Sowo

Privacy Policy

Last updated: 21 August 2026

Sowo is the trading name of SOWO LIMITED, a company registered in Scotland (company number SC890878) with its registered office at Stirling FK8. We run the website usesowo.com and its subdomains, and the Sowo iOS app. We are the data controller for the personal data described below. Everything here applies to both the website and the app unless it says otherwise; section 1a covers the parts that exist only in the app.

This page is written in plain English. If something is unclear, email join@usesowo.com and we will answer in plain English too.

1. What we collect and why

Provider applications

When someone applies to list their service through /join, we collect their full name, email, phone number, service category, area, years of experience, a short bio, and their Instagram, TikTok or Facebook handles if they share them. We use this to decide whether to invite them onto Sowo and to contact them about the outcome. Legal basis: legitimate interest (running a marketplace).

Accounts

When you sign up, Supabase records your email and a hashed password, or your Google account identifier if you choose to sign in with Google. We store your display name, an optional avatar and your general location (e.g. “London”) on your profile. Legal basis: contract (we need an account to give you the service).

Provider listings

For data-protection enquiries, contact us at join@usesowo.com. We are the data controller for the personal data covered by this policy. Approved providers add a bio, skills, languages, services, prices, social links and portfolio images to their listing. These appear publicly on /browse and on the provider's profile page. Legal basis: contract.

Verification documents

If a provider asks to be verified, we ask for documents like a photo ID, proof of address and any relevant qualifications. These are uploaded to a private storage bucket that only Sowo moderators can read; they never appear on the public profile. Providers can remove documents from /account/verification at any time. Legal basis: legitimate interest (verifying providers protects users who book them).

Requests, messages and quotes

When you post a request (for example “Need a hair stylist in N16 for a wedding”) we store the title, description, area and category. When you message a provider we store the conversation, message bodies, and any quote (service, price, note). Messages are visible to the two participants and, if a moderator needs to investigate a report, to Sowo. Legal basis: contract.

Bookings and payments

Sowo does not store card details. When you pay for a service we redirect you to Stripe Checkout; Stripe processes the card, holds the authorised amount until the job is confirmed, and sends us a booking record (amount, currency, status, references). Provider payouts go through Stripe Connect. Legal basis: contract.

Reviews and vouches

After a booking you can leave a star rating and a short review. Other Sowo users can also vouch for a provider they trust. Your name shown on a review or vouch is the display name from your profile. Legal basis: legitimate interest (trust signals are the point of the marketplace).

Reports and moderation

If you report a listing, message or user, we store the report, the target, your reason and the resolution. Sowo moderators can also hide listings, suspend accounts or revoke a verified badge, and we keep an audit log of who took what action. Legal basis: legitimate interest (keeping the marketplace safe).

Analytics (only if you opt in)

If you accept the cookie banner, Google Analytics (GA4) records how you use the site: pages viewed, rough location derived from your IP, device and browser type, and events like tapping “Join as a provider”. We use this only to understand and improve Sowo, never for advertising. It is off until you accept, and you can withdraw consent at any time from the Cookies page. Legal basis: consent. See our Cookies policy for the detail.

1a. The Sowo iOS app

The app collects no analytics and contains no advertising or tracking software. We do not track you across other companies' apps or websites, we never touch the advertising identifier, and we do not share your data with data brokers. The analytics described above is a website feature and is off unless you accept the cookie banner on the site.

Location

The app asks for location only while you are using it, and only when you tap something that needs it: detecting your area on the home screen, setting the area on your profile, a provider profile or a listing. If you refuse, everything still works and you type a postcode instead. To turn coordinates into an area name we send them to postcodes.io, a UK postcode lookup service. We store the resulting area and postcode centroid, not your exact position, and we never use location for advertising. Legal basis: consent, then contract for the area we store.

Notifications

If you allow notifications, we store a push token for your device so we can send you booking, order and message alerts. Tokens go to Expo's push service and on to Apple to reach your phone, and a message notification includes the sender's name and the start of the message. You can switch individual alerts off in Settings, and news and offers stay off unless you turn them on. The token is deleted when you sign out or delete your account. Legal basis: contract, and consent for news and offers.

Signing in and app lock

You can sign in with an email and password, with Apple, or with Google. Sign in with Apple can hide your real email behind a relay address, and we only ever see what Apple passes on. If you turn on the app lock, Face ID and your PIN are handled by your device, and we never receive your biometrics. When you record a sign-in we store the city and country your network resolves to, so you can spot a session you do not recognise.

