Privacy Policy
DoneIt · Ireland
Last updated: 14 September 2026
This page explains what personal data we collect, why we need it, and what we do with it. We've kept it as plain as we can — no legal padding, just what you actually need to know. Questions? Email info@doneit.ie.
1. Who we are
DONEIT LIMITED, a company registered in Ireland under company number 825844 and trading as DoneIt (doneit.ie), is the data controller for the purposes of the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018. We operate in Ireland. For any data protection query, contact us at info@doneit.ie.
2. What we collect
- Account details: your name and email address when you sign up, and your phone number if you choose to verify it.
- Profile: your county, bio, skills, rates, and any photos you add to your public profile.
- Job details: what you need done, where, and your rough budget.
- Messages: conversations through the DoneIt messenger.
- Payment records: when you buy credits, our payment processor handles your card details — we never see or store your full card number, only a record that a purchase happened.
- Business verification: if you apply for a business account, the document you upload as proof (for example a business registration or VAT certificate), which we store securely and use only to review and verify your business.
- Usage data: which pages you visit and basic browser/device information.
- Cookies: see the Cookie Policy tab.
3. Why we use it and our legal basis
- To run the platform (matching jobs, keeping your account secure, processing credit purchases) — legal basis: performance of our contract with you.
- Essential service emails (someone applied to your job, your application was accepted, a new message) — legal basis: legitimate interests / contract. These are part of the service and can't be fully switched off while your account is active, though you control message and alert frequency in Settings.
- Optional emails (matching-jobs digest, weekly summary, any marketing) — legal basis: your consent, which you give at sign-up and can withdraw at any time in Settings or via the unsubscribe link in every such email.
- Fraud prevention and safety — legal basis: legitimate interests.
- Legal compliance — where Irish or EU law requires us to hold or process certain data.
We don't sell your data, and we don't use it for third-party advertising.
4. Who we share it with
We use a small number of processors, named here, and only to run the service:
- Supabase — our database and sign-in provider. Stores your account data in Frankfurt, Germany (EU).
- Netlify — hosts and serves the website.
- Resend — sends the emails described above.
- Stripe (Stripe Payments Europe, Ireland) — handles card payments when you buy credits on the website. Your card details go to Stripe, never to us.
- OneSignal — delivers push notifications, only if you turn them on.
- Didit — identity and phone verification, only if you choose to verify. Where you verify your identity, Didit processes the ID document and selfie you submit to confirm the document is genuine and matches you. We receive only the result (verified or not) and a reference — we never store your ID document or the images.
- Apple, Google and RevenueCat — if you buy credits inside the iOS or Android app, the purchase is handled by the App Store or Google Play; RevenueCat tells us the purchase went through so we can add the credits.
- Sentry — records technical errors so we can fix faults, hosted in the EU. When an error happens it may also keep a short replay of the screens that led to it, with all text masked and images blocked, so we can see what broke. It does not record sessions that have no error. We use no product-analytics or behaviour-tracking service.
- Capgo — delivers updates to the mobile app.
- Google Fonts — the site's typefaces are loaded from Google, so your browser sends its IP address to Google when it fetches them. No cookie is set and nothing else is shared.
Each acts under a data-processing agreement and may only use your data to provide their service to us. No data brokers. No ad networks. Some of these companies are based in the United States; where your data reaches them there, the transfer is covered by the EU–US Data Privacy Framework or the European Commission's standard contractual clauses, as GDPR requires.
5. Your rights
Under GDPR you have the right to access, correct, export (data portability), restrict, object to, or delete your personal data, and to withdraw consent at any time. Go to Settings in your account to download your data or delete your account. For anything else, email info@doneit.ie — we aim to respond within one month, as required by GDPR.
If you're unhappy with how we've handled your data, you have the right to lodge a complaint with the Irish Data Protection Commission at dataprotection.ie.
6. How long we keep it
Your data stays until your account does. When you delete your account the parts that identify you — your name, photo, phone number and profile — are erased immediately, not at the end of some window. Records that are also somebody else's history, such as a completed job, a review or a message in their inbox, stay but stop carrying your name.
Two things outlive that. Transaction records may be kept for up to 6 years to meet Irish tax and accounting law. And we keep encrypted backups of the database for up to 90 days so the service can be restored after a failure, which means a copy of your data can sit in a backup for that long before it rolls off. Anonymised aggregate data (for example, total job counts) may be kept indefinitely.
7. Children
DoneIt is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a minor has created an account, tell us at info@doneit.ie and we'll remove it.
8. Changes to this policy
If we make a significant change, we'll notify you through the platform or by email. The "last updated" date above always reflects the current version.
9. Questions?
Email info@doneit.ie. A real person reads it.