Browse all guides
Your data and GDPR
You are holding personal data about your cleaners and about the people whose homes they go into. This is where that data sits, how to get it back out, and which obligations are yours rather than ours.
On this page
This guide describes what the product actually does with your data. It is not the legal document: the policy that governs it is at cleanflo.io/privacy, and the same text is inside the app under the Privacy link at the foot of the sidebar. Where the two disagree, the policy wins.
Where the data actually lives
Everything in CleanFlo sits in one Postgres database run by Supabase, on servers in the EU. Supabase is the primary data processor and operates under a data processing agreement. Database contents are encrypted at rest with AES-256, and everything between your browser and the server travels over TLS.
The separation between companies is enforced in the database rather than in the application. Every table carries a company id and every read is filtered through a row-level security policy tied to the account making the request. A query from your account cannot return another company's rows even if the front end asked it to, because the database refuses.
| What CleanFlo holds about a cleaner | What it does not hold |
|---|---|
| Name, email address, phone number | National Insurance number |
| Job title, whether they are active | Bank details for payroll |
| Their jobs, and photos taken on those jobs | DBS certificates |
| Their messages and reactions | Right-to-work documents |
| Location points captured against a job | Any movement history between jobs |
That last row is worth reading twice. Location points are held against the job record they belong to and are deleted with it. They are never retained separately, never aggregated across jobs, and never used to build a picture of where somebody went during their day.
Getting a copy of everything
The fourth tab of Settings is Data Export, and its subtitle names its purpose: "Download your data as CSV files. This fulfils your right to data portability under GDPR." Six tables, one button each, and one button underneath that does all six.
Manage your company and account
Exported files are in CSV format and can be opened in Excel, Google Sheets, or any spreadsheet application.
- A single table downloads as cleanflo_clients_2026-08-14.csv, dated so successive copies do not overwrite each other.
- All six together download as one file, cleanflo_export_2026-08-14.csv, with each table introduced by a comment line reading "# Clients (12)".
- The final toast counts the lot: "All data exported (243 rows across 6 tables)."
- An empty table says so rather than downloading nothing: "No clients to export."
That combined file is what to reach for if somebody asks you to hand over everything, whether that is a new system, an accountant, or a subject access request from a former cleaner. It is not the whole database: messages, health and safety records and inventory are not among the six tables, and those come out of their own screens.
If you stop paying
The important sentence first: nothing is deleted. A lapsed subscription pauses access. It does not remove a single job, invoice, client or message, and everything is exactly where you left it when you come back.
What you see instead of the app depends on why billing stopped, and each state names its own way out.
Cleaners see a different screen again. Theirs is headed Access Suspended and tells them the company's subscription needs attention and to contact their manager, because there is nothing they can do about it and nothing useful in telling them about a card.
Brennan Cleaning Ltd's subscription needs attention. Please contact your manager to restore access.
No price, no card and no way to pay: this is not the cleaner's bill to settle.
Deleting your account, and what gets kept
There is no delete-account button anywhere in CleanFlo. No danger zone on Settings, no self-service closure, no "type your company name to confirm". Deletion is an email to privacy@cleanflo.io, and it is answered within 30 days.
That is deliberate rather than an omission. An owner account can see every invoice, every staff record and every incident in the business, and a single misclick that destroyed all of it irreversibly would be an appalling thing to build. It is also not a decision anybody has to make in a hurry: cancel your subscription and the data waits.
Deletion is also not unconditional, because some of what CleanFlo holds you are legally required to keep. The retention periods in the policy are these.
| What | How long it is kept |
|---|---|
| Account data | Your subscription, plus 2 years after the account closes |
| Invoices and payment records | 7 years, in line with HMRC requirements |
| Health and safety incident reports | At least 3 years from the date of the incident |
| Staff and cleaner records | 2 years after deactivation, or until you ask for deletion |
| Job location points | Deleted with the job they belong to |
| Server logs and analytics | Up to 12 months |
So a request to erase everything will honour everything it can and hold back the financial records until the statutory period is up. That is the normal position for any business system and it is worth knowing before you promise a former employee that every trace of them has gone.
The bit that is yours, not ours
The word that matters is controller. CleanFlo and Supabase are processors: we hold and move data on your instruction. You are the controller of the personal data in your account, because you decided to collect it and you decide what happens to it. That means most of the obligations sit with you, and no software can take them off you.
Where CleanFlo helps is the mechanical part. A subject access request from a former cleaner is answerable from the Data Export tab plus their staff record, and a request from a client is answerable from the clients and locations exports. Neither takes long. What CleanFlo cannot do is decide your lawful basis, write your privacy notice, or hold the conversation with the ICO.
| Personal data | Where it lives | Who can see it |
|---|---|---|
| Cleaner name, phone, email | Staff record | Owner only |
| Job start and finish pointsCaptured when a job is started on the phone | Job verification | Owner only |
| Client contact name and email | Client record | Owner only |
| Home address and access notesKey safe codes, alarm codes, parking | Location record | Assigned cleaner |
| Photos taken at a job | Job record | Owner and cleaner |
| Incident reports naming a person | Health & Safety | Owner only |
Four habits worth having
Export at every quarter end
Press Export All Data when you do the VAT return and keep the dated file somewhere backed up. It costs a minute and it makes every other problem smaller.
Write access notes as if the client will read them
They are personal data about somebody's home, and they are visible to whichever cleaner is booked. "Key safe left of the porch, code on the job" is useful. Anything about the occupant that is not needed to clean the property should not be there at all.
Deactivate leavers on their last day
Not at the end of the month. Deactivation ends access immediately while keeping the record, so there is no reason to wait.
Keep one owner account per person
A shared login means you cannot tell who did what, and the activity feed becomes useless. Two owners is two accounts.
Common questions
Where is my data physically stored?
If I cancel, how long do I have to get my data out?
A former cleaner has asked for everything you hold on them. What do I do?
Can I delete a single client and everything about them?
Still stuck?
Open Support in the app and send us a ticket, or email the team. A real person reads every one.