Photos and the camera roll

The app asks for photo access only when you choose a picture, for a profile photo, a listing, a message, a review or a verification document. It never reads your library in the background.

Deleting your account from the app

Settings has a permanent delete. It removes your account and credentials, deletes your uploaded files, and anonymises the records we must keep, such as an order's tax history. If you signed in with Apple, we also revoke that with Apple. See section 3 for what is retained and why.

2. Who else sees your data

We do not sell your data. We share it only with the small set of processors below, all under data-protection agreements:

  • Supabase (database, auth, storage). EU servers (Frankfurt). Holds your profile, listings, messages, requests, bookings and verification documents.
  • Stripe (payments and payouts). Processes your card and the provider's payout. Subject to Stripe's own privacy notice.
  • Resend (transactional email). Sends emails like “new message”, “payment held” or “verification approved”. US-based; transfers are covered by the UK–US Data Bridge.
  • Vercel (hosting). Serves the site and our API routes. US and EU edge locations.
  • Google Analytics (usage analytics). Website only, and only if you accept the cookie banner. Receives the usage data described above. US-based; transfers are covered by the UK–US Data Bridge. The app sends it nothing.
  • Expo (push notifications, app only). Holds your device push token and passes notification text to Apple so it can reach your phone.
  • Apple and Google (sign-in, if you use it). They confirm who you are and pass us your name and an email address, which with Apple may be a private relay address.
  • postcodes.io (UK postcode lookup, app only). Receives a postcode, or coordinates when you ask the app to detect your area, and returns the area name. It receives nothing else about you.
  • OpenStreetMap (map tiles). Draws the small map on a provider's profile.

If we add another processor, we will list it here before it starts handling your data.

3. How long we keep it

  • Provider applications: up to 12 months from submission if not approved; for the duration of the listing if approved.
  • Accounts, listings, messages, reviews, requests: while your account is active. Temporary deactivation hides the account and can be reversed by signing in within 30 days. Permanent deletion, available in Account settings, disables sign-in and removes or anonymises profile data, listings, requests, message content, verification documents, device tokens and sign-in history.
  • Verification documents: while you hold the verified badge. If you remove them or your verified status ends, the documents are deleted.
  • Booking and payment records: 6 years from the booking date, in line with HMRC retention rules for financial records.
  • Moderation audit log: 6 years from the action, so we can answer questions about decisions taken.

4. Cookies

Two kinds. First, the strictly-necessary session cookie Supabase sets to keep you signed in, which expires when you sign out. Second, opt-in Google Analytics cookies, which are off until you accept the consent banner and are never used for advertising. Full detail, and a control to change your choice, is on our Cookies page.

5. Your rights

Under UK GDPR you have the right to:

  • Ask what data we hold about you.
  • Have inaccurate data corrected.
  • Have your data deleted (subject to the retention rules above).
  • Object to processing based on legitimate interest.
  • Withdraw consent where consent is the basis.
  • Export your data in a portable form.
  • Complain to the Information Commissioner's Office (ICO) if you think we have got it wrong.

You can permanently delete your account directly from Account settings in the Sowo app. For any other request, email join@usesowo.com. We aim to respond within 14 days and have 30 days by law.

6. Security

Data is encrypted in transit (TLS) and at rest. Access to the production database is restricted to the founder and named admins, and every admin action is logged. Verification documents are kept in a separate storage bucket that is only readable by moderators. Passwords are hashed by Supabase, not stored in plain text.

7. Children

Sowo is not for under-18s. If you believe an account belongs to someone under 18, email us and we will close it.

8. International transfers

Most data stays in the EU (Supabase Frankfurt). Stripe, Resend, Vercel and, if you opt in, Google Analytics move some data to the US; those transfers rely on the UK–US Data Bridge and Standard Contractual Clauses.

9. Changes to this policy

If we change what we collect or who sees it, we update this page and bump the “last updated” date at the top. For significant changes we will also email registered users.

10. No surprise data uses

We will not use your data for something this policy does not describe. If a future feature needs new data, we will update this page before it ships.

11. Contact

SOWO LIMITED
Stirling FK8
join@usesowo.com for anything about this policy, or support@usesowo.com for help with your account, which is the address the app uses.

Privacy Policy · Sowo