1. Scope and contact
This policy applies to inTaraf. It covers personal data and related operational data handled through the inTaraf website,
APIs, listing workflows, AI-assisted tools, search, media processing, support workflows, payment-connected services,
notification systems, and account controls.
For privacy questions, data-access requests, deletion support, or concerns about automated review, contact
support@intaraf.com.
The data controller for your account is WodoTech LTD, company number 14739595, trading as inTaraf, with a registered
office at 124-128 City Road, London, England, EC1V 2NX, United Kingdom, unless a jurisdiction-specific legal notice or footer
identifies a more specific controller for your region.
If you use the service on behalf of a business or organization, this policy applies to personal data processed through
that business account as well as personal data about individual account users.
2. Data we collect
Depending on how you use the service, we may collect and process the following categories of data:
- Account and identity data: email address, phone number, name, username, profile fields, language,
accessibility settings, visibility settings, OTP verification records, session metadata, account role, and account status.
- Listing and user content: titles, descriptions, prices, categories, features, add-more fields, locations,
reviews, chat messages, reports, claims, support messages, refund requests, business profile content, and submitted forms.
- Original and normalized listing text: the original user-entered title and description, detected language,
translated or normalized English shadow text, searchable tokens, category signals, and safety signals.
- Media and media-derived data: uploaded photos, uploaded videos, generated images, image prompts, reference
images, gallery selections, thumbnails, video frames, OCR findings, image metadata, media quality signals, and moderation
findings.
- Location and local-context data: country, city, neighborhood, manual address, latitude/longitude when you
provide or confirm them, approximate geo context, and location preferences used to tailor the local experience.
- Wallet, payment, and billing data: wallet balance, ledger entries, fee events, refund requests, payment
provider identifiers, checkout metadata, purchase status, chargeback or dispute signals, and purchase or failure events
received from payment providers.
- Search and AI assistant data: search queries, AI Search messages, detected query language, translated or
normalized query text, ranking signals, result-click signals, and safety or abuse-prevention data.
- Device, delivery, and diagnostics data: IP address, user agent, locale, app version, browser or device
type, push token, notification delivery state, error logs, rate-limit records, abuse-prevention logs, and security-related
operational records.
- Cookies and browser storage: session identifiers, consent choices, preferences, feature flags, drafts,
device-local settings, and other storage described in Section 8.
3. How we use data
We use data to operate, secure, moderate, bill, localize, and improve the service, including to:
- create accounts, verify sign-in, maintain sessions, and prevent unauthorized access;
- publish, review, archive, rank, display, and manage listings;
- power chat, reviews, reports, claims, support, refunds, wallet, and notification workflows;
- detect language, translate or normalize listing text, and create backend shadow data for search, category detection, and moderation;
- process media, create thumbnails, extract or inspect OCR text, analyze uploaded photos or videos, and review generated images;
- infer or suggest listing category, type, relevant gallery images, key features, and additional options;
- run AI-assisted listing creation, AI Search, AI-generated images, content assistance, and automated moderation;
- rank search results and improve cross-language discovery without replacing the user's original text;
- calculate, record, display, and reconcile wallet charges, AI fees, media fees, refunds, purchases, and chargebacks;
- send OTP messages, receipts, listing status updates, safety notices, admin messages, and product notifications;
- detect spam, scams, fraud, policy violations, prohibited content, harmful media, and platform abuse;
- comply with legal obligations, enforce our Terms, defend claims, and maintain security or accounting records.
4. Legal bases where applicable
Where the UK GDPR applies, the purpose of the processing determines the legal basis. Our current purpose-level mapping is:
- Contract: creating and securing your account, publishing and managing listings, delivering chat and other features you request, and administering paid features.
- Consent: non-essential browser storage and optional provider-backed features where the consent flow says consent is required. You may withdraw consent at any time without affecting earlier lawful processing.
- Legitimate interests: protecting users and the platform, preventing fraud and abuse, moderating and ranking content, diagnosing failures, improving service reliability, and establishing or defending claims. These interests are balanced against your rights and expectations.
- Legal obligation: tax and accounting records, lawful authority requests, regulatory duties, and other records the law requires us to keep or disclose.
You have the right to object to processing based on legitimate interests. See Section 15 or contact us to exercise that
right. If a purpose or basis materially changes, we will update this notice before beginning the new processing where required.
5. Listings, public content, and visibility
Listings and some profile or business information are designed to be visible to other users once approved and published.
Public content may include title, description, price, category, features, location context, images, videos, review content,
seller information, business information, and listing status.
- Do not submit private or sensitive information in public listing fields unless you intend it to be public and have the legal right to share it.
- Listings may remain visible, archived, indexed internally, or retained in moderation records after edits, reports, or removal where needed for safety or legal reasons.
- Search, category pages, AI Search, and recommendation systems may use both visible listing content and backend shadow data to rank results.
