Privacy Policy
Last updated: June 28, 2026
1. Scope and Data Controller
This Privacy Policy explains how IVV SERVICES, operating company of the IVVER platform, acting as data controller, processes personal data in connection with the IVVER mobile application, website, marketplace, and related services (the "Service").
IVVER operates a digital marketplace connecting users seeking to rent or book assets or related services ("Customers") with independent professionals making their assets or services available ("Providers"). Depending on the User's role, IVVER may process different categories of personal data.
This Policy applies to processing carried out by IVVER as data controller under Regulation (EU) 2016/679 ("GDPR"), French data protection rules where applicable, and any other data protection law applicable to the User.
For privacy-related questions or requests, Users may contact IVVER at privacy@ivver.ma.
2. Personal Data Processed
2.1 Account and Contact Data
IVVER may process account and contact data provided by the User, including first name, last name, email address, phone number, profile photograph, language preferences, account role, authentication identifiers, and account status.
2.2 Authentication Data
IVVER processes data required to create, secure, and access the User account, including login credentials or authentication tokens, one-time password data, session data and, where selected by the User, authentication data received from third-party sign-in providers.
2.3 Location Data
IVVER processes precise location data, including GPS coordinates and related geographic information, where enabled by the User. Such data is used to allow Customers to search for available assets or services near a chosen location and to allow Providers to indicate the location of assets or services listed on the marketplace.
The User may disable location permissions at any time through device settings. Certain search, listing, or proximity features may then be unavailable or limited.
2.4 Asset, Listing, and Booking Data
IVVER processes data relating to assets, services, listings, and bookings, including asset or service characteristics, photographs, registration or identification references where applicable, availability, pricing, deposit information, booking dates, booking duration, booking status, amount, currency, service fees, payment status, and booking history.
2.5 Files, Images, and Documents
IVVER processes files, images, and documents uploaded by Users, including asset or service photographs, profile images, documents required for Provider verification, legal or contractual documents required before the creation or performance of a booking, and supporting documents used to prevent fraud, secure transactions, or manage disputes.
Depending on the context, these documents may include identity documents, driving licence documents, corporate documents, representative identity documents, or other supporting documents required for the relevant marketplace transaction.
2.6 Payment and Transaction Data
Card payment details are processed directly by an authorised third-party payment service provider. IVVER does not have access to, and does not store, full card numbers, card verification codes, or equivalent sensitive card credentials.
IVVER may process limited transaction metadata, including the booking reference amount, service fees, currency, service-fee payment status, timestamps, payment method references, transaction identifiers, refund status, and reconciliation data, for booking management, accounting, support, fraud prevention, and legal compliance.
2.7 Messaging and Communications
IVVER processes messages exchanged through the in-app messaging feature, message metadata, read receipts, support requests, complaints, and communications sent by email or in-app notification.
IVVER may access messages where necessary to investigate a report, resolve a dispute, prevent fraud or abuse, ensure marketplace safety, or comply with a lawful request from a competent authority.
2.8 Notification, Device, Security, and Diagnostic Data
IVVER may process push notification identifiers, device identifiers, device type, operating system, language, app version, IP address, technical logs, security signals, crash reports, performance data, and diagnostic events. These data are used for notification delivery, account security, fraud prevention, troubleshooting, and Service improvement.
3. Purposes and Legal Bases
IVVER processes personal data for the following purposes and legal bases:
- Account creation and management: performance of the contract or pre-contractual measures.
- Marketplace operation: performance of the contract, including listings, searches, bookings, messaging, and User support.
- Location-based search and listing features: performance of the Service and, where required, User consent through device permissions.
- Provider and Customer verification: performance of the contract, legitimate interest in preventing fraud, and legal obligations where applicable.
- Payment and transaction management: performance of the contract, legal obligations, accounting requirements, and legitimate interest in securing transactions.
- Notifications and transactional communications: performance of the contract and legitimate interest in informing Users about bookings, messages, and important Service events.
- Security, fraud prevention, and dispute management: IVVER's legitimate interest and, where applicable, compliance with legal obligations.
- Service maintenance and improvement: IVVER's legitimate interest in maintaining a reliable and secure Service.
- Legal compliance: compliance with legal, tax, accounting, regulatory, or judicial obligations.
IVVER does not sell personal data and does not disclose personal data to advertisers for behavioural advertising or cross-app tracking purposes.
