Skip to main content
SortedHQ

Legal

Privacy policy

How SortedHQ collects, uses, shares, and protects your personal data.

Version 2026-06-11 · amended 3 September 2026

Website analytics on this browser

Current setting:Checking

Reading the setting for this browser.

When your browser allows it, the setting is a single on/off value stored on this device, and clearing your browser storage clears it. It contains no identifier and is never sent to us. Each browser and device is set separately. See Cookies and similar technologies below for what is sent and who receives it.

This Privacy Policy explains how SortedHQ collects, uses, shares, and protects personal data. It applies to customers and partners using the SortedHQ platform in select areas across Ireland, and to anyone who has started — but not finished — an application to become a partner. By using the platform you confirm that you have read and understood this Policy.

1. Who we are

SortedHQ is a trading name of Lara Private Limited, a company registered in Ireland (company number 821014). Our VAT status and registered office address are being finalised and will be published here before our public launch. SortedHQ operates an online intermediation platform connecting customers with independent service partners across Cleaning, Beauty, Gardening, and Handyman categories. Lara Private Limited is the data controller for the personal data described in this Policy. You can contact us about any privacy matter at support@sortedhq.ie.

2. What this Policy covers

This Policy covers all personal data we collect from you when you create a customer or partner account, begin an application to become a partner (whether or not you complete it), request or accept a booking, contact us, or otherwise use the SortedHQ website or progressive web app. It does not cover third-party websites or services that we link to but do not operate.

3. What we collect and why

The list below describes the main categories of personal data we process, what we use them for, and the legal basis under the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.

