |
We do not buy data about you from data brokers, and we do not collect data about you from social media.
4. Why we process your data, and our lawful basis for each purpose
UK GDPR requires a lawful basis for every use of personal data. Here is the full map:
| Purpose | Data used | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Creating and administering your account; authenticating you; sending essential service emails (verification, password reset, booking reminders) | Account data, technical/auth data, notifications | Contract — necessary to provide the Platform under our Terms and Conditions |
| Vetting Engineer applications before approval | Engineer profile, admin review notes | Contract — steps taken at your request before and after entering the Engineer agreement |
| Matching Challenges to Engineers, managing bookings and availability, and running Calls | Challenges, bookings, availability, Call session data | Contract |
| Metered per-second billing, applying the "both-present" rule, and maintaining the Token ledger | Presence heartbeats, Call telemetry, financial ledger | Contract — accurate billing is core to the service you have agreed to |
| Processing Token purchases and Engineer payouts via Stripe | Email, internal user ID, purchase amounts, Stripe references | Contract |
| Displaying Maker→Engineer ratings and using Engineer→Maker ratings internally to maintain marketplace quality and safety | Ratings | Legitimate interests — our interest in a trustworthy, safe marketplace where Users can make informed choices |
| Detecting and preventing fraud, abuse, account compromise, and off-platform circumvention; securing the Platform | IP address, user-agent, session records, ledger data, telemetry | Legitimate interests — our interest in keeping the Platform, its Users, and its payments secure |
| Handling disputes, refunds, and chargebacks | Ledger, Call session data, transcripts (where held), communications | Contract and Legitimate interests — resolving disputes fairly and defending legal claims |
| Keeping immutable financial records | Financial ledger | Legal obligation — UK tax and accounting law requires us to retain financial records |
| Providing the AI challenge assist (Section 13) when you choose to use it | Draft Challenge text, category, tags, your answers to clarifying questions | Contract — providing a Platform feature you actively invoke |
| Producing a Call transcript, when the feature is enabled | Call audio (processed by Daily.co), transcript text | Consent — of both Call participants; the feature is OFF by default and you may decline |
| Notifying you of material changes to our terms or this policy | Email address | Legal obligation and Legitimate interests — keeping you properly informed |
| Responding to lawful requests from courts, regulators, or law enforcement | Whatever is lawfully required | Legal obligation |
Where we rely on legitimate interests, we have balanced our interest against your rights and concluded the processing is proportionate, is within your reasonable expectations as a User of a paid marketplace, and does not override your interests. You can object to any legitimate-interests processing (see Section 11).
We do not use your data for third-party advertising, and we do not sell it.
5. Marketing
We do not send marketing emails at launch. The emails we send are transactional (verification, password reset, booking and session reminders) and are part of running your account. If we introduce marketing in future, we will only send it in line with PECR — with your consent or, for existing customers, under the "soft opt-in" with a clear unsubscribe in every message — and we will update this policy first.
6. Engineer identity verification (KYC) — the special position of Stripe
Engineers are paid via Stripe Connect Express. To open a payout account, Stripe collects information directly from the Engineer — typically identity details, date of birth, address, identity documents, and bank account details — to satisfy its "know your customer" (KYC), anti-money-laundering, and financial-services obligations.
Two things matter here:
- We never see or store that KYC data. RubberDuck stores only your Stripe Connect account ID, your payout status, and payout references.
- Stripe acts as an independent data controller for KYC and payment processing, under its own legal obligations and its own privacy policy: https://stripe.com/gb/privacy. Questions about data Stripe collected directly from you should be directed to Stripe; we will help you route them if you contact us.
What we send to Stripe: for Makers, your email address, the purchase amount, and an internal user ID/metadata so we can reconcile payments; for Engineers, your email address and internal user ID to initiate onboarding of your connected payout account.
