Skip to content
Legal · Updated July 2026

Privacy Policy

TidyShift is software that commercial cleaning companies use to run their operations — leads, quotes, schedules, crews, photos, proof-of-service reports and invoices. That means we hold information about your business, your people and your clients. This policy explains exactly what we collect, why we collect it, who else touches it, and what you can ask us to do with it. We have tried to write it in the same plain language we use everywhere else on this site.

This document is a plain-English template written for TidyShift. It is not legal advice, and it has not yet been reviewed by counsel. Please have a qualified attorney review and adapt it — including the jurisdiction, notice periods and liability figures — before you rely on it in production.

Who we are

TidyShift ("TidyShift", "we", "us") provides an operations platform for commercial cleaning companies. This policy covers our marketing site at tidyshift.com and the TidyShift application.

When you use TidyShift to manage your own clients, crews and buildings, you are the controller of that information and we are the processor acting on your instructions. For information about your own account and your use of our site, we are the controller. If your customer or your employee asks us about their data, we will point them back to you and help you answer.

What we collect

Account information. Your name, work email address, phone number, company name, role and password credentials — the minimum we need to create an account, sign you in, bill you and reach you about the service.

Business data you enter. Everything you or your team put into TidyShift: clients and contacts, sites and buildings, cleaning plans and checklists, quotes and pricing, schedules and shifts, employee and contractor records, clock-in and clock-out times, notes, invoices and payment status. Some of this is personal information about your staff and your clients, and you decide what goes in.

Job photos and proof-of-service content. Before and after photos taken in the field, the area and task each photo belongs to, the time it was captured, who captured it, supervisor approvals, and the branded reports generated from them.

Usage analytics. We use PostHog to understand how the product and this site are used — pages and screens viewed, features opened, buttons clicked, approximate location derived from IP address, browser and device type, and error events. This helps us find what is confusing or broken. We do not use it to build advertising profiles.

Communications. Messages you send us by email, in a demo call, or through in-product support, along with our replies.

Technical logs. IP address, timestamps, request paths and error traces, kept for security, debugging and abuse prevention.

We do not collect payment card numbers. Card details are entered with our payment processor and never reach our servers; we only see the last four digits, the card brand and the billing status.

How we use it

To provide the service: run your account, keep your schedule and records in sync, generate quotes, checklists, reports and invoices, and send the notifications you have asked for.

To power the Copilot: read your own business data so the Copilot can answer your questions and draft suggestions for you to approve. The Copilot operates on your account data to serve you.

To support you: answer your questions, investigate faults and restore data when something goes wrong.

To bill you: process subscriptions, renewals, trials and refunds through our payment processor.

To improve the product: understand aggregate usage patterns, measure whether a change helped, and prioritise the roadmap.

To keep things safe and lawful: detect abuse, prevent fraud, enforce our Terms, and meet legal or tax obligations.

We do not use your business data, your job photos or your client reports to train general-purpose AI models for other customers or third parties.

We do not sell your data

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done this and we do not plan to. Your client list, your pricing and your photos are your competitive advantage — not our inventory.

We will not disclose your data to a third party except to the sub-processors listed below who operate the service on our behalf, where you have asked us to (for example, an integration you connect), or where we are legally required to.

Sub-processors and service providers

We rely on a small number of vendors to run TidyShift. Each is bound by contract to protect the data they handle and to use it only to provide their service to us.

Hosting and infrastructure: cloud hosting, managed database and object storage providers that run the application and store your records and photos.

Product analytics: PostHog, for the usage analytics described above.

Email delivery: a transactional email provider used to send account notices, client reports and invoice reminders on your behalf.

Payments: a payment processor that handles card details, subscriptions and invoices for your TidyShift plan.

AI processing: a large language model provider that processes the specific data needed to answer a Copilot question or draft a suggestion. Content sent for this purpose is not used to train that provider’s models.

We will keep this list current. If you need the named entities and their locations for a vendor review, email hello@tidyshift.com and we will send you the up-to-date list.

Photos and proof-of-service reports

Photos deserve their own paragraph because they are the most sensitive thing most cleaning companies put into TidyShift. Photos are stored privately and are visible only to your account — your owners, your supervisors and, where you have granted access, your crews.

A proof-of-service report is only sent to your client after a supervisor in your account approves it. When a report is shared with a client, we generate a link scoped to that report; anyone with the link can view that report, so treat it as you would an emailed PDF.

Photos carry the time they were taken and who took them. We do not add facial recognition, and we do not analyse photos for any purpose beyond generating the report and the quality scores inside your account. Ask your crews not to photograph people or documents unnecessarily — the point is the floor, not the person standing on it.

Retention

We keep your business data for as long as your account is active, because that history is what makes your next bid sharper.

After you cancel, your data stays available for 30 days so you can export it or change your mind. After that window we delete or irreversibly anonymise your account data within 90 days, except where we must keep records longer for tax, accounting or legal reasons — typically invoices and payment records.

Backups are retained on a rolling schedule and are overwritten in the ordinary course, so a deleted record may persist in a backup for a short period before it ages out.

Usage analytics are retained in aggregate and are not tied to your business records.

Security

Data is encrypted in transit with TLS and encrypted at rest. Access to production systems is limited to the small number of staff who need it, protected by multi-factor authentication, and logged.

Inside your account, permissions are role-based: owners see everything, supervisors see the buildings assigned to them, and cleaners see only their own jobs and checklists.

No system is perfectly secure. If a breach affects your data, we will notify you without undue delay, tell you what we know, and tell you what we are doing about it.

Your rights

You can ask us to give you a copy of the personal information we hold about you, correct it if it is wrong, export your business data in a machine-readable format, or delete it.

Most of this you can do yourself inside the product — edit records, export data, or delete an account. For anything you cannot do in-product, email us and we will handle it within 30 days.

Depending on where you live, you may have additional rights: California residents have rights under the CCPA/CPRA (including the right to know, delete, correct and to opt out of sale or sharing — which does not apply to us, because we do neither), and residents of the EEA and the UK have rights under the GDPR, including the right to object, to restrict processing and to lodge a complaint with a supervisory authority. We will never charge you or degrade your service for exercising a right.

If your request concerns data held inside a customer’s TidyShift account — for example, you are a cleaner or a client of a company that uses TidyShift — please contact that company directly. We will forward your request and assist them.

Children

TidyShift is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child’s information has been entered into TidyShift, tell us and we will delete it.

International transfers

TidyShift is operated from the United States and our infrastructure is primarily located there. If you use TidyShift from outside the United States, your information will be transferred to and processed in the US and in other countries where our sub-processors operate.

Where we transfer personal data out of the EEA or the UK, we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, together with appropriate technical safeguards.

Changes to this policy

We will update this policy as the product changes. When we make a material change, we will update the date at the top and tell you by email or in the product before the change takes effect. Continuing to use TidyShift after that means you accept the updated policy.

Contact

Questions, requests or complaints about privacy go to hello@tidyshift.com. A real person reads that inbox and will get back to you.