Skip to content
Extero
Home Terms Sign in Start free trial
Legal

Privacy Policy

Last updated 28 July 2026 Covers extero.app, app.extero.app, portal.extero.app and the Extero mobile apps

We don't sell data, we don't run advertising trackers, and we don't mine your customer list. Here is exactly what we hold, why we hold it, and who else touches it.

Controller details — to be completed before launch

The data controller for this policy is [LEGAL ENTITY NAME], company number [COMPANY NUMBER], registered office [REGISTERED ADDRESS], United Kingdom. ICO registration number [ICO NUMBER, if registered].

Privacy questions and data rights requests: [email protected].

The short version

There are two kinds of personal data here. Yours — your name, email, business details and billing records — where we decide how it's used and are the controller. And your customers' — the names, addresses, phone numbers and job photos you put into Extero — where you decide, you are the controller, and we only act on your instructions as your processor.

On this page

  1. Who is responsible for what
  2. What we collect about you
  3. Data you enter about your customers
  4. Why we use it, and our lawful bases
  5. Who else processes it
  6. Where data goes
  7. How long we keep it
  8. How we protect it
  9. Cookies and local storage
  10. Your rights
  11. Children
  12. Changes and contact

1 Who is responsible for what

We are the controller for the data about you as our customer: your account, your business profile, your subscription and billing history, your support emails, and technical records of how the app is used.

You are the controller for the personal data you enter about the people you clean for. We are your processor for that data: we store it, move it where you tell us to, and delete it when you tell us to. We do not decide what you collect, we don't use it for our own purposes, and we never sell it or share it with other Extero users.

That split matters in practice. If one of your customers asks to see or delete what's held about them, the request is yours to answer — and we'll help you do it.

2 What we collect about you

When you create an account

  • Your email address and a password, stored only as a secure hash — we never see or store the password itself.
  • Your business name, and later whatever you add to your business profile: trading name, phone number, address, logo, bank details for invoices.
  • If you sign in with Apple or Google, the identifier and basic profile they pass us. We don't get your password.

When you subscribe

  • Subscription status, plan, renewal dates and payment history. Card details go straight to Stripe and are never stored on our systems.

While you use the app

  • Technical records needed to run and secure a service: IP address, device and browser type, app version, timestamps, and error logs.
  • Records of messages and emails sent through Extero — recipient, time, delivery status and content — so you have a history and so billing for message credits is accurate.
  • Push notification tokens, if you allow notifications on a mobile device.

When you contact us

  • Your emails to support and our replies, kept so we have the history when you write again.

We do not run advertising pixels, behavioural profiling or third-party ad trackers across our site or app. Our marketing pages (extero.app) may record a basic visit log for our own operations — page path, approximate time, IP address, browser/device type, and referrer — so we can understand traffic to the product site. This is not sold or used for advertising.

3 Data you enter about your customers

Depending on how you work, this typically includes names, addresses, phone numbers, email addresses, notes, job and cleaning history, prices and amounts owed, before and after photos, Direct Debit mandate references, and any leads you receive.

You are responsible for having a lawful basis to hold it, for telling your customers what you do with it, and for keeping it accurate. Please don't put anything in Extero that you don't need — particularly special category data such as health information. The notes field is not the place for it.

If you connect Facebook Lead Ads on the Growth plan, the contact details people submit in your lead form arrive in your leads inbox. Those people gave that information to you, and it is yours to handle accordingly.

4 Why we use it, and our lawful bases

Running your account Creating your workspace, signing you in, syncing your data across web and mobile. Basis: performance of our contract with you.
Billing Taking subscription payments, handling failed payments, keeping accounting records. Basis: contract, and legal obligation for the records we must keep.
Support Answering your questions and investigating faults you report. Basis: contract, and our legitimate interest in supporting our own product.
Security and abuse prevention Bot checks on sign-up, rate limiting, fraud and abuse investigation, audit logs. Basis: legitimate interests, and legal obligation where it applies.
Service emails Confirming your address, resetting your password, telling you about changes that affect you. Basis: contract.
Improving the product Understanding which features are used and where things break. Basis: legitimate interests. We use aggregated and technical data for this, not your customer list.
Marketing emails Only if you ask for them, or where we're allowed to email an existing business customer about closely related features. Basis: consent or legitimate interests, and every one has an unsubscribe link.

5 Who else processes it

We use established providers rather than building everything ourselves. Each is bound to process data only for the purpose we've engaged them for.