7. Who we share your data with
We share personal data only where this policy describes, and never sell it. Recipients fall into four groups:
(a) Other Users — as part of how the Platform works. Matched Engineers see the Maker's Challenge and relevant profile details; Makers see approved Engineer profiles (bio, experience, specialties, work examples, rate band, average rating, public ratings); both parties see each other on a Call. See our Terms and Conditions for what each party may do with information learned on a Call.
(b) Our staff. PixelBeard Limited admin staff use a secured admin panel to approve Engineers, handle disputes and refunds, adjust wallets with an audited reason, view or erase transcripts, and manage configuration. Admin actions against your wallet are recorded in the ledger with the acting admin's ID.
(c) Sub-processors and service providers — listed in full below.
(d) Authorities and successors. Courts, regulators, and law enforcement where legally required; and a buyer or successor entity if we sell or reorganise the business (we would notify you of any change of controller).
7.1 Sub-processor list
| Provider | What they do for us | Personal data involved | Location / transfers | Privacy policy |
|---|---|---|---|---|
| Stripe (Stripe Payments UK / Stripe group) | Token purchases via Stripe-hosted Checkout (RubberDuck is Merchant of Record; card data never touches our systems — PCI-DSS is handled by Stripe) and Engineer payouts via Stripe Connect Express, including KYC (as an independent controller — see Section 6) | Maker: email, purchase amount, internal user ID/metadata. Engineer: email, internal user ID; plus KYC data Stripe collects directly | UK/EU/US — Stripe group transfers are safeguarded by Stripe's intra-group arrangements and, where applicable, the UK IDTA / UK Addendum to the EU SCCs | stripe.com/gb/privacy |
| Daily.co (Daily) | Real-time 1:1 WebRTC video and audio for Calls; when transcription is enabled, Daily processes Call audio to produce the text transcript. Meeting tokens carry your internal numeric user ID and role so Daily can echo your identity back to us on webhooks. We store no raw media | User ID, role, display name, Call audio/video in transit (not persisted by us), transcript text when enabled | US — safeguarded by the UK IDTA / UK Addendum to the EU SCCs | daily.co/legal/privacy-policy |
| Anthropic (Claude) | The optional AI challenge assist (Section 13): when a Maker uses it, the draft Challenge text, chosen category/tags, and the Maker's free-text answers to clarifying questions are sent to Anthropic's API to generate suggestions | Challenge draft text and answers only — no name, email, or user ID is sent — but free text may incidentally contain personal data you typed | US — safeguarded by the UK IDTA / UK Addendum to the EU SCCs | anthropic.com/legal/privacy |
| [EMAIL DELIVERY PROVIDER — TO BE CONFIRMED] | Transactional email delivery (verification, password reset, booking reminders). We will name the provider here once selected | Email address, message content | To be confirmed with the provider | To be confirmed |
| Laravel Cloud | Hosting for our API and admin panel (infrastructure sub-processor) | All Platform data, as host | See Section 8 | laravel.com |
| Vercel | Hosting for our web frontend (infrastructure sub-processor) | Technical request data as host of the web app | US/global edge — UK IDTA / UK Addendum to the EU SCCs | vercel.com/legal/privacy-policy |
We currently use no third-party analytics, error-tracking, SMS, or advertising/marketing services. If we add a Sub-processor whose processing materially affects you, we will update this list.
8. International transfers
We are UK-based and our Users are in the UK, but some Sub-processors (Daily.co, Anthropic, Vercel, and parts of the Stripe group) process data in the United States or other countries outside the UK.
Where personal data leaves the UK, we ensure one of the following safeguards under Articles 44–49 UK GDPR:
- the destination is covered by UK adequacy regulations (including, for certain US recipients, the UK–US "Data Bridge" extension to the EU–US Data Privacy Framework, where the recipient is certified); or
- we have in place the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs) with the recipient, together with any additional measures needed.
You can ask us for more information about the safeguard applying to a specific transfer via [PRIVACY CONTACT EMAIL].
