CleanItAll is a product of Just Sanity Limited, registered in England and Wales, company number 11870564 ("we", "us"). This notice covers the CleanItAll app at app.cleanitall.io, its customer portal and API, and this website.
Who is responsible for what
Two different things happen in CleanItAll, and keeping them apart matters because your rights differ in each case.
Your own account. When you sign up, we decide how your name, email address and business details are used. For that information Just Sanity Limited is the data controller. The same goes for the logins of team members you invite.
Your customers' records. When you add a customer to your round, you decide what goes in and what it is used for: their name, address and phone number, the price, the note about the side gate. For those records you are the controller and we are your processor. We handle them on your instructions and not for our own purposes. That includes your customers' own use of the customer portal to pay, book holidays or ask for a quote.
If you are a customer of a cleaning business that uses CleanItAll, that business is responsible for your details. Ask them first, and we will help them answer you.
What we collect
When you sign up: your name, email address and a password. Your password is hashed with bcrypt, which stores it in a form that cannot be read back, including by us. If you sign in with Google instead, Google gives us your name, email address and profile picture.
When you set up your business: the business details you enter, such as its name, phone number, email address, logo and VAT number, and the settings for your invoices and payments.
When you run your round in it: your customers' names, addresses, phone numbers and email addresses; the price, cycle and notes for each property, including any access details you choose to record; jobs, photos and checklists; quotes, invoices, payments and balances; and the emails and texts you send through the app.
When you use the service: each sign-in attempt is recorded with the IP address and browser it came from, so that repeated failures can be locked out. Calls to the API are logged with the IP address that made them. If something goes wrong in the app, an error report is sent so we can find and fix it (see Sentry below).
We never receive or store card details. Card payments are taken on pages hosted by Stripe, or on a Stripe card reader, and the card details go straight to Stripe. Bank details for a Direct Debit are entered on GoCardless's own pages and go straight to GoCardless.
Why we handle it, and on what legal basis
- To provide the service you signed up for: your round, your customers, invoicing, payments and messages. Basis: performance of a contract.
- To send the emails the service depends on, such as confirming your address and resetting your password. Basis: performance of a contract.
- To bill you for your plan and keep financial records. Basis: performance of a contract, and legal obligation for the records we must keep.
- To keep the service secure and working, including sign-in lockouts, logs and error reports. Basis: our legitimate interest in a service that works and is not abused.
This website uses no analytics and sets no cookies. The cookie notice lists what the app stores on your device.
Who else sees it
We use the following providers. Each receives only what it needs to do its job, and several only come into play when you connect your own account with them.
- Our hosting provider, which runs the servers CleanItAll is served from: Vultr (The Constant Company, LLC), in London.
- Stripe, to bill you for your plan and, when you connect your own Stripe account, to take card payments from your customers. Those payments go to your Stripe account, not to us.
- GoCardless, when you connect your GoCardless account to collect Direct Debits. The customer and payment details a mandate or a payment needs go to GoCardless under your account.
- Twilio, when you connect your Twilio account for texts and WhatsApp. Messages, and the numbers they go to, pass through your own Twilio account. If you buy text credits from us instead, campaign texts sent on them go through our own Twilio account, with the same details.
- Google, for the maps and address search in the app, which receive the addresses you look up and view; for "Sign in with Google" if you use it; and for reading a Gmail inbox if you connect one (see Gmail).
- Microsoft, if you connect an Outlook or Microsoft 365 inbox.
- Email. Invoices, reminders and statements to your customers go out through your own mail server if you set one up in the app, and otherwise through ours: our own mail server, on the same host as the app.
- Xero, QuickBooks (Intuit) or Sage, only if you connect one. Your invoices, payments and the customer details on them are sent to your accounting software.
- HMRC, only if you connect Making Tax Digital for VAT. Each return you submit sends your VAT registration number, the figures on the return and the technical details HMRC's fraud prevention rules require.
- Sentry, in its EU region, for error reports from the app. A report can include your account identifier, the page you were on and what the browser was doing. It does not record replays of your screen.
- Your browser's push service (run by Google, Mozilla or Apple, depending on the browser), if you allow the app to send you notifications.
