CleanTracker
Privacy Policy
How Idealrent ApS processes personal data in connection with CleanTracker's website, accounts, support, billing, and service operations.
Provider: Idealrent ApS, CVR 38302388, Monica Zetterlunds Vej 27, 4., 2450 København SV, Denmark · [email protected]
1. Who is responsible for your data?
CleanTracker is a service provided by Idealrent ApS. Idealrent ApS is the controller for the processing described in this Privacy Policy: our website, customer and account administration, subscriptions, support, security, and communications about the service.
This Policy does not make Idealrent ApS the controller for all information stored by customer organizations in CleanTracker. A customer organization is generally the controller for operational personal data it enters into and manages through the service. Idealrent ApS processes that data as a processor on the customer’s documented instructions. See our Data Processing Agreement for those terms.
2. Who and what this Policy covers
This Policy covers personal data about:
- website visitors and people who contact us;
- prospects, account holders, and users;
- organization owners, administrators, and billing contacts;
- people who receive account, support, email, or SMS communications; and
- people whose technical identifiers appear in security, request, and diagnostic logs.
Depending on how you interact with CleanTracker, we may process your name, email address, telephone number, organization and account metadata, authentication identifiers, role and access information, subscription plan, billing contact details, Stripe customer or subscription identifiers, support messages, communication content and delivery metadata, IP address, device/browser data, request metadata, and security or diagnostic information.
3. Purposes and legal bases
We process account, organization, authentication, and subscription information to create and administer accounts, provide the requested service, manage the customer relationship, and perform our contract. We process contact and billing information to administer subscriptions, payments, bookkeeping, and tax obligations.
We process support conversations and transactional communications to answer requests, deliver invitations, password resets, reminders, service messages, and other operational communications. CleanTracker currently sends transactional communications, not marketing newsletters, through these service channels.
We process logs and technical information to secure, operate, debug, and improve the service; prevent misuse and fraud; establish or defend legal claims; and meet legal obligations. These activities rely, as applicable, on performance of contract, compliance with legal obligations, and our legitimate interests in operating a secure and reliable B2B service. Where a particular activity requires consent, we will request it separately.
You are generally required to provide the account and billing information needed to enter into and administer the customer relationship. Without it, we may be unable to create an account or provide a paid service.
4. Authentication
CleanTracker uses Better Auth for account authentication. If you choose social login, Google or Apple may process authentication identifiers and may provide us with an identifier, name, or email address depending on your choice and that provider’s settings. The provider also processes data under its own terms and privacy notice. Social login is optional where offered.
5. Billing and payments
Stripe is used for CleanTracker subscription billing and for Stripe Connect/customer-payment functionality. We process plan, organization, billing-contact, subscription, and payment metadata and relevant Stripe identifiers. Stripe may act in different legal roles depending on the payment activity, including as a payment provider processing information for its own regulatory, fraud-prevention, and payment-network purposes. Payment-card details are handled through Stripe’s payment environment rather than being stored directly by CleanTracker.
6. Support and communications
Crisp provides customer-support chat. When you use chat or otherwise contact support, Crisp may process contact information, conversation content, technical context, and chat-session information. Do not include information that is not necessary for your support request.
Resend delivers transactional email, and GatewayAPI delivers transactional SMS where that channel is used. Recipient contact details, message content, and delivery metadata may be processed to send and troubleshoot those messages.
7. Website technologies
The website stores a language preference cookie. It also stores your light/dark theme preference in local storage and a theme cookie. Crisp may set a session identifier needed to maintain the support-chat session across pages and visits.
Umami analytics code is installed but disabled. We therefore do not currently run Umami website analytics tracking. We do not make the broader claim that the website uses no cookies or local storage because the preferences and support features described above use those technologies.
8. CleanTracker as processor for customer operational data
Customer organizations decide why and how they use CleanTracker for their operations. Data processed on their behalf can include customer and contact information, employee or worker information, account members, jobs and visits, schedules, internal notes and instructions, time registration, check-in/check-out data, optional point-in-time location data, invoicing/accounting-related operational data, and imported CSV content.
Customers may enter free-text notes or instructions, which can contain personal data. CleanTracker is not designed to require special-category or criminal-offence data. Customers must limit content to information necessary and lawful for their use of the service.
Time and location registration
An organization can choose whether to enable visit check-in. When enabled, an employee manually checks in and out in the mobile app. CleanTracker records the relevant timestamps, employee/visit association, and resulting work-duration information.
When location registration is enabled by the organization, CleanTracker may record the employee’s current location when the employee manually checks in or out. The inspected product implementation requests a point-in-time position for those actions and does not continuously track employee location. A user can be offered the option to continue without location if location permission is unavailable. The customer organization controls the feature and is responsible for using it lawfully.
AI-assisted CSV import
When a user chooses the AI-assisted CSV import, data contained in that import may be processed by OpenAI to interpret, normalize, and structure the imported customer data. This is limited to the selected import; it does not mean that all CleanTracker data is sent to OpenAI.
9. Hosting, integrations, and other recipients
CleanTracker’s primary application and database infrastructure is hosted by Render in Frankfurt, Germany. Render also processes application/server logs and technical request information.
Customers can choose to connect Dinero or Billy. When enabled, relevant customer, invoice, contact, and transaction information is sent to the selected accounting provider under both the CleanTracker integration and the customer’s relationship with that provider. Third-party integrations may have their own terms and privacy practices.
Expo supports mobile-application infrastructure. Apple and Google provide their respective app-store and platform services. These platform providers are not described as subprocessors in every context because their role depends on the service and their direct relationship with the user.
See the current Subprocessors and recipients list for details and source links.
10. International transfers
Although CleanTracker’s primary hosting and database are in Frankfurt, some providers may process or permit access to personal data outside the EU/EEA. Where Idealrent ApS is responsible for such a transfer, we use an applicable adequacy decision, the European Commission’s Standard Contractual Clauses, or another lawful safeguard. Provider-specific information is maintained on the Subprocessors page. We do not claim that all processing remains exclusively in the EU.
11. Retention and deletion
We keep controller-side account, relationship, support, billing, and security data only for as long as needed for the relevant purpose. Some records may be retained longer where required for accounting or other statutory obligations, fraud and security, contractual documentation, or establishing, exercising, or defending legal claims.
Customer operational data processed on behalf of a customer is retained during the customer relationship and for up to 30 days after termination. It is then deleted from active systems. Backup copies expire through the normal backup cycle afterward; the current primary database backup retention is approximately three days. This operational-data rule does not require deletion of separate controller-side records that Idealrent ApS must or may lawfully retain for the reasons above.
12. Your rights
Subject to the conditions in applicable data-protection law, you may request access, correction, deletion, restriction, or portability of your personal data, and object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting prior lawful processing.
If your request concerns operational data entered by a CleanTracker customer, contact that customer organization first because it is normally the controller. We assist customers with requests as required by the DPA.
Contact us at [email protected]. You may also complain to the Danish Data Protection Agency (Datatilsynet) or another competent supervisory authority.
13. Changes
We may update this Policy when our service or legal obligations change. The effective and last-updated dates above identify the published version. Material changes will be communicated through an appropriate service or customer channel where required.