Summary
iDharma collects only what it needs to run the marketplace — your account and profile information, verification documents, payment data, project communications, and basic technical data. We use it to operate the platform, verify consultants, process payments, prevent fraud, and improve the product. We do not sell your personal data. You can access, correct, delete, or export your data at any time, and California and EU/UK residents have additional rights. We keep data only as long as needed or as the law requires. For any privacy request, email connect@idharma.us and we respond within 30 days.
01 Information We Collect
We collect only what is needed to run the marketplace, verify identities, process payments, and keep the platform secure.
- Account information — name, email, phone, password (stored hashed), country, and language.
- Profile information — photo, bio, skills, experience, education, certifications, and social links.
- Verification documents — government ID, proof of address, and references. These are encrypted and used only for verification.
- Transaction data — project briefs, proposals, contracts, milestones, payments, amounts, and recipient or payer identifiers.
- Communications — platform messages, support tickets, and video call metadata.
- Technical data — IP address, browser, device, pages visited, referral source, and timestamps.
- Cookies — see our Cookie Policy for the full list and purposes.
02 How We Use Your Information
Every use of your data maps to one of the operational, legal, or product purposes below.
- Operate the marketplace — matching, communications, payments, and dispute resolution.
- Verify identity and credentials of consultants applying to join the network.
- Process payments and payouts via Stripe Connect.
- Detect fraud and abuse across the platform.
- Communicate updates, security alerts, and platform changes.
- Marketing — only with your consent; you can unsubscribe from every email.
- Aggregate analytics to improve the product. This data is always de-identified.
03 Legal Bases for Processing
Where data protection law requires a legal basis for processing, we rely on the following:
- Performance of a contract — to provide the marketplace, process transactions, and deliver the services you sign up for.
- Legitimate interests — to secure the platform, prevent fraud and abuse, and improve the product through de-identified analytics.
- Legal obligation — to meet tax, accounting, identity-verification, and other regulatory requirements.
- Consent — for marketing communications and for non-essential cookies, which you can withdraw at any time.
06 Data Retention
We keep data only as long as needed for the purpose we collected it — or as the law requires.
- Account and profile — the active period plus 7 years post-closure for legal, tax, and dispute purposes.
- Payment records — 7 years, per US tax law.
- Verification documents — 2 years after revocation or expiry, then deleted.
- Marketing data — retained until you unsubscribe.
- Logs — 12 months, unless longer retention is required for a security investigation.
07 Your Rights
You have full rights over your data — including access, correction, deletion, and portability.
- Access — request a copy of the data we hold about you.
- Correction — fix any inaccuracies.
- Deletion — request account deletion. We keep only what we must for legal and tax obligations.
- Portability — export your data in machine-readable JSON.
- Opt out of marketing — unsubscribe at any time.
- California residents (CCPA) — the right to know, the right to delete, the right to opt out of sale (we do not sell), and the right to non-discrimination for exercising these rights.
- EU / UK residents (GDPR) — the right to object, the right to restrict processing, and the right to lodge a complaint with your supervisory authority.
To exercise any right, email connect@idharma.us. We respond within 30 days.
08 Security
We use industry-standard encryption in transit (TLS 1.3) and at rest (AES-256). Verification documents are encrypted with separate keys. We conduct an annual security review, and SOC 2 readiness is in progress with a target completion of Q3 2026.
Found a vulnerability? Report it to connect@idharma.us under our Vulnerability Disclosure policy. We acknowledge reports within 72 hours.
09 International Transfers
iDharma operates from the United States. If you access the service from outside the US, your data is transferred to the US under Standard Contractual Clauses or equivalent safeguards recognized under applicable data protection law.
10 Children's Privacy
iDharma is not intended for users under 18. We do not knowingly collect data from minors. If you believe a minor has registered, email connect@idharma.us and we will delete the account promptly.
11 Changes to This Policy
We will notify you of material changes via email and in-platform notice at least 30 days before they take effect. Continued use after the effective date means acceptance. Past versions are archived at /privacy-policy/changelog.
12 Contact Us
Privacy questions, requests, or concerns? Reach the team directly. For data and privacy requests, email connect@idharma.us. For general questions, you can also contact connect@idharma.us.
United States