Teisinė informacija
Privatumo politika
NamuGo yra paslaugų platforma, jungianti žmones, kuriems reikia darbų namuose, su nepriklausomais meistrais, galinčiais juos atlikti. Šis pranešimas paaiškina, kokius asmens duomenis renkame, kodėl ir ką galite dėl to daryti.
Paslaugą teikia MB Rgdv, Lietuvos mažoji bendrija (MB), ribotos civilinės atsakomybės privatusis juridinis asmuo, juridinio asmens kodas 308135355, buveinės adresas Klaipėda, Ragainės g. 13-9, LT-92196. Bendrija nėra PVM mokėtoja. Mes esame visų čia aprašytų duomenų valdytojas. Visais privatumo klausimais rašykite support@namugo.eu — atsakome į kiekvieną žinutę.
1. Ką renkame
Jei naudojatės NamuGo kaip Klientas
- Paskyra: vardas, el. pašto adresas ir telefono numeris. Jei prisijungiate per Google ar Apple, gauname iš jų identifikatorių, patvirtinantį jūsų tapatybę — jūsų slaptažodžio niekada negauname.
- Užsakymo duomenys: paslaugos adresas, jūsų problemos aprašymas, neprivaloma nuotrauka „prieš“ ir bet kokios pastabos apie namus, kurias nuspręsite pridėti.
- Susirašinėjimas programėlėje su jūsų užsakymui priskirtu meistru.
- Mokėjimo duomenys: Stripe kliento nuoroda ir kiekvienam užsakymui autorizuotos bei nuskaitytos sumos. Jūsų kortelės numeris niekada nepasiekia NamuGo — jį tiesiogiai renka ir saugo Stripe.
- Jūsų sutikimo įrašas: jei darbas atliekamas nepasibaigus 14 dienų atsisakymo laikotarpiui, saugome faktą, kad tai patvirtinote, nes įstatymas reikalauja, kad galėtume tai įrodyti (žr. Paslaugų teikimo sąlygų 4.4 sk.).
- Įvertinimai ir atsiliepimai, kuriuos paliekate meistrui.
- Įrenginio vieta — nuskaitoma vieną kartą užsakymui: siekiant patikrinti, ar įvestas adresas patenka į aptarnaujamą teritoriją, ir, jei leidžiate, apskaičiuoti maršrutą realiuoju laiku ir atvykimo laiką, kai meistras jau pakeliui. Vietos nesekame nuolat ir niekada fone.
Jei naudojatės NamuGo kaip Meistras
- Darbo profilis: vardas, telefonas, el. paštas, miestas, siūlomos specializacijos ir pageidaujama kalba.
- Gimimo data ir gyvenamosios vietos adresas. Renkami dėl konkrečios teisinės priežasties, ne profiliavimui: ES platformų atskaitomybės taisyklės (Tarybos direktyva (ES) 2021/514, „DAC7“) įpareigoja mus rinkti šiuos kiekvieno meistro duomenis ir kasmet deklaruoti Lietuvos mokesčių administratoriui. Tai taip pat leidžia patvirtinti, kad atitinkate mūsų Sąlygose nurodytą minimalų amžių.
- Patvirtinimo dokumentai: valstybės išduoto asmens dokumento nuotrauka ir — reguliuojamoms specializacijoms — sertifikatas ar licencija bei profesinės civilinės atsakomybės draudimo įrodymas, kiekvienas su galiojimo pabaigos data. Datą saugome, kad galėtume įspėti prieš dokumentui baigiant galioti ir sustabdyti tos specializacijos užsakymų priskyrimą, jei jis nustos galioti.
- Vieta realiuoju laiku, kai užsakymo būsena yra „pakeliui“: kai priimate užsakymą, periodiškai nuskaitome jūsų įrenginio vietą — taip pat ir kai programėlė veikia fone — kad klientas matytų jūsų padėtį ir tikslų atvykimo laiką. Sekimas prasideda ir baigiasi automatiškai kartu su užsakymo būsena: jis sustoja iškart, kai atvykstate, atšaukiate užsakymą, arba jis kitaip baigiasi, o pasibaigus užsakymui ankstesnių vietos duomenų nebesaugome.
