Privacy Policy
Last updated: May 21, 2026
1. Introduction
Miba ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you use our platform. We comply with the Israeli Privacy Protection Law (1981), the EU General Data Protection Regulation (GDPR), and other applicable data protection laws.
2. Information We Collect
We collect information that you provide directly:
- Account information (name, email, phone number)
- Profile information (bio, avatar, service areas)
- Job posting details (descriptions, locations, budgets)
- Messages sent through our platform
- Payment information (processed by third-party providers)
We automatically collect:
- Device information (browser type, IP address)
- Usage data (pages visited, features used)
- Cookies and similar technologies (see Section 8)
3. Legal Basis for Processing
We process your personal data based on the following legal grounds under GDPR Article 6:
- Contract performance — to provide our marketplace services and fulfill our agreement with you
- Legitimate interest — to improve our platform, prevent fraud, and ensure security
- Consent — for optional features such as marketing communications, which you may withdraw at any time
- Legal obligation — to comply with tax, accounting, and regulatory requirements
4. How We Use Your Information
We use your information to:
- Provide and maintain our Service
- Facilitate connections between customers and providers
- Process transactions and send related information
- Send notifications about your account and jobs
- Respond to your comments, questions, and requests
- Improve our Service and develop new features
- Detect and prevent fraud and abuse
5. Information Sharing
We may share your information with:
- Other users as necessary to provide the Service (e.g., job details with providers)
- Third-party service providers who assist in our operations (see Section 6)
- Law enforcement when required by law
- In connection with a merger, acquisition, or sale of assets
We do not sell your personal information to third parties.
6. Third-Party Processors
We use the following third-party services to operate our platform. Each processes data in accordance with their own privacy policies:
- Cloudinary (image storage and processing) — cloudinary.com/privacy
- Pusher (real-time messaging) — pusher.com/legal/data-protection
- Resend (email delivery) — resend.com/legal/privacy-policy
- Vercel (hosting and deployment) — vercel.com/legal/privacy-policy
- Google OAuth (authentication) — policies.google.com/privacy
7. International Data Transfers
Your data may be transferred to and processed in countries outside of Israel and the European Economic Area (EEA). When we transfer data internationally, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other appropriate safeguards as required by applicable law, to ensure your data receives an adequate level of protection.
8. Cookies
We use only essential cookies required for the proper functioning of our Service:
- Session cookie — maintains your login state
- CSRF token — protects against cross-site request forgery
- Locale preference — remembers your language choice
- Cookie consent — records your acknowledgment of this policy
We do not use analytics, advertising, or tracking cookies. Since we only use strictly necessary cookies, we do not require opt-in consent under the ePrivacy Directive, but we inform you of their use through our cookie banner.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including encryption in transit (TLS) and at rest, secure servers, access controls, and regular security audits. However, no method of transmission over the Internet is 100% secure.
10. Your Rights
Under GDPR and applicable privacy laws, you have the right to:
- Access your personal data (via GET /api/v1/users/me/export)
- Correct inaccurate data (via your profile settings)
- Request deletion of your data (via account deletion in settings)
- Object to processing of your data
- Restrict processing in certain circumstances
- Data portability — export your data in a machine-readable JSON format
- Withdraw consent at any time without affecting prior processing
- Lodge a complaint with a supervisory authority
To exercise these rights, contact us at privacy@mi-ba.com or use the self-service features in your account settings.
11. Data Retention
We retain your personal data according to the following schedule:
- Active account data — retained while your account is active
- Deleted account data — personal information is anonymized immediately upon account deletion
- Transaction records — retained for 7 years after creation for tax and legal compliance
- Messages — retained for 1 year after account deletion for dispute resolution, then deleted
- Audit logs — retained indefinitely in anonymized form (no personal identifiers)
- Backups — purged within 30 days of data deletion
12. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to you, we will also notify you directly without undue delay, providing details of the breach and recommended protective measures.
13. Children's Privacy
Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we discover that we have collected data from a child under 18, we will delete it promptly.
14. Changes to This Policy
We may update our Privacy Policy from time to time. We will notify you of material changes by posting the new Privacy Policy on this page, updating the "Last updated" date, and sending an email notification. Changes take effect 14 days after posting unless otherwise stated.
15. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at privacy@mi-ba.com.