BroomDesk
FeaturesPricingCompareBlogFree tools
Log inStart free trial

Privacy policy

Last updated August 12, 2026. This is our own document, written by the operator of BroomDesk. It is not legal advice from a law firm, and it is not a substitute for advice about your own business.

The short version

  • If you are a cleaning business using BroomDesk: we hold your account details, and we hold your clients' records on your behalf. Your clients' data is yours. We only touch it to run the service you asked for.
  • If you are the client of a cleaning business: your details are in that business's account. They decide what to keep and for how long. Ask them first, and we will help them answer you.
  • We do not sell data and we run no ad tracking. Page views on this website are counted with Plausible, which sets no cookie, stores nothing on your device and builds no profile of you.
  • Everything lives on servers in the United States, in the AWS us-east-1 region. For data from the EEA and the UK, standard contractual clauses cover the transfer.
  • Cancel and your data stays readable for at least 90 days so you can take it with you. Deletion after that is done by us on request, within 30 days of you asking. There is no automatic purge job in the product yet, and we would rather say so than describe one.
  • Records that prove someone agreed to receive texts are kept at least 5 years, because that is the evidence that protects everyone if a complaint is ever made.
  • To see, correct, export or delete your data, email support@broomdesk.com.

The summary is here to be read. The full text below is what applies.

1. Who is responsible for what

This is the part people get wrong, so it comes first. There are two different relationships in BroomDesk.

  • Your account with us. Your name, work email, phone number, business details, billing history and how you use the app. For this, Amortoae Petru PFA (CUI 52361814) is the controller. This policy describes what we do with it.
  • The records you put into the app. Your clients, their addresses and entry instructions, their message history, your workers, your job applicants. For this, you are the controller and we are your processor. We act on your instructions, which in practice means the settings you choose and the actions you take in the product. The terms are in the data processing addendum.

Practically: if you are a homeowner who got a text from a cleaning company, that company decides what happens to your data. Contact them. If they need us to act, we will.

2. What we collect

Account and billing data

Name, email address, phone number, business name, business address, role, and the plan you are on. Your password is handled by our authentication provider, Supabase, and stored as a hash. We never see it. Card numbers go straight to Stripe and never reach our servers. We hold the last four digits, the card brand and your payment history so the billing page can show them.

Records you enter or import

Client names, addresses, phone numbers, email addresses, property details, entry instructions and door codes, visit history, quotes, invoices and payments, photos taken on jobs, SMS and email threads, consent history, worker records including pay rates and clock-in locations, and job applicants. Entry instructions and door codes are encrypted with a separate application key before they are stored.

Data from your clients

When someone books through your widget or uses the client portal, we collect what the form asks for: contact details, service address, property details, the choices they made, and whether they ticked the marketing box. That goes into your account.

Usage, device and security data

Server logs from our hosting provider, including IP address, browser user agent, requested page and timestamps. Error reports through Sentry, configured so that personal data is not attached to events. Rate-limiting counters keyed on IP address, held briefly to stop password guessing and widget abuse. An audit log of significant actions inside your account, recording who did what, when, and from which IP.

Website analytics

The public pages of broomdesk.com load Plausible, which counts page views and the site that sent you. It runs for every visitor and is not behind the cookie banner, because it sets no cookie, stores nothing on your device, gives you no cross-site identifier and builds no profile. It is not loaded inside the app after you sign in. The cookie policy says the same thing in more detail.

What we do not collect

No advertising identifiers. No cross-site tracking. No advertising pixels, session recording or heatmaps of any kind. No background location: the cleaner app reads location only at the moment someone taps clock in or clock out, and only where the business has switched that on.

3. Why we are allowed to process it

Under the GDPR and the UK GDPR, our lawful bases for the data we control are:

WhatWhyLawful basis
Account, login, support, billingTo give you the service you signed up forPerformance of a contract
Logs, error reports, rate limits, audit logTo keep the platform secure, working and abuse-freeLegitimate interests
Invoices, tax records, consent evidenceBecause accounting and messaging law requires recordsLegal obligation
Emails the product sends youPayment failure notices, team invitations, and our reply when you write to us. Card receipts come from Stripe.Performance of a contract
Marketing emails from us to youOnly if you asked for them, and every one can be stoppedConsent

For the records you enter about your clients and workers, the lawful basis is yours to determine. We process them on your instructions.

4. Who we share it with

We use a small set of service providers to run the platform. Each one is listed, with what it does and where it processes, on the subprocessors page. They may use the data only to provide their service to us.

Two of those deserve calling out. Phone numbers and message text go to Twilio so a text can actually be delivered. Where you use the AI receptionist or AI photo quoting, the conversation text or the photo goes to the Anthropic API to produce the reply or the estimate. We send what the feature needs and nothing more.

Beyond that: we disclose data if a law or a valid legal order requires it, and we would tell you unless we are prevented from doing so. If the business is ever sold, account data transfers with it and account owners are told by email. We do not sell personal data and we do not share it for anyone else's advertising.