4. Recipients and Sharing
IVVER may disclose personal data only where necessary for the operation of the Service, the performance of a booking, compliance with legal obligations, the protection of Users, or the defence of IVVER's rights.
Certain data may be shared between Customers and Providers where strictly necessary to establish, perform, evidence, or manage a booking. This may include identity information, booking details, asset information, contractual documents, and limited contact or messaging data.
IVVER also relies on service providers acting as processors or independent providers, depending on the context. These providers may include hosting and cloud infrastructure providers, authentication and account security providers, payment service providers, content delivery and file storage providers, email and notification providers, mapping providers, security and anti-abuse providers, and diagnostics or error-monitoring providers where those features are enabled.
IVVER may disclose data to competent public authorities, courts, regulators, or law enforcement authorities where required by applicable law or where necessary to establish, exercise, or defend legal claims.
5. Retention Periods
IVVER retains personal data only for as long as necessary for the purposes described in this Policy, subject to legal retention obligations and dispute-management needs.
- Account data: retained while the account is active, then deleted or anonymised after account deletion, subject to legal retention obligations.
- Booking and transaction data: retained for the duration necessary to perform the booking and then for the applicable statutory limitation, accounting, tax, fraud-prevention, and dispute-management periods.
- Accounting and transaction records: retained for the legal period applicable to accounting and tax records, which may be up to ten (10) years where required.
- Identity and booking documents: retained for the duration necessary to establish and perform the booking, and for up to thirty (30) days after the scheduled end of the booking, unless a longer period is necessary due to a dispute, fraud report, legal obligation, or authority request.
- Provider verification documents: retained while the verification status is active and for as long as necessary for trust, security, fraud-prevention, legal compliance, or dispute-management purposes.
- Messages: retained for the period necessary to provide messaging, manage bookings, resolve disputes, and comply with legal obligations.
- Security, logs, and diagnostics: retained for the period necessary to secure and maintain the Service, generally not exceeding twenty-four (24) months unless an incident, dispute, or legal obligation requires a longer retention period.
6. Account and Data Deletion
Users may request deletion of their account and associated personal data through the in-app account deletion feature or through the online account deletion process made available by IVVER.
Account deletion results in the deletion or anonymisation of personal data, subject to data that IVVER must retain to comply with legal obligations, prevent fraud, secure transactions, resolve disputes, or establish, exercise, or defend legal claims.
7. Security
IVVER implements appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. These measures include encryption in transit, secure authentication, access controls, secure file storage, monitoring, and internal restrictions on access to sensitive data.
No system is completely secure. Users remain responsible for maintaining the confidentiality of their credentials and for using secure devices and networks.
8. International Transfers
IVVER may process or store personal data in countries where IVVER or its service providers operate. Where personal data is transferred outside the European Economic Area or another jurisdiction offering an adequate level of protection, IVVER implements appropriate safeguards, such as standard contractual clauses or equivalent mechanisms where required by applicable law.
9. User Rights
Subject to applicable law, Users may request access to their personal data, rectification of inaccurate data, deletion of data, restriction of processing, portability of data, objection to processing based on legitimate interests, and withdrawal of consent where processing is based on consent.
Requests may be sent to privacy@ivver.ma. IVVER may request information necessary to verify the identity of the requester and will respond within the timeframe required by applicable law, generally within one (1) month for GDPR requests unless a legally permitted extension applies.
Users located in the European Union may lodge a complaint with their competent data protection authority. Users in France may contact the CNIL.
10. Cookies and Tracking Technologies
IVVER does not use advertising identifiers, cookies, or cross-app tracking technologies for behavioural advertising or advertising profiling. The Service may use local storage, secure storage, device preferences, or similar technical mechanisms solely to maintain sessions, remember preferences, support offline functionality, secure the account, and deliver push notifications.
11. Minors
The Service is not intended for children. Transactional features such as booking, listing, verification, or payment may be subject to age, licence, identity, or legal capacity requirements set out in the Terms of Service and applicable law.
If IVVER becomes aware that it has collected personal data from a minor without the required authorisation, IVVER will take appropriate steps to delete or anonymise such data.
12. Changes to this Policy
IVVER may update this Policy to reflect changes in the Service, legal requirements, security practices, or data processing operations. In case of material changes, IVVER will inform Users through the application, by email, or by any other appropriate means.
13. Contact
For privacy questions or to exercise rights, Users may contact:
- Data Controller: IVV SERVICES, operating company of the IVVER platform.
- Privacy contact: privacy@ivver.ma
- Support: support@ivver.ma