- Išmokų identifikatoriai: jūsų asmens ar įmonės kodas ir nuoroda į jūsų Stripe išmokų paskyrą. Jūsų banko sąskaitos numerį renka ir saugo Stripe, o ne mes — NamuGo jo niekada nemato ir nesaugo.
- Darbo įrašai: nuotraukos „po darbo“, susirašinėjimas su klientais ir klientų paliekami įvertinimai.
Iš visų programėlių naudotojų
Kai atliekate saugumui svarbų veiksmą — prisijungiate, įkeliate dokumentą, ištrinate paskyrą — užfiksuojame veiksmą, laiko žymą ir IP adresą vidiniame audito žurnale. Tai skirta sukčiavimo, piktnaudžiavimo ir paskyros saugumo incidentų tyrimui. Tai nenaudojama jūsų profiliavimui, reklamos auditorijoms kurti ar sekti jus kitose paslaugose.
Mūsų svetainės lankytojams
Mūsų svetainė nenaudoja slapukų, analitikos ir neįkelia šriftų, skriptų ar paveikslėlių iš trečiųjų šalių — puslapiai pateikiami visi iš mūsų pačių serverio, todėl vien juos skaitydami nieko apie save neatskleidžiate niekam kitam. Mūsų prieglobos tiekėjas saugo įprastus serverio prieigos žurnalus saugumo ir patikimumo tikslais.
2. Kodėl naudojame ir koks teisinis pagrindas
- Sutarčiai su jumis vykdyti (BDAR 6(1)(b) str.) — užsakymo suderinimas su meistru, mokėjimo autorizavimas ir nuskaitymas, atsiskaitymas su meistrais ir pagalba.
- Teisinėms prievolėms vykdyti (6(1)(c) str.) — apskaitos ir sąskaitų faktūrų įrašai bei meistrų pajamų deklaravimas mokesčių administratoriui pagal DAC7.
- Dėl mūsų teisėtų interesų (6(1)(f) str.) — meistro tapatybės, kvalifikacijos ir draudimo patikrinimas prieš jam patenkant į kieno nors namus, ir aukščiau aprašyto saugumo audito žurnalo palaikymas. Laikome tai proporcinga, nes alternatyva — siųsti nepatikrintus nepažįstamus žmones į namus.
- Jūsų sutikimu (6(1)(a) str.) — neprivalomos funkcijos, kurias patys įjungiate, pvz., tiesioginiai pranešimai. Sutikimą galite atšaukti bet kada įrenginio nustatymuose, ir tai nepaveiks nieko kito.
3. Automatiniai sprendimai
NamuGo nepriima automatinių sprendimų, sukeliančių jums teisines pasekmes BDAR 22 str. prasme. Užsakymai priskiriami pagal fiksuotas taisykles: atsižvelgiama į jūsų miestą, registruotas specializacijas, prisijungimo būseną ir dokumentų galiojimą. Šiam tikslui nenaudojamas vertinimas balais ar profiliavimas. Kiekvieno meistro dokumentus prieš patvirtinant paskyrą peržiūri žmogus, ir kiekvieną ginčą taip pat nagrinėja žmogus.
4. Su kuo dalijamės duomenimis
Dalis dalijimosi neatsiejama nuo pačios platformos veikimo: jūsų užsakymui priskirtas meistras mato paslaugos adresą ir to užsakymo susirašinėjimą, o jūs matote jo vardą, įvertinimą ir susirašinėjimą. Meistro tikslus adresas ir gimimo data klientams niekada nerodomi.
Be to, duomenimis dalijamės tik su tiekėjais, kurie mūsų vardu užtikrina paslaugos veikimą:
- Stripe — mokėjimų autorizavimas, nuskaitymas, grąžinimai ir meistrų išmokų paskyros (įskaitant paties Stripe atliekamą tapatybės patikrinimą).
- Cloudflare R2 — užsakymo nuotraukų ir patvirtinimo dokumentų saugykla.
- MapTiler — programėlėse rodomi žemėlapio sluoksniai. Rodant žemėlapį perduodama prašoma žemėlapio sritis ir įprasti ryšio duomenys.
- Google LLC / Apple Inc. — tik jei pasirenkate prisijungti per jų paskyrą.
- Expo — tiesioginių pranešimų pristatymas.
