Privacy Policy
Effective date: 28 September 2026 · Operator: DigitAI Solutions Ltd. (“Dodolist”, “we”)
Optional Microsoft advertising measurement
After you accept the updated measurement choice, Microsoft Advertising UET can measure public page views, listing steps, technical failure codes and confirmed published listings. Our events do not contain listing text, photos, messages or contact details. Microsoft also receives technical connection data and may use UET identifiers. Clarity and session recording are disabled. UET stays off inside the controlled Dodolist app and on private account routes.
With consent, a validated Microsoft click identifier can be linked to the existing first-party listing attribution for campaign evaluation. It follows the same maximum 180-day attribution retention. Temporary campaign storage in this tab expires after 24 hours. You can reject or withdraw optional measurement through Privacy choices in the footer. New Microsoft events stop and reachable browser identifiers are removed. The marketplace works without consent. Microsoft privacy information.
1. Who we are
Dodolist (dodolist.mu) is a local online marketplace for Mauritius operated by DigitAI Solutions Ltd. For anything related to your personal data, contact us at support@dodolist.mu.
This policy covers the website dodolist.mu and the Dodolist mobile apps for Android and iOS (published on Google Play and the App Store by Dodolist Mauritius). The apps show the same marketplace as the website; wherever this policy says “Dodolist”, it means both. The measurement differences inside the controlled app view are explained below.
2. What data we collect
- Account data — email address, display name, a securely hashed password, your language preference, and optionally an avatar, phone/WhatsApp number and profile details you add yourself.
- Social sign-in — if you sign in with Google, Facebook or X we receive your name, email address and (where provided) profile picture from that provider, with your consent in the provider’s dialog. We never receive your password for those services.
- Listing content — titles, descriptions, prices, photos, location and tags of the ads you publish. Listings are public by design. From the location you enter we derive the district, so buyers can filter by area.
- Languages you speak — up to three, if you choose to state them. They are shown next to your contact details so buyers know whether to call or write. The first one also sets the language Dodolist opens in for you.
- Messages and chat attachments — conversations between buyers and sellers. Where photo attachments are enabled, we store the photo you select after reducing its size and removing embedded metadata such as GPS location. Camera originals are not kept as an additional permanent copy. Where PDF attachments are enabled, the selected PDF and its display filename are stored for private download. PDF contents and embedded metadata are preserved; review the document before sharing it.
- Reviews — ratings and comments you leave for sellers (shown publicly with your display name).
- Favourites & search alerts you save.
- Search improvement data — for up to 90 days we keep the normalized words entered in marketplace search, the number of results and whether the visitor opened a result. A random one-search token connects that first click to the search. We do not attach a user ID, cookie ID, IP address or browser identifier. Queries containing an e-mail address, URL or phone-like number are discarded instead of stored.
- Bookings — if you request or accept an appointment for a service listing we store the requested date and time, an optional note, the booking status and, for providers, the availability hours you configure. Booking details are visible to both parties.
- Google Calendar (optional) — service providers can connect their Google Calendar. We then store an access token, read only your free/busy times to block booked slots, and add or remove events for confirmed bookings. We never read event titles or contents of your other appointments. You can disconnect at any time under Dashboard → My Bookings or revoke access in your Google security settings.
- Reports — if someone reports one of your ads, we store the reason given, the time, and our decision, so that moderation is traceable. The person who reported an ad is never shown to you.
- Moderation records — if content you submit violates our content policy (e.g. weapons or drugs), we record the incident on your account (warning count and any temporary posting suspension).
- Payment & subscription data — if you subscribe to Dodolist Pro, payments are handled by Stripe. We never see or store your card number; we store only your subscription status and Stripe references.
- Identity verification (optional) — the “Verified Seller” check is run by Stripe Identity. Your ID document and selfie are processed by Stripe; we store only the result (verified yes/no) and a Stripe reference — never the documents themselves.
- Technical data — IP address, browser information and server logs needed to run and secure the service, plus the cookies listed below.
- Listing campaign attribution — if you open the seller flow through a campaign link, we save only its source, medium, campaign, content and term parameters with the listing created from that draft. We do not store the full campaign URL or
fbclidwith the listing.
3. Permissions the apps ask for
The Dodolist apps ask for as little as possible, and only at the moment you use the feature. You can refuse every one of them and still browse, search, and message sellers.
- Camera and photo library — only when you choose a photo for your listing or a private chat. We upload exactly the photos you select. We never scan your gallery, and we do not read photos in the background.