6. Media analysis, OCR, AI moderation, and generated content
Photos and videos are important to listing quality and platform safety. We may analyze uploaded media, generated images,
gallery selections, image prompts, reference images, thumbnails, video frames, and related metadata.
- Media may be reviewed for relevance, category detection, policy compliance, fraud, abuse, prohibited content, and quality.
- We may use AI vision, OCR, image classification, video-frame analysis, metadata checks, and human review where needed.
- OCR text may be used to detect contact details, payment instructions, QR codes, political persuasion, hate, scams, sensitive information, or other policy issues.
- Generated-image prompts, reference images, and outputs may be stored and reviewed for support, billing, safety, abuse prevention, and product improvement.
- Media analysis is not designed for biometric identification, face recognition, or identity matching unless we clearly state otherwise and have a lawful basis or your consent where required.
- Uploaded image or video analysis may trigger wallet or paid usage events as described in the Terms.
Our detailed media and generated-image rules are available in the photo and video rules.
7. Translation, shadow data, and cross-language search
inTaraf supports listings and search across languages. The original title, description, and user-entered content should
remain available as submitted by the user unless the user edits or deletes them. Separately, backend systems may store
detected language, translated text, normalized English shadow text, category signals, and searchable metadata.
- Original user content is the source of truth for user-facing listing text.
- Shadow or normalized data may be used for search, sorting, category detection, AI Search, moderation, fraud detection, and analytics.
- Search queries and AI Search messages may be translated or normalized before searching so results can be ranked across different listing languages.
- Translation and AI outputs can be inaccurate; users should review final listing content before submission.
8. Cookies, local storage, and similar technologies
inTaraf uses cookies, local storage, session storage, IndexedDB, and similar browser-side storage to keep the service
working and to remember user choices.
- Essential storage: required for login, security, consent state, account routing, drafts, and core service integrity.
- Functional storage: used for UI preferences, language, local experience controls, accessibility settings, and feature state.
- Product and diagnostics storage: used to understand errors, performance, feature use, abuse patterns, and service health.
- Third-party related storage: used when optional external services are enabled or needed, such as payments, translation, maps, notifications, or media delivery.
Some browser-side storage is necessary for the service to function. Optional categories are off until you make a positive
choice. The consent flow offers equally direct accept and reject choices, lets you choose categories separately, and does
not dispatch consent-dependent provider requests before consent. You can revisit and withdraw optional choices through the
site's cookie/language controls or your browser settings.
9. Data sharing and service providers
We do not sell personal data. We do not share personal data for cross-context behavioral advertising. We share data only as
needed to operate the service, process user-requested actions, comply with law, enforce our Terms, or protect users and the
platform.
- Cloudflare: hosting, content delivery, edge compute, Workers AI, queues, R2 storage, D1 database services, and related platform infrastructure.
- Cloudflare Stream: video upload, storage, processing, playback, and usage tracking when video is used.
- Stripe: browser checkout, payment events, wallet top-up processing, disputes, refunds, and payment records.
- RevenueCat: mobile billing event handling, app-store purchase validation, subscription or entitlement records, and store-purchase reconciliation.
- Firebase Cloud Messaging: push notification delivery and device token handling.
- Twilio: SMS OTP and related delivery records.
- ZeptoMail / Zoho: email OTP, transactional email, receipts, and account notices.
- Google Cloud Translation: translation, language detection, and related language features when those features are used.
- OpenAI and Poe: optional AI-assisted text, search, classification, and image features when you request or use those features. We send only the inputs needed for the requested operation.
- Map and geocoding services: MapLibre/OpenStreetMap tile services, Nominatim-style geocoding flows, and location lookup features.
- sim2link: optional integration data if you choose to connect, verify, or use that service.
- Professional and compliance support: auditors, lawyers, payment-risk providers, security vendors, or fraud-prevention services where needed.
Service providers may process data in different countries. Their handling is governed by their own terms, privacy policies,
and contractual obligations to us where applicable.
10. AI, automated processing, and human review
We use automated systems to support listing creation, category detection, translation, search ranking, media selection,
AI-generated images, fraud prevention, and moderation. These systems may affect listing status, search ranking, content
visibility, fee events, or whether a listing is sent to human review.
- AI systems may classify a listing as approved, needing changes, rejected, or requiring human review.
- AI systems may infer category, relevant features, additional options, image relevance, political signals, prohibited content, and safety risk.
- Low-confidence, sensitive, political, or high-risk cases may be escalated to human review.
- You may be asked to edit, replace, blur, clarify, or remove content before a listing can proceed.
- Automated systems can be wrong; contact support if you believe a review outcome is incorrect.
- Where available, you may request a manual review or appeal of an automated moderation outcome through support or the product flow.
Our listing review and AI moderation approach is described in the Terms.
11. Payments, wallet, fees, and billing records
Wallet and payment data is used to process purchases, top-ups, refunds, platform fees, AI usage, media processing, image
generation, video processing, moderation-related charges, and accounting records.