- Brevo — su paslauga susiję el. laiškai, pvz., patvirtinimo kodai ir kvitai.
- openrouteservice (HeiGIT gGmbH) — kai užsakymas „pakeliui“, meistro esama koordinatė ir kliento namų koordinatė siunčiamos maršrutui ir atvykimo laikui apskaičiuoti. Nė viena pusė nesidalija tikslesnėmis koordinatėmis, nei būtina šiam skaičiavimui.
- Sentry — gauna techninį pranešimą, kai paslaugoje įvyksta klaida, kad gedimai būtų ištaisyti, o ne liktų nepastebėti. Sąmoningai sukonfigūruota siųsti tik pačią klaidą ir ją sukėlusią kodo vietą: jokių IP adresų, slapukų, užklausų turinio ar paskyrų identifikatorių.
- Render ir Neon — programos ir duomenų bazės priegloba ES (Frankfurtas).
Duomenis taip pat galime atskleisti, kai to reikalauja įstatymas, arba kompetentingai institucijai, tiriančiai konkretų atvejį. Asmens duomenų neparduodame ir nesidalijame jais su niekuo jų pačių reklamos ar rinkodaros tikslais.
5. Perdavimas už ES ribų
Mūsų programos ir duomenų bazės infrastruktūra veikia ES viduje. Kai kurie aukščiau nurodyti tiekėjai — Stripe, Google, Apple — yra įsisteigę už EEE ribų ir gali ten tvarkyti duomenis. Tokiu atveju perdavimas grindžiamas Europos Komisijos standartinėmis sutarčių sąlygomis arba taikomu tinkamumo sprendimu. Galite paprašyti mūsų nurodyti taikomas apsaugos priemones.
6. Kiek laiko saugome
- Ištrynus paskyrą jūsų profilis, įkeltos nuotraukos ir patvirtinimo dokumentai, aktyvios sesijos ir pranešimų identifikatoriai ištrinami nedelsiant — įskaitant pačius failus saugykloje, o ne tik duomenų bazės įrašus.
- Sandorių įrašai (sumos, datos, sąskaitų duomenys) saugomi tiek, kiek reikalauja Lietuvos apskaitos teisės aktai — šiuo metu iki 10 metų. Tai teisinė prievolė, kurios negalime atsisakyti paprašius.
- DAC7 įrašai saugomi tiek, kiek nustato juos reikalaujančios mokesčių taisyklės.
- Užsakymų ir susirašinėjimo istorija saugoma tol, kol egzistuoja susijęs užsakymo įrašas.
- Saugumo audito įrašai saugomi tik tiek, kiek reikia saugumo tikslui, dėl kurio buvo surinkti.
7. Kaip saugome
Srautas tarp programėlių ir mūsų serverių šifruojamas perdavimo metu (TLS, privalomas). Patvirtinimo dokumentai ir užsakymų nuotraukos niekada nėra viešai išvardyti ar naršomi — jie pasiekiami tik per trumpalaikes, individualiai pasirašytas nuorodas, išduotas jums arba peržiūrą atliekančiam darbuotojui. Prieiga prie veikiančios sistemos duomenų suteikiama tik tiems, kam jos reikia paslaugai užtikrinti.
8. Jūsų teisės
Pagal BDAR turite teisę susipažinti su savo duomenimis, juos ištaisyti, ištrinti, apriboti jų naudojimą, gauti juos perkeliamu formatu ir nesutikti su tvarkymu, grindžiamu teisėtu interesu. Kai tvarkymas grindžiamas sutikimu, jį galite atšaukti bet kada.
Paskyrą ir daugumą susijusių duomenų galite ištrinti patys bet kuriuo metu abiejų programėlių profilio skiltyje. Dėl visko, ko neapima savitarnos ištrynimas, rašykite support@namugo.eu — atsakysime per vieną mėnesį.
Jei manote, kad netinkamai tvarkėme jūsų duomenis, galite pateikti skundą Lietuvos priežiūros institucijai: Valstybinei duomenų apsaugos inspekcijai, vdai.lrv.lt. Būtume dėkingi už galimybę pirma ištaisyti klaidą patys.