5. Where it is processed

The database, file storage and authentication run on Supabase in the AWS us-east-1 region in the United States. The application runs on Vercel. Most of our other providers are US-based.

For personal data coming from the EEA, the UK or Switzerland, transfers to the United States rely on the European Commission's standard contractual clauses, together with the UK international data transfer addendum. Those clauses are incorporated into our data processing addendum, which you can accept without contacting us.

6. How long we keep it

  • While you are a customer: for as long as your subscription is active.
  • After cancellation: the account becomes read-only and stays readable for at least 90 days so you can get your records out. Subscribing again in that window brings everything back.
  • Deletion after that: we delete the organisation's data when you ask us to, within 30 days of the request, and we do not need a reason. This is something the operator does, not a scheduled job: there is no automatic purge in the product today, so an account nobody asks about stays read-only rather than quietly disappearing on day 91. If you want it gone on day 91, email support@broomdesk.com and it will be.
  • Messaging consent records: kept for at least 5 years, and kept even after the related client record is deleted. If a regulator or a court asks whether a person agreed to receive texts, this is the answer. The record holds the phone number, what was agreed, when, and the evidence of how.
  • Invoices and accounting records: kept for the period Romanian and EU accounting law requires, in an anonymised form where the personal detail is no longer needed.
  • Audit log entries: retained for the life of the account as a security record.
  • Error reports and server logs: kept on the short retention window our providers apply, currently weeks rather than years.
  • Deleting one client: there is no self-serve button for this yet. Email us naming the account and the client and we remove their personal details within 30 days, keeping anonymised financial totals so the books still balance.

7. Security

Every table that holds tenant data is protected by database row-level security, so one business cannot read another's rows even if application code has a fault. Integration tokens and property entry details are encrypted with AES-256-GCM using a key held outside the database. Traffic is encrypted with TLS. Photos are stored privately and served through short-lived signed links. Roles inside your account limit what each person can see, cleaners included. Sensitive actions are written to an audit log. Webhooks from Stripe, Twilio and Resend are signature-verified before anything is trusted. Access to production is limited to the operator.

No system is perfect. If a breach affects your personal data we will tell you, and where we are the processor we will tell you within 72 hours of confirming it so you can meet your own obligations.

8. Your rights

If you are in the EEA or the UK you have the right to access your data, correct it, delete it, restrict or object to processing, get a portable copy, and withdraw consent where consent is the basis. Rights in other places, including California, are broadly similar and we apply the same process to everyone rather than sorting people by geography.

To exercise any of them, email support@broomdesk.com from the address on the account, or use the contact form. We answer within 30 days, usually much sooner, and we will not charge you or ask why. If we ever have to refuse, we will say which exemption we are relying on.

If your data is in a cleaning business's account, send your request to that business. Their number and email are on the messages they send you. We support them in answering, and if they do not, write to us and we will chase it.

You can also complain to a supervisory authority. In Romania that is the National Supervisory Authority for Personal Data Processing (ANSPDCP). In the EEA and the UK you can go to the authority where you live.

9. Cookies

Five cookies exist, and all five are strictly necessary: the sign-in session for the app, the client portal session, the demo sandbox session, a region label the cookie banner reads, and the cookie that remembers your answer to that banner for 12 months. Nothing non-essential is set, and the banner shows in the EEA, the UK, and wherever we cannot read a country. The cookie policy lists all five by name with lifetimes, and the cookie preferences page is where you change your answer.

10. Children

BroomDesk is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child entered data here, tell us and we will remove it.

11. Changes

When this policy changes we update the date at the top. For changes that materially affect how we handle your data, we email account owners at least 14 days before they take effect.

Questions

Questions about how we handle personal data, or a request about your own. Email support@broomdesk.com, or use the contact form. We reply within one business day.

BroomDesk is operated by Amortoae Petru PFA (CUI 52361814), Romania. Postal address and registration details are on any invoice we issue you through Stripe.

BroomDesk

Software for cleaning businesses. Flat price, unlimited team members, your clients stay yours.

Amortoae Petru PFA (CUI 52361814)

Product
  • Features
  • Booking widget
  • Scheduling
  • AI receptionist
  • Payroll
  • Commercial cleaning
  • Pricing
Compare
  • All comparisons
  • vs ZenMaid
  • vs Jobber
  • vs Automaid
  • vs BookingKoala
  • vs Housecall Pro
Learn
  • Blog
  • RSS feed
  • Free tools
  • Price calculator
  • Widget docs
  • API docs
Company
  • About
  • Contact
  • Live demo
  • FAQ
  • Log in
  • Start free trial
Legal
  • Terms of service
  • Privacy policy
  • Refund policy
  • SMS policy
  • Acceptable use
  • Cookies
  • Cookie preferences
  • Data processing
  • Subprocessors
© 2026 BroomDesk. Built for the people who keep places clean.Made in the EU, built for US cleaning teams