1. Who we are
MatchU is a marketplace that connects local businesses with user-generated-content (UGC) creators. It is operated from Quebec, Canada by [COMPANY LEGAL NAME], located at [STREET ADDRESS, CITY, QUEBEC, POSTAL CODE].
The person responsible for the protection of personal information at MatchU is [NAME, TITLE OF THE PERSON RESPONSIBLE FOR PERSONAL INFORMATION], reachable at [PRIVACY EMAIL].
2. What we collect
We only collect what the service needs to work. Depending on your role and how you use MatchU:
Account
- Your email address, a hashed password (we never store the password itself), your role (creator or business), username, legal first and last name, and phone number.
- How we use your email and phone number: only to log you in, verify your account, reset your password, and send essential service notices. They are never displayed to other users and never sold. They are shared only with the provider that delivers our emails (and, if we add text messages later, the SMS provider), solely to deliver those messages. Both are deleted with your account.
- If you sign in with Google or Apple, we receive your email address and basic profile from that provider instead of a password.
- Your theme preference, whether your email is verified, the date you accepted the Terms of Use, and the version of this policy you accepted.
Creator profile
- Display name, bio, city and country, approximate coordinates if you provide them, languages, interests, niches, content formats, platforms, skills, experience level, availability (including hours per week and on-site availability), a profile photo or a preset avatar, portfolio images, video links, and links to your social accounts.
Business profile
- Company name, logo, website, industry, pitch, one or more store addresses (up to ten, with coordinates and a Google place identifier when address autocomplete is enabled), and the brief that describes the content the business is looking for (niches, formats, platforms, languages, dates, product description, usage rights, experience wanted, on-site needs).
Activity on the platform
- Interests and contacts: which businesses a creator expresses interest in, which creators a business contacts, and whether a business accepted or declined an interest, with the date.
- Follows and shortlists.
- Roster entries a business keeps about creators it has contacted or accepted: a stage (New, Talking, Active, Past), private notes and tags, and a history of stage changes.
- Messages and group posts, including when a message was delivered and seen, reactions to group posts, and when you last opened a group.
- In-app notifications and whether you have read them.
- Service requests a business sends to the MatchU team, and the team's status updates and notes on them.
- Events: whether you unlocked the events area, and when you confirm attendance to an event, your name, email, phone number, and a ticket code are added to that event's guest list.
- Usage limits: counts of your daily swipes or weekly contacts, and your premium or boost status.
- Timestamps: when your account was created and when you were last active.
Technical data
- Your IP address, read from the request only to limit abuse (for example repeated login or sign-up attempts). These counters are kept in memory for minutes and are not written to our database.
- Standard server logs kept by our hosting provider (IP address, browser user agent, requested URL, and timestamps).
- The cookies described in section 6.
Administrative records
- Actions taken by the MatchU team in the admin panel (for example closing an account or updating a service request) are logged with the administrator's email, the target account's email, and a short description.
We do not collect payment card information: MatchU does not process payments between businesses and creators. We do not use advertising trackers or third-party analytics.
3. Why we collect it
Each purpose below uses only the information listed next to it:
- Create and secure your account, and let you log in. Email, hashed password or sign-in provider, email verification status, IP address for rate limiting.
- Show your profile to the other side of the marketplace so businesses and creators can find each other. Creator profile fields, business profile fields, addresses and briefs, username, legal name (see section 7).
- Run interests, contacts, rosters, messaging, groups, and notifications. Interests, accept and decline answers, roster entries, messages and group posts with delivered and seen times, reactions, notifications.
- Apply the usage limits of your plan. Daily swipe and weekly contact counts, premium and boost status.
- Organize community events and check attendees in. Your name, email, phone number and ticket code on the guest list.
- Handle requests you send to the team. Service requests, their status and notes, and your contact information.
- Remember your preferences. Theme choice, profile visibility setting.
- Prevent abuse, enforce our rules, and keep the service reliable. IP-based rate limiting, server logs, administrative records.
- Meet our legal obligations, including keeping a record of the consent you gave and the policy version you accepted.
We do not use your information for advertising, and we never sell it.
4. Consent and how to withdraw it
You consent to this collection and use when you create an account (by ticking the box that says you agree to the Terms of Use and have read this policy), and each time you add information to your profile or use a feature. We record the date of that consent and the version of this policy you accepted. When this policy changes in a way that matters, we show you the new version and ask you to review it again.
Some information is required for the service to work (for example an email address to log in, or a profile for the other side to see). Without it we cannot provide the service. Everything else, such as portfolio images, social links, addresses, or events, is up to you.
You can withdraw your consent at any time by editing or removing information in Settings, or by having your account deleted, which removes the account and everything attached to it (section 8): write to [PRIVACY EMAIL] or, when available, use Settings, Privacy & data.
5. Where your data goes
MatchU runs on cloud providers whose servers are located outside Quebec, mainly in the United States. Law 25 requires us to tell you this: your personal information is transferred to and stored in those locations. Before using each provider we assessed the sensitivity of the information, the purposes, and the protections in place. Our agreements with providers limit them to processing information on our behalf, and each one only receives what it needs for its role:
- Vercel (United States) hosts the application and processes every request, including server logs.
- Neon (PostgreSQL database on AWS, us-east-2 region, United States) stores account, profile and activity data.
- Cloudflare R2 (object storage distributed on Cloudflare's global network) stores the images you upload: profile photos, logos, and portfolio pictures.