9. Vaikai
NamuGo nėra skirta vaikams. Paskyrai susikurti turite būti bent 18 metų, ir mes sąmoningai nerenkame jaunesnių asmenų duomenų. Jei manote, kad paskyrą susikūrė nepilnametis, praneškite mums ir ją pašalinsime.
10. Šio pranešimo pakeitimai
Jei atliksime esminį pakeitimą, kaip tvarkome jūsų duomenis, atnaujinsime versiją ir datą šio puslapio viršuje ir informuosime jus programėlėje prieš pakeitimui įsigaliojant. Tolesnis naudojimasis NamuGo po to reiškia, kad taikomas atnaujintas pranešimas.
English version
NamuGo is a marketplace app that connects people who need work done in their home with independent tradespeople who can do it. This notice explains what personal data we collect, why, and what you can do about it.
The service is operated by MB Rgdv, a Lithuanian small partnership (mažoji bendrija, MB), a private legal entity with limited liability, company code 308135355, registered office at Klaipėda, Ragainės g. 13-9, LT-92196. The company is not registered for VAT. We are the data controller for everything described here. For any privacy question or request, write to support@namugo.eu — we answer every message.
1. What we collect
If you use NamuGo as a Client
- Account: your name, email address and phone number. If you sign in with Google or Apple, we receive an identifier from them confirming who you are — we never receive your password.
- Job details: the service address, your description of the problem, an optional "before" photo, and any home-profile notes you choose to add.
- Messages you exchange in the app with the Master assigned to your job.
- Payment data: a Stripe customer reference and the amounts authorized and charged per job. Your card number never reaches NamuGo — Stripe collects and stores it directly.
- Your consent record: if a job is performed inside the 14-day withdrawal period, we store the fact that you confirmed this, because the law requires us to be able to prove it (see §3).
- Ratings and reviews you leave about a Master.
- Device location — read once per booking, both to check the address you entered is inside an area we cover and, if you allow it, to compute a live route and arrival estimate once a Master is on the way. We do not track your location continuously and never in the background.
If you use NamuGo as a Master
- Working profile: name, phone, email, city, the trades you offer, and your preferred language.
- Date of birth and residential address. These are collected for a specific legal reason, not for profiling: EU platform-reporting rules (Council Directive (EU) 2021/514, "DAC7") require us to hold them for every Master and report annually to the Lithuanian tax authority. They also let us confirm you meet the minimum age in our Terms.
- Verification documents: a photo of a government-issued ID, and — for regulated trades — a trade certificate or licence and proof of professional liability insurance, each with its expiry date. We store the expiry so we can warn you before a document lapses and stop matching you for that trade if it does.
- Live location while a job is "on the way": once you accept a job, we read your device location periodically — including while the app is in the background — so the Client can see your position and an accurate arrival time. Tracking starts and stops automatically with the job status: it stops the moment you arrive, cancel, or the job otherwise ends, and we do not keep a history of past positions beyond that job.
- Payout identifiers: your personal or company code, and a reference to your Stripe payout account. Your bank account number is collected and held by Stripe, not by us — NamuGo never sees or stores it.
- Work records: "after" photos you upload, messages with Clients, and the ratings Clients leave about you.
From everyone using the apps
When you take an action that matters for security — signing in, uploading a document, deleting your account — we record the action, a timestamp and the IP address it came from in an internal audit log. This exists to investigate fraud, abuse and account-security incidents. It is not used to profile you, build advertising audiences, or track you across other services.
If you report someone from a job chat, we keep your report: who reported whom, the reason you chose, anything you wrote, and a copy of the message you reported. We keep it even if you or the person you reported later delete your account, because a report about someone's conduct is of no use if it disappears the moment they leave — this is the one thing account deletion does not erase. Blocking somebody is recorded on your own account, so that the two of you are not matched again.
Visitors to our website
Our website sets no cookies, runs no analytics, and loads no fonts, scripts or images from third parties — pages are served complete from our own hosting, so simply reading them does not share anything about you with anyone else. Our hosting provider keeps standard server access logs for security and reliability.
2. Why we use it, and our legal basis
- To perform our contract with you (Art. 6(1)(b) GDPR) — matching a job with a Master, handling payment authorization and capture, paying Masters, and providing support.