  • Contact details and address — Operating your account and delivering bookings. Legal basis: GDPR Art. 6(1)(b) (performance of contract).
  • Date of birth — Identifying you as a unique individual and routing under-21 partner applications for admin review. Legal basis: Art. 6(1)(b) (contract); Art. 6(1)(f) (legitimate interest in safe service delivery).
  • Immigration permission (Stamp) and expiry date — Verifying your right to work in Ireland. Legal basis: Art. 6(1)(c) (legal obligation under the Immigration Act 2004 and the Employment Permits Acts 2003–2014).
  • Partner bank details (IBAN, BIC, account-holder name) — Paying you for completed bookings via SEPA bank transfer. Legal basis: Art. 6(1)(b) (performance of your partner agreement). Recipients: internal finance and operations staff who reconcile and dispatch payouts, and your bank via the SEPA scheme. Retention: for as long as your partner account is active, plus the period required by Irish tax and anti-fraud record-keeping rules under the Taxes Consolidation Act 1997 and the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 (as amended).
  • Account-change records and admin-action audit log — We log which of your account fields were changed, who made the change (an administrator, or you), and when. The audit log records the field names only — it never stores the previous or new values. Where a SortedHQ administrator takes an action on your customer or partner record (for example, approving an account, applying or voiding a fee, or resolving a stalled booking), we also record the email address of the administrator who made that decision as the actor on the audit entry. The deciding administrator's email may be recorded on a partner profile and may be visible inside the SortedHQ admin portal during dispute resolution. Legal basis: Art. 6(1)(f) (legitimate interest in fraud prevention and dispute resolution). Retention: same as your partner account.
  • Booking dispute and escalation records — Where SortedHQ resolves a dispute or remediates an exceptional booking outcome — for example a Stalled Booking under §6D of the partner terms, an admin-initiated cancellation, or a refund decision — we record the outcome of the decision, the administrator's choice on any associated partner fee, the deciding administrator's email, the time of the decision, and a short factual note describing the reasoning. We use these records to resolve the immediate dispute, to maintain a defensible audit trail of administrative decisions, and to evidence those decisions if a customer or partner later contests them. Legal basis: GDPR Art. 6(1)(f) — the legitimate interests of SortedHQ in dispute resolution, audit, and defending its decisions, balanced against the limited categories of data recorded. Retention: 6 years from the date of the decision, in line with the limitation period under Section 11(1)(a) of the Statute of Limitations Act 1957. You can ask us to erase these records under Article 17 GDPR; SortedHQ may decline an erasure request where the records remain necessary for the establishment, exercise, or defence of legal claims, in which case SortedHQ will explain why on request.
  • Transaction records — Tax record-keeping and limitation-period defence. Legal basis: Art. 6(1)(c) (legal obligation under the Taxes Consolidation Act 1997 and the Statute of Limitations Act 1957 s.11(1)(a)).
  • Saved payment cards — When you choose to save a card for faster future checkout, your full card number and security code are sent directly to and stored by our payment processor — never by SortedHQ. We do not see, receive, or store your full card number or CVV. We retain only a customer reference held with our payment processor, an opaque payment-method token it issues, and the display details it returns to us (card brand, the last four digits, and the expiry month and year) so you can recognise the card and reuse it when you book. Saving a card is optional, and you can remove a saved card at any time from your account. We authenticate the card with you at the moment you save it, and a saved card may then be used to authorise future bookings — including recurring bookings you set up — in line with the strong-authentication rules applied by our payment processor. Legal basis: Art. 6(1)(b) GDPR (performance of the contract for the booked service) where you reuse a saved card to pay for a booking, and Art. 6(1)(f) (our legitimate interest in offering a faster checkout) where you save a card for later use.
  • IP address and device information — Fraud prevention and platform security. Legal basis: Art. 6(1)(f) (legitimate interest).
  • Web Push subscription data — browser-issued endpoint URL, public encryption keys (p256dh, auth), and user-agent string. Used to deliver Job Broadcast alerts to your device. Legal basis: Art. 6(1)(b) GDPR — performance of the partner agreement.
  • Records of the terms, declarations and confirmations you accept (date and time, IP address, browser user agent, and a copy of the exact wording you were shown and ticked) — Whenever you accept our terms, make a declaration, or confirm a statement of practice, we keep a record of it. Today this covers our customer and partner terms and conditions, your self-employed declaration, and — if you offer meal prep — your confirmation of the food-hygiene conduct code. We keep a copy of exactly what was on screen at the time, so that both you and we can later see precisely what you agreed to rather than relying on the current wording. We use these records to evidence the basis on which you use SortedHQ or provide services through it — in particular in the event of any dispute about the terms that applied, or, for the self-employed declaration, about your employment status. Confirming a statement of practice is a record of what you told us; it is not a statement that SortedHQ has checked or verified it. Legal basis: Art. 6(1)(f) GDPR (legitimate interests of SortedHQ in evidencing the terms agreed and in defending its lawful business model, balanced against your interest in the data being limited to what is necessary). Retained for the duration of your relationship with SortedHQ and for 6 years after the last booking, in line with the Irish statute of limitations.
  • Booking request details (county, town, service, sub-product, scheduled time, and — for beauty bookings — the gender of the menu you selected) — Used to compute an Eligible Partner Pool of partners who are approved, have switched themselves on as available for new jobs, cover your area, offer the service and sub-product you chose and have set a price for it, and are within their working-hour limit. A partner's customer rating is not one of these criteria. Before any partner has accepted, the only information about that pool we make available to you is aggregate: the number of partners eligible for your booking; the price range; and whether every partner in that pool has a displayed customer rating of 4.5 or above — this is "no" whenever any of them has no reviews yet. We do not share any individual partner's name, photo, contact details, or price with you before a partner accepts your booking. Legal basis: Art. 6(1)(b) GDPR (performance of the contract for the booked service).