- We may store wallet ledger entries, balance changes, fee reason, feature used, request identifiers, provider references, and timestamps.
- Stripe or app-store payment providers may collect payment-card or store-account information directly; we generally receive payment identifiers and status rather than full card details.
- Refund, chargeback, dispute, fraud, tax, and accounting records may be retained longer than ordinary product records.
- Fee-related rules are described in the Terms.
12. Notifications and communications
We send service-related emails and, where enabled, push notifications or SMS messages. Some notices are essential and
cannot be disabled, such as OTP messages, wallet receipts, security notices, legal notices, and certain admin or safety
messages.
- Chat push notifications may be sent for new messages if enabled.
- Chat email reminders may be rate-limited to reduce inbox volume.
- Payment failures, refund or chargeback events, listing lifecycle changes, moderation results, and low-balance events may trigger alerts.
- You can manage many notification preferences in Settings.
13. Retention
We apply the following standard periods. A shorter period applies where data is no longer needed; a legal hold or unresolved
safety, fraud, payment, complaint, or legal matter may require a longer period. When no fixed period applies, we use necessity,
legal requirements, risk, and the status of the related account or listing as the retention criteria.
- Active account and listing data are generally retained while the account remains in use.
- Expired sessions and one-time verification-code records are removed on a bounded schedule after 7 days.
- Unauthenticated visitor AI history and assistant telemetry are retained for up to 30 days.
- Notification delivery, communication-delivery, playback, and similar operational records are retained for up to 90 days.
- Chat and review history may be retained for up to 730 days to preserve conversation context, investigate reports, and protect platform integrity.
- Wallet, purchase, refund, dispute, chargeback, tax, accounting, and provider-reconciliation evidence may be retained for up to 2,555 days (seven years).
- Listings, media, OCR findings, moderation, support, report, claim, security, and abuse-prevention records are retained while the listing/account is active and afterwards only while needed for appeals, repeat-abuse prevention, legal compliance, or an unresolved matter.
- Local browser storage remains on your device until you clear it, it expires, or the product removes it.
- Backups and logs may retain limited data for a period after deletion from active systems.
14. Account deletion and what happens to data
This section is our public account-deletion resource. If you want to delete your inTaraf account, sign in and go to
Settings > Delete account. If you cannot access the account, contact
support@intaraf.com from your registered email address and mention account deletion.
When account deletion is completed, the system currently does the following:
- removes or anonymizes profile data, contact details, business profile data, sessions, OTP records, and integrations;
- archives owned listings and removes them from active discovery and related search surfaces;
- deletes review media and active feature-session data, while retaining required wallet, payment, refund, and reconciliation evidence against a deleted-user record rather than an active profile;
- preserves some conversation, review, support, report, claim, audit, and moderation history as anonymous or deleted-user history where needed for platform integrity;
- retains certain payment, refund, chargeback, fraud-prevention, accounting, security, and legally required records where necessary.
Deleting your account may not remove content that other users have copied, cached, exported, screenshotted, or included in
their own records. Admin accounts and accounts tied to unresolved legal, payment, fraud, or safety issues may require manual
handling rather than the self-service deletion flow.
15. Your choices and rights
You can usually do the following directly through the product or by contacting us:
- access and update profile information;
- edit or delete draft listing content before submission;
- change language, accessibility, cookie, and notification preferences;
- replace or remove listing media where the product allows it;
- request account deletion;
- ask questions about how your data is handled;
- ask us to review an automated moderation outcome if you believe it is wrong.
Depending on where you live, you may also have additional legal rights relating to access, correction, deletion,
restriction, objection, portability, appeal, or complaint to a regulator. We may need to verify your identity before acting
on certain requests.
In the UK, you may lodge a complaint with the Information Commissioner's Office (ICO).
We would welcome the opportunity to address your concern first, but contacting us is not a prerequisite to complaining to the ICO.
16. Security and international processing
We use technical and organizational safeguards intended to protect data, including HTTPS, access controls, credential and
session checks, provider-level security features, logging, and operational review. No service can guarantee absolute
security.
Because we use cloud, payment, communication, translation, and media providers, data may be processed in different
countries depending on the provider, route, service used, and your location. Where required, we rely on contractual,
technical, and organizational safeguards to support those transfers.
If we confirm a security incident involving personal data, we will investigate, contain, and remediate it and will provide
notices when required by applicable law.
17. Children and sensitive data
The service is not intended for users under 18 years old, or under the age of majority in their jurisdiction if higher, and
is not intended for unlawful use.
Do not submit sensitive personal data, identity documents, medical records, bank details, private messages, children's
information, or third-party personal data unless the feature clearly requires it and you have the legal right to provide it.
If you believe a child is using the service or personal data has been provided to us improperly, contact
support@intaraf.com. We may restrict the
account, remove data, or request proportionate age evidence where necessary.
18. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the effective date and post the updated
version on this page. Material operational changes may also be reflected in product notices, consent flows, store
disclosures, or support documentation where appropriate.