Privacy Policy
Version of 25.09.2026
Translation for information. In case of discrepancy, the Russian version prevails. Русская версия
The platform is in its launch phase. The details of the personal data operator will be published after the legal entity is registered. The document will be additionally reviewed by a lawyer for compliance with the personal data legislation of the Republic of Tajikistan.
1. Who processes the data
Data is processed by the administration of the GHOST.TJ platform (website ghost.tj). Questions about data: info@ghost.tj.
2. What data we collect
- Account: name, email, password hash (we never see the password itself), two-factor protection settings.
- Quick request without registration: name, phone, email and company name (if provided), task description, selected category, IP address.
- Companies: name, legal details, TIN, registration number, address, city, phone, email, website, bank details, description, logo, portfolio, team members and their roles.
- Verification documents: registration certificate, tax and bank documents, powers of attorney.
- Deals: requests, quotes, contracts, milestones, invoices, bank transaction numbers, reviews, activity log.
- Messages and files: chat messages about requests and contracts, attached files.
- Telegram: chat ID — only if you connected notifications yourself.
- Favorites and notifications: saved services and companies, history of on-site notifications.
- Technical data: IP address, browser, request time, session cookie; anonymized counters of service and profile views.
3. Why
- registration, login and account protection;
- company verification and fraud prevention;
- matching contractors, passing requests, quotes and messages between the parties;
- preparing contracts, invoices and acts of acceptance;
- notifications by email, on the website and in Telegram;
- responding to a quick request: a platform manager contacts you by phone or email;
- statistics for contractors (views, response time, rating) and service improvement;
- compliance with legal requirements.
We do not sell data and do not use it for third-party advertising.
4. Who sees what
- All visitors see the public profile of a verified company: name, city, description, logo, portfolio, services, contacts provided by the company, reviews and rating.
- The public request feed shows the request text, budget, timeline, category and the customer's city, but not the customer's company name. The customer can turn off showing the request in the feed when creating it.
- A contractor with access to a request sees it in full, including files and the customer's company name.
- Messages and files are visible only to the participants of a specific request or contract and to the administration (for resolving disputes and complaints).
- A quick request (name, phone, email, task) is visible to the administration and to up to 5 suitable verified contractors to whom it is passed automatically so they can contact you. If the request was left on a company page, only that company receives it.
- Verification documents and bank details are not published. They are visible to company members with the appropriate role and to the administration; the contractor's bank details are also printed on the contractor's invoices for the customer.
5. Transfer to third parties
Data is transferred only to those without whom the service cannot work: the hosting provider, the email service for sending messages, Telegram (only if you connected the bot), the Cloudflare Turnstile bot protection service (if enabled), and government authorities — in cases expressly provided for by law. If analytics is enabled on the website (Google Analytics, Yandex Metrica), it receives anonymized visit data.
6. Cookies
We use essential cookies for login and form protection. Analytics cookies are set only if analytics is enabled in the platform settings.
7. How long we keep data
- Account and company data — for as long as the account exists.
- Contracts, invoices, acts and the activity log — for the period required for accounting and dispute resolution.
- Quick requests — up to 2 years if no deal resulted from them.
- Database backups — up to 14 days on the server; an additional copy, encrypted in transit, is kept in a private chat of the platform administration.
- Technical logs — up to 14 days.
8. Your rights
- change your name and email in your profile;
- download your data in JSON format (Profile → Data export);
- turn off Telegram notifications;
- delete your account (if you own a company, first transfer ownership to another member);
- ask us to delete a quick request or correct data — write to the support email.
9. Security
The connection to the website is encrypted (HTTPS). Verification documents and message files are kept in private storage and are provided only to the parties to the deal. Bank details and secret settings are stored encrypted. Access to the administration panel is protected by two-factor authentication.
10. Changes
In case of material changes, we will update the version date and notify registered users by email.