Privacy Policy
Version 2026-10-08-v1 · Effective 8 October 2026
What personal data GoAhead processes, why, who we share it with, how long we keep it, and your rights.
1. Who is responsible
The controller is GoAhead (Nova Viae), Leyweg 813, 2541 SN Den Haag, Nederland, Chamber of Commerce no. 66898064. Send privacy questions to support@goaheadapp.online.
For employee data in GoAhead Teams, the provider (the employer) is the controller and GoAhead processes that data on its behalf under the data processing agreement.
2. What we process
Account: name, email, phone, language, country and password (hashed) or your Google sign-in.
Address and location: your delivery or service address and, with your permission, your location to show nearby providers.
Orders and bookings: what you order or book, from whom, when, amounts, notes and status. Stripe processes payment details; we only see the payment status and last digits.
Communication: messages with providers, support conversations, reviews and reports.
Providers: business details, identity documents for verification, bank and tax details for payouts and legal reporting.
Technical: IP address, device and browser data, logs and security events (such as sign-ins and two-step verification).
Usage (only with consent to analytics cookies): pages visited, the campaign or website you came from, a random visitor ID and, if you are signed in, your account ID.
AI features: the text you enter and the data needed to answer your request.
Voice: dictation uses your own device or browser speech recognition. GoAhead stores no audio recordings.
Data from others: from Google if you sign in with Google (name and email), from Stripe (payment status) and from providers (the status of your order or booking, for example completed or no-show).
3. Why, and on what legal basis
Performing our contract: your account, orders, bookings, payments, messages, support, aftercare, reviews and AI features you choose to use.
Legal obligation: accounting and tax retention, reporting provider income to the Dutch Tax Administration (DAC7), handling notices of illegal content and requests from authorities.
Legitimate interest: security and preventing fraud and abuse, improving the platform with anonymised statistics, and ordering search results. Our interest is a safe, well-functioning platform for customers and providers.
Consent: analytics and marketing cookies (such as the Meta Pixel), location and marketing messages. Withdraw consent any time under Account → Privacy & cookie settings. Withdrawal applies from that moment on.
For an account, order or booking you need to give your name, email address and the details needed for payment and delivery. Without them we cannot carry out your order or booking. Anything else is voluntary.
4. Who we share data with
The provider you order or book with: your name, contact details, address (when delivery or a home service needs it) and your notes. The provider is then responsible for that data itself.
Reviews you post are publicly visible on the provider's page.
Service providers working for us: Supabase (database and storage, EU), Stripe (payments), Vercel (website hosting), Resend (email), OpenAI and Anthropic (AI features, including the GoAhead assistant), Twilio and WhatsApp (provider messaging channels), Google (Sign in with Google) and OpenStreetMap (address search).
Stripe also processes payment data as an independent controller, for example for fraud prevention and legal checks. See Stripe's privacy policy for that.
Meta, only with your consent to marketing cookies: see the Cookie Policy. GoAhead and Meta are joint controllers for collecting and sending that data. What Meta does with it afterwards is Meta's responsibility under Meta's privacy policy. You can exercise your rights with us and with Meta.
Authorities when the law requires it, such as the Dutch Tax Administration.
We never sell your data.
5. Data outside the EU
Some service providers are based in the United States, such as Vercel, Resend, OpenAI, Anthropic, Twilio, Google and Meta. We only use providers certified under the EU-US Data Privacy Framework or bound by the European Commission's standard contractual clauses. You can request a copy of these safeguards at support@goaheadapp.online.
6. How long we keep data
Account data: while your account exists. After closure we delete or anonymise it within 30 days.
Orders, bookings, payments and invoices: 7 years, as required by Dutch tax law.
Support conversations and reports: 2 years after they close.
Security and audit logs: 2 years.
Analytics data (only with consent): 13 months.
Provider verification documents: up to 1 year after the relationship ends, unless the law requires longer.
7. Security
Data is encrypted in transit and at rest. Access is restricted by role in the database, administrators must use two-step verification, and changes to sensitive data are recorded in an audit log that cannot be altered.
8. Your rights
You have the right to access, correct, delete, restrict and port your data. You can withdraw consent at any time.
Right to object: where we rely on legitimate interest, you can always object on grounds relating to your situation. You can always object to use for direct marketing; we then stop.
Download your data and request deletion under Account → Your data, or email support@goaheadapp.online. We respond within one month. For a complex request this can be extended by two months; we tell you within the first month if so.
If you are not satisfied, you can complain to the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl) or the authority in your country.
9. Automated decisions
GoAhead makes no fully automated decisions with legal effect. Stripe's fraud checks can stop a payment; contact support for a human review.
10. Children
GoAhead is not meant for children under 16. If we find an account belongs to a child, we delete it.
11. Changes
We tell you in advance, in the app or by email, about material changes to this policy.