Quick summary
This Privacy Policy explains how Tuskers Digital Services (Private) Limited ("Tuskers", "we", "us" or "our") collects, uses, stores, shares and protects personal data when people use Tuskers.lk and related Tuskers services.
- Tuskers connects customers in Sri Lanka and overseas with eligible Sri Lankan freelancers and business providers.
- We do not sell personal data.
- Full card numbers and CVVs are submitted directly to HNB/CyberSource and are not received or stored by Tuskers.
- Before an offer is accepted and the required advance payment is completed, users see only limited provider profile information and only the task city, not the precise task address.
- After that payment, the accepted parties receive the contact information needed to complete the task. The precise task address is disclosed only to the accepted provider.
- Tuskers does not currently use AI or solely automated systems to approve or suspend accounts, verify identities, rank offers or make other decisions that have legal or similarly significant effects.
- Privacy requests may be sent to hello@tuskers.lk. Complaints may be sent to complaints@tuskers.lk.
This summary is provided for convenience. The full policy below governs and should be read carefully.
Who we are and how this policy applies
Tuskers Digital Services (Private) Limited operates Tuskers.lk. Tuskers provides an online platform through which customers can post tasks, eligible freelancers and businesses can submit offers, and the parties can connect after the required platform steps and payment have been completed.
For the personal data described in this policy, Tuskers generally acts as the controller: the organisation that determines why and how that data is processed. In some limited situations, another party, such as a payment provider or another user acting independently, may be a separate controller for its own processing.
This policy applies to:
- the Tuskers.lk website;
- Tuskers subdomains and web-based account areas;
- future Tuskers mobile applications;
- related support, payment, communication, promotional and administrative services operated by Tuskers Digital Services (Private) Limited; and
- interactions with Tuskers by telephone, email, SMS, WhatsApp, live chat or other approved channels.
This policy applies to visitors, customers, freelancers, business providers, business representatives, people whose information is included in a task or portfolio, support contacts and job applicants. It does not govern a third-party website or service merely because it is linked from Tuskers.
This policy is intended to reflect the Personal Data Protection Act, No. 9 of 2022 of Sri Lanka, as amended by the Personal Data Protection (Amendment) Act, No. 22 of 2025, together with other applicable laws. If another privacy law applies to a user because of their location, that user may have additional rights.
Eligibility, location and minors
Account holders
An individual must be at least 18 years old to create, own or independently operate a Tuskers account. By creating an account, the person confirms that they are at least 18 and have legal capacity to accept the applicable Tuskers terms.
Provider accounts are currently limited to eligible Sri Lankan citizens and eligible Sri Lankan business accounts represented by an authorised adult. Tuskers may request proof of citizenship, identity, authority or business status. Customers may live in Sri Lanka or elsewhere and may use Tuskers to hire eligible Sri Lankan providers.
Use involving a person under 18
A person under 18 may receive customer-side services only through an account owned and controlled by a parent, legal guardian or other responsible adult who is authorised to act for that minor. The adult must conduct the transaction, control the login credentials, provide any required permissions, and remain responsible for the task, payment, communications and information submitted. A minor must not independently create or operate an account.
No person under 18 may register as, offer work as, or complete tasks as a freelancer, business representative or other provider through Tuskers. If Tuskers reasonably believes that an account owner or provider is under 18, Tuskers may request proof of age and restrict, suspend or close the account.
Personal data relating to a child is treated as sensitive. An adult who submits a child's information must have lawful authority to do so, disclose only what is necessary and avoid placing unnecessary child information in public task descriptions or attachments.
Key terms
Customer means a person or authorised business representative who uses Tuskers to post or arrange a task.
Provider means an eligible freelancer, business provider or authorised business representative who offers or provides services through Tuskers. Also referred to as a service provider.
Personal data means information that identifies, relates to, describes or can reasonably be linked to an identifiable individual.
Processing includes collecting, recording, organising, storing, viewing, using, sharing, changing, retrieving, analysing, restricting, deleting or otherwise handling personal data.
Special-category or sensitive data includes information requiring greater protection, such as health data, certain criminal-history information, biometric or genetic data used for identification, religious or political beliefs, sexual orientation, racial or ethnic origin, and personal data relating to a child.
Personal data we collect
The data collected depends on the user's role, the features used and the information required for a particular task. Some fields are mandatory and others are optional. Tuskers will identify required fields where practical. If required information is not provided, Tuskers may be unable to create or verify an account, publish a task or profile, process a payment or payout, investigate a complaint, or provide another requested service.
Account and contact information
We may collect:
- full name, first name and account display name;
- date of birth, age and gender;
- residential, business or mailing address, city and district;
- telephone number, email address and preferred language;
- username, password credentials in protected form, account role and account status;
- profile photograph; and
- notification, communication and marketing preferences.
A profile photograph is not currently used by Tuskers for facial recognition, biometric matching or liveness verification.
Identity, eligibility and verification information
For account safety, provider eligibility and category-specific checks, we may collect and retain:
- National Identity Card or passport number, expiry details and copies or images of the document;
- proof of citizenship, age, address or authority to represent a business;
- business registration or representative information;
- professional licences, registrations, qualifications, certificates and work-experience records;
- police clearances, criminal-history or suitability records where reasonably necessary for a particular service category, safety review, investigation or legal requirement;
- health or medical information where it is genuinely relevant to a regulated or safety-sensitive role and may lawfully be requested; and
- verification decisions, admin review notes, dates and audit records.
Identity and eligibility checks are currently conducted by authorised Tuskers admin staff. Tuskers does not currently require a facial/liveness check or use an AI system to decide whether an identity document is genuine. We may compare submitted information with reliable records, issuing bodies or publicly available professional registers where this is lawful and necessary.
We will seek to limit sensitive records to what is reasonably necessary. Tuskers may request specific consent or rely on another lawful condition where special-category data is processed.
Provider profile and professional information
We may collect:
- profile biography, service categories and service descriptions;
- qualifications, certificates, licences and work experience;
- previous-project portfolios, photographs, videos, documents and descriptions;
- availability, service areas, city and preferred task locations;
- offers, quoted rates, pricing information and availability responses;
- provider performance, task history, compliance and account-administration records; and
- bank-account details and account-holder information required for payouts.
Public-profile information must not contain another person's confidential data unless the provider has permission to use it. Providers are responsible for obtaining any client, employee, model, photographer or rights-holder permission needed for portfolio material.
Task, offer and work information
When a customer posts or manages a task, or a provider submits an offer or completes work, we may collect:
- task title, category, description, requirements and instructions;
- photographs, videos, documents, plans, designs and other attachments;
- task city, district and exact task address;
- requested dates, timing, availability and service location;
- budget, offers, accepted price and task-payment structure;
- questions posted about the task and the customer's replies;
- offer acceptance, advance-payment, completion, cancellation and dispute records; and
- evidence or records submitted in connection with performance, complaints, refunds or disputes.
Tuskers does not currently provide unrestricted private in-platform messaging between customers and providers. The task question-and-reply feature is limited to genuine task-related questions. Users must not use it to exchange telephone numbers, email addresses, social-media details, external payment instructions or other personal contact details before the platform permits contact. Tuskers may review, moderate, restrict or remove content to enforce these rules, prevent fraud and protect users.
Payment, refund, commission and payout information
We may collect or generate:
- payer and payee identity and contact information;
- billing details and the amount, currency, date, time and status of a transaction;
- gateway transaction references, authorisation status and limited masked payment details supplied by the payment provider;
- advance payments, final payments processed through Tuskers, commissions, gateway charges, holds, refunds and adjustments;
- provider bank-account and payout details;
- payout eligibility, schedules, payment confirmations and histories; and
- invoices, receipts, reconciliation, accounting, tax, chargeback, fraud and audit records.
Full card numbers, card-security codes or CVVs are entered into the HNB/CyberSource payment environment and are not received or stored by Tuskers. HNB and CyberSource process card data under their own security and privacy responsibilities. Tuskers receives the limited transaction information needed to confirm, record, support, reconcile and investigate the payment.
