Skizze
How it worksBrowse ServicesBrowse Freelancers
Sign InGet Started
AI & AutomationArchitecture & EngineeringBusiness & ConsultingData & AnalyticsDesign & VisualEducation & CoachingEntertainment & GamingFashion & StyleFood & CulinaryHealth & WellnessLegal & ComplianceMarketing & GrowthMusic & AudioPets & AnimalsPhotography & EditingProgramming & TechnologySustainability & ESGUnique & Innovative ServicesVideo & AnimationWeb3 & BlockchainWriting & Translation
Skizze

Modern freelance marketplace. Find talent, get it done.

Platform

  • Browse Services
  • Search
  • How It Works
  • Pricing
  • For Clients
  • For Freelancers
  • Enterprise

Company

  • About
  • Blog
  • Careers
  • Press
  • Contact
  • Success Stories

Support

  • Help Center
  • FAQ
  • Safety Tips
  • Trust & Safety
  • Report an Issue
  • Verified Freelancers

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Refund Policy
  • Dispute Policy
Platform
  • Browse Services
  • Search
  • How It Works
  • Pricing
  • For Clients
  • For Freelancers
  • Enterprise
Company
  • About
  • Blog
  • Careers
  • Press
  • Contact
  • Success Stories
Support
  • Help Center
  • FAQ
  • Safety Tips
  • Trust & Safety
  • Report an Issue
  • Verified Freelancers
Legal
  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Refund Policy
  • Dispute Policy

© 2026 Skizze. All rights reserved.

Made with intention. Worldwide.

Privacy Policy

Last updated: April 27, 2026

1. Introduction

Skizze ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform. It is structured to satisfy the transparency obligations of the EU/UK General Data Protection Regulation (GDPR, Articles 13 and 14) and the Brazilian Lei Geral de Proteção de Dados (LGPD, Articles 9 and 18).

By creating an account, you confirm you have read this Policy and our Terms of Service.

2. Information We Collect

2.1 Information You Provide

  • Account information: name, email address, hashed password
  • Profile information: bio, skills, location, profile photo, languages, hourly rate
  • Service listings: titles, descriptions, pricing, packages, sample images
  • Communications: messages exchanged through the in-platform chat
  • Reviews and ratings you publish about other users
  • Identity verification documents (only when you opt in to the verified badge)

2.2 Information Collected Automatically

  • Device information: browser type, operating system, language preference
  • Usage data: pages visited, features used, timestamps
  • IP address and approximate, city-level geolocation derived from it
  • Essential cookies — see our Cookie Policy for the full list

2.3 Information We Do NOT Store Ourselves

We never see or store your full payment card details. Card data, CVV and the full PAN are handled exclusively by Stripe (our PCI DSS Level 1 certified payment processor). Skizze only retains a Stripe customer/account identifier and the high-level transaction record (amount, status, timestamps).

3. How We Use Your Information — Legal Basis

Under GDPR Article 6 and LGPD Article 7, we are required to disclose the legal basis on which we process each category of personal data. Below is our mapping:

PurposeLegal basis
Operate the Platform: account, profile, listings, chat, orders, payoutsPerformance of contract (GDPR 6(1)(b) / LGPD 7-V)
Audit log of payments, withdrawals and account-deletion eventsLegal obligation (GDPR 6(1)(c) / LGPD 7-II)
Stripe Connect KYC for freelancers receiving payoutsLegal obligation (anti-money-laundering)
Fraud prevention, abuse detection, off-platform contact filteringLegitimate interest (GDPR 6(1)(f) / LGPD 7-IX)
Transactional email (order updates, payment receipts, security alerts)Performance of contract
Marketing emails, non-essential cookies, optional analyticsConsent (GDPR 6(1)(a) / LGPD 7-I) — opt-in, revocable any time

4. Sub-processors

We do not sell your personal data. To run the Platform, we share specific data with the following sub-processors. Each is bound by a Data Processing Agreement (DPA) compliant with GDPR Article 28 / LGPD Article 39, and where applicable, by Standard Contractual Clauses (SCCs) approved by the European Commission for transfers to the United States.

