Privacy Policy - CleanSync Premium
Effective date: 2026-07-07
Last updated: 2026-07-07
1. Introduction
CleanSync Premium ("CleanSync", "we", "our", or "us") respects your privacy. This Privacy Policy explains how we collect, use, store, disclose, and protect personal information when you use the CleanSync mobile applications, websites, APIs, and related services (collectively, the "Platform").
This Privacy Policy is designed to comply with:
- The Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's federal private-sector privacy law;
- The Personal Health Information Protection Act, 2004 (PHIPA) of Ontario, where we process information that may constitute personal health information in Ontario; and
- Other applicable laws of the Province of Ontario and Canada, including the Canada Anti-Spam Legislation (CASL).
By creating an account or using the Platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Platform.
1.1 Definitions
- "Personal Information" means information about an identifiable individual, including name, email address, phone number, address, location data, photographs, device identifiers, and any other information that can be used to identify you.
- "Health-Related Information" means information that relates to the physical or mental health of an individual, the provision of health care, or health history. Under PHIPA, this may include information disclosed in "house rules" (for example, allergies, sensitivities, or medical conditions).
- "Partner Company" means a third-party residential cleaning business that uses the Platform to manage and perform cleaning services.
- "Worker" means an individual employed or engaged by a Partner Company who uses the CleanSync Worker app to perform services.
- "Client" means an individual who uses the CleanSync Client app to book, manage, and pay for cleaning services.
- "Sub-processor" or "Service Provider" means a third party that processes Personal Information on our behalf.
2. Information We Collect
We collect Personal Information that is necessary to operate the Platform and to provide the services requested by our users. The information we collect depends on your role.
2.1 Account and Profile Information (all users)
- First name, last name, and email address
- Phone number
- Password (hashed using bcrypt; we do not store plaintext passwords)
- Profile type (client, manager, or worker)
- Optional profile photo / avatar
- Authentication tokens and session data
For users who sign in through Google or Apple, we also collect:
- Provider name and provider subject identifier
- Email address and email-verified status provided by the provider
2.2 Client Information
When you add a property or request a service, we collect:
- Property nickname, full residential address, city, postal code
- Latitude and longitude coordinates (derived from the address for geofencing)
- Property details such as number of bedrooms, bathrooms, and square footage
- Access instructions (for example, lockbox codes, concierge instructions, building access)
- Parking information
- "House rules" that you choose to provide, which may include health-related information (for example, allergies, asthma, pets, chemical sensitivities, or accessibility needs)
- Billing address and billing email
- Invoice frequency preference
- Preferred payment method type (for example, e-Transfer). We do not collect or store credit card numbers or banking credentials.
2.3 Manager / Partner Company Information
When a Partner Company registers and uses the CleanSync Manager app, we collect:
- Business name, legal name, and business number (HST/GST number where applicable)
- Business address, phone number, and email
- Manager name, title, and contact information
- Commission rate agreed with CleanSync (default 10% of eligible Customer Revenue)
- Team, client, schedule, quote, service, invoice, and attendance records created through the Platform
2.4 Worker Information
When a Partner Company adds you as a worker, we collect:
- Name, email, and phone number
- Internal employee identifier assigned by the Partner Company
- Hourly rate or compensation rate set by the Partner Company
- Employment status (active, on leave, or inactive)
- Optional profile photo
- Check-in and check-out data, including GPS coordinates, timestamp, accuracy, and manual-reason notes
- Optional check-in selfie photo
- Service photos (before/after) that you capture through the app
- Device token for push notifications
2.5 Technical, Usage, and Communication Data
- Device tokens for Firebase Cloud Messaging (FCM) push notifications
- IP address and user-agent collected in audit logs (where technically available)
- App interactions, service status changes, and feature usage
- Emails and notifications sent to you (transactional and, with your consent, marketing)
- Error and crash reports processed through Sentry, with PII stripped before transmission
2.6 Cookies and Similar Technologies
The CleanSync mobile apps do not use traditional browser cookies. However, the Platform uses device identifiers and FCM tokens that are functionally similar for the purpose of delivering notifications and maintaining secure sessions. We do not use third-party advertising cookies, web beacons, or cross-app tracking technologies in the current version of the Platform. If we introduce analytics or marketing tracking in the future, we will obtain your consent before activating those technologies.
