Privacy Policy

Last updated: September 18, 2026

This English translation is provided as a courtesy and may lag behind the Spanish version in structure and detail. The Spanish version, available at https://conectee.com/legal/privacy, is the binding and controlling version and is the one kept fully up to date.

Arkline Digital LLC ("Conectee", "we", "us") is a limited liability company organized in Wyoming, United States of America, with its address at 30 N Gould St Ste R, Sheridan, WY 82801, USA. This Privacy Policy describes how we collect, use, share, and protect your personal information when you use the Conectee mobile application, the website conectee.com, the client web portal, and related services (the "Platform").

By using the Platform, you agree to the practices described in this Policy.


1. Information We Collect

1.1. Information you provide to us

Category Data
Account First and last name, email, password (stored hashed), phone number (verified via SMS), role (Provider/Conecte), profile photo, address, date of birth and gender (optional), language preference
Identity verification (Providers) Official ID document (front and back), verification selfie, CURP (Mexican unique population registry code, for individuals, stored encrypted, never in plain text), and business details where applicable. Each document you upload is retained in versioned form: prior versions are not overwritten and remain available for verification and fraud-prevention purposes
Financial CLABE bank account, account holder name, and beneficiary address for withdrawals (CLABE stored encrypted), tax declaration for payments from a foreign entity (W-8BEN type), and the change history of your bank details. Card data is captured and stored exclusively by our payment processor (Stripe); Conectee never sees or stores card numbers
Services and content Published services, prices, service and portfolio photographs, service location and coverage area (including coordinates), quotes, chat messages and attachments, reviews, support tickets, and dispute evidence
End-client data When a Conecte registers a request or a Client uses the portal: name, phone, email, company, service details, service address and coordinates, and attached photographs

By uploading your ID document and verification selfie, you give your express consent to the processing of this sensitive and biometric data for the purpose of verifying your identity and preventing fraud, in accordance with this Policy.

If you register another person's data (for example, a Conecte registering a potential client), you represent that you have their authorization.

1.2. Information collected automatically

Category Data
Technical and device IP address, device type and platform, device identifiers, user-agent, push notification tokens
Security and anti-fraud Date/IP of last login, logs of access to client contact data (IP, device, user-agent), signals of possible platform circumvention (message patterns, cancellation rates), change history of identity data (name, email, phone) and of service operational data, audit logs
Biometric authentication If you enable it, only a cryptographic public key per device is registered. Your biometric data (fingerprint, face) never leaves your device and is not accessible to Conectee
Usage and stability App usage events, performance metrics, and crash reports (through analytics and stability services)

2. How We Use Information

  • Operating the Platform: accounts, catalogs, recommendation attribution, quotes, connections, chat, scheduling, reviews, wallet, and withdrawals.
  • Charges and payouts: charging commissions to Providers via their payment method on file, distributing earnings to Conectes and referrers, and processing SPEI withdrawals.
  • Verification and security: verifying identity and phone number, preventing fraud, detecting commission evasion, protecting accounts (2FA, biometrics, anti-bot controls), and auditing access.
  • Communications: transactional notifications via push, email, and SMS (verification), and where applicable WhatsApp messages; you can configure your notification preferences in the app.
  • Legal compliance: meeting legal obligations, valid government requests, and defense of claims.

In addition, we process your information for the following secondary purposes, which you may object to at any time (Section 6) without affecting your access to the Platform:

  • Service improvement: usage analytics, error diagnostics, and performance.
  • Non-transactional communications: news, promotions, and other marketing communications; you can disable these from your notification preferences in the app or by requesting to unsubscribe when you receive them.

We do not sell your personal information.

3. Who We Share Information With

We share information only in these cases:

  • Between users, to operate the service: the Provider and the Client receive each other's contact details when a Connection is unlocked, that is, when the Client accepts a quotation (for fixed-price services, which need no quotation, when the Client confirms the request). The Conecte who originated the Connection sees the Client's name and the Connection status from the start, but receives the Client's phone number and email only when the Connection is unlocked, at the same moment and under the same rule as the Provider; before that moment the Platform does not show those details to the Conecte. The Conecte and the Provider also see the information necessary for the transaction (service, quotation, status, the amounts due to each). The Provider's catalog (services, photos, area) is publicly visible through shareable links.
  • How we display your name: on catalogs, public profiles, shareable links, the Client portal before hiring, reviews, notifications, and emails sent to third parties, Providers' and Conectes' names are shown as first name and first surname (for example, "Mariana Solís"), and Clients' names as first name and last-name initial (for example, "Raúl D."). Your full name is shared only between the two parties to a Connection, and only once the Client accepts a quotation or confirms the hiring: at that point the Client sees the Provider's full name and the Provider sees the Client's full name. The Conecte who originated the Connection never sees the Provider's or the Client's full name. Companies are identified by their approved trade name or legal name, never by their representative's personal name. Conectee's authorized staff who administer the Platform do have access to full names for operations, verification, and compliance purposes.
  • Service providers (processors), grouped by category:
    • Payment processing: card processor (Stripe) for commission charges and card validation; international payments provider (Wise) for disbursing withdrawals via SPEI.
    • Communications: transactional email delivery, verification SMS, and push notifications (including Google Firebase services and, where applicable, WhatsApp Business).
    • Infrastructure: server and database hosting, encrypted file storage, delivery networks, bot and attack protection services (for example, Cloudflare), and antivirus scanning of uploaded files. If our servers are unavailable, requests that clients submit through Conectee links (name, email, phone and service description) are stored temporarily on Cloudflare's network until our servers process them, and are then deleted from there.
    • Maps and geolocation: when you use the app's map, map tiles are loaded from OpenStreetMap, and the conversion of coordinates into addresses uses your platform's geocoding service (Apple or Google); these providers receive your IP address and the queried coordinates.
    • Analytics and stability: usage metrics, crash reports, and app performance (Google Firebase); on Android, the Google Play install referrer to attribute invitations.
  • Authorities: where required by applicable law, court order, or valid request, or where necessary to protect rights, safety, or to prevent fraud.
  • Business succession: in the event of a merger, acquisition, or asset sale, with notice to users.