Communications and customer support
We may collect communications sent to or from Tuskers, including:
- emails, support requests, live-chat messages and attachments;
- complaint, cancellation, refund, dispute and payment enquiries;
- telephone number, call time, call notes and, where enabled, call recordings;
- SMS, WhatsApp and notification delivery or response records; and
- feedback and responses to surveys.
Where calls are recorded, Tuskers will provide notice where required. Support communications may contain sensitive information, so users should submit only what is relevant to their request.
Device, usage and security information
When a person visits or uses Tuskers, we and our service providers may automatically collect:
- IP address and approximate location derived from the IP address;
- browser type, operating system, device type, language and screen information;
- pages viewed, links selected, feature interactions and timestamps;
- referring page, campaign source and general navigation information;
- account login, session, authentication, failed-login and logout records;
- cookie, advertising, analytics or similar identifiers; and
- error, performance, fraud-prevention, security and audit logs.
Tuskers does not collect precise GPS location through the platform unless this policy and the relevant permission request are updated before that feature is introduced.
Maps and address information
Google Maps may be used to display maps, assist with address entry or identify an area. Tuskers does not intend to retain every map search, suggested address or map interaction. We do retain the task address, city, district or other location that the user finally submits as part of a task or account. Google may independently receive information about map interactions, device details and IP address under Google's own terms and privacy practices.
Careers and business representative information
If a person applies for work with Tuskers, we may collect their name, contact details, curriculum vitae, qualifications, employment history, references, interview notes and related application information. If a business creates or manages an account, we may collect the representative's identity, position, authority, contact details and account activity. The business and representative must ensure that any employee information submitted to Tuskers is accurate, authorised and lawfully disclosed.
Information we do not intentionally collect or use
Unless this policy is updated and an appropriate notice or permission is provided, Tuskers does not intentionally:
- collect precise GPS location;
- retain a user's complete Google Maps search history;
- receive or store full payment-card numbers or CVVs;
- use profile photographs for facial recognition or liveness verification;
- provide unrestricted private messaging before the required acceptance and payment steps;
- sell personal data; or
- use AI or solely automated decision-making for account approval or suspension, identity checks, fraud decisions, task recommendations or offer ranking.
Users must not upload unnecessary highly sensitive information, card data, account passwords, private third-party documents or unlawful content into task descriptions, questions, portfolios or support channels.
How we obtain personal data
We may obtain personal data:
- directly from the user during registration, verification, profile creation, task posting, offer submission, payment, support or marketing interactions;
- from another user, such as where a customer provides information about a person at the task location, a business provides representative information, or a party submits dispute evidence;
- automatically from the user's device and use of the platform;
- from payment, communications, analytics, security and other service providers;
- from public or official sources used to check professional, business or eligibility information; and
- from a person who refers, represents or is authorised to act for the individual.
A user who gives Tuskers personal data about another person must have a lawful basis and appropriate authority to do so, must give that person any required notice, and must submit only data relevant to the intended purpose.
Why we process personal data and our legal bases
We process personal data only for specified and legitimate purposes. Depending on the circumstances, our legal basis may be performance of a contract, steps requested before entering a contract, compliance with law, consent, protection of life or safety, or Tuskers' or another party's legitimate interests where those interests are not overridden by the person's rights.
| Purpose | Typical processing | Primary legal basis or condition |
|---|---|---|
| Create and administer accounts | Register users, authenticate logins, maintain profiles, provide notifications and manage account settings | Contract or pre-contract steps; legitimate interests in operating the platform |
| Verify identity and eligibility | Check age, citizenship, identity, business authority, qualifications, licences and suitability for relevant categories | Contract or pre-contract steps; legal obligations where applicable; legitimate interests in trust, safety and fraud prevention; consent or another lawful condition for sensitive data |
| Operate the task marketplace | Publish permitted profile and task information, receive offers, record acceptance, disclose authorised contact details and support task completion | Contract or pre-contract steps |
| Process payments and payouts | Initiate gateway payments, confirm status, calculate commission, manage holds, refunds, reconciliation and provider payouts | Contract; legal obligations; legitimate interests in payment administration and fraud prevention |
| Provide support and resolve disputes | Respond to enquiries, record calls or chats, investigate complaints, assess refunds and preserve evidence | Contract; legitimate interests in service quality, safety and legal claims; consent where required for recording |
| Protect Tuskers and its users | Secure accounts, detect abuse, moderate content, prevent contact-detail leakage, investigate fraud and enforce platform rules | Legitimate interests in security, fraud prevention, network integrity and enforcement; legal obligations where applicable |
| Improve and measure the service | Diagnose errors, analyse feature use, create aggregated statistics and improve design, reliability and categories | Legitimate interests in improving the service; consent where required for non-essential cookies or tracking |
| Send operational communications | Send OTPs, account alerts, task updates, payment notices, policy notices and support responses | Contract; legal obligations; legitimate interests in service administration and security |
| Send and personalise promotions | Send opted-in promotional email, SMS or WhatsApp messages and tailor content using account role, interests or activity | Consent for promotional messaging where required; legitimate interests only where permitted by applicable law |
| Meet legal and regulatory duties | Keep accounting records, respond to lawful requests, manage legal claims and comply with court or regulatory directions | Legal obligation; public interest where applicable; legitimate interests in establishing, exercising or defending claims |
| Recruit staff | Review applications, arrange interviews and contact referees | Pre-contract steps requested by the applicant; legitimate interests in recruitment; consent where required |
Where we rely on legitimate interests, those interests may include operating and improving Tuskers, protecting users, preventing fraud, keeping systems secure, enforcing our rules, recovering amounts owed and establishing or defending legal claims. We consider the nature of the data, the context, reasonable expectations and potential impact before relying on this basis.
Where processing is based on consent, consent may be withdrawn using the method described at collection or by contacting Tuskers. Withdrawal does not make earlier lawful processing unlawful and does not affect processing required on another legal basis.
Profile, task and contact visibility
Tuskers is designed to limit unnecessary disclosure before a customer and provider enter the paid task stage.
| Stage | Information that may be visible | Information kept restricted |
|---|---|---|
| Before offer acceptance and advance payment | Provider's first name, city, profile photograph, approved biography, skills, qualifications, service information, availability/service areas and approved portfolio; task category, description, budget and city; task questions and replies | Provider's full name, exact address, company name where applicable, telephone number and email; customer's direct contact details; exact task address |
| After offer acceptance and successful required advance payment | The accepted customer and provider receive the telephone numbers, email addresses and relevant addresses needed for the task; transaction and task status is shown to the parties | The precise task address is disclosed only to the accepted provider and authorised Tuskers staff or processors who require it; unrelated providers do not receive it |
| Public or platform profile | Approved profile information and portfolio content designated for display may be available through the platform | Identity-document copies, bank details, verification notes, full residential address and other private account information are not public profile fields |
Tuskers may hide, remove or restrict information where needed to protect privacy, enforce platform rules or comply with law. Publicly displayed information can be copied, photographed, indexed or cached by other people or services. Although Tuskers may take reasonable steps to remove content from its own service, it cannot guarantee deletion of copies made outside its control.
Users who receive another user's contact details or task address may use that information only for the accepted task, related payment, safety, support or legal purposes. They must not publish it, use it for unrelated marketing, sell it, harass the person or share it unnecessarily.
After receiving information for an accepted task, each user is independently responsible for handling that information lawfully and securely. Tuskers cannot fully control a user's conduct outside the platform, but may investigate misuse and take account or legal action where appropriate.
Payments and financial information
Online card payments are processed through HNB/CyberSource. The payment page or component may be hosted or controlled by the gateway even where it appears within the Tuskers experience. Users should review any gateway notice presented during payment.
Tuskers stores transaction references, payment status, amount, receipts, commissions, refunds, payout history and limited masked details supplied by the gateway. Tuskers may disclose transaction information to HNB/CyberSource, banks, payment networks, professional advisers, auditors, authorities or the affected users where necessary to process or investigate a transaction, meet accounting duties, address fraud or resolve a dispute.
Provider bank-account details are used to administer payouts and confirm payment records. Providers must keep these details accurate and must not submit a bank account they are not authorised to use.
Service providers and other recipients
Tuskers uses external organisations to operate parts of the service. Those organisations may act as processors for Tuskers or as independent controllers for their own regulated or operational activities.
| Provider or category | Function | Data that may be involved |
|---|---|---|
| Amazon Web Services (AWS), primary region Singapore | Hosting, infrastructure, storage, backups, security and service delivery | Account, profile, task, communication, transaction metadata and technical data stored in Tuskers systems |
| Google Maps | Map display and address assistance | IP/device information, map interactions and the location or address entered or selected |
| HNB and CyberSource | Payment-gateway and card processing | Payer, billing and transaction information; card data is provided directly to the gateway |
| Dialog | OTPs, SMS notifications and, where consented, promotional SMS | Telephone number, message content or template, delivery status and related logs |
| Brevo | Operational email, newsletters and promotional email | Name, email address, preferences, campaign and delivery/engagement information |
| tawk.to | Live chat and support communications | Name or contact details supplied in chat, message content, attachments and technical data |
| Analytics and advertising providers, which may include Google Analytics and Meta Pixel | Usage measurement, campaign attribution, audience insights and, where permitted, personalised advertising | Cookie/device identifiers, IP address, page and event activity, campaign and approximate-location data |
| CAPTCHA and social sign-in providers, where enabled | Prevent abuse, secure forms and support optional authentication | IP address, browser/device signals, security interactions and, for social sign-in, profile information authorised by the user |
We may also disclose personal data where reasonably necessary to:
- another user as described in the profile and task visibility section;
- banks, accountants, auditors, insurers, lawyers and other professional advisers;
- law-enforcement bodies, regulators, courts, tax authorities or government agencies in response to a valid legal requirement or where necessary to protect rights and safety;
- investigate suspected fraud, prohibited conduct, security incidents or threats;
- enforce Tuskers terms, recover amounts owed, or establish, exercise or defend legal claims;
- protect a person in an emergency involving life, health or safety; or
- support a merger, investment, financing, reorganisation, sale of assets or transfer of business, subject to appropriate confidentiality and lawful processing requirements.
Tuskers does not currently permit developers, outsourced customer-support staff or administrators located outside Sri Lanka to access user information on Tuskers' behalf. This does not mean that every third-party technology provider is located in Sri Lanka.
International and cross-border processing
Tuskers is based in Sri Lanka, but personal data may be processed outside Sri Lanka. In particular, Tuskers' AWS hosting region is Singapore. Other providers, including CyberSource, Brevo, tawk.to, Google, Meta and security or social-login providers, may process data in countries where they or their subprocessors operate.
Countries outside Sri Lanka may have different data-protection laws. When arranging cross-border processing, Tuskers will seek to use lawful transfer conditions and safeguards appropriate to the circumstances. These may include contracts requiring confidentiality and data protection, vendor due diligence, access restrictions, data minimisation, security controls, explicit consent where appropriate, or transfers necessary to perform a contract requested by the user.
Customers outside Sri Lanka understand that using a Sri Lankan platform to engage a Sri Lankan provider necessarily involves processing information in Sri Lanka and may involve the cross-border technology services described above.
Cookies, analytics and online advertising
Tuskers and its providers may use cookies, pixels, local storage and similar technologies to:
- keep users signed in and remember preferences;
- secure accounts, prevent abuse and balance traffic;
- understand how pages and features are used;
- diagnose errors and measure performance;
- attribute sign-ups or activity to a campaign; and
- personalise or measure advertising where permitted.
Strictly necessary technologies are used to provide and secure the service. Where applicable law requires consent for analytics, advertising or other non-essential technologies, Tuskers will request it through an appropriate choice mechanism. A user can adjust available cookie settings and browser controls, although disabling necessary technologies may prevent parts of the service from working. Analytics and advertising providers may link information collected through Tuskers with information from other websites or accounts under their own policies. Users must not upload sensitive information into fields that may be measured as analytics events. Further details may be provided in the Tuskers Cookie Policy and the consent interface used on the service.
Operational messages and marketing
Operational communications
Tuskers may send communications necessary to operate an account or transaction, including OTPs, security alerts, task and offer updates, payment and payout notices, support responses, policy updates and administrative messages. These are not promotional messages, and a user may be unable to opt out while maintaining an account or active task.
Promotional communications
Tuskers may send promotional email, SMS or WhatsApp messages about Tuskers services, opportunities, offers or platform news where the recipient has consented or where another lawful basis is clearly available under applicable law. Where consent is required, the marketing choice will be clearly presented and will not be a condition of using the core service.
Every promotional electronic message will provide, or be linked to, a reasonable free method to unsubscribe or opt out. A user may also opt out by changing available account preferences or contacting support@tuskers.lk. It may take a short operational period to apply the request. Service messages concerning an account or transaction may continue.
Tuskers may use a user's role, city, service interests, task categories, campaign interactions or platform activity to choose more relevant promotions. Tuskers does not use such personalisation to make a decision that has a legal or similarly significant effect. Sensitive identity, medical or police-clearance information will not be used to personalise promotions.
We do not sell personal data
Tuskers does not sell, rent or trade personal data for money. Sharing information with processors, payment providers, accepted task parties, advisers, authorities or transaction counterparties for the purposes described in this policy is not a sale of personal data.
Retention and deletion schedule
Tuskers keeps personal data only for as long as reasonably necessary for the purpose collected, including to operate accounts and tasks, make payments, meet legal and accounting duties, prevent fraud, resolve disputes and establish or defend claims. The following standard schedule applies unless a shorter period is appropriate or a longer period is required by law, court order, unresolved dispute, security incident, investigation or legal hold.
| Record or information | Standard retention period |
|---|---|
| Incomplete account registrations or abandoned drafts | Up to 90 days after the last activity |
| Rejected or withdrawn provider applications | Application data up to 12 months after the decision or withdrawal; limited decision and fraud-prevention records up to 3 years where justified |
| Active account, contact and profile data | While the account is active; core account and account-administration records up to 6 years after closure |
| NIC/passport copies, verification documents, licences, police clearances and other sensitive eligibility records | While required for active verification, then normally up to 3 years after account closure; up to 6 years where connected with fraud, a dispute, safety issue or legal claim; rejected-application documents normally no more than 12 months unless an exception applies |
| Verification result and audit trail | While the account is active and up to 6 years after closure, preferably without retaining a full document copy where the verification status is sufficient |
| Tasks, offers, questions and replies, acceptance, completion and task attachments | Up to 6 years after completion, cancellation or last task activity; unnecessary attachments may be deleted or anonymised earlier |
| Exact task address and task-location contact details | Normally up to 3 years after task completion or cancellation; up to 6 years if needed for a dispute, safety matter, fraud review or legal claim |
| Payment, commission, refund, receipt, accounting and payout transaction records | At least 5 years after the end of the relevant year of assessment and normally up to 6 years, or longer if required by tax, accounting, payment or legal obligations |
| Current provider bank payout instructions | While the payout relationship is active and for up to 3 years after the last payout or account closure; transaction records containing limited bank details may be retained under the payment-record period |
| Routine support emails, live chats, call notes and call recordings | Up to 2 years after the interaction; if connected to a complaint, transaction or dispute, retain with the relevant record for up to 6 years after resolution |
| Complaints, disputes, fraud investigations, chargebacks, safety incidents and legal claims | Up to 6 years after final resolution, or longer while proceedings, enforcement or a legal hold remains active |
| Login, IP, device, access and routine security logs | Normally up to 12 months; security-incident or fraud-related logs up to 3 years or longer where necessary for an active investigation |
| Marketing consent, campaign and preference records | Active consent and engagement records up to 2 years after the last relevant interaction; a minimal suppression record may be retained as long as needed to honour an opt-out |
| Tuskers-controlled analytics identifiers | Normally up to 14 months; aggregated or anonymised statistics that no longer identify a person may be kept longer |
| Unsuccessful job applications | Up to 12 months after the recruitment process ends, unless the applicant consents to a longer talent-pool period or a legal issue requires retention |
| Backups | Deleted data may remain in protected, access-restricted backups for up to 90 days before being overwritten, unless a security or legal hold applies |
When a retention period ends, Tuskers will delete, securely dispose of, de-identify or aggregate the data, subject to technical limitations and legal requirements. Truly anonymised information that can no longer reasonably identify a person may be retained and used for statistics, service planning and research.
Account closure and deletion requests
A user may request account closure or deletion by contacting Tuskers. Closing an account does not necessarily delete all information immediately. Tuskers may retain the minimum information required to:
- complete or document outstanding tasks, payments, payouts, refunds or chargebacks;
- comply with tax, accounting, corporate, payment or other legal duties;
- prevent fraud, repeated abuse or unauthorised re-registration;
- preserve complaints, disputes, safety reports and evidence;
- establish, exercise or defend legal claims; and
- maintain suppression records so marketing opt-outs remain effective.
Where full deletion is not lawful or appropriate, Tuskers may restrict access, remove information from public display, separate it from active systems or anonymise it where reasonably possible. Residual copies may remain temporarily in backups under the retention schedule.
Security and confidentiality
Tuskers uses technical and organisational measures designed to protect personal data against unauthorised access, misuse, alteration, disclosure, loss or destruction. Depending on the risk and system involved, measures may include:
- role-based access and limiting sensitive-data access to authorised personnel;
- confidentiality obligations and staff training;
- authentication controls and secure password handling;
- encryption in transit and other encryption where appropriate;
- network, application, logging, monitoring and backup safeguards;
- secure payment processing through the external gateway;
- vendor assessment and contractual protections;
- incident-response, access-review and account-recovery procedures; and
- physical and administrative safeguards for records handled by staff.
No website, transmission or storage system is completely secure. Tuskers cannot guarantee absolute security. Users must protect their passwords and OTPs, use accurate contact details, log out of shared devices and promptly report suspected account compromise. Tuskers will never ask a user to provide a full card number, CVV, password or OTP through a public task question.
Personal data breaches
Tuskers maintains processes to identify, investigate, contain and document suspected personal data breaches. Where a breach is likely to create a risk to individuals or where notification is required by law or a regulator, Tuskers will notify the Data Protection Authority, affected individuals or other relevant parties in the required form and timeframe. A notice may describe the nature of the incident, likely effects, actions taken and practical steps the person can take.
Users should report suspected privacy or security incidents promptly to support@tuskers.lk or complaints@tuskers.lk.
Your privacy rights
Subject to applicable law and lawful exceptions, a person may have the right to:
- ask whether Tuskers processes their personal data and request access to it;
- request correction or completion of inaccurate or incomplete data;
- withdraw consent where processing is based on consent;
- object to or request that Tuskers refrain from certain further processing;
- request erasure in circumstances recognised by law;
- request review of a decision based solely on automated processing that creates a legally significant or similarly serious continuing impact;
- ask for information about the purposes, categories, recipients, sources, retention and cross-border processing of their data; and
- complain to Tuskers and, where available, appeal or complain to the Data Protection Authority of Sri Lanka.
Tuskers does not currently use the kind of solely automated significant decision-making described above, but the right is stated for completeness and future transparency.
How to submit a request
Send a written request to hello@tuskers.lk with the subject line Privacy Request, or send it by post to the correspondence address in the contact section. Explain the right being exercised, the account or transaction concerned and the response address.
To protect users, Tuskers may request reasonable information to verify identity and authority. Verification information collected for a request will be used only to assess and respond to that request, protect other users and meet legal record-keeping duties. An authorised representative may be required to provide written authority. A parent or legal guardian may exercise applicable rights for a minor.
Tuskers aims to respond without undue delay and within one month of receiving a complete verified request. Where a request is complex or numerous, Tuskers may extend the response period by up to two additional months and will notify the requester of the extension within the first month. Requests are ordinarily handled free of charge, although Tuskers may charge a fee or refuse a manifestly unfounded, excessive or repetitive request where permitted by law.
Some rights are not absolute. Tuskers may refuse or limit a request where necessary to comply with law, protect another person's rights, preserve evidence, prevent or investigate crime or fraud, address security, complete a transaction, or establish or defend a legal claim. Where required, Tuskers will explain the reason and available complaint or appeal route.
Automated processing and AI
Tuskers does not currently use AI or solely automated systems to:
- approve or suspend an account;
- verify identity documents or perform facial/liveness checks;
- decide that a user committed fraud;
- rank offers or determine which provider receives a task;
- approve or reject a payout, refund or dispute; or
- make another decision producing legal or similarly significant effects.
Authorised Tuskers admin staff make these decisions using relevant records and platform rules. Tuskers may use ordinary rules, filters, analytics or security alerts to support staff, prioritise review or personalise promotions, but a human remains responsible for significant decisions. If this practice materially changes, Tuskers will update this policy and provide any notice or rights required by law.
Business accounts and responsibility for other people's data
A business account must be managed by an authorised adult representative. The representative is responsible for account administration, information submitted, communications, task quality and compliance with Tuskers rules on behalf of the business, without limiting any responsibility the business itself may have.
Where a business provides employee, contractor, customer or representative data, the business confirms that it has authority and a lawful basis to do so and has provided any required privacy notice.
Tuskers may contact the business or representative to verify authority. If a representative leaves or changes role, the business must promptly update account access and contact details.
External services and links
Tuskers may link to third-party websites, profiles, applications or services. Tuskers does not control those third parties and is not responsible for their privacy practices. Users should review the third party's notice before providing data. A link does not mean Tuskers endorses the third party's handling of personal data.
Changes to this policy
Tuskers may update this policy to reflect changes in law, platform features, providers, security practices or business operations. The updated version will show a revised effective or last-updated date. Where a change materially affects how personal data is used or a user's rights, Tuskers will provide reasonable notice through the website, account, email or another appropriate channel before or when the change takes effect, as required by law.
Continued use after an update does not replace consent where the law requires a new, specific consent.
Contact us and make a complaint
Privacy requests are handled through Tuskers' general company contacts rather than through a named individual published in this policy. Use the following contact details:
| Purpose | Contact |
|---|---|
| Privacy requests and general business enquiries | hello@tuskers.lk |
| Customer and provider support | support@tuskers.lk |
| Payments, refunds and payouts | payments@tuskers.lk |
| Complaints and disputes | complaints@tuskers.lk |
| Careers | careers@tuskers.lk |
| Hotline | +94 77 766 9420 |
| Correspondence address | 7th Floor, Sathara Building, No. 122, Avissawella Road, Maharagama, Sri Lanka |
Please do not send identity-document copies or highly sensitive information by ordinary email unless Tuskers specifically requests it and provides an appropriate submission method.
If a person is dissatisfied with Tuskers' response, they may contact the Data Protection Authority of Sri Lanka, subject to the procedures and rights in force at the relevant time:
Data Protection Authority of Sri Lanka
First Floor, Block 5, Bandaranaike Memorial International Conference Hall (BMICH), Bauddhaloka Mawatha, Colombo 07, Sri Lanka
- Email:
- info@dpa.gov.lk
- Website:
- www.dpa.gov.lk
- Telephone:
- +94 (0)11 269 7241 or +94 (0)11 269 7237
Document information
- Policy owner:
- Tuskers Digital Services (Private) Limited
- Effective date:
- 4 August 2026
- Last updated:
- 4 August 2026
- Language:
- English