3. How We Use Your Information
We use Personal Information only for the purposes described in this Privacy Policy or as otherwise disclosed to you at the time of collection.
| Purpose | Examples |
|---|---|
| Provide and manage services | Create accounts, schedule services, allocate workers, manage checklists, record attendance, validate check-in/check-out through geofencing, generate invoices |
| Communicate with you | Send service confirmations, reminders, status updates, and support messages via push notification, email, or SMS |
| Facilitate payments and commissions | Generate invoices for Clients, Partner Companies, and CleanSync commissions; record payment method preferences. CleanSync does not process or hold Client payments. |
| Ensure safety and quality | Verify worker presence at the property, review service photos, investigate incidents, and resolve disputes |
| Comply with legal obligations | Respond to lawful requests, meet tax and accounting record-keeping requirements, report security incidents |
| Protect the Platform | Authenticate users, enforce access controls, detect fraud, maintain audit logs, and monitor security |
| Marketing (with consent) | Send promotional communications only if you opt in. Marketing consent is collected separately and defaults to off. |
We do not sell your Personal Information. We do not use Personal Information for behavioural advertising or automated profiling in the current version of the Platform.
4. Legal Basis and Consent
Under PIPEDA, we generally rely on meaningful consent as the legal basis for collecting, using, and disclosing Personal Information.
When you register, we ask you to confirm that you have read and agree to our Terms of Use and this Privacy Policy. Depending on your role and app, we may also ask for specific consents, including:
- Consent to receive marketing communications (optional; default off)
- Consent for location services during check-in/check-out (Workers)
- Consent for camera access to capture service photos and selfies (Workers and Clients)
- Consent to receive push notifications (all users)
You may withdraw your consent at any time through the Privacy Settings in the app or by contacting us at cleansync@drumblow.com. Withdrawing consent may affect your ability to use certain features. For example, without location consent, a Worker may be required to submit a manual check-in with a reason, subject to manager approval.
5. Sharing and Disclosure of Information
5.1 Sharing Between Users
The Platform is designed to share limited information among the parties involved in delivering a cleaning service:
- Clients: can see their own properties, service details, quotes, invoices, service photos, and ratings.
- Partner Companies / Managers: can see client and property information, worker schedules, attendance records (including GPS coordinates), service photos, and invoices related to their own business.
- Workers: can see service assignments, property access instructions, house rules, and checklists for the services to which they are assigned. Workers can see only the photos they or their team members have uploaded.
5.2 Service Providers and Sub-processors
We use the following Sub-processors to operate the Platform. Each is contractually required to protect Personal Information in a manner consistent with this Privacy Policy and applicable Canadian privacy laws.
| Sub-processor | Service | Location / Data Handling |
|---|---|---|
| Oracle Cloud | Cloud infrastructure and hosting (PostgreSQL, Redis, VM) | Canada (primary production region) |
| Firebase / Google | Push notifications (FCM) and, where used, social authentication | United States (data may be processed outside Canada) |
| Brevo | Transactional and marketing email delivery | European Union / international |
| Cloudinary | Storage, processing, and delivery of photos and PDF invoices | United States / international CDN |
| Google Maps API | Address geocoding and map display | United States / international |
| Sentry | Error and crash reporting with PII stripped | United States |
| Vercel | Hosting of public marketing pages and legal documents | United States |
We may update this list from time to time. We will notify users of material changes through the Platform or by email.
5.3 International Transfers
Some Sub-processors process data outside Canada, including in the United States and the European Union. Where Personal Information is transferred outside Canada, we rely on contractual safeguards (such as data processing addenda and, where applicable, Standard Contractual Clauses) to ensure an adequate level of protection.
5.4 Legal and Safety Disclosures
We may disclose Personal Information:
- When required by law, court order, subpoena, or other legal process;
- To government or law enforcement agencies when necessary to protect our rights, property, or safety, or the rights, property, or safety of others;
- In connection with a merger, acquisition, financing, or sale of all or part of our business, subject to confidentiality obligations.