ProviderPurposeLocation
SupabaseDatabase, authentication, file storage, real-time messagingUnited States (SCCs apply)
StripePayment processing, Connect payouts, fraud screening (PCI DSS Level 1)United States, Ireland (SCCs apply)
ResendTransactional and notification email deliveryUnited States (SCCs apply)
VercelWeb hosting, edge runtime, content deliveryGlobal edge — primary region: United States (SCCs apply)
SentryError tracking and performance monitoring (operational diagnostics only)United States (SCCs apply)

We may also disclose your data when required by law, court order, or governmental authority, or in connection with a merger, acquisition, or sale of assets — in which case we will notify you before your data becomes subject to a different policy.

5. Cookies & Tracking

We rely on a minimal set of cookies. The full inventory and durations are documented in our Cookie Policy. In summary:

  • Essential — Supabase auth tokens (sb-*-auth-token), OAuth PKCE verifier, and the cookie-consent state. These are required for the Platform to function and cannot be opted out of.
  • Analytics / marketing — none active at this time. If we introduce analytics in the future, they will be loaded only after you give explicit consent through the cookie banner.

6. Data Retention

We keep personal data only for as long as necessary for the purpose for which it was collected:

  • Active account data: retained while your account exists.
  • Account deletion: personal identifiers removed immediately on hard-delete; backups containing the data age out within 7 days (Supabase point-in-time recovery window).
  • Audit log of financial events (payments, withdrawals, refunds, MFA changes, account deletions): retained for 5 years after the event, as required by accounting and anti-fraud regulations. PII is anonymized after the active account is deleted.
  • Chat messages: retained while at least one of the participants still has an active account, then deleted alongside their data.
  • Stripe-side records (invoices, payouts, KYC) follow Stripe's own retention schedule, which we cannot shorten.

7. Your Rights

Wherever you live, we honor the following rights — even if your jurisdiction does not strictly require us to. EEA/UK residents are protected by GDPR Articles 15-22; Brazilian residents are protected by LGPD Article 18.

  • Access the personal data we hold about you (GDPR Art. 15 / LGPD 18-II)
  • Rectification — correct inaccurate or incomplete data (GDPR Art. 16 / LGPD 18-III)
  • Erasure — delete your account and associated data (GDPR Art. 17 / LGPD 18-VI). Available self-service from Dashboard → Settings → Account.
  • Restriction of processing in certain cases (GDPR Art. 18)
  • Data portability — receive your data in a machine-readable format (GDPR Art. 20 / LGPD 18-V). Request via email.
  • Object to processing based on legitimate interest (GDPR Art. 21)
  • Withdraw consent at any time, where processing relies on consent
  • Lodge a complaint with your local data-protection authority — for EEA, your national DPA; for the UK, the ICO; for Brazil, the Autoridade Nacional de Proteção de Dados (ANPD); for Portugal, the CNPD.

To exercise these rights, email our Data Protection Officer at dpo@skizze.io. We respond within 30 days (GDPR) / 15 days (LGPD), or notify you of an extension where the law allows.

8. International Transfers

Skizze operates globally. Personal data is processed primarily on servers located in the United States (Supabase, Stripe, Resend, Vercel, Sentry). Where data is transferred from the EEA, UK, or Switzerland to the US, we rely on the European Commission's Standard Contractual Clauses (SCCs). Where data is transferred from Brazil, the transfer is grounded on Article 33 of the LGPD using equivalent contractual safeguards. Copies of the relevant SCCs are available on request from our DPO.

9. Data Security

We implement industry-standard security measures: encryption in transit (TLS 1.2+), database row-level security policies on every table containing personal data, hashed and salted passwords (Supabase Auth), optional two-factor authentication, server-side rate limits on sensitive endpoints, an immutable audit log of privileged actions, and a regex-based content filter on chat. No method of transmission is 100% secure, but we treat security as a design constraint, not an afterthought.

10. Children's Privacy

The Platform is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe a minor has provided us data, contact us at dpo@skizze.io and we will delete the records promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes — anything that broadens our processing or introduces new sub-processors — will be announced by email and by an in-Platform notice at least 14 days before they take effect. Non-material changes (typo fixes, clarifications) take effect immediately and are reflected in the "Last updated" date above.

12. Data Protection Officer & Contact

For privacy questions, rights requests, or complaints, you can reach our Data Protection Officer at:

  • Email: dpo@skizze.io
  • General privacy inbox: privacy@skizze.io

For everything not specifically related to data protection, see our general contact and help pages.