Privacy Policy
Last updated 3 August 2026
CleanCut Pro is field-service management software for home-service businesses. This policy explains what personal information we handle, why, who we share it with, and what choices you have.
Who we are, and the two kinds of people in this policy
CleanCut Pro (“we”) provides software to home-service businesses. The distinction below matters, because our obligations differ:
- Our customers. The businesses that sign up, and their staff. We are the controller of their account information.
- Our customers’ clients. The homeowners and businesses our customers serve. Our customers enter that information; we store and process it on their behalf, as a processor. If you are one of those clients and want your information changed or deleted, contact the business you hired — they control it. We’ll help them action it.
What we collect
- Account details
- Your name, email address, and a hash of your password (we never store passwords in a readable form). Your business name, and any phone, email, website, and address you add.
- Client records
- Whatever our customers enter about their clients: names, addresses, phone numbers, email addresses, property details, and notes.
- Work records
- Requests, quotes, jobs, visits, invoices, payments, expenses, checklists, and notes — including any personal information typed into free-text fields.
- Photos and files
- Job-site photos and attachments uploaded from the web or mobile app. Note that photos can carry embedded camera metadata (including, on some devices, the location where the photo was taken). We do not read or use that metadata, but we do not strip it either — it is stored as part of the file.
- Timesheets
- Clock-in and clock-out times, the visit worked, optional notes, and approval status. No location is recorded when clocking in or out.
- Push notification tokens
- If you use the mobile app and enable notifications, a device token so we can deliver them.
- Reviews (optional)
- If a customer connects Google Business Profile, we store the reviews on that profile — including the reviewer’s public display name, rating, comment, and profile photo URL.
- Server logs
- Technical logs of requests and errors, which include IP addresses. Logged errors are written so they identify records by internal ID rather than by email address.
- Marketing enquiries
- If you request a demo, the name, email, and company you submit.
What we do not collect
We want to be specific rather than vague here, because these are common in field-service software and we do not do them:
- No device or GPS location tracking of staff — not during a shift, not in the background, not at clock-in.
- No third-party analytics, advertising, or tracking pixels. There is no Google Analytics, no advertising SDK, and no cross-site tracking in the web app or the mobile app.
- No card numbers. Payments are handled entirely by Stripe; card details are entered on Stripe’s systems and never reach ours.
- We do not sell personal information, and we do not share it for cross-context behavioural advertising.
Why we use it
- To provide the service — the whole product is storing and organising this information for our customers.
- To send transactional email on a customer’s behalf (quotes, invoices, payment reminders) and to their staff.
- To send marketing email that a customer chooses to send to their own clients, subject to the opt-out below.
- To take payment for subscriptions and to let customers take payment from their clients.
- To keep the service secure and working — rate limiting sign-in attempts, diagnosing errors, preventing abuse.
- To respond to support requests.
Where the GDPR applies, our lawful bases are performance of a contract (providing the service), legitimate interests (security, abuse prevention, service improvement), and consent where required (for example push notifications and marketing to prospects).
Cookies
We set one cookie: your sign-in session. It is strictly necessary — the application cannot keep you logged in without it. We do not use advertising, analytics, or tracking cookies, which is why you will not see a cookie consent banner.
Who we share it with
We use the following service providers. The first four are used for every account; the rest only apply if a customer chooses to connect them.
- Google Cloud
- Hosting and database (Cloud Run and Cloud SQL, in the United States). All application data is stored here.
- Stripe
- Subscription billing, and payment processing for our customers’ invoices. See Stripe’s privacy policy.
- Resend
- Outbound email delivery. Recipient addresses and message contents pass through this provider.
- Expo
- Push notification delivery to mobile devices, if notifications are enabled.
- Intuit QuickBooks (optional)
- If a customer connects QuickBooks, invoice, payment, customer, and service data is sent to their QuickBooks company.
- Google Business Profile (optional)
- If a customer connects their Google Business Profile, we read their reviews and can post replies they write.
We also disclose information where legally required, and to professional advisers or an acquirer in connection with a corporate transaction. We will not sell your data.
Where it is stored, and international transfers
Data is stored in the United States. If you are in the UK, EU, or elsewhere outside the US, using CleanCut Pro means your information is transferred to and processed in the US. Where required, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum) with our providers.
How long we keep it
We keep account and work records for as long as an account is active. If a subscription lapses, the account is locked but the data is retained so it is still there if the customer returns.
Account owners can delete the account and all of its data themselves, from Settings → Danger zone on the web or in the iOS app. Deletion is scheduled with a 30-day grace period: the account is disabled immediately, every account manager gets an email with a one-click restore link, and after 30 days everything is permanently erased — every client, quote, job, invoice, payment record, time entry, note, checklist, and uploaded photo. The CleanCut Pro subscription is canceled and connected QuickBooks, Google Business Profile, and Stripe authorizations are revoked. Before deleting, you can email yourself a JSON export of your business records from the same screen.
Team members who are not owners can remove their own access and login at any time, from the same place. That takes effect immediately and does not delete the business’s records — hours they logged stay with the business, no longer attributed to them.
Backups are retained for up to 14 days, so deleted data can persist in backups for that period before aging out. If you cannot sign in, email support@cleancutpro.io and we will handle the deletion for you.
Marketing email and opting out
Marketing email our customers send through CleanCut Pro — campaigns and review requests — includes an unsubscribe link. Using it stops all marketing email from that business immediately.
Opting out does not stop transactional messages you would reasonably expect about work you have commissioned: a quote you asked for, an invoice you owe, or a payment reminder. If you want those to stop, contact the business directly.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal information, to object to or restrict processing, and to withdraw consent. Residents of California and similar jurisdictions have the right to know what is collected and to delete it, and not to be discriminated against for exercising those rights.
To exercise any of these, email support@cleancutpro.io. If your information was entered by a business that uses CleanCut Pro, please contact that business — they decide what happens to it, and we will assist them. If you are in the EU or UK you also have the right to complain to your local data protection authority.
Security
Passwords are hashed with bcrypt. Traffic is encrypted in transit with TLS, and data is encrypted at rest by our hosting provider. Access to every record is scoped to the account that owns it, and sign-in attempts are rate limited. Credentials and API keys are held in a managed secret store, not in our source code. No system is perfectly secure, but if a breach affects your information we will notify you and any regulator as required by law.
Children
CleanCut Pro is business software and is not intended for anyone under 16. We do not knowingly collect information from children.
Changes
If we change this policy we will update the date at the top, and for material changes we will notify account owners by email.
Contact
Email support@cleancutpro.io with any question about this policy or your information. See also our Terms of Service.