9. How long we keep your data
| Data category | Retention period | Why |
|---|---|---|
| Account and profile data (Maker and Engineer profiles, availability) | While your account is active; deleted or irreversibly anonymised after account closure or a verified erasure request, except where a row below requires longer | Providing the service |
| Web session records (IP, user-agent) and API tokens | API tokens expire after 14 days; session and expired-token records are cleared periodically | Security and authentication only |
| Password-reset tokens | Minutes to hours (single-use, short-lived) | Security |
| Challenges, bookings, ratings, notifications | While your account is active; then deleted or anonymised with the account (public ratings may be retained in anonymised form to preserve Engineer rating integrity) | Providing the service; marketplace trust |
| Call session records (timings, billed seconds, telemetry, presence heartbeats) | While your account is active, and as needed to evidence billing for the periods below | Billing accuracy and dispute resolution |
| Call transcripts (when the feature is enabled) | 90 days by default, then automatically deleted by a daily job; held longer only where needed for an active dispute; admins can erase earlier on request | Dispute resolution; Users' reference |
| Financial ledger (wallet transactions, earnings, payout records) | At least 6 years after the relevant financial year, in line with UK tax and accounting requirements. The ledger is immutable and is retained even if you close your account | Legal obligation |
| Engineer vetting records and admin review notes | Duration of the Engineer relationship plus up to 6 years | Defending legal claims; regulatory accountability |
When you close your account or we accept an erasure request, we delete or anonymise everything except what the table above requires us to keep, and we restrict what we keep to that purpose only.
10. Cookies and similar technologies (PECR)
We keep this deliberately minimal. At launch the Platform uses only strictly-necessary and functional storage — no analytics cookies, no marketing or advertising cookies, and no third-party tracking. Under PECR, strictly-necessary storage does not require prior consent, which is why you will not see a cookie banner; we still disclose everything here:
| Name / type | Set by | Purpose | Kind |
|---|---|---|---|
| Authentication token (browser localStorage, not a cookie) | RubberDuck web app | Keeps you signed in to the web app (Bearer token; expires after 14 days) | Strictly necessary |
| Laravel session cookie (and associated CSRF token) | RubberDuck API / admin panel | Session state and security for the API and admin panel | Strictly necessary |
| Theme preference (localStorage) | RubberDuck web app | Remembers your light/dark theme choice | Functional |
Stripe cookies (e.g. __stripe_mid, __stripe_sid) |
Stripe, on its hosted Checkout pages | Fraud prevention and payment session integrity during checkout | Strictly necessary (set by Stripe on Stripe's pages — see stripe.com/gb/privacy) |
If we ever introduce analytics, advertising, or any non-essential cookies, we will add a consent banner and obtain your consent before setting them, and we will update this section.
11. Your rights and how to exercise them
Under UK GDPR you have the right to:
- Access — get a copy of your personal data (a "subject access request")
- Rectification — correct inaccurate or incomplete data
- Erasure — have your data deleted ("right to be forgotten"), subject to the retention obligations in Section 9 (for example, we must keep the financial ledger)
- Restriction — limit how we use your data while a dispute or check is resolved
- Portability — receive the data you provided to us in a structured, commonly used, machine-readable format
- Objection — object to processing based on legitimate interests (see the table in Section 4)
- Withdraw consent — where processing is based on consent (currently only Call transcription, when enabled), withdraw it at any time without affecting processing that already happened
11.1 How to exercise them
Email [PRIVACY CONTACT EMAIL] from the address on your account (or otherwise prove your identity — we may ask for verification to protect your data). We will respond within one month; if a request is complex we may extend by up to two further months, and we will tell you if so. Exercising these rights is free, unless a request is manifestly unfounded or excessive.
