Privacy

Last updated 28 August 2026

What this covers

Shinivo is software that independent cleaners use to run their own business. Two different groups of people appear in it: the cleaner who has an account, and their customers, whose details the cleaner records in order to do the work.

The cleaning business decides what customer information goes in and how it is used. We hold it on their behalf.

What we collect from cleaners

The email address and name used to sign in, a password stored only as a salted hash, and the business details entered during setup: business name, owner name, phone, contact email, service area, time zone and description.

For a Team account, we also store invited staff names and email addresses, their role, job assignments, and the actions they take on assigned work so the business has an operational record.

If a subscription is started, our payment provider handles the card. We never see or store card numbers.

What gets stored about customers

When someone books through a cleaner's page we store the name, email, phone and service address they enter, along with any access or job notes they choose to add.

If the business proposes extra work during a job, we store the description, amount, who requested it, whether the customer approved or declined, and when. The approval record stores a hash of the random link. When email delivery is used, the link expires after 24 hours and also appears in the restricted outbound delivery record needed to send it.

We ask for nothing beyond what is needed to turn up at the right house at the right time. There are no fields for identity documents, financial account details or background check information, because the product does not need them.

Card payments

Cash is never handled by us and leaves no payment record beyond the amount a cleaner records against the job.

Card payments are optional and exist only for a cleaner who has connected their own Stripe account. When a customer chooses to pay by card, they enter it on a page hosted by Stripe. The number never reaches our servers and we never store it. Stripe holds the card against that booking and tells us only that one exists.

To do that, a Stripe customer record is created for that person, carrying the name and email they gave when booking. We store the identifiers Stripe gives back so the right card can be charged for the right job, and nothing else about the card.

The charge itself is created through our Stripe platform and settled into the cleaner's own Stripe account. We take no part of it.

Private notes

Notes a cleaner writes about a job or a customer are visible only to that business. They are never shown on a public booking page and never included in an email to a customer.

We ask cleaners not to store alarm codes or key locations in these fields, and say so in the product where those fields appear.

Separation between businesses

Every record belongs to exactly one cleaning business. Access is decided from the account membership after sign in, not from anything in a web address, and this is covered by automated tests.

One cleaning business cannot see another's customers, bookings, notes, services or settings.

Within a Team account, owners control invitations and roles, managers can coordinate operations, and staff access is limited to work assigned to them. Staff do not receive owner billing or access to every customer in the business.

Analytics

We record a small set of product events, such as a booking page being viewed or a booking being requested, to understand whether the product works.

The properties allowed into analytics are restricted to a fixed list that contains no names, addresses, contact details or note text.

Photographs of the work

A cleaner can attach photographs to a job. These are pictures of the inside of a home, so they are treated as some of the most sensitive information here.

Before and after photographs are shown to the customer for that booking. A photograph marked as a problem stays private to the cleaning business unless they choose to share it.

The files are never stored in a publicly readable location and are never reachable by guessing a web address. Every request for one goes through a check of who is asking: the business account it belongs to, or the customer holding the link to that specific booking.

A cleaner can delete a photograph they added, which removes both the record and the stored file.

Reviews

A customer can leave a review only after a job they actually booked has been completed, and only once for that job. There is no way to post a review for a business you have never used.

A review shown on a Marketplace profile carries a first name only. Email addresses, phone numbers, addresses and booking details are never shown alongside it.

Getting your data out, and deletion

A cleaner can export their customers, bookings and services as CSV at any time, from Settings.

There is no button that deletes a whole business. Ask us and we will delete the account and its records; we will tell you when it is done. We are deliberate about this rather than automatic, because a cleaning business's records include work other people are relying on, and because any introduction fee already owed has to be settled rather than deleted along with the account.

Backups, where they exist, are overwritten on their own schedule.

Where this stands today

This notice describes how the product currently behaves, in plain language.

It is not a substitute for legal advice, and it has not been reviewed by a lawyer. Anyone taking this to production should have it reviewed against the rules that apply to them.