  • Ratings and reviews — when a booking is completed we invite the customer to rate the partner from 1 to 5, and we invite the partner to rate the customer on the same scale. Ratings run in both directions, one each per booking. In each case we store the rating, the review text if any, and which booking it relates to. The two are published differently, and deliberately so. We show each partner's average rating and review count to customers choosing a partner, and to that partner in their own dashboard. A rating a partner leaves about a customer is not published anywhere and is not averaged: it can be seen only by the two parties to that booking and by SortedHQ administrators. We do not use a partner's rating to decide which jobs are offered to them, to order any list, or to prefer one partner over another; and we do not use a customer's rating to decide whether their bookings are accepted. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest, and customers' interest, in customers being able to choose a partner on the basis of other customers' experience, and in both sides being able to record how a booking went, balanced against the limited data recorded. Retention: we keep a rating and review with the booking it relates to, for as long as we keep that booking — the six-year period described in section 7. Closing an account does not delete ratings already left about that person.
  • Partners you have booked before ("Book someone again") — When you have completed a booking with a partner, we may show you that partner's first name again as a "Book someone again" option on a later booking, so you can ask for them by name. If you request a partner this way, we may also name that partner in a notice to you where they do not take the booking — whether they decline it or are not eligible for it at that time. If you turn on the fallback option when you book — it is on by default and you can switch it off — and your requested partner does not take the booking, we re-broadcast your booking details to our other eligible partners in your area in the same anonymised way as any other booking (those other partners are not told you had requested a specific partner). Naming your requested partner applies only to the notice we send to you. Legal basis: Art. 6(1)(b) GDPR (performance of the contract for the booked service).
  • Service-interest signals — when you tap a service tile we record which service you tapped, the outcome shown, a coarse signed-in or anonymous flag and, where available, your county and service-area. We do not record your name, contact details, IP address or device. We use this to decide where to add services and partners. Legal basis: Article 6(1)(f) GDPR — our legitimate interest in understanding demand for our services and planning where to add services and partners. We treat these signals as low-risk data because they carry no direct identifiers, and we keep them for no longer than 13 months.
  • Coverage-check signals — when you use the homepage coverage checker to see which services are available in your area, we record the Eircode district (the first part of your Eircode, also called the routing key — for example "D02") and the outcome shown (whether we are live, coming soon, or not yet in that area). We never store your full Eircode, and we do not record your name, contact details, IP address or device. We use this to plan coverage and gauge demand when deciding where to add services and partners. Legal basis: Article 6(1)(f) GDPR — our legitimate interest in coverage and demand planning. We treat these signals as low-risk data because they carry no direct identifiers, and we keep them for no longer than 13 months.
  • Registered interest in a service for your area — separate from the anonymous service-interest signals above, when you are signed in and ask us to tell you once a service becomes available in your area, we record your account identity (so the request is linked to you), the service and the service-area you asked about, and any preferred date or note you choose to add. We use this only to email you once that service goes live in your area, and to gauge demand when deciding where to add services and partners. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in matching you with services you have asked about and planning where to add services and partners, balanced against the limited data recorded. Unlike the anonymous signals above, this record is linked to your account. We keep it for up to 13 months, and we delete or anonymise it when you close your account.
  • Records of the emails we send you — when we send you an email (for example a one-time passcode, a booking update, a job alert, a payout notice, or a reply from support) we keep a record that it was sent. That record holds the type of email, the date and time, whether it was sent, failed, or was held back because our email channel was paused, and the reference our email provider gives the message. It identifies you by your account identifier only: we do not store your name, email address or phone number in it, and we never store the subject line or the content of the message. Where an email carries an attachment we also record the file name, type and size and a reference to where the file is stored, never a copy of the file itself. We use these records to answer questions about whether a message reached you, to spot delivery problems, and to show that we sent notices we are required to send. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in keeping a reliable record of our own communications, balanced against the limited data recorded. We keep these records for no longer than 13 months, and when you close your account we unlink them from you.
  • Part-finished partner applications — when you start a partner application we save what you enter on the first screen before you upload anything: your name, email address, phone number, the services you chose, the county and the Eircode districts you said you cover, and how far through the application you got. We also record your marketing choices: whether you asked us to email you, whether you asked us to ring you, the date and time you made each of those choices separately, and a reference to the exact wording that was on screen when you made them — so that if we later reword the question, we can still show what you actually agreed to. If you asked us to tell you when we start covering your county, we record that request, when you made it and the wording of the button you pressed, separately from the marketing choices above. We use it to send you the secure link that lets you finish on another device or another day, to see where people stop so we can fix that part of the form, and to follow up with you about your application. Where our team follows up with you about a part-finished application, we also record whether you have been contacted, a short free-text note written by the administrator who contacted you, and that administrator's identity; those details are held with the rest of the application and are included if we export the list internally. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in recruiting the partners who provide services on SortedHQ, balanced against the limited data recorded, a 24-month ceiling, no profiling, and not disclosed to any other organisation as its own controller — our transactional email provider handles it as our processor solely to deliver these emails, and our database hosting provider stores it as our processor (see sections 5 and 6). Contacting you about partner work more generally is separate, and we ask for it by channel: there is one tick box for email and a different one for telephone, both switched off unless you turn them on. We do that only if you gave us explicit consent for that channel (Art. 6(1)(a)), we record which channel you agreed to and when, and you can withdraw either at any time by emailing support@sortedhq.ie. If you asked us to tell you when we go live in your county, that request is your consent to that one message (Art. 6(1)(a)), and we rely on it whether or not you also ticked the marketing boxes; it does not extend to anything else, and you can withdraw it the same way. You can object to us holding a part-finished application at all under Article 21, or ask us to erase it under Article 17, by emailing support@sortedhq.ie.

We do not knowingly collect special category data (Art. 9). If you provide such data to us in an unsolicited free-text message, we will not process it further and will ask you to email us at support@sortedhq.ie if any action is required.

4. Cookies and similar technologies

We use a small number of first-party cookies and similar browser storage that are strictly necessary either to operate the platform or to give effect to a choice you have made. We do not use advertising trackers, and we do not use analytics that follow you across other websites. On our public pages we use one third-party analytics service, provided by our hosting and website analytics provider; it is cookieless and is described under "Website analytics" below. Our other analytics are the first-party, cookieless signals described in §3.

  • Session cookies (HMAC-signed, HttpOnly) — keep you logged in as a customer, partner, or admin. Legal basis: strictly necessary (Regulation 5(5) of the ePrivacy Regulations 2011 (S.I. No. 336 of 2011)).
  • Service worker and offline cache — powers offline use of the app and, for partners, delivers Job Broadcast push notifications when you have granted permission. Legal basis: strictly necessary for the core service; the push channel additionally relies on your consent at the browser permission prompt.
  • Browser session storage (`sessionStorage`) — short-lived flags used to remember that you dismissed certain in-app prompts for the rest of your browser session (for example: `sortedhq-install-nudge-dismissed`, `sortedhq-push-denied-banner-dismissed`, `sortedhq-push-prompt-dismissed`). These are cleared when you close the tab. Legal basis: strictly necessary.
  • Coverage-check de-duplication cookie (`sortedhq_cc_seen`, HttpOnly, session-scoped) — a functional cookie that holds a short-lived record of the coverage checks you have already run this session, so that retyping the same Eircode does not create a duplicate analytics row. It contains no identifier — only a short hash of the area and outcome already shown — and is cleared when you close your browser. Legal basis: strictly necessary (it carries no identifier and exists only to keep our own analytics accurate).
  • Website-analytics opt-out flag (`sortedhq-analytics-opt-out`, browser local storage) — written only if you use the control on this page to switch off the website analytics described below. It is a single on/off value. It contains no identifier, no date and no account reference, it is never sent to us, and clearing your browser storage clears it. Legal basis: strictly necessary (it exists only because you asked for it, and only to give effect to your objection).
  • Partner-invite dismissal flag (`sortedhq-partner-invite-dismissed`, browser local storage) — written only if you dismiss the partner invite on our home page, so we do not show it to you again for 30 days. It records the time you dismissed it and nothing else, it contains no identifier and no account reference, and it is never sent to us. Legal basis: strictly necessary (it exists only to honour a choice you made).

Website analytics

This section describes our website only. The SortedHQ apps do not run website analytics.

On our public pages only — our home page, our service and service-area pages, our pricing, contact, help and policy pages, our sign-up and sign-in pages, and the page where you start a booking — we use an analytics service from our hosting and website analytics provider to understand how people find and move around our website: page views, the website or search engine you arrived from, and coarse technical information such as country, device type, operating system and browser. We use this to see which pages and channels bring people to SortedHQ, and to decide where to grow.

That service is cookieless. It does not set a cookie, and it does not follow you across other websites. It is never used for advertising, and we do not send it your name, email address, phone number or account identifier.

We deliberately limit what is sent. No page view is recorded on the SortedHQ admin area, on payment links, or on your account pages, your bookings, your cart or the checkout — including the final step where you review and pay for a booking. Before a page view is sent, the web address is reduced: we keep only campaign-tracking parameters (for example the utm_source parameter that tells us an ad or a post brought you here) and, where the address carries an Eircode, a shortened form of it — the routing key, which is the first three characters and identifies a postal district rather than a single building. Every other parameter is dropped. These controls are designed to keep personal data out of what we send, but we cannot promise they catch everything.

Because there is no cookie, our hosting and website analytics provider recognises a returning visit using a short-lived value it works out from technical details your browser sends with every request, such as your IP address and browser type. That value is pseudonymous — it is not your name, and we cannot use it to look you up — but we treat it as personal data rather than as data that is not personal data at all.

Our hosting and website analytics provider acts as our processor for this analytics under a written data-processing agreement (see §5 and §6), and keeps the data for a limited period set by our plan with it, after which it deletes the data; you can ask us what that period currently is. You can also ask us to name that provider — see §6. Legal basis: Article 6(1)(f) GDPR — our legitimate interest in understanding how people find and use our website so that we can improve it and plan where to grow.

You have the right to object to this processing at any time under Article 21 GDPR. You can switch it off for this browser using the control on this page, and you can also block it with a content- or tracker-blocking extension. If you email us at support@sortedhq.ie we will record your objection and confirm in writing. Switching it off stops future page views being sent from this browser. Because the records already collected carry no identifier we can link to you, we cannot find and delete your past records — your objection stops the collection going forward.

5. Sharing your personal data

We share personal data only as needed to operate the platform or where we are required to by law:

  • When you (as a customer) book a service and a partner claims it, we share with that partner the customer's name, service address, phone number, and the details of the job. Legal basis: GDPR Art. 6(1)(b) (performance of the contract for the booked service). The partner becomes an independent controller for that data and processes it in line with their own legal obligations.
  • When you (as a partner) claim a booking, we show the customer your first name, your profile photo if you uploaded one, your bio if you wrote one, your Garda-vetting self-declaration, your aggregate customer rating and review count, and the per-booking gross/net price split. Once you accept (claim) a booking, we also share your stored mobile phone number with that specific customer, so that they can contact you about that booking while it is active; we share it only with that one customer and only for that one active booking, and it stops being shown once the booking is completed or cancelled. Your full name, email, address, and identity documents are not shown to the customer. Legal basis: GDPR Art. 6(1)(b).
  • Where a customer you have completed a booking with asks for you again by name on a later booking, we may show that customer your first name when they make the booking, and may name you in a notice to that customer if you do not take the job — whether you decline it or are not eligible for it at that time. We share only your first name in this way; your full name, contact details, and address are never shared with the customer unless and until you accept the booking. Legal basis: GDPR Art. 6(1)(b).
  • With our payment processor, our transactional email provider, and our SMS provider so that we can take and reconcile payments and send you booking confirmations, receipts, and operational notifications. Each operates under a written data-processing agreement. Where you save a card, our payment processor stores the card details in its own secure vault as a processor on our behalf; the only things SortedHQ keeps are a customer reference held with our payment processor, the payment-method token, and the display details described in §3.
  • With your bank, via the Single Euro Payments Area (SEPA) scheme, when we pay you out for completed bookings. We share only the data your bank needs to receive the payment: the IBAN, BIC, account-holder name, payment amount, and a reference identifying the booking.
  • With our hosting and infrastructure providers, under written data-processing agreements. That is more than one company: the provider that stores our database, and our hosting and website analytics provider, which hosts the SortedHQ website and app and, on our public pages only, also provides the cookieless website analytics described in §4.
  • When you enable push alerts, your browser's push endpoint URL routes through your browser vendor's push service (Apple, Google, Mozilla, or Microsoft). These services may operate servers outside the EEA. We rely on Standard Contractual Clauses and adequacy decisions where applicable.
  • With An Garda Síochána, the Revenue Commissioners, the Workplace Relations Commission, or other Irish authorities where we are legally required to do so or where you have given your consent.

Where we describe a provider by category above rather than by name, you can ask us to name it — see §6.

We do not sell your personal data.

6. International transfers

Some of the processors we use process personal data outside the European Economic Area — our payment processor, our transactional email provider, our SMS provider, and our hosting and website analytics provider, which is headquartered in the United States. Where a processor does so, we rely on the European Commission's Standard Contractual Clauses or, where that processor is certified under it, the EU–US Data Privacy Framework adequacy decision.

Where this Policy describes a processor by category rather than by name, you can ask us to name it, to tell you which safeguard applies to it, and to give you a copy of that safeguard, by emailing support@sortedhq.ie. We will also identify our processors in response to a request for access to your personal data under Article 15 GDPR.

7. How long we keep your data

We keep personal data only as long as we need it for the purposes set out in this Policy. As a default rule, account data and transaction records are retained for the duration of your relationship with SortedHQ and for six years after closure, in line with Section 11(1)(a) of the Statute of Limitations Act 1957 and tax record-keeping obligations under the Taxes Consolidation Act 1997. Booking dispute and escalation records (see §3) are also retained for the same six-year period from the date of the relevant administrative decision, for the dispute-resolution and audit purposes set out there. Marketing-preference data is retained until you withdraw consent or close your account. If you have no account — for example because you only started a partner application — your marketing choices are held with that application and go when it does, under the rule below.

Messages you send us through the contact form, and our replies, are kept for up to 13 months and then deleted, unless they relate to a booking dispute or another matter we must retain for longer under this Policy. If you ask us to delete your account, the content of your support messages and the name and email you submitted with them are removed; a non-identifying record that a ticket existed, along with its triage history (such as its status and which administrator handled it), may be kept for audit.

Records of the emails we send you, described in §3, are kept for up to 13 months. If you close your account we unlink those records from you: the account reference is removed, leaving only the type of email, the date and time, and the outcome.

A part-finished partner application, described in §3, is deleted immediately once you submit the application. Otherwise we keep it while it is still useful to us in recruiting partners, and in any event for no longer than 24 months from the day you started it. You can ask us to delete it at any time before then, or object to us holding it at all, by emailing support@sortedhq.ie — we act on that by deleting the record outright rather than marking it. The same rule applies whichever kind of application you started, including if you only asked to be told when we reach your county.

Push subscription data is retained until you revoke browser permission, the subscription endpoint expires (HTTP 404/410 from the push service), or you close your account — whichever is first.

Website-analytics data, described in §4, is kept by our hosting and website analytics provider for a limited period set by our plan with it and is then deleted; you can ask us what that period currently is.

Ratings and reviews, described in §3, are kept with the booking they relate to and for the same six-year period as that booking. They are not deleted when a partner or a customer closes their account: a review is a record of one completed booking, and it stays attached to that booking.

Saved-card details (the payment-method token issued by our payment processor and the brand, last four digits, and expiry we hold for display) are retained for as long as the card remains saved on your account. Once a saved card has expired it can no longer be used for checkout — our payment processor stops it being usable past its expiry — and we hold only its display details so you can still recognise and remove it; you can remove an expired card at any time. When you remove a saved card, the card is detached from your record held with our payment processor and is no longer available to you for checkout. When you close your account, your saved cards are removed.

8. Automated decisions about your eligibility to accept jobs

SortedHQ uses an automated rule to check, at the moment you try to accept a job, whether accepting it would push you over the weekly working-hour limit attached to your declared immigration permission (Stamp). The rule operates on:

  • your declared Stamp and its expiry date;
  • the hours you have already accepted through SortedHQ in the current week (Monday 00:00 to Sunday 23:59:59.999, Europe/Dublin); and
  • the hours this particular job would consume.

If accepting the job would exceed your limit, the rule refuses the claim. This is an automated decision and you have the right to contest it.

To request human review, email support@sortedhq.ie. A person will respond within 2 working days. You may express your point of view and provide additional information for the reviewer to consider.

Alongside the working-hour rule, a small number of other automated checks run at the moment you try to accept a job. They check whether your profile is complete, whether your account is currently under review, and — for meal-prep jobs only — whether you have confirmed the food-hygiene conduct code. Where one of these refuses a job, we tell you which check refused it and how to resolve it. Most are cleared by you in a minute or two without needing to contact us: completing the missing profile details, or confirming the conduct code. If you cannot clear one, or you think it applied to you wrongly, email support@sortedhq.ie and a person will review it within 2 working days.

The under-21 admin-review routing at signup is also a partly-automated step; you can contact us at the same address if you want to discuss it.

9. Your rights

Under the GDPR and the Irish Data Protection Act 2018 you have the right to:

  • access the personal data we hold about you;
  • ask us to correct inaccurate or incomplete data;
  • ask us to delete data in defined circumstances;
  • ask us to restrict or object to processing;
  • ask us to transfer data you have provided to us (data portability);
  • withdraw consent at any time where processing is based on consent.

To exercise any of these rights — including requesting deletion of your account and associated personal data — email support@sortedhq.ie with the subject line "Data request". We will respond within one month and will not charge a fee for the first request. Account deletion requests are processed manually; we will confirm deletion by email once complete. Some data must be retained for the period required by Irish law even after account deletion — including transaction records, tax records, and the booking dispute and escalation records described in §3 and §7, which SortedHQ retains for the six-year limitation period for the establishment, exercise, or defence of legal claims (Art. 17(3)(e) GDPR). Where you had contacted us through the contact form, deleting your account removes the content of those messages and the name and email you submitted with them, but a non-identifying record that a ticket existed, along with its triage history, may be kept for audit (see §7).

10. Complaints

If you are not satisfied with how we have handled your personal data, you have the right to complain to the Data Protection Commission of Ireland at https://www.dataprotection.ie or by post to 21 Fitzwilliam Square South, Dublin 2, D02 RD28.

11. Changes to this Policy

We may update this Privacy Policy from time to time. Where a change is material we will tell you by email or via the platform before the change takes effect.

Amendments since this version was published:

  • 3 September 2026 — corrected the description of how we build the Eligible Partner Pool: a partner's customer rating is not one of the criteria. No change to what we collect or why.
  • 3 September 2026 — added a "Ratings and reviews" entry to section 3, describing data we were already collecting and showing: what a rating is, who sees it, how long we keep it, and that it is not used to decide which jobs a partner is offered. We have not started collecting anything new.
  • 25 August 2026 — processors are now described by category rather than by name; no change to what we collect, why, or who receives it.
  • 3 September 2026 — added part-finished partner applications: what we keep if you start an application without finishing it (including the follow-up notes our team writes about it), the legitimate-interest basis we rely on, the separate consents for email and telephone marketing and the records that evidence them, and how long we keep it — deleted on request at any time, and in any event after 24 months. Sections 2, 3 and 7 were widened accordingly.

12. Contact

If you have any questions about this Policy or about how we use your personal data, please email support@sortedhq.ie.

Privacy policy — SortedHQ