Pilot document · 15 July 2026
Privacy notice
This notice explains the intended handling of information submitted during the Homle pilot.
Information collected
The initial request accepts only a general access approach. Homle rejects door, gate, alarm and key-safe codes, passwords and exact hidden-key locations, and the tab recovery draft omits them. Exact access instructions belong only in the protected accepted-booking workflow.
Customers may provide their name, organisation, contact details, property location, cleaning requirements, requested date and arrival window, property photos, a reviewed text transcript or checklist of their instructions, and a timestamped confirmation that the final concise checklist includes every task they want quoted. Before a quote is active, the customer may replace their requested date or arrival window through the private tracker and provide a short reason. Homle keeps each earlier and replacement timing as append-only audit history; an exact retry does not create another entry. A sent quote freezes the then-current requested timing beside the exact proposed visit, and an acceptance records the customer's separate confirmation of that proposed schedule. Homle does not intentionally retain an audio recording. The first Cleaner application asks for name, contact details, work areas, experience, service preferences, usual availability, one exact first-available date and start/end time, and eligibility confirmations. After applying, the private tracker separately asks for a short professional introduction, languages and the equipment and cleaning-products plan. Those profile-starter details remain private and unverified during application review and are not published automatically. The first exact window is planning evidence only: it is not confirmed or used for matching. After screening and approval, a cleaner may submit or re-confirm an exact future date, start and end time plus an optional short timing note through the private tracker. Forms create a random technical retry identifier and a one-way submission fingerprint so a network retry does not create a duplicate record; these values stay out of customer, cleaner and control-desk views. A cleaner-submitted time remains pending until the control desk records a confirmation or decline note. The control desk may also record separately verified exact availability windows and later withdrawal events so Homle does not promise an unconfirmed slot. After both sides accept a proposed job, Homle may record the full service address, named access contact, arrival instructions, equipment plan and emergency instructions needed for that visit. It may also record non-sensitive external payment evidence: a booking reference, the verified amount and time, and after completion separate customer-receipt and cleaner-payout references, verified settlement amounts, time and an internal evidence note. These fields stay out of customer and cleaner booking packs and do not contain card or bank details. The control desk records screening confirmations and an internal note, but it is not designed to store identity documents, document numbers, alarm or key-safe codes, passwords, provider credentials, bank details or card details.
Why it is used
- To assess and respond to cleaning requests.
- To assess cleaner applications and discuss suitable opportunities.
- To coordinate an agreed pilot job and handle related questions.
- To keep basic records needed to operate safely and resolve problems.
- To protect forms and private links from repeated automated attempts; the local pilot temporarily holds a client network address in memory for this purpose and does not add it to the customer or cleaner record.
Legal basis
The intended legal bases are taking steps at a person’s request before a contract, performance of an agreed contract, and Homle’s legitimate interests in operating and improving the pilot. Separate consent will be requested for any optional marketing.
Sharing and storage
Only the minimum job information needed to consider or coordinate a match should be shared between a customer and cleaner. A time submitted through the cleaner tracker is visible in the private control desk but is not shared with customers and is never used for matching until Homle records a separate confirmation. Before booking confirmation, the cleaner opportunity shows only the outward-code area, scope, hazards and proposed pay. If the customer separately chooses to allow it, the one selected cleaner may also review the frozen room photos and notes through that high-entropy private opportunity link while the offer is active; the images use header-based authorisation, are marked non-cacheable and are revoked when the opportunity is withdrawn, declined or expires. Without that choice, pre-booking photos remain Homle-only. After both sides accept and Homle records the booking, separate high-entropy private links show each recipient only their booking pack: the cleaner receives the address and access details needed for the visit, while the customer view does not expose cleaner contact details or pay. Reviewed room photos and notes then become available to both sides through the confirmed booking packs. A separate private customer tracker link shows the request stage and customer actions without exposing contact details, access instructions, cleaner identity or cleaner pay. A separate private cleaner tracker shows the application reference, recorded onboarding stages, that applicant's own professional introduction/languages/equipment plan and their own pending exact times. It does not return identity, contact, postcode, travel coverage, screening notes, decision notes or the authorisation token and cannot approve, assign, publish or promise work. Profile changes are accepted only before screening or an approval decision completes. Link tokens are removed from the visible address before the browser requests tracker, opportunity, quote or booking data, and protected images are marked non-cacheable. Customers and cleaners should keep private links confidential, and customers should avoid including people, identity documents, post, keys or security codes in photos. To continue from a request into a room scan, the request reference and email may be held in that browser tab for up to 30 minutes; the handoff is removed after the scan is saved or the tab is closed. While a room scan is being edited, its request-bound transcript and checklist may also remain in that tab for up to 30 minutes so a reload can recover the text. This recovery draft never contains email, private link tokens, photos or videos; it is removed on successful submission, expiry, explicit discard or tab closure. Information should not be sold. Before launch, Homle must document every hosting, speech-recognition, messaging and payment provider that processes personal data.
Retention
An incomplete Cleaner application may keep its allowlisted contact, work-preference, profile and availability entries in the current browser tab for up to 30 minutes so a reload does not erase the application. The right-to-work and privacy consent confirmations are never stored or restored and must be made again. If a submission response is interrupted, only its random retry key is retained with the exact draft so retrying cannot silently create a duplicate application. The recovery draft is removed after successful submission, expiry, explicit discard or tab closure.
An incomplete cleaning request may keep its allowlisted property scope, timing, access and contact entries in the current browser tab for up to 30 minutes so a reload or poor connection does not erase the request. Privacy consent and the anti-spam field are never stored or restored. If a submission response is interrupted, only its random retry key is retained with the exact draft so retrying cannot silently create a duplicate request. The recovery draft is removed after successful submission, expiry, explicit discard or tab closure.
During a manual room-time review, the exact scan's room-minute entries, preparation time, confidence choice and internal evidence note may stay in the current control-desk tab for up to 30 minutes. The recovery draft contains no room media and never stores or restores visual-open checks, checklist reconciliation, price-sensitive confirmations, calculated hours or an approval decision. Those confirmations must be completed again from the evidence after every reload. The draft is removed after a recorded review decision, expiry, explicit discard or tab closure.
The founder must record separate retention periods for room photos and videos attached to inactive enquiries and completed bookings before launch. Homle’s private control desk classifies each scan against those periods but never deletes media automatically. An eligible deletion requires a current verified private backup, the exact scan reference and a written reason; Homle keeps the non-media request record and an append-only deletion audit. Other records connected with completed work may need different periods for tax, accounting, insurance or dispute purposes, so the full schedule and production storage arrangements must still be confirmed before launch.
Your rights
People may ask to access, correct or delete their information, restrict or object to some uses, or request a portable copy where applicable. They may also complain to the UK Information Commissioner’s Office.
Removing Homle from a connected Facebook account sends a signed deletion request to Homle. The response provides a private confirmation link that shows only the request stage. It does not expose the Facebook identifier, email address or other account details. A received request remains subject to the retention and identity-verification requirements described above.
Contact
A verified Homle privacy email and the legal operator’s postal address must be inserted before public launch.