Skip to main content

Privacy Policy

Last updated: August 2026 · Governed by Canadian federal law (PIPEDA)

1. Who we are and our Privacy Officer

CleanConnect PRO ("we", "us", "our") is a Canadian online marketplace that connects property owners and commercial clients with independent cleaning professionals and cleaning businesses. We are operated from Canada and comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and all applicable provincial privacy laws.

Privacy Officer: The individual responsible for overseeing compliance with this Privacy Policy and Canadian privacy law can be reached at:

Privacy Officer, CleanConnect PRO
Email: privacy@cleanconnectpro.com

General support inquiries: support@cleanconnectpro.com

2. Information we collect

Account information — all users

  • Full name, email address, phone number, city and province
  • Role on the platform (property owner or cleaner/business account)
  • Password (stored as a bcrypt hash — never readable by platform staff)
  • Profile photo (optional)

Property owners only

  • Property addresses, property type, bedroom and bathroom count, square footage
  • Access notes (lockbox codes, entry instructions, buzz codes) — part of your property record, disclosed to the assigned cleaner only on the day of service; the cleaner's access ends when the job completes (see Section 5)
  • iCalendar (iCal) URL from Airbnb, VRBO, or other short-term rental platforms (optional, for auto-scheduling)
  • Stripe Customer ID (we never store full card numbers or CVV codes)
  • Preferred cleaner designations and block lists

Quote requests — people who do not have an account

You can ask us what cleaning your space should cost at /quote without creating an account. If you do, we collect only what is needed to answer you:

  • Business name, your name, email address, and phone number if you choose to give one
  • City and, optionally, postal code. We do not ask for the full street address — that is needed only if you decide to go ahead
  • What kind of space it is, roughly how big, how often you need it cleaned, and anything you tell us in the notes
  • The price range we showed you and the exact wording we showed it in, so that our written quote can be checked against what you were told
  • A one-way hashed form of your IP address, used only to stop automated abuse of the form. We do not store the address itself

Purpose: answering your request, and nothing else. Asking us a question is not consent to marketing, and a quote request never adds you to a mailing list (see Section 14). If you do not go on to create an account, we keep the request for 24 months so we can honour a quote you come back to, and then delete it. You can ask us to delete it sooner at any time — see Section 10.

Cleaners and business account holders only

  • Business or company name, years of experience, bio, service types, service city
  • Stripe Express Account ID (links to your Stripe account — we do not hold your bank details)
  • On-call availability preference
  • Credentials self-reported on your profile: insurance coverage level, bonding status, certifications, equipment, Google Maps URL, website, social media URLs
  • Credential documents you upload — certificates of insurance, bonding certificates, and WSIB clearance certificates, together with the issuer, coverage amount and expiry date shown on them. Purpose: verifying the credentials displayed on your public profile. These documents are stored privately and are visible only to you and Platform administrators — never to clients, who see only the verified fact and its expiry. They are retained while the credential is displayed and for 24 months afterwards for audit, and are deleted when you delete your account.
  • Internal capability level (Levels 1–3) and trust score derived from profile credentials and platform track record. This level sets how many cleans you may hold at once and your directory placement; it is not shown to clients
  • GPS check-in location data — a single location captured when you start a job (and when unlocking property access details). Purpose: confirming the assigned cleaner arrived at the correct property (job verification) and providing evidence in dispute resolution. This check-in point is never used for advertising or profiling, and is kept for no purpose beyond confirming job attendance and disputes.
  • In-job live location — while a job is in progress, your device's location for the safety tools described in “Location data — Cleaners and Team Members on shift” below. This is separate from the single check-in point above: it updates while you are working, we keep only the most recent point and no history, and it is erased when the job is completed or cancelled. It is never collected when you are not working a job.
  • Job-start selfie — see Section 7 below for full disclosure
  • Background check status — see Section 8 below for full disclosure
  • Work portfolio photos (optional, uploaded voluntarily to public profile)
  • Public directory listing — cleaner profiles (name, city, bio, credentials, ratings, portfolio) appear in the public cleaner directory by default. You may opt out of the directory at any time in your settings; opted-out profiles are not publicly accessible.

Team Members (Worker accounts)

If a Business Account Holder adds you as a Team Member, the following information is collected about you on the Platform at the Business Account Holder's direction:

  • Full name and email address
  • Identity verification materials submitted for Platform verification
  • Background check status (Approved/Not Approved) — see Section 8
  • GPS check-in and check-out data for each assigned job
  • In-job live location while an assigned job is in progress, for the safety tools described below — most recent point only, erased when the job ends
  • Job-start selfie for each assigned job
  • Checklist completion records and photos for assigned jobs
  • In-platform communications on assigned jobs
  • Job assignment history and performance flags

All data collected in relation to a Team Member profile is retained permanently for audit, dispute, and legal purposes, even after removal from a business account. This is a legal necessity — job evidence cannot be retroactively destroyed after disputes or legal proceedings are initiated. Team Members have PIPEDA access and correction rights over their own personal information — contact us directly, not through the business account holder.

Job and transaction data — all users

  • Job details: title, date, checklist items, status history, timestamps
  • Messages between parties through in-platform chat
  • Photos uploaded as part of checklist completion, problem reports, or arrival condition documentation
  • Payment amounts, platform fees, HST, payout records, T4A-reportable earnings
  • Dispute records and resolution outcomes, if any

Technical data

  • IP address and browser or device type (collected by Supabase and Hostinger infrastructure)
  • Session cookies (required for authentication — see Section 11 on Cookies)
  • Push notification permission status (stored locally on your device)
  • Signup referral tag — if you arrive through an invitation or campaign link, a short referral code is stored on your account so we know which outreach brought you to the Platform. It is never shared or used for advertising.

Location data — Cleaners and Team Members on shift

While a Cleaner or Team Member is working a job — from when they start the clean until it is marked complete or cancelled — we collect their device's location to show it to them, to the emergency contacts they choose to share it with, and to our team for safety response. We collect location only while a job is in progress, we keep only the most recent location, not a location history, and we stop — and erase the last point — when the job ends. Starting a clean turns this on; completing or cancelling the job turns it off. Sharing the location with contacts is off unless the cleaner turns it on. If you press the safety alert button, we also record that event and the location at that moment so our team and your contacts can respond. Location is never collected when you are not working a job, and is never collected from property Owners. This is separate from the one-time GPS check-in taken when a job starts (Section 6).

3. How we use your information

We use personal information only for the following purposes:

  • Operating the marketplace — matching owners with cleaners, facilitating job postings and claims
  • Processing, holding, and releasing payments securely via Stripe
  • Sending transactional notifications by email (via Resend), SMS (when enabled), and desktop push notifications — including job alerts, payment receipts, dispute updates, and account security alerts
  • Generating HST receipts for platform fees
  • Investigating and resolving disputes between parties
  • Detecting and preventing fraud, impersonation, and account abuse
  • Providing the optional cleaner safety tools — sharing your live location with contacts you choose while you are working a job, confirming a booking on the “I belong here” page, and, if you press the safety alert, texting your contacts and alerting our team (these tools are aids, not an emergency-response service — see the Terms)
  • Administering the internal capability level system, based on your self-reported business details and platform track record
  • Reviewing credential documents you upload (liability insurance, bonding, WSIB clearance) so that the fact and expiry date — never the document itself — can be shown to clients
  • Issuing T4A slips to account holders who earn $500 or more in a calendar year, as required by the Canada Revenue Agency
  • Complying with applicable Canadian law and responding to valid legal requests

We do not sell your personal information. We do not use your data for advertising or third-party marketing. We do not profile you for purposes beyond platform safety and job integrity.

4. Third-party service providers

We share limited personal information with the following service providers:

ProviderPurposeData sharedLocation
SupabaseDatabase, authentication, file storage, and real-time subscriptionsAll user and job data, stored files (photos, documents)USA
StripePayment processing and cleaner/business payout managementName, email, payment details, Stripe account identifiersUSA
ResendTransactional email deliveryName, email address, job-related notification contentUSA
HostingerWeb hosting and application deliveryIP address, server request logsVarious
CertnCriminal-record background checks (not identity confirmation — see Stripe Identity below)Name, date of birth, government ID particulars, consent documentationCanada / USA
Stripe IdentityConfirming a Cleaner's identity before their first job (the “ID check”). Separate from payments, and separate from the criminal-record check above.A photograph of your government ID and a selfie taken at the same time, captured and held by Stripe. The Platform receives only a status and a session reference — it never receives or stores the document or the selfie.USA
Google Identity Services“Continue with Google” sign-in and sign-up, when you choose itYour Google account email and name, returned to us as a sign-in token. Loaded only on the sign-in and sign-up pages.USA
TwilioSMS delivery (transactional job alerts, phone sign-in codes, and cleaner safety texts — the live-shift link and safety-alert messages)Phone number and message content. For safety texts, the emergency contact phone numbers a Cleaner saves and the safety message sent to them.USA
Google Maps PlatformAddress geocoding (converting property addresses to map coordinates for proximity checks)Property street addresses and cities (no names attached to geocoding requests)USA
OpenStreetMapDisplaying the live map on the “Share My Shift” page a Cleaner's contacts openThe approximate map coordinates of the Cleaner's current location, sent from the viewer's browser to load the map tiles. No name or account data.Various (EU/UK)
AnthropicAI features — the Spritz assistant and AI checklist generationMessages you send to the assistant; property/job descriptions used to generate checklists. Not used to train AI models.USA

All providers are bound by data processing agreements that require them to protect your personal information in accordance with PIPEDA standards. Where data is transferred to providers in the United States, we rely on contractual protections (standard data processing agreements containing data protection clauses) as the mechanism for cross-border transfer under PIPEDA Principle 7. You acknowledge that data stored with US-based providers is subject to US law, including applicable law enforcement access provisions.

We do not share your personal information with any other third party except as required by valid Canadian law, court order, or law enforcement request.

5. Property addresses and access notes

Property information is disclosed in stages based on the 3-stage reveal system described in the Terms of Use: city and neighbourhood at the marketplace browse stage; street name only (no house or unit number) at the time of job claim; and the full address, unit or lot number, lockbox codes, and access notes only to the assigned cleaner on the day of service — access notes additionally require the cleaner to be physically near the property where location can be verified.

How access notes are protected:access notes are part of the Owner's property record and are retained while the property exists — they are the Owner's own data, reused for future jobs, and are deleted when the Owner edits them or deletes the property or account (plus a limited backup-retention period). What is strictly time-boxed is the cleaner's access: notes are released server-side only on the day of service, are never embedded in web pages ahead of time, and access ends automatically when the job completes or the cleaner is replaced. Every release is logged, and a release that cannot be location-verified is flagged to the Owner immediately. Owners are advised to change access codes if they have any security concerns after a job is completed.

6. Payment data

We do not store credit card numbers, CVV codes, or full banking details at any point. All payment data is handled directly by Stripe. We store only:

  • Stripe Payment Intent IDs (reference numbers used to track transaction status)
  • Payment amounts, platform fees, HST calculations, and payout records
  • Your Stripe Customer ID (property owners) or Stripe Express Account ID (cleaners and business accounts)

7. Photos and job-start selfies

Job photos (checklist, before/after, problem reports)

Photos uploaded through the Platform in connection with a job — including checklist before/after photos, arrival condition documentation, and problem reports — are stored in Supabase Storage. They are accessible only to the Owner and the assigned Cleaner or Business Account Holder for that job, and to Platform administrators for dispute resolution. We do not use property photos for advertising, marketing, or any purpose beyond facilitating the job.

Job-start selfies — purpose-specific consent

A job-start selfie is a photograph that a Cleaner or Team Member takes of themselves before entering the property at the start of each job. Job-start selfies are collected solely for:

  • Confirming that the verified, assigned person is the individual who arrived at and completed the job
  • Detecting and deterring impersonation, identity fraud, and unauthorized substitution (sending an unverified person under a verified account)
  • Providing verifiable, timestamped photographic evidence in dispute resolution proceedings

Job-start selfies are not used for facial recognition, biometric profiling, advertising, marketing, identity analysis outside of dispute or fraud review, or any purpose beyond those listed above.

Phase 2 — biometric facial comparison: The Platform may in the future introduce automated comparison of job-start selfies against stored profile photos to confirm the assigned person arrived. This capability constitutes biometric processing under applicable privacy law. It will not be activated without separate, express, informed consent from each affected Cleaner or Team Member at the time it is introduced. Biometric templates, if ever generated, would be deleted immediately after each comparison — they would not be retained as a standalone dataset. Your acceptance of this Privacy Policy does not constitute consent to biometric processing. Separate opt-in will be required.

8. Identity confirmation and background checks

These are two different checks, run by two different providers, and it is worth being precise about which is which.

Identity confirmation (the “ID check”) is handled by Stripe Identity. Before a Cleaner starts their first job they photograph a government ID and take a selfie at the same time; Stripe compares the two. That document and selfie are captured by and held with Stripe — the Platform never receives, views or stores them. What we receive back is a status (pending, verified or failed) and a session reference. This check confirms identity only. It is not a criminal-record check.

Criminal-record background checks are processed by Certn, a Canadian background check provider, and are required only for work inside a private residence. A check is initiated only after the person requests it, and their details and consent are collected directly through Certn's own secure form — the Platform never handles your SIN. Checks are conducted with the express consent of the person being checked, obtained at the time of the request.

What information is shared with Certn:

  • Full name, date of birth, and government identification particulars as provided by the person being checked
  • Your consent confirmation and timestamp

What the Platform receives back from Certn:

  • An outcome status: Approved or Not Approved
  • Certn's check completion confirmation

The underlying background check report — including any specific findings — is not received, stored, or viewed by the Platform. The Platform stores only the outcome status flag and the date of the check.

Business Account Holders who receive background check results for their Team Members receive the outcome status (Approved/Not Approved) only. They do not receive the underlying report, the reason for any denial, or any specific finding. Team Members may request a copy of their own background check result from Certn directly through Certn's privacy procedures.

Background check consent is specific to the purpose stated at the time it is obtained — it does not extend to any other use of your personal information, and it may not be re-used for a subsequent check without fresh consent.

9. Communications — email, SMS, and push notifications

The Platform uses the following channels to send communications to registered users:

  • Email — via Resend. Used for all transactional notifications (job alerts, payment receipts, dispute updates, account alerts, background check outcomes) and, with your separate consent, marketing communications.
  • SMS text messages — via SMS provider integration. Used to send time-sensitive transactional alerts for job events (job claimed, payment released, urgent job broadcast, on-call alert). SMS is used for transactional purposes only — no marketing SMS without separate consent.
  • Desktop push notifications — triggered through your browser's Notification API. Used for real-time job activity alerts when the Platform is open in your browser. Push notification permission is requested in your browser and can be revoked through your browser settings at any time. Push notification permission state is stored locally on your device only.

By creating an account, you consent to receive transactional communications through these channels for the purpose of operating your account and facilitating your use of the Platform. These communications are necessary for the Platform to function and cannot be individually opted out of while your account remains active.

See Section 14 below for CASL marketing consent and opt-out rights.

10. Your rights under PIPEDA

As a Canadian resident, you have the following rights regarding your personal information:

  • Access — request a copy of the personal information we hold about you. We will respond within 30 days of receiving a verifiable request.
  • Correction — ask us to correct inaccurate or incomplete information. Some corrections (such as job records) may be noted but not deleted where retention is legally required.
  • Withdrawal of consent — withdraw consent for any non-essential use of your personal information. Withdrawal does not affect previous lawful processing.
  • Deletion — request deletion of your account and associated personal information. Note that we may retain transaction records, payment history, and tax-related data for up to 7 years as required by the Canada Revenue Agency.
  • Complaint — if you are unsatisfied with our response, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada (see Section 20).

Team Members have all of the above rights over their own personal information independently of the Business Account Holder who added them. Contact us directly at privacy@cleanconnectpro.com.

We will respond to all rights requests within 30 days. For complex requests, we may extend this to 90 days with notice provided by day 30.

11. Cookies and tracking

We use one type of cookie: a session authentication cookie set by Supabase Auth when you log in. This cookie is strictly necessary to keep you authenticated during your session. It is deleted when you log out or when your session expires. We do not use advertising cookies, tracking pixels, cross-site trackers, or analytics cookies of any kind.

We do measure which pages are visited, and we do it ourselves. When you open a page we record the page address, the website that referred you (the site name only, never the full link), and any campaign tag in the address you arrived on. To tell one visit apart from the next, your browser holds a random number for as long as that tab stays open. It is not a cookie, it is erased the moment you close the tab, and it is never connected to your account.

We do not record your IP address, your device or browser details, or your identity, so these records cannot be traced back to you and are not personal information. Nothing is sent to any outside analytics company — there is no Google Analytics, no advertising network and no third-party tracker anywhere on this platform. The records are kept on our own systems, are visible only to us, and are deleted after 90 days.

12. Data retention

Data typeRetention periodReason
Account data (name, email, phone)Until account deletionOperational necessity
Job and message history3 years after job completionDispute fallback, T4A audit trail
Payment and transaction records7 yearsCRA requirement
Quote requests from people without an account24 monthsHonouring a quote you come back to; deleted automatically after that
Page-visit records (no IP, no device details, no identity)90 daysUnderstanding which pages are useful
Session and server logs90 daysSecurity and fraud detection
Checklist and job photos (no dispute)12 months after job verifiedPost-job dispute window + reasonable buffer
Job-start selfies12 months after job verifiedIdentity fraud detection and dispute evidence
GPS check-in and check-out data12 months after job completionAttendance verification and dispute evidence
In-job live locationOnly the most recent point, kept while a job is in progress; erased when the job is completed or cancelled. No location history is stored.Cleaner safety (live sharing) with minimal retention
Safety-alert (panic) records3 yearsResponding to and accounting for a safety incident
Emergency contacts a Cleaner savesUntil the Cleaner removes them or deletes their accountSo the safety tools can reach them
Access notes and lockbox codesPart of the property record — until the owner edits them or deletes the property/account, plus a limited backup-retention period. Cleaner access ends at job completion.Owner's own reusable property data; cleaner exposure strictly time-boxed
Dispute evidence packages (photos, GPS, selfies, messages)PermanentLegal proceedings, law enforcement referrals
Background check status — solo cleanersDuration of active account; deleted on account deletionPlatform eligibility gate
Background check status — Team Members24 months after removal from all business accountsLegal protection for business account holder in post-engagement disputes
Team Member job records and evidencePermanentCannot be retroactively destroyed after legal proceedings are initiated
Phase 2 biometric facial templates (if introduced)Deleted immediately after each comparisonMinimum retention — no standalone biometric dataset retained
T4A records7 yearsCRA requirement

Deleted data may persist in encrypted database backups for a limited additional period until those backups age out of rotation. Backups are not queried in normal operation and are used only for disaster recovery.

13. Cross-border data transfers

Your personal information may be stored and processed in the United States by our service providers (Supabase, Stripe, Resend). Under PIPEDA Principle 7, when personal information is transferred to a third party for processing, we remain responsible for protecting it with comparable standards to those we apply in Canada. We achieve this through:

  • Data processing agreements (DPAs) with each provider, incorporating data protection obligations
  • Service providers bound to use data only for the specific purpose disclosed in Section 4
  • Contractual requirements that providers notify us of any government access request

You acknowledge that data stored in the United States is subject to access by US law enforcement and intelligence agencies under applicable US laws (including the US CLOUD Act), which may provide different protections than Canadian law. If you have concerns about cross-border transfer, contact our Privacy Officer.

14. CASL and marketing communications

All commercial electronic messages sent by CleanConnect PRO comply with the Canadian Anti-Spam Legislation (CASL). We send marketing communications only with your express prior consent, obtained separately from your acceptance of these Terms.

You may withdraw consent for marketing communications at any time:

  • Email: use the unsubscribe link in any marketing email
  • SMS: reply STOP to any marketing text message
  • In writing: email support@cleanconnectpro.com

Opt-out requests are honoured immediately and permanently. We maintain a suppression list and will not re-add you to marketing communications after you opt out. Transactional communications (job notifications, payment receipts, account alerts) are not subject to CASL opt-out while your account remains active — they are necessary for the Platform to operate.

Quote requests. If you ask us for a quote at /quote, you have asked us a question and we reply to it. That reply, and any follow-up about that specific request, is the whole of what your enquiry permits — it does not add you to a marketing list, and we will not send you promotional messages on the strength of it.

15. Data breach notification

In the event of a breach of security safeguards affecting personal information that creates a real risk of significant harm to individuals, CleanConnect PRO will:

  • Report the breach to the Office of the Privacy Commissioner of Canada as soon as feasible
  • Notify all affected individuals directly by email as soon as feasible, containing the information required under PIPEDA's breach notification regulations
  • Maintain a breach record as required by law

We implement technical and organizational safeguards to protect personal information, including row-level security on our database, restricted access to sensitive data by system layer, encrypted data transmission (TLS), and access controls limiting which platform functions can read sensitive data such as access notes or background check materials. Access notes are subject to additional protection: they are released server-side only, only to the assigned cleaner on the day of service, with every release logged and cleaner access revoked at job completion.

16. Automated decisions

The Platform does not make automated decisions about users that produce legal effects or that significantly affect them without human review. Capability level is computed algorithmically from your self-reported business details and platform track record, but decisions with material consequences (e.g., a reduced level, suspension, removal from the platform) involve human review by Platform administrators. Credential documents are never assessed automatically — every insurance, bonding or WSIB certificate is opened and read by a Platform administrator, and there is no automated approval path. Background check outcomes are determined by our background check provider (Certn) in accordance with their process, and all denials are reviewed by Platform administrators before any access restriction is applied.

17. Children's privacy

CleanConnect PRO is not intended for users under 18 years of age. We do not knowingly collect personal information from minors. If you believe a minor has created an account or been added as a Team Member without parental consent, contact us immediately at privacy@cleanconnectpro.com and we will investigate and delete the information promptly.

18. Quebec Law 25 (Loi 25) — note for Quebec residents

Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25 (Act 25), imposes additional privacy obligations for personal information about Quebec residents, including enhanced transparency requirements, stricter consent standards, and expanded individual rights including the right to data portability.

We are committed to complying with Law 25 requirements as they apply to Quebec residents. If you are a Quebec resident and have questions about your rights under Law 25 or wish to exercise them, contact our Privacy Officer at privacy@cleanconnectpro.com.

19. Changes to this policy

We will post material changes to this Privacy Policy with an updated "Last updated" date. For changes that materially affect the way we collect, use, or share your personal information, we will notify all registered users by email at least 14 days before the change takes effect. Continued use of the Platform after the effective date constitutes your acceptance of the updated policy.

20. Contact and complaints

To exercise your privacy rights, ask questions about this policy, or report a privacy concern:

Privacy Officer, CleanConnect PRO
Email: privacy@cleanconnectpro.com

General support:
Email: support@cleanconnectpro.com
Website: cleanconnectpro.com

We will respond to all privacy requests within 30 days. If you are not satisfied with our response, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada:

Website: www.priv.gc.ca
Toll-free: 1-800-282-1376

Quebec residents may also contact the Commission d'accès à l'information du Québec (CAI):

Website: www.cai.gouv.qc.ca

© 2026 CleanConnect PRO · Questions? support@cleanconnectpro.com