Membership AgreementRefund & Cancellation PolicyPrivacy PolicyTerms of Use

Privacy policy

Effective date: September 22, 2025

1. Who we are

2Global, Inc. (“2Global,” “we,” “us,” “our”) operates the Yoogo platform (networking, content publishing, recruiting, projects/gigs, product marketplace, and chat).
Address: 2514 Whitney Ave. #185892, Hamden, CT 06518, USA

Controller For personal data we collect via the Services, 2Global is the controller. Our payment partners (e.g., PayPal and Braintree) act as independent controllers for payment data you submit to them directly.

EU representative (GDPR Art. 27). Leon David, support@yoogo.com
UK representative (UK GDPR Art. 27). Leon David, support@yoogo.com
Swiss point of contact. Leon David, support@yoogo.com

2. Scope & changes

This Policy covers our websites, apps, and modules (Marketplace, Recruiting, Projects/Gigs, Publishing, Chat). We may update this Policy; material changes will be announced in-product or by email.

3. Children

The Services are not for children under 16 and we do not knowingly collect their data. If you believe we have, contact us and we’ll delete it.

4. Data we collect

Account & identity. Name, email, password hashes, profile data, organization, verification/KYC info where required (licenses, IDs where legally necessary).
Transactional. Subscription tier, invoices, payment metadata (handled by PayPal/Braintree), cancellations, refunds/credits..
Content. Posts, listings, messages, attachments, reviews, project briefs, RFQs/quotes, job posts/applications.
Usage & device. Log data (IP, timestamps, pages, referrers), device/OS/browser, telemetry, crash logs, approximate location (from IP), cookies/SDK identifiers.
Support & safety. Reports, abuse flags, sanctions screening results, fraud/risk signals.
Marketing. Email preferences, campaign and attribution data if enabled.
Sensitive data. Do not send payment card data, bank credentials, government IDs, health data, or special-category data in Chat. If processing of special categories is ever required, we will obtain explicit consent or rely on a clear legal basis with safeguards.

4A. Payments & PCI-DSS (after §4 “Data we collect”)

We don’t collect or store full payment card details. Subscriptions are processed by independent payment processors—Braintree and PayPal—via hosted fields/redirects. Card numbers, CVV/CVC, and bank credentials are sent directly to the processor and never touch our servers.

What we receive from processors (limited billing data): transaction IDs, payment method type/brand, the last four digits and expiry month/year (if provided by the processor), PayPal payer/account ID, billing name and address, authorization/settlement status, and timestamps. We use this data for receipts, fraud prevention, accounting, refunds, and dispute handling.

Controller roles. For payments you make on Braintree or PayPal, those providers act as independent controllers of your payment data under their own privacy notices. 2Global is the controller of the limited billing metadata we receive back from them.

PCI scope. We design our integration so that we do not process, store, or transmit cardholder data on our systems (PCI “SAQ A” posture). If we ever change this, we will update our security controls and this Policy first.

Payouts (if enabled). If we enable payouts, we may collect your PayPal account email/ID to route funds. We will not collect or store bank account numbers unless required and with appropriate safeguards.

5. Sources

Directly from you; your organization (if you’re a business user); other users (e.g., messages, reviews); third-party providers (payment, anti-fraud/verification); and publicly available sources.

6. Why we use your data (purposes & GDPR legal bases)

  • Provide the Services & account (contract, Art. 6(1)(b))
  • Payments & subscriptions (contract/legal obligation, Art. 6(1)(b)/(c))
  • Security, fraud, abuse, sanctions compliance (legitimate interests/legal obligation, Art. 6(1)(f)/(c))
  • Marketplace & Chat operations (contract/legitimate interests, Art. 6(1)(b)/(f))
  • Service improvement & analytics (legitimate interests/consent where required, Art. 6(1)(f)/(a))
  • Communications—transactional and (where permitted) marketing (Art. 6(1)(b)/(f)/(a))
  • Legal compliance (Art. 6(1)(c))
  • Vital/public interest (Art. 6(1)(d)/(e)) in rare cases (e.g., imminent harm reports)

You may object to processing based on legitimate interests where your rights outweigh our interests.

7. Cookies & similar technologies

We use cookies/SDKs for authentication, security, basic analytics, and (optionally) marketing. In regions that require it, we display a consent banner and honor choices (including Global Privacy Control (GPC) where applicable). You can manage preferences in Cookie Settings.

8. Sharing your data

We share only as needed to operate, protect, or comply:

  • Processors (service providers): hosting, storage, analytics, email, support tools, security, KYC/risk, moderation—under Data Processing Agreements (DPAs) acting on our instructions.
  • Payment processors (independent controllers): PayPal and Braintree receive payment info directly from you.
  • Other users: content you publish; messages to recipients; profile elements per your settings.
  • Authorities/rights holders: to comply with law or protect safety/rights; to respond to lawful requests and IP notices.
  • Change of control: mergers, acquisitions, financing—data may transfer subject to this Policy.

We do not sell personal data. Where “sale”/“share for targeted advertising” might be defined broadly by law, you can opt out (see §13).