11.2 An honest note about self-service
We do not yet offer in-product account deletion or data export. Right now, access, erasure, and export requests are handled manually by our team when you email us — the rights themselves are unaffected and we will honour them within the statutory timescales. We are building a self-serve flow for account deletion and data export, and will update this policy when it is available.
11.3 What erasure looks like in practice
On a verified erasure request we delete or irreversibly anonymise your account, profiles, Challenges, bookings, ratings, notifications, and any transcripts, and we retain only what Section 9 obliges us to keep (principally the immutable financial ledger, held for tax and accounting law), restricted to that purpose.
If you are unhappy with how we handle a request, you can complain to the ICO (Section 1).
12. Automated decision-making and profiling
We do not make any decision about you based solely on automated processing that produces legal effects or similarly significantly affects you (UK GDPR Article 22).
Specifically:
- Matching. At launch, matching a Challenge to an Engineer is a concierge process: our system may suggest candidates, but a human (our admin team) confirms every match. No booking is created or refused by an algorithm alone.
- AI challenge assist. The AI feature (Section 13) only produces suggestions — a rewritten draft, clarifying questions, and suggested category/tags. The Maker decides what to submit. It makes no decision about you.
- Billing. Per-second billing is automated arithmetic applied under the rules in our Terms and Conditions (rate snapshot, both-present rule); it is the performance of the contract you agreed to, and disputes are reviewed by a human admin.
If we ever introduce solely-automated decision-making with legal or similarly significant effects, we will update this policy first and provide the safeguards Article 22 requires (including human review on request).
13. AI features and transparency
AI challenge assist. When a Maker drafts their first Challenge, they can optionally use an AI assistant to improve it. If you use it, we send your draft Challenge text, your chosen category/tags, and your free-text answers to the assistant's clarifying questions to Anthropic (the provider of the Claude model) to generate a rewritten draft and suggestions. We do not send your name, email address, or user ID. Because the input is free text, anything you type in it will be transmitted — so do not include personal data you would not want processed by Anthropic. The output is only a suggestion; you choose what to submit.
Call transcription. See Section 2.10: OFF by default at launch, requires both participants, processed by Daily.co from Call audio, stored as text only for 90 days by default, and no raw audio or video is ever kept by RubberDuck.
We do not use your Content to train our own AI models.
14. Children
The Platform is for adults. You must be at least 18 years old to create an account, purchase Tokens, or provide services as an Engineer (see our Terms and Conditions). We do not knowingly collect personal data from anyone under 18; if you believe a child has created an account, contact [PRIVACY CONTACT EMAIL] and we will delete it.
15. How we protect your data
- Passwords are stored only as strong one-way hashes (bcrypt/argon2) — never in plain text.
- Encryption in transit: all traffic to the Platform uses TLS (HTTPS).
- Payments: card and bank data never touch our systems; Stripe's PCI-DSS-certified infrastructure handles them end to end.
- API tokens are stored hashed and expire after 14 days.
- No raw media: Call audio and video are never recorded or stored by RubberDuck; at most a text transcript is kept, under the rules in Section 2.10.
- Least privilege: admin capabilities sit behind a separate, access-controlled panel; sensitive admin actions (wallet adjustments, refunds, transcript erasure) are attributed to the acting admin and audited.
- Financial integrity: the append-only ledger design means records cannot be silently altered.
No system is perfectly secure. If a personal data breach occurs that risks your rights and freedoms, we will notify the ICO within 72 hours where required and tell you directly where the risk to you is high, as UK GDPR requires.
16. Changes to this policy
We may update this policy as the Platform, the law, or our Sub-processors change. The "Last updated" date and version at the top will change with every revision. For material changes — for example, a new purpose of processing, a new Sub-processor that materially affects you, or enabling transcription — we will give you advance notice by email or prominent in-Platform notice before the change takes effect.
Earlier versions are available on request from [PRIVACY CONTACT EMAIL].
This Privacy Policy should be read together with our Terms and Conditions, which govern your use of the Platform.