- Resend (United States) sends transactional emails such as email verification links, only when email sending is configured.
- Google receives your basic profile if you choose to sign in with Google. If address autocomplete is enabled, the address you type on a business profile is sent to Google Places to suggest matches. Map links open Google Maps in your browser, which is then subject to Google's own policy.
- Apple receives your sign-in request if you choose to sign in with Apple.
Sign in with Google, sign in with Apple, address autocomplete and email sending are optional integrations that are only active when configured; when they are off, nothing is sent to those companies.
6. Cookies
MatchU uses only cookies that are necessary for the service:
- Session cookie (essential): a signed token that keeps you logged in. It expires when your session does.
- CSRF token and callback cookies (essential): protect the login form against cross-site request forgery and remember where to return you after signing in.
- Sign-up cookies (essential, 10 minutes): during sign-up with Google or Apple, two short-lived cookies carry the role you picked and your consent to the Terms and this policy until the account is created, then they are removed.
- Theme cookie (
matchu-theme): remembers your chosen theme so the page renders in it on the next visit.
We set no third-party cookies and use no advertising or analytics trackers. Because these cookies are strictly necessary, there is no cookie banner: blocking them in your browser will prevent you from logging in.
7. Sharing with other users
- Your public profile is visible to logged-in members of either role, subject to your privacy setting (everyone, or only people you have interacted with). For creators it shows your display name, username, legal first and last name under your username, photo, bio, city, languages, interests, formats, platforms, skills, experience, availability, portfolio images, and links. For businesses it shows the company name, logo, website, industry, pitch, store addresses, and brief. Your phone number and email are never shown to other members.
- Businesses you express interest in see that you did, together with your profile, and can accept or decline. If a business declines, you are not told: it simply appears as still waiting.
- Creators a business contacts are told which business reached out and can message it.
- Roster entries (stage, private notes, tags) are visible only to the business that wrote them. Creators do not see them.
- Followers and following lists are visible on profiles.
- Group members see each other's names, pictures, posts and reactions within the group. The business hosting the group can see which members have opened it and when.
- Event hosts and the MatchU team see the guest list (name, email, phone, ticket code) of the events you confirm.
- The MatchU team can access account data through an admin panel to run the service, handle requests, and moderate. Actions the team takes on an account are logged.
We do not sell personal information and we do not share it with advertisers.
8. Retention and deletion
We keep your information for as long as your account exists. To delete your account, write to [PRIVACY EMAIL] or, when available, use Settings, Privacy & data. Deletion removes the account and everything attached to it: profile, uploaded images (removed from storage), interests, follows, shortlists, roster entries, messages, group memberships and posts, notifications, service requests, and event confirmations.
- Server logs: kept by our hosting provider under its retention rules. We aim to keep server logs no longer than 30 days.
- Rate-limiting counters: held in memory for the length of the window (minutes) and then discarded.
- Backups: our database provider keeps backups for a limited period under its own retention schedule; deleted data disappears from backups when they expire.
- Administrative records: the log of team actions is kept for accountability after an account is deleted. It contains the email address involved and a short description, not your profile content.
- Messages you sent to others are deleted with your account.
9. Your rights
Under Law 25 and PIPEDA you have the right to:
- Access the personal information we hold about you and know how it is used.
- Correct information that is inaccurate or incomplete. Most fields can be edited directly in Settings.
- Delete your information by asking us to delete your account (write to us or, when available, use Settings, Privacy & data).
- Portability: receive the information you gave us in a structured, commonly used format. To request a copy of your data, contact us at [PRIVACY EMAIL].
- Withdraw consent as described in section 4.
- Complain. If you are not satisfied with how we handled your request, you may file a complaint with the Commission d'accès à l'information du Québec or the Office of the Privacy Commissioner of Canada.
To exercise these rights, write to [PRIVACY EMAIL] from the email address on your account so we can confirm it is you. We answer within 30 days. There is no charge.
10. Security
We protect your information with measures proportionate to its sensitivity. In summary: passwords are stored as one-way hashes and never in clear text; all connections use HTTPS; every request is checked for a valid session and for role and ownership, so a member can only read or change what belongs to them; the messaging gate is enforced on the server, not only in the interface; login, sign-up, and email attempts are rate limited; uploads are limited to image files of a bounded size and go straight to storage under a key tied to your account; the site sends security headers (including a content security policy) that block framing and unexpected script sources; and the MatchU team's access to accounts is restricted to named administrators and logged.
No system is perfectly secure. If a confidentiality incident involving your information presents a risk of serious injury, we will notify the Commission d'accès à l'information du Québec and the people affected, as Law 25 requires, and record the incident in our incident register.
11. Changes to this policy
This policy is versioned. The version and the "Last updated" date at the top change whenever the text changes. When a change affects what we collect, why, or who we share it with, logged-in members see a notice inside the app asking them to review the new version, and we keep a record of which version each member accepted. Continuing to use MatchU after reviewing the new version means you accept it.
12. Contact
Person responsible for the protection of personal information: [NAME, TITLE OF THE PERSON RESPONSIBLE FOR PERSONAL INFORMATION], [PRIVACY EMAIL].
General support: [SUPPORT EMAIL]. Mail: [COMPANY LEGAL NAME], [STREET ADDRESS, CITY, QUEBEC, POSTAL CODE].