Trust
Security & Data at CleaningQA
CleaningQA stores operational quality-control information: client sites, inspection records, corrective actions and supporting evidence. Access is designed around organisations, roles and deliberately scoped sharing links, so you control who can see and act on your data. This page describes how the product actually works today. We do not claim certifications we do not hold.
Account security
Using CleaningQA requires an account. You sign in with an email address and password, or with a single-use sign-in link sent to your email address. Sessions are issued by our managed authentication service, and signing out clears the session in your browser.
Every account reaches operational data only through membership of an organisation. Permission checks run on our servers on each request, not just in the interface, so hiding a button is never the only thing preventing an action.
An organisation must keep at least one active administrator: the system refuses a change that would remove the last one. Administrators also cannot change their own role, which prevents accidental self-lockout and silent privilege changes.
Multi-factor authentication is not currently offered. If that matters for your procurement process, tell us.
Organisation and data isolation
CleaningQA is multi-tenant software. Every client, site, checklist, inspection, corrective action, evidence file and report belongs to one organisation, and organisation-level access controls prevent one customer organisation from reading or changing another organisation's data.
These controls are enforced in the database itself and in server-side checks, rather than by the browser. A request for data belonging to an organisation you are not a member of returns nothing.
Roles and permissions
Organisation admin — manages organisation settings, clients and sites, checklists, report branding, team membership and billing.
Supervisor — runs inspections, raises and manages corrective actions, reviews submitted corrections and shares client reports. Supervisors do not manage billing.
Cleaner or contractor — completes an assigned corrective action through a secure link, without needing a CleaningQA account and without access to anything else in your organisation.
Team members join by email invitation. Invitations are single-use, time-limited and bound to the invited email address, and can be revoked before they are accepted.
Secure corrective-action links
When you assign a corrective action, CleaningQA creates a link scoped to that single action. It shows the task, the site and area, the evidence requirement and the due date — nothing else from your organisation.
Reassigning an action revokes the previous link and issues a new one, so a former recipient cannot keep working on it. Once an action is verified and closed, its links are revoked automatically and the action can no longer be updated through them. Links that are invalid, revoked or expired fail safely: the page simply reports that the link is no longer usable.
Link tokens are stored as one-way hashes rather than in readable form, so the stored record cannot be turned back into a working link.
Client report sharing
Finalised inspection reports can be shared with a client through a dedicated link. Each link is scoped to one submitted report and carries no access to your dashboard, your other clients or any other report.
You can revoke a report link at any time; revoked or invalid links fail safely. An expiry date is optional, so not every shared link expires on its own — revoke links you no longer want in circulation. Shared report and corrective-action pages are marked so search engines do not index them, and they are not listed in our sitemap.
Inspection data and evidence
The operational data CleaningQA holds for you includes client and site details, inspection responses and findings, corrective actions and their notes, photographic evidence, verification history and records of shared reports.
Photographs and logo files are held in private storage. They are never publicly browsable: the product issues short-lived, signed links when an authorised person or a valid share link needs to display an image.
Historical records
Finalised inspection and report records are designed to preserve the context that applied when they were created. When an inspection starts, the checklist is frozen as a snapshot, so later edits to your template do not alter a completed inspection or its score. Report branding is snapshotted in the same way.
Once an inspection is submitted, the product blocks changes to its snapshot, score and responses, and corrective-action history is recorded as an append-only trail rather than being rewritten.
Payments
Paid subscriptions are sold through Paddle, which acts as the Merchant of Record and handles checkout, payment processing, invoices and tax. CleaningQA does not receive or store full payment card details.
We store the references needed to run your subscription: the Paddle customer and subscription identifiers, your plan, currency and subscription status. Subscription status changes are only accepted from Paddle events whose signature we verify.
More detail is in our Refund & Cancellation Policy and on Paddle's website.
Hosting and infrastructure
CleaningQA runs on managed cloud infrastructure provided through Lovable, with the database, authentication and file storage provided by Supabase. We do not operate our own servers.
The application and all of its links are served over HTTPS. We have not published a hosting region, an uptime commitment or a disaster-recovery guarantee here, because we will not state something we cannot evidence from our own configuration. If your procurement process needs specifics, contact us and we will answer precisely.
Data retention and deletion
Your organisation's data is kept for as long as your account is active. Cancelling a subscription does not delete your records: access to start new operational work stops, while existing inspections, actions and reports remain available to view and print.
You can ask us to delete your organisation's data by emailing hello@cleaningqa.com. Billing and tax records are retained for at least six years as required by UK law. Our Privacy Policy sets out the rest. We have not published a fixed deletion window, because we have not implemented one; we handle requests individually.
Getting your data out
There is currently no self-service bulk export. Reports and inspection summaries can be printed or saved as PDF from the browser, and you can request a copy of your organisation's data by emailing hello@cleaningqa.com.
Service providers
We use these providers to deliver the service:
- Lovable — application hosting and infrastructure.
- Supabase — database, authentication and file storage for your operational data and evidence.
- Paddle — Merchant of Record for subscriptions: checkout, payments, invoices and tax.
- Email delivery — sending account, invitation and workflow notification emails.
Analytics
We use our own first-party analytics to understand which pages bring people to CleaningQA and how new customers get started. With your permission it stores a random identifier in your browser, the page you were on when tracking started, the referring website domain and any campaign parameters in the link. Nothing is stored before you allow analytics, and you can withdraw permission at any time through Cookie settings. We do not use third-party advertising trackers and do not sell this data.
Search keyword and ranking information comes from Google Search Console, which reports aggregated data about our site and does not identify individuals.
Keeping your account secure
A few practical things help keep your organisation's data safe. Give each team member their own account rather than sharing one login. Keep your password private and do not reuse it elsewhere. Remove team members when they no longer need access. Share corrective-action and client report links only with the people they are intended for, and revoke a link if it goes astray.
Report a security concern
If you believe you have discovered a security issue affecting CleaningQA, contact us at hello@cleaningqa.com with enough information for us to investigate it. Please do not publish the details before we have had a chance to respond. We will acknowledge genuine reports, though we do not currently offer a guaranteed response time or a paid bounty.