9. Security

We use administrative, technical, and organizational measures appropriate to risk (access controls, encryption in transit/at rest for key data, network segmentation, least-privilege, audit logs, vulnerability management). No method is 100% secure.

10. Retention

We keep personal data only as long as necessary for the purposes in §6, including legal/accounting requirements and dispute resolution. Typical examples:

  • Account & billing records: 7 years (tax/finance)
  • Security logs:12–24 months
  • Chat messages: for the life of the account or longer as required by law (e.g., legal holds)
  • Backups: limited rolling periods

When no longer needed, we delete or anonymize the data.

11. International data transfers (GDPR/UK GDPR/Swiss FADP)

We are U.S.-based. Your data may be processed in the United States and other countries where our providers operate. For transfers from the EEA/UK/Switzerland to countries without an adequacy decision, we rely on:

  • EU Standard Contractual Clauses (SCCs) + UK IDTA/Addendum + Swiss addendum,
  • Transfer Impact Assessments and supplementary safeguards (encryption, access controls, minimization),
  • Derogations (GDPR Art. 49) only where strictly necessary (e.g., explicit consent or to perform a contract you request).

If a vendor participates in an approved framework (e.g., EU-U.S. Data Privacy Framework/UK Extension/Swiss-U.S.), we may rely on that in addition to SCCs.

You can request a copy of our transfer safeguards (redacted) at support@yoogo.com.

12. Your rights (EU/UK/Swiss & many other regions)

You can access, correct, delete, or port your data; restrict or object to certain processing; and withdraw consent at any time (does not affect prior processing). We respond within 30 days (extendable where permitted).

How to exercise: use in-product tools where available or email support@yoogo.com with subject “Privacy Request.” You may lodge a complaint with your supervisory authority (e.g., an EU DPA, the UK ICO, or the Swiss FDPIC).

Automated decisions. We do not make decisions with solely automated processing that produce legal or similarly significant effects; where we use automated fraud/abuse screening, you may request human review.

13. U.S. state privacy rights (CA/CO/CT/VA/UT and others)

Depending on your state, you may have rights to know/access, delete, correct, data portability, and to opt out of:

  • “Sale” of personal data,
  • “Sharing” or Targeted Advertising,
  • Profiling with legal/similarly significant effects.

We will honor GPC signals for opt-outs where required. To exercise rights or appeal a decision (CO/VA/CT), contact support@yoogo.com; we’ll reply within 45 days (extendable).

Do Not Sell/Share. We do not “sell” personal data for money. If any use could be deemed a “sale” or “share” under state law, you can opt out via our Do Not Sell or Share link or by sending a request.

Sensitive data. We do not collect/use “sensitive” categories except where necessary and permitted (e.g., government IDs for KYC when required), and then with heightened safeguards/consent as required.

14. Brazil (LGPD), Canada (PIPEDA), Australia, Singapore, Japan, and others

We process your data under recognized lawful bases (consent, contract, legitimate interests, legal obligation). You can exercise access, correction, deletion, portability (where applicable), and objection/withdrawal of consent through support@yoogo.com. You may contact your local regulator if you disagree with our response.

15. Module-specific details

Marketplace. Listings, RFQs, quotes, transaction metadata; compliance screening (sanctions/export); risk-based KYC.
Recruiting. Job posts, applications, CVs; sharing with prospective employers as directed.
Projects & Gigs. Briefs, proposals, milestones; collaboration artifacts.
Publishing. Public posts/profiles; visibility controls where offered.
Chat. Not end-to-end encrypted; processed for delivery, safety, moderation, spam/malware scanning, and improvement; see Chat Terms.
Payments. Handled by PayPal/Braintree as independent controllers.

16. Data subject requests & verification

We may verify identity (e.g., logged-in request, email confirmation, or additional info). We may deny/limit a request where an exception applies (legal privilege, trade secrets, others’ privacy). We will explain our decision and how to appeal where required.

17. Third-party links & services

Third-party sites and services are outside our control and governed by their own policies.

18. Contact us

2Global, Inc.
2514 Whitney Ave. #185892, Hamden, CT 06518, USA
Email:support@yoogo.com
EEA/UK/CH users may also contact their local authority or our EU/UK representatives (see §1).

Appendix A — International Transfer Mechanisms

  • We execute DPAs with all processors, incorporating SCCs/UK Addendum/Swiss addendum and security obligations.
  • We conduct Transfer Impact Assessments for high-risk transfers and apply supplementary safeguards (e.g., encryption, strict access).
  • If/when we self-certify to an approved framework (e.g., EU-U.S. DPF), we will update this Policy and maintain a public certification record.

Appendix B — Cookie & Consent Essentials

  • Consent banner for EEA/UK/CH before any non-essential cookies (analytics/ads); granular choices by purpose.
  • Always-on necessary cookies only for core functionality/security.
  • GPC honored where required; settings page for changes; consent logs retained for audit.

Appendix C — How to Exercise Your Rights

  • In-product: Account → Privacy (export, delete, correct where available).
  • Email: support@yoogo.com with subject “Privacy Request” and your request type.
  • We will verify your identity and respond within 30–45 days depending on jurisdiction (extensions as permitted).