Trust

Security & Data at CleaningQA

CleaningQA stores operational quality-control information: client sites, inspection records, corrective actions and supporting evidence. Access is designed around organisations, roles and deliberately scoped sharing links, so you control who can see and act on your data. This page describes how the product actually works today. We do not claim certifications we do not hold.

Account security

Using CleaningQA requires an account. You sign in with an email address and password, or with a single-use sign-in link sent to your email address. Sessions are issued by our managed authentication service, and signing out clears the session in your browser.

Every account reaches operational data only through membership of an organisation. Permission checks run on our servers on each request, not just in the interface, so hiding a button is never the only thing preventing an action.

An organisation must keep at least one active administrator: the system refuses a change that would remove the last one. Administrators also cannot change their own role, which prevents accidental self-lockout and silent privilege changes.

Multi-factor authentication is not currently offered. If that matters for your procurement process, tell us.

Organisation and data isolation

CleaningQA is multi-tenant software. Every client, site, checklist, inspection, corrective action, evidence file and report belongs to one organisation, and organisation-level access controls prevent one customer organisation from reading or changing another organisation's data.

These controls are enforced in the database itself and in server-side checks, rather than by the browser. A request for data belonging to an organisation you are not a member of returns nothing.

Roles and permissions

Organisation admin — manages organisation settings, clients and sites, checklists, report branding, team membership and billing.

Supervisor — runs inspections, raises and manages corrective actions, reviews submitted corrections and shares client reports. Supervisors do not manage billing.

Cleaner or contractor — completes an assigned corrective action through a secure link, without needing a CleaningQA account and without access to anything else in your organisation.

Team members join by email invitation. Invitations are single-use, time-limited and bound to the invited email address, and can be revoked before they are accepted.

Inspection data and evidence

The operational data CleaningQA holds for you includes client and site details, inspection responses and findings, corrective actions and their notes, photographic evidence, verification history and records of shared reports.

Photographs and logo files are held in private storage. They are never publicly browsable: the product issues short-lived, signed links when an authorised person or a valid share link needs to display an image.

Historical records

Finalised inspection and report records are designed to preserve the context that applied when they were created. When an inspection starts, the checklist is frozen as a snapshot, so later edits to your template do not alter a completed inspection or its score. Report branding is snapshotted in the same way.

Once an inspection is submitted, the product blocks changes to its snapshot, score and responses, and corrective-action history is recorded as an append-only trail rather than being rewritten.

Payments

Paid subscriptions are sold through Paddle, which acts as the Merchant of Record and handles checkout, payment processing, invoices and tax. CleaningQA does not receive or store full payment card details.

We store the references needed to run your subscription: the Paddle customer and subscription identifiers, your plan, currency and subscription status. Subscription status changes are only accepted from Paddle events whose signature we verify.

More detail is in our Refund & Cancellation Policy and on Paddle's website.

Hosting and infrastructure

CleaningQA runs on managed cloud infrastructure provided through Lovable, with the database, authentication and file storage provided by Supabase. We do not operate our own servers.

The application and all of its links are served over HTTPS. We have not published a hosting region, an uptime commitment or a disaster-recovery guarantee here, because we will not state something we cannot evidence from our own configuration. If your procurement process needs specifics, contact us and we will answer precisely.

Data retention and deletion

Your organisation's data is kept for as long as your account is active. Cancelling a subscription does not delete your records: access to start new operational work stops, while existing inspections, actions and reports remain available to view and print.

You can ask us to delete your organisation's data by emailing hello@cleaningqa.com. Billing and tax records are retained for at least six years as required by UK law. Our Privacy Policy sets out the rest. We have not published a fixed deletion window, because we have not implemented one; we handle requests individually.

Getting your data out

There is currently no self-service bulk export. Reports and inspection summaries can be printed or saved as PDF from the browser, and you can request a copy of your organisation's data by emailing hello@cleaningqa.com.

Service providers

We use these providers to deliver the service:

  • Lovable — application hosting and infrastructure.
  • Supabase — database, authentication and file storage for your operational data and evidence.
  • Paddle — Merchant of Record for subscriptions: checkout, payments, invoices and tax.
  • Email delivery — sending account, invitation and workflow notification emails.

Analytics

We use our own first-party analytics to understand which pages bring people to CleaningQA and how new customers get started. With your permission it stores a random identifier in your browser, the page you were on when tracking started, the referring website domain and any campaign parameters in the link. Nothing is stored before you allow analytics, and you can withdraw permission at any time through Cookie settings. We do not use third-party advertising trackers and do not sell this data.

Search keyword and ranking information comes from Google Search Console, which reports aggregated data about our site and does not identify individuals.

See our cookie policies for the UK and US.

Keeping your account secure

A few practical things help keep your organisation's data safe. Give each team member their own account rather than sharing one login. Keep your password private and do not reuse it elsewhere. Remove team members when they no longer need access. Share corrective-action and client report links only with the people they are intended for, and revoke a link if it goes astray.

Report a security concern

If you believe you have discovered a security issue affecting CleaningQA, contact us at hello@cleaningqa.com with enough information for us to investigate it. Please do not publish the details before we have had a chance to respond. We will acknowledge genuine reports, though we do not currently offer a guaranteed response time or a paid bounty.