6. Your Privacy Rights
Under PIPEDA and applicable Ontario law, you have the following rights:
6.1 Right to Access
You may request access to the Personal Information we hold about you. The Platform provides a self-service data export through Settings → Privacy → Export My Data or via the API endpoint GET /api/v1/me/data-export.
6.2 Right to Correction
You may request correction of inaccurate or incomplete Personal Information. You can update much of your profile directly in the app. For other requests, contact us at cleansync@drumblow.com.
6.3 Right to Withdraw Consent
You may withdraw consent for optional processing (such as marketing, push notifications, or location services) at any time through the app's Privacy Settings or by contacting us.
6.4 Right to Delete Your Account
You may request deletion of your account through Settings → Privacy → Delete Account or by contacting us. We will anonymize or delete your Personal Information within 30 days, except where retention is required by law (for example, tax or accounting records).
6.5 Right to Complain
If you believe we have not handled your Personal Information appropriately, you may file a complaint with:
- CleanSync Privacy Officer at cleansync@drumblow.com
- Office of the Privacy Commissioner of Canada (OPC) at www.priv.gc.ca or 1-800-282-1376
- Information and Privacy Commissioner of Ontario (IPC) at www.ipc.on.ca if your complaint relates to personal health information
6.6 Response Time
We will respond to access and correction requests within 30 calendar days of receipt. In limited circumstances, we may extend this period by an additional 30 days and will notify you of the reason and your right to complain to the OPC. We generally do not charge a fee for these requests; if a fee is necessary, we will provide an estimate in advance.
7. Security
We implement technical, organizational, and physical safeguards appropriate to the sensitivity of the information we hold, including:
- Encryption in transit using TLS 1.3
- Encryption at rest for databases and backups
- Role-based access control (RBAC) restricting access to information based on user role and company affiliation
- Signed URLs with expiration for access to photos and PDF invoices
- Bcrypt hashing for passwords
- Audit logging of sensitive actions (for example, login, account deletion, check-ins, photo uploads)
- PII stripping before error reports are sent to Sentry
No method of transmission or storage is completely secure. If you have reason to believe your interaction with us is no longer secure, please contact us immediately.
8. Data Retention
We retain Personal Information only as long as necessary for the purposes described in this Privacy Policy or as required by law.
| Data Category | Retention Period | Action After Period |
|---|---|---|
| Active account data | During the life of your account | Retain |
| Deleted account data | 30 days after account deletion | Permanently delete or anonymize |
| GPS / attendance location data | 30 days after the service | Delete |
| Service photos (before/after) | 90 days after the service (configurable by Partner Company) | Delete |
| Invoices and billing records | 7 years, as required by the Canada Revenue Agency (CRA) | Retain in encrypted archive |
| Security audit logs | 1 year | Delete |
| Operational logs and notifications | 90 days | Delete |
| Device tokens | Until you uninstall the app, revoke permission, or delete your account | Delete |
9. PHIPA and Health-Related Information
Some information that Clients choose to provide in "house rules" or access instructions may constitute personal health information under PHIPA (for example, allergies, asthma triggers, chemical sensitivities, or mobility limitations).
If you provide health-related information:
- We will treat it as sensitive information;
- We will share it only with the Partner Company and Workers assigned to your service, to the extent necessary to perform the service safely;
- We will retain it only for as long as necessary and in accordance with our retention schedule;
- Workers and Partner Companies are required to keep this information confidential and to use it only for the purpose of delivering the cleaning service.
If you are a Worker or Manager, you must not disclose a Client's health-related information to any unauthorized person.
10. Children's Privacy
The Platform is not directed to individuals under the age of 18. We do not knowingly collect Personal Information from children under 13. If we learn that we have collected Personal Information from a child under 13 without verifiable parental consent, we will delete that information promptly.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Platform or by email at least 30 days before the changes take effect, unless a shorter notice period is required by law. The "Last updated" date at the top of this policy indicates when the policy was most recently revised.
12. Contact Us
For questions, concerns, or requests related to this Privacy Policy or our privacy practices, please contact:
CleanSync Privacy Officer
Email: cleansync@drumblow.com
Address: Sarnia, Ontario, Canada
CleanSync Premium — Privacy Policy (Draft)