- Location — optional, and only if you tap “use my location” while creating a listing, to set the place shown on that ad. You can type the location instead, or leave it at district level. We do not track your movements and we do not collect location in the background.
- Notifications — only if you allow them, to tell you about new messages about your ads.
The apps contain no advertising SDKs and no analytics or tracking SDKs. We do not use Apple’s App Tracking Transparency framework because we do not track you across other companies’ apps or websites, and we do not sell personal data.
Signing in with Google or Apple happens in the operating system’s own dialog. We receive your name and email address (with Apple, a private relay address if you choose to hide it) — nothing else, and no password.
You can delete your account and your ads at any time, in the app under Profile → Account, or on the web at dodolist.mu/delete-account. Details are in section 8 below.
4. How we use your data
- To run the marketplace: publish your listings, show your public seller page (you can switch it off under Privacy Settings), deliver chat messages and notify you by email about new enquiries.
- AI features: when you use the AI listing assistant or the bulk import, the photos and text you provide are sent to Google (Gemini) to draft the listing, estimate a price and check for prohibited content. Listing texts and your boutique description are also machine-translated into English, French and Creole via the same service.
- Maps & location: to show a listing’s location and let you pick a spot, we use OpenStreetMap and Nominatim; your place search may be sent to those services.
- Payments & verification via Stripe (see above).
- Safety: spam filtering, rate limiting, Cloudflare Turnstile bot checks on registration, and automated content moderation: listing photos are screened by Google image analysis (SafeSearch and object labels) and AI-assisted listings are checked for prohibited items. Violations can lead to a recorded warning and a temporary posting suspension on your account (see our Terms of Use).
5. Who we share data with
We do not sell your data. We share data only with the processors needed to run Dodolist:
- Google — Sign-In, Calendar (only if you connect it), image safety checks and AI (Gemini) processing of listing photos/text.
- X — only if you choose it for sign-in.
- Meta (Facebook) — sign-in, if you choose it. On the website outside the controlled Dodolist app view, and only after you explicitly allow measurement, we use the Meta Pixel: your browser tells Meta which pages you looked at, so that we can measure our adverts on Facebook and Instagram and show them to people who have already visited Dodolist. Meta may link this to your Facebook or Instagram account.
With that same opt-in our server also reports three of these events directly to Meta (Conversions API): creating an account, publishing a listing, and actually contacting the person who posted an offer or wanted ad by clicking phone, WhatsApp or email, or by successfully starting a new chat. Merely revealing a masked number does not report a contact event. This second path exists because ad blockers and browser settings stop a large share of the browser-side reports. What we send is your IP address, your browser identification, the two Meta cookies, the public listing ID, listing type and contact channel — the same event carries an identifier so it is counted once, not twice. We do not send Meta your name, e-mail address, phone number or chat message, neither in plain text nor hashed. Meta Pixel, Meta custom flow events and Meta Conversions API are always disabled for the controlled Dodolist app view, including a listing that becomes public later through email confirmation. - Google Analytics 4 — after you explicitly allow measurement, aggregated statistics on how Dodolist is used (pages, devices, countries), so we can see what works and what does not. It is never loaded in the controlled Dodolist app view.
- Stripe — payments, subscriptions and identity verification.
- OpenStreetMap / Nominatim — map tiles and place search.
- Our hosting provider — servers located in the European Union (Germany).
- Authorities, if we are legally required to disclose data.
Private chat attachments: these are not public listing images and are not sent to Google image analysis, Gemini or Meta for content processing. Access requires an authenticated participant in the conversation. If a participant reports an attachment, authorised moderators can review that reported attachment and its limited report details to handle abuse. This restricted access is not a claim of end-to-end encryption.
6. What is public
- Your listings (including machine translations), your display name or store name and avatar/logo.
- Your seller page (profile or Pro boutique) with your active listings and received reviews — you can hide it under Dashboard → Privacy Settings.
- Reviews you write, with your display name.
- Your phone number is shown masked and revealed only when a visitor actively taps “Show”.
- The languages you state that you speak, if you fill them in.
7. Cookies and measurement
- Session cookie (dodolist_session) — keeps you logged in, for up to 30 days.
- Language cookie (dodolist_lang) — remembers your chosen language for one year.
- Measurement choice (dod_measurement_consent and dod_measurement_version) — a necessary first-party preference cookie that remembers for 180 days whether you allowed or declined optional measurement. It does not itself measure your activity.
- Meta Pixel (_fbp and related identifiers) — only after opt-in, measures our adverts and lets us show them to people who have visited Dodolist before. This is advertising technology and it works across websites.
- Google Analytics 4 (_ga, _ga_*) — only after opt-in, aggregated usage statistics.
- Our own visitor counter — counts page views without setting any cookie. It stores a daily one-way hash of your IP address and browser, which cannot be turned back into a person, and deletes it after two days.
- Our own seller-flow measurement — records fixed technical steps and error codes without listing text, names, email addresses, phone numbers, filenames, full user agents or raw IP addresses. It remains active in the controlled Dodolist app view so we can find load and publishing failures without sending them to third-party analytics. These event rows are deleted after 90 days.
- Our own contact-intent measurement — records an intent only when a visitor actually clicks phone, WhatsApp or email to reach the person who posted an offer or wanted ad, or when the first message of a new chat has been successfully stored. Revealing a masked number alone is not counted. We store the host, timestamp, public listing ID, listing type (offer or wanted), channel and a random event ID used to collapse same-tab repeats and transport retries. To give those actions an honest denominator, we also record one contactable listing view per browser tab after excluding the owner, administrators and sold listings; that narrow row contains only host, timestamp, public listing ID, listing type, the channels available on that listing and another random event ID. We do not store the contacting person’s user ID, name, contact detail, message, raw IP address or full browser identification in either table. The events therefore remain linked to the public listing, but do not identify the person who viewed or contacted it. The dashboard shows deduplicated opportunities, intents and contacted listings — not counts of people or completed sales. A rate is shown only for a fully measured window with a minimum sample. These rows are deleted after 90 days.
- Our own search-improvement measurement — stores the normalized marketplace query, result count and at most the first listing opened from that search. A random token links those two events and is not reused for another search. No account, cookie ID, IP address or browser identifier is stored; queries containing an e-mail address, URL or phone-like number are rejected. We use the aggregate to identify missing English, French and Kreol variants and zero-result searches. These rows are deleted after 90 days.
- Listing campaign attribution — the five campaign parameters described above are frozen when a new seller draft starts and linked only to the listing that draft creates. Opening another campaign URL later does not change an existing draft. Unlinked attribution is deleted after 180 days. For a linked listing, the raw parameters and technical flow ID are cleared after 180 days; only the app/web context and measurement choice remain with its listing ID so that a delayed app listing is not reported later.
Optional Google Analytics, Microsoft Advertising UET, Meta Pixel, Meta custom flow events and Meta Conversions API do not run until you choose Allow analytics & ads. You can change or withdraw that choice at any time through Privacy choices in the footer; declining also removes the measurement cookies that Dodolist can remove. Browser tracking protection and content blockers remain additional controls. Dodolist works the same without optional measurement.
8. Retention & deletion
- Account data is kept for as long as your account exists. You can delete your account yourself — in the app or on the web under Dashboard → Account Details, or at dodolist.mu/delete-account; this removes your account and takes all your listings offline.
- Sent chat messages, including their photo and PDF attachments, remain available to the other participant after account closure, subject to moderation and applicable erasure obligations. Closing your account does not automatically erase the other participant’s conversation. Contact support@dodolist.mu to request access to or erasure of your chat data; we assess the request, any necessary evidence retention and relevant backup copies.
- Server logs are kept for a short period for security purposes.
- First-party seller-flow event rows are deleted after 90 days.
- First-party contact-intent rows are deleted after 90 days; contactable-view rows follow the same 90-day limit.
- First-party search-improvement rows are deleted after 90 days.
- Unlinked listing campaign attribution is deleted after 180 days. For linked listings, the raw campaign parameters and technical flow ID are cleared after 180 days while the narrow app/web and consent safeguards remain.
- You can also request deletion or a copy of your data at any time via support@dodolist.mu.
9. Your rights
Under the Mauritius Data Protection Act 2017 — and, where applicable, the EU GDPR — you have the right to access, correct, delete and receive a copy of your personal data, to object to certain processing, and to lodge a complaint with the Data Protection Office. Just write to support@dodolist.mu and we will help.
10. Children
Dodolist is not directed at children. You must be at least 16 years old (or the age of digital consent in your country) to create an account.
11. Changes to this policy
We may update this policy as the service evolves. Material changes will be announced on the site; the effective date above always shows the current version.
12. Contact
DigitAI Solutions Ltd.
support@dodolist.mu
