Anonymity Isn't a Feature. It's an Architecture.
Most platforms that claim to protect user privacy do it with a policy: a rule that says employees shouldn't share your contact details, or a setting a user can toggle. That's a promise, not a guarantee — it depends on every person and every process following the rule correctly, forever.
The structural alternative
A different approach is to make identity leakage impossible by construction, rather than merely discouraged by policy. That means: the records that describe an order — its status, its files, its messages — simply have no field where a name, an email address, or a phone number could be stored. Not "we don't populate that field." There is no field.
Why this matters for a two-sided marketplace
In a jewelry CAD marketplace, both sides have a real reason to want this:
A policy-based "please don't share contact info" doesn't hold up under real incentive to break it. A structural guarantee — there's nowhere to put it — does.
What this looks like in practice
Every message between a client and a designer is labeled only by role: "Client" or "Designer," never a name. A participant can read the entire conversation history for an order and learn nothing about who's on the other end. The same applies to the independent QC reviewer — they're identified to both parties only by role.
The trade-off is real, and worth it
Structural anonymity means some things a normal marketplace makes easy — direct relationship-building, repeat-client discounts negotiated informally, reputation systems tied to a real identity — don't work the same way here. That's the point. The entire value of the anonymity guarantee comes from it being non-negotiable.