Download the app

Privacy policy

In force since 4 August 2026.

This is a translation of the French original. In the event of any discrepancy, the French version prevails.

JL CAPITAL, a French limited liability company (SARL) with share capital of €1,000, registered with the Bordeaux Trade and Companies Register under number 993 098 920, with its registered office at 3 place Léon Duguit, 33800 Bordeaux, France, is the controller for the processing described below as regards the operation of the Service, its billing and its security.

For the data a Manager records about its properties, its Cleaners and its guests, THE MANAGER is the controller: we act as processor, on its instructions alone, under article 28 of the GDPR.

The agreement governing that processing is published on the website, on the "Data processing" page. It applies automatically, with no separate signature.

Any request about your data is made through the contact form on the website or in-app support.

1. What we collect

ACCOUNT: first and last name, phone number, e-mail address, password (hashed, never readable), language, profile photo if you add one, role, company and business address if you provide them.

PROPERTIES AND ORGANISATION: property names and addresses, street photo, number of guests, time slots, checklists, stock, thresholds, access codes and instructions, notes.

CLEANINGS AND PROOF: dates, actual durations, status, property condition rated out of 5, photos and videos taken in the application, with our server timestamp, a SHA-256 fingerprint and, if the device allows it, the location at check-in.

EXCHANGES: messages between members of the same organisation, reported incidents, conversations with support.

MATCHING: for a Cleaner who turns on "Find work", their address and the geographic coordinates calculated from it, their working radius, their first name, their photo and the number of cleanings they have completed. Before acceptance, a Manager sees neither the address nor the phone number, only a distance.

PAYMENT: Stripe customer identifier, last four digits and card brand, invoice history. NO card data passes through or is stored on our servers.

REFERRALS: referred accounts, amounts, and for payment: IBAN, account holder, and where applicable company, registration number and address.

TECHNICAL: sign-in and function call logs, IP address, device and browser type, notification tokens, session identifiers.

TRACKERS: see article 7.

2. Why, and on what basis

PERFORMANCE OF THE CONTRACT (article 6.1.b): creating and maintaining the account, scheduling cleanings, running checklists, stock, access codes, proof and messaging, managing the subscription, collecting payment, issuing invoices, paying referral rewards, providing support.

LEGITIMATE INTEREST (article 6.1.f): securing the Service and preventing fraud, in particular referral fraud; measuring usage to improve the product; defending our rights in the event of a dispute. You may object to this processing on grounds relating to your particular situation.

LEGAL OBLIGATION (article 6.1.c): retention of accounting and tax records, response to lawful requisitions.

CONSENT (article 6.1.a): non-exempt audience measurement and advertising trackers, unsolicited marketing communications, access to location and notifications on your device. Consent may be withdrawn at any time, as easily as it was given.

We do not use your data to train artificial intelligence models, and we do not sell it.

3. How long

Account and profile: for the term of the contract, then three years from the last contact, so that the relationship can be resumed; then deletion or anonymisation.

Inactive account: deleted after three years without a sign-in, following prior notice.

Properties, checklists, stock, access codes: for the term of the contract, then ninety days after termination, then deletion.

Cleanings and photo or video proof: a rolling twenty-four months, the period during which a dispute remains plausible; beyond that, deletion, save for an ongoing dispute or a retention obligation.

Messages and support conversations: three years from the last exchange.

Invoices and accounting records: ten years, under article L123-22 of the French Commercial Code.

Referrals: proof of payment ten years (accounting); IBAN and bank details deleted thirteen months after the last transfer.

Technical and security logs: twelve months.

Proof of consent to trackers: six months; tracker lifetime: thirteen months at most; audience data from trackers: twenty-five months at most.

A Cleaner’s location: the calculated coordinates are deleted as soon as "Find work" is turned off. The location recorded at check-in follows the fate of the cleaning it belongs to.

Messages from the website contact form: three years.

4. Who has access

Internally, only authorised people, for what their role requires, and under a confidentiality undertaking.

Within your organisation, access follows the roles described in the terms of use: a team manager only sees their scope, a Cleaner only their cleanings.

Our processors, each bound by a contract compliant with article 28 of the GDPR: Google Ireland Limited (Firebase and Google Cloud: hosting, database, file storage, notifications, data stored in the European Union); Google Ireland Limited (Google Maps Platform: address geocoding and street photo); Stripe Payments Europe, Ltd. (payment, invoicing, VAT calculation); Resend, Inc. (transactional e-mail delivery); Anthropic PBC (support: the content of a support conversation is sent to produce a suggested reply and to translate it; it is not used to train models); Meta Platforms Ireland Ltd. and Google Ireland Limited (audience measurement and advertising, only after consent).

Administrative or judicial authorities, on a lawful requisition.

5. Transfers outside the European Union

Hosting and storage take place in the European Union. Some processors may nevertheless access data from the United States (Stripe, Resend, Anthropic, Meta, Google). Those transfers are governed by the European Commission standard contractual clauses and, where applicable, by the organisation’s certification under the EU-US Data Privacy Framework, supplemented by technical measures (encryption in transit and at rest, minimisation).

6. Security

Exchanges are encrypted in transit, data at rest. Integration secrets (property management software credentials) are encrypted with AES-256-GCM using a key held outside the database.

Access to every piece of information is checked ON THE SERVER, on every read: it is not the application that decides what you are allowed to see. Passwords are hashed and are never readable, including by us.

In the event of a data breach likely to create a risk to your rights, we notify the French data protection authority within seventy-two hours and inform you without delay where the risk is high.

7. Cookies and trackers

NECESSARY TRACKERS, set without consent: session and authentication, language preference, security and fraud prevention, and remembering your choice about trackers.

AUDIENCE MEASUREMENT AND ADVERTISING, set AFTER your consent: Google Tag Manager, which orchestrates the tags; Google Analytics 4, to understand how the site is used; Google Ads and the Meta pixel (Facebook, Instagram), including its server-side conversions interface, to measure how well our advertising works and to build audiences. These tools may set identifiers and send browsing data to their publishers, who also process it on their own account, as joint or independent controllers depending on the case.

You choose the first time the site is displayed, refusing being as simple as accepting, and you can change your mind at any time from the tracker management link in the footer. Refusing does not prevent you from using the Service.

Your browser also lets you block or erase trackers that have already been set.

8. Automated decisions

The Service takes no decision producing legal effects concerning you on the sole basis of automated processing. The automated assistant in the messaging system suggests replies; it decides neither a suspension, nor a refusal, nor a payment.

9. Your rights

You have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to give directions about what happens to your data after your death.

These rights are exercised through the contact form on the website or in-app support. We reply within one month, extendable by two months if the request is complex, and may ask for proof of identity in case of reasonable doubt.

If the request concerns data recorded by a Manager (your cleanings, your proof, your exchanges within its organisation), we forward it to that Manager, who is the controller.

You may lodge a complaint with the French data protection authority, CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, cnil.fr, or with the supervisory authority of your country of residence.

10. Minors

The Service is not intended for and is not offered to minors under sixteen. An account created in breach of this rule is deleted as soon as we become aware of it.

11. Changes

This policy may change. Any substantial change is brought to your attention in the application or by e-mail, at least thirty days before it takes effect where the change requires it.