Our providers are required to process data only on our instructions and with adequate security measures.

4. Security

We apply reasonable technical and organizational measures, including:

  • Encryption in transit (TLS) across the Platform.
  • AES-256-GCM encryption of sensitive financial data (CLABE) and authentication secrets (2FA).
  • Passwords stored with strong hashing (bcrypt); session tokens with revocation.
  • Card data handled exclusively by Stripe (Conectee has no access to card numbers).
  • File storage accessed via short-lived signed links, with antivirus scanning of uploads.
  • App integrity controls (App Check), anti-bot protection (Turnstile/reCAPTCHA), rate limits, and audit logs.
  • Encrypted database backups (GPG AES-256) and an encrypted replica of documents in restricted-access external storage; internal access controls.

No system is infallible; if we detect a security incident affecting your data, we will take reasonable steps to mitigate it and notify you where appropriate.

5. Data Retention

  • Active account: we retain your information for as long as your account exists.
  • Account deletion: upon request, your account is deactivated with a 30-day recovery period. Once that period ends, your personal profile data (name, email, phone, address, date of birth, gender, biography, business details, and profile photo) is irreversibly anonymized, and your profile photo and portfolio are deleted from storage.
  • Identity documents: verification documents (ID, selfie, and business documents, including their versions) are retained with restricted access for 5 years from anonymization, for legal obligations, fraud prevention, and defense of claims. Once that period expires, they are permanently deleted from storage and from the external replica.
  • Transactional records: records of transactions, commissions, withdrawals, wallet movements, and bank-detail and identity-data histories are retained after anonymization for tax, accounting, fraud-prevention, and legal-defense purposes; the personal data they contain (for example, the encrypted CLABE and account holder name) is deleted or anonymized when the 5-year retention period expires, retaining only the amounts and dates of the movements.
  • Backups: database backup copies rotate automatically under a tiered retention schedule (daily, weekly, and monthly copies); deleted data disappears from backups as they rotate. The external document replica is purged in accordance with the 5-year retention period described above.
  • Security and anti-fraud logs: retained for as long as necessary for the purposes described.

6. Your Choices and Rights

  • Access and correction: you can review and update your profile information directly in the app. For security reasons, once your identity verification has been approved, identity data (first and last name, date of birth, CURP, and legal business name) can only be corrected by contacting support; every correction is logged.
  • Deletion: you can delete your account from the app (Settings) under Section 5.
  • Notifications: you can configure push, email, and receipt-delivery preferences in the app; essential transactional messages (for example, verification codes) cannot be disabled.
  • Other requests: for any request regarding your personal data (access, rectification, deletion, objection, or a copy of your information), write to [email protected], including your name, a means of contacting you, a document proving your identity (or your representative's), and a clear description of the right you wish to exercise. In the app, the "Privacy" section of Settings directs you to this Policy and to this email address.
  • Response periods. We will let you know whether your request is granted within 20 business days of receiving it, and, if granted, will carry it out within the following 15 business days. Both periods may be extended once for an equal period where the particular circumstances of the case justify it, which we will notify you of.
  • Data protection authority. If you believe we did not address your request in accordance with the law, you may contact Mexico's competent personal data protection authority.

7. International Transfers

Arkline Digital LLC is organized in the United States. Your information may be processed and stored in the United States and other jurisdictions where our providers operate, whose data protection laws may differ from those of your country of residence. By using the Platform, you consent to these transfers.

8. Minors

The Platform is intended exclusively for persons 18 years of age or older. We do not knowingly collect information from minors. If you believe a minor has provided us data, contact us so we can delete it.

9. Cookies and Similar Technologies

The website and client portal use cookies and equivalent technologies strictly necessary for session handling, security, and anti-bot protection (for example, Cloudflare Turnstile). The mobile app uses device identifiers for push notifications, security, and analytics, as described in this Policy.

10. Changes to this Policy

We may update this Policy. Significant changes will be notified through the Platform or by email. The last-updated date appears at the top of this document. Continued use of the Platform after changes take effect constitutes acceptance.

11. Contact

For any question or request regarding this Policy or your personal data:


This Policy is drafted in Spanish, which is the prevailing version. This English translation, available at https://conectee.com/legal/en/privacy, is provided as a courtesy.