Privacy Policy
Last updated 28 September 2026
1. Scope
This policy describes how JaniSync collects and uses information through the JaniSync platform, used by a commercial cleaning company (“Customer”) and its own employees (“cleaners”). Customer is responsible for its own use of the service and for giving its employees any additional notice its jurisdiction requires beyond what is described below.
2. What we collect
Account information for owners (name, email, password — stored as a one-way hash, never in plain text); employee (“cleaner”) profile information entered by an owner (name, pay rate, a 4‑ or 6‑digit PIN, stored the same way passwords are); building and site addresses entered by an owner; timesheets and bid/proposal data; and, at clock-in and clock-out only, device GPS coordinates used to verify attendance at a job site.
3. If you only used the public bid calculator
You can use the bid calculator on our website without an account, and it sends nothing to us until you ask it to. If you request the quote as a PDF, we store the email address you give us, the company name if you provide one, and the quote you generated, so that we can send you that document and so we know which quote it was. We send the one email you asked for; we do not add you to a sequence, and we do not share or sell the address. We delete these records after 24 months if you never became a customer and we never contacted you, and you can ask us to delete yours sooner at any time using the contact details in Section 15 — you do not need an account to make that request.
4. What we do not collect
JaniSync does not track employee location continuously, in the background, or at any point between clock-in and clock-out. Location is captured only at the two moments described above, only from a device actively being used to clock in or out, and only while the app is open and the action is taking place.
5. How we use information
We use the information above to provide the service: authenticating owners and cleaners, verifying attendance at a job site, computing payroll totals, generating bid prices, and sending account and billing notifications. We do not sell personal information, and we do not use it for third-party advertising.
6. Retention
Raw location coordinates are purged after 90 days. The derived record of whether a clock-in was verified at the job site, and the hours themselves, are retained for the period required for payroll and wage-and-hour recordkeeping — currently seven years — regardless of subscription status, because deleting evidence that someone was paid correctly is not a privacy protection for that person.
7. Deletion and account closure
An organization owner may request deletion of their organization’s account from Settings at any time. This anonymizes personal information belonging to every owner and employee on the account — names, emails, phone numbers, and device credentials are destroyed — while the underlying shift and payroll math is retained with nothing identifying attached to it, to meet the recordkeeping obligation described above. An employee may separately request export or erasure of their own data by asking their employer, who can action it from the Roster screen.
8. AI features and automated decisions
Bid-pricing recommendations are generated only for organizations that enable AI features; data sent to our AI provider excludes names, exact addresses, wage rates, and PIN information. Sharