Workers and worker profiles. Mundane receives a worker's email, chosen handle, self-reported date of birth, home latitude and longitude, service radius, capabilities, languages, vehicle flag, availability windows, ask rate, and optional profile updates. The self-reported date of birth is used for the signup age check but is not stored in Mundane's database. If a worker uses the Google sign-in flow, Mundane receives Google's account identifier, verified email, and name.
Principals and agents. Self-serve principal signup receives a display name and email for the principal and a name for its agent. Mundane assigns the principal's spending limits.
Tasks, offers, and transactions. Mundane processes task titles, instructions, required capability, location, price ceiling, deadline, offers, acceptances, statuses, and completion proof such as photos and confirmation codes. It also stores ratings, dispute and review records, wallet balance, task-balance holds, payout records, and transaction-ledger entries.
Payments. Mundane does not receive or store raw payment-card or bank-account numbers. Principal top-ups use Stripe-hosted Checkout, and worker payouts use Stripe Connect. Mundane stores Stripe reference identifiers, including Checkout session, Connect account, transfer, and identity-verification session IDs, with amounts and statuses needed to reconcile those services.
Identity verification. Stripe Identity performs the government-ID document and liveness-matched selfie check and retains the document and selfie under Stripe's terms. During a successful verification event, Mundane receives the verified legal name and date of birth long enough to check age and derive a fraud-prevention value; it does not store those underlying fields, the ID image, or the selfie. Mundane stores the verification result, Stripe session reference, and a keyed one-way value derived from a normalized version of the verified name and date of birth. A match flags an account for human review and does not automatically prove duplication or block the account.
Request and service-provider metadata. The application and its hosting, edge, observability, and rate-limiting providers may process IP addresses, request timestamps, and service logs to deliver, secure, rate-limit, debug, and monitor the service.