Supabase Database, authentication, file storage and server functions — the core of the service.
Cloudflare Hosting and delivery of our sites, DNS, and the Turnstile bot check on sign-up and password reset.
Stripe Our subscription billing, and — through your own connected account — card payments from your customers.
GoCardless Direct Debit mandates and collections through your own connected account.
Twilio Sending and receiving the text and WhatsApp messages you send from the app, and providing your business number.
Resend Delivering transactional email — confirmations, password resets, and the quotes and invoices you email.
Ideal Postcodes UK address and postcode lookup when you add a customer.
OpenAI Optional AI features only — suggesting a reply to a lead, or reading customer details from a photo you upload. Used only when you trigger the feature, and not used to train their models on our account.
Meta Only if you connect Facebook Lead Ads on the Growth plan, to receive the leads your own ads generate.
Apple and Google App distribution, push notifications, optional sign-in, and the maps app your device opens for directions.
Google Fonts Our marketing pages load fonts from Google, which means Google receives the IP address of visitors to those pages.

We will also disclose data where the law requires it — a valid court order or regulatory demand — and, if the business is ever sold or reorganised, to the buyer under equivalent obligations. We'll tell you if that happens.

6 Where data goes

We aim to keep data in the UK and the European Economic Area. Some of the providers above are based in, or have operations in, the United States and elsewhere, so some data is transferred outside the UK.

Where that happens we rely on the safeguards UK and EU law provides — the UK's International Data Transfer Agreement or Addendum, the EU Standard Contractual Clauses, or an adequacy decision covering the provider. You can ask us which applies to a particular provider.

7 How long we keep it

  • Your account and business data: for as long as the account is open.
  • After you close the account: a short grace period — normally 30 days — during which it can be restored or exported, then deletion.
  • Trials that never became subscriptions: deleted after a period of inactivity.
  • Billing and tax records: six years, because UK tax law requires it.
  • Message and email delivery logs: kept for a limited period for dispute resolution and credit accuracy.
  • Security and audit logs: kept for a limited period, then deleted or aggregated.
  • Your customers' data: for as long as you keep it. Delete a customer in the app and it goes; there is no shadow copy we keep for ourselves.

8 How we protect it

  • Everything travels over encrypted connections (TLS), and data is encrypted at rest by our hosting provider.
  • Each business sits in its own workspace, enforced at the database level with row level security, so one account cannot read another's data.
  • Passwords are stored as salted hashes. Sign-up, sign-in and password reset are protected by a bot check.
  • Team permissions let you hide prices, round values and financials from staff who don't need them.
  • Access to production systems is limited to those who need it for support or operations.

No system is perfectly secure. If a breach ever affects your data we will tell you and, where required, the ICO — within 72 hours of becoming aware of it.

9 Cookies and local storage

We use only what the service needs to work, which is why you don't get a cookie banner asking to track you:

  • Your session — stored in your browser so you stay signed in, or in secure device storage on mobile.
  • Your preferences — such as the theme you picked.
  • The bot check — Cloudflare Turnstile sets what it needs to confirm you're a person on sign-up and password reset.

Clearing your browser storage signs you out. There are no advertising or cross-site tracking cookies to opt out of.

10 Your rights

Under UK and EU data protection law you can ask us to:

  • tell you what personal data we hold about you, and give you a copy;
  • correct anything inaccurate;
  • delete your data, where we don't have to keep it;
  • restrict or object to a particular use, including any use based on legitimate interests;
  • give you your data in a portable format, or send it to someone else;
  • stop sending you marketing, at any time.

Email [email protected] and we'll respond within one month. There's no charge unless a request is excessive or repetitive.

If one of your cleaning customers contacts us directly, we'll point them to you, because you're the controller of that data — and then help you deal with it.

If you're unhappy with how we've handled your data you can complain to the Information Commissioner's Office at ico.org.uk, or on 0303 123 1113. We'd appreciate the chance to put it right first.

11 Children

Extero is a tool for running a business and isn't intended for anyone under 18. We don't knowingly collect data from children. If you believe a child's data has ended up with us, tell us and we'll remove it.

12 Changes and contact

We'll update this policy as the product changes or we add a provider. The date at the top always reflects the current version, and if a change materially affects how we use your data we'll email you before it takes effect.

Questions, requests, or something here that doesn't match what you've experienced — email [email protected]. Our Terms of Service sit alongside this policy.

© Extero. All rights reserved. Home · Terms · Contact