- To comply with legal obligations (Art. 6(1)(c)) — accounting and invoicing records, and DAC7 reporting of Master earnings to the tax authority.
- For our legitimate interests (Art. 6(1)(f)) — verifying a Master's identity, qualifications and insurance before they can enter anyone's home, and keeping the security audit log described above. We consider these proportionate because the alternative is sending unverified strangers to people's homes.
- With your consent (Art. 6(1)(a)) — optional features you switch on yourself, such as push notifications. You can withdraw consent at any time in your device settings, without affecting anything else.
3. Automated decisions
NamuGo does not make automated decisions that produce legal effects about you within the meaning of Art. 22 GDPR. Job matching applies fixed rules — your city, the trades you registered for, whether you are online, and whether your documents are valid — rather than scoring or profiling you. A human being reviews every Master's documents before an account is approved, and a human reviews every dispute.
4. Who we share data with
Some sharing is inherent to how a marketplace works: a Master assigned to your job sees the service address and your messages for that job, and you see their name, rating and messages. A Master's exact address and date of birth are never shown to Clients.
Beyond that, we share data only with the providers that operate the service on our behalf:
- Stripe — payment authorization, capture, refunds, and Master payout accounts (including identity verification Stripe performs itself).
- Cloudflare R2 — storage for job photos and verification documents.
- MapTiler — map tiles displayed in the apps. The requested map area and ordinary connection data are sent when a map is shown.
- Google LLC / Apple Inc. — only if you choose to sign in with their account.
- Expo — delivery of push notifications.
- Brevo — transactional email such as verification codes and receipts.
- openrouteservice (HeiGIT gGmbH) — while a job is "on the way", the Master's current coordinate and the Client's home coordinate are sent to compute the route and estimated arrival time. Neither side's exact coordinates are shared beyond what this calculation needs.
- Sentry — receives a technical report when the service hits an error, so faults get fixed instead of going unnoticed. It is deliberately configured to send only the error itself and the code path that produced it: no IP addresses, no cookies, no request contents, and no account identifiers.
- Render and Neon — application and database hosting, in the EU (Frankfurt).
We may also disclose data where the law requires it, or to a competent authority investigating a specific matter. We do not sell personal data, and we do not share it with anyone for their own advertising or marketing.
5. Transfers outside the EU
Our application and database infrastructure runs inside the EU. Some providers above — Stripe, Google, Apple — are established outside the EEA and may process data there. Where that happens, the transfer relies on the European Commission's Standard Contractual Clauses or an applicable adequacy decision. You can ask us for details of the safeguards used.
6. How long we keep it
- When you delete your account, your profile, uploaded photos and verification documents, active sessions and notification tokens are deleted immediately — including the actual files in storage, not just the database records.
- Transaction records (amounts, dates, invoice data) are kept for as long as Lithuanian accounting law requires — currently up to 10 years. This is a legal obligation we cannot waive on request.
- DAC7 records are kept for the retention period set by the tax rules that require them.
- Job and chat history is kept while the related job record exists.
- Security audit entries are kept only as long as needed for the security purpose they were collected for.
7. How we protect it
Traffic between the apps and our servers is encrypted in transit (TLS, enforced). Verification documents and job photos are never publicly listed or browsable — they are reachable only through short-lived, individually signed links issued to you or to a reviewer. Access to production data is limited to those who need it to operate the service.
8. Your rights
Under the GDPR you have the right to access your data, correct it, delete it, restrict how we use it, receive it in a portable format, and object to processing we base on legitimate interest. Where processing is based on consent, you can withdraw it at any time.
You can delete your account and most associated data yourself, at any time, from the Profile screen in either app. For anything self-service deletion does not cover, write to support@namugo.eu and we will respond within one month.
If you believe we have handled your data wrongly, you can complain to the Lithuanian supervisory authority: Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate), vdai.lrv.lt. We would appreciate the chance to put it right first.
9. Children
NamuGo is not intended for children. You must be at least 18 to create an account, and we do not knowingly collect data from anyone younger. If you believe a minor has created an account, tell us and we will remove it.
10. Changes to this notice
If we make a material change to how we handle your data, we will update the version and date at the top of this page and notify you in the app before it takes effect. Continuing to use NamuGo after that means the updated notice applies.