We do not sell personal data, and we do not share it for advertising.
Accounts you connect
None of the connections below is switched on unless you set it up yourself. The passwords, keys and tokens they need are stored encrypted. You can disconnect any of them from the app's settings, and you can also withdraw access from the provider's side at any time. Disconnecting Twilio deletes your Twilio credentials from CleanItAll.
Gmail
What we access. When you connect a Gmail inbox, Google asks you to let CleanItAll read your email and see your email address and basic profile. We cannot send, change or delete mail through that permission.
How we use it. CleanItAll checks the inbox and copies new messages into your CleanItAll inbox: the sender, recipients, subject, body and attachments. It does this so that an email from a customer can be matched to their record.
Sharing. We do not share data received from Google with anyone. We do not sell it, use it for advertising, or use it to develop, improve or train artificial intelligence or machine learning models. No one at CleanItAll reads it unless you ask us to in order to help you, it is needed for security, or the law requires it.
Removing access. Removing the inbox in CleanItAll deletes its stored credentials and every message copied from it. You can also remove CleanItAll from your Google Account at any time, under myaccount.google.com/permissions.
CleanItAll's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Outlook and Microsoft 365
When you connect a Microsoft inbox, Microsoft asks you to let CleanItAll read your mail and know your name and email address. We use that access only to copy new messages into your CleanItAll inbox, as for Gmail above, and we do not share Microsoft mailbox data with anyone, sell it, use it for advertising or use it to train artificial intelligence models. Removing the inbox in CleanItAll deletes its credentials and the messages copied from it.
Payments, accounts and tax
Connecting Stripe, GoCardless, Xero, QuickBooks, Sage or HMRC lets CleanItAll act on that account for you: taking payments into it, sending invoices and payments to your books, or submitting a VAT return you have checked. CleanItAll stores the tokens each provider issues, encrypted, and uses them only for those jobs.
Your customers' details
Where we act as your processor, we handle your customers' details only to run CleanItAll for you, under the data processing terms in our terms of service. We use only the providers listed above, help you answer a customer who asks to see, correct or delete their details, and tell you without undue delay if we become aware of a breach that affects them.
So that your round works without signal, the app keeps a copy of your jobs, customers and invoices on your phone or computer. That copy is on your device, under your control. The cookie notice explains what is kept and how to remove it.
How long we keep it
Your account details: for as long as the account is open. After you close it, for 30 days, in case you change your mind; then it is deleted, apart from financial records we are required to keep for longer.
Your customers' records: for as long as your account is open, so your history is there when you need it. After you close your account, they are kept for 30 days with the account, then deleted, with their photos, files and copied emails. You can delete a customer, or ask us to delete everything, sooner.
Sign-in records, logs and error reports: sign-in records and our server and API logs are kept for 90 days, long enough to look into a break-in, then deleted. Error reports in Sentry are kept for 30 days.
Where it is held
CleanItAll's servers are in the United Kingdom, in London. Photos and files you upload are stored on those servers, not with a separate storage provider. Some of the providers listed above process data outside the UK. Where they do, those transfers rely on the safeguards UK data protection law requires, such as adequacy regulations or the international data transfer agreement.
How it is protected
Every connection to the app is made over HTTPS. Passwords are hashed and cannot be read back. Repeated failed sign-ins lock the account for a while. The credentials for the accounts you connect are stored encrypted.
Your rights
Under UK data protection law you can ask us to:
- give you a copy of the personal data we hold about you;
- correct anything that is wrong;
- delete it, where we have no continuing reason to keep it;
- restrict or object to how we use it;
- provide it in a portable format;
- stop relying on legitimate interests, where you object and we have no overriding grounds.
Email privacy@cleanitall.io and we will respond within one month. Our registered office is shown on the Companies House register.
If you are unhappy with how we have handled your information you can complain to the Information Commissioner's Office at ico.org.uk, though we would rather you raised it with us first so we can put it right.
Changes to this notice
If we change how we handle personal data we will update this page and the date at the top. Where a change materially affects you, we will tell account holders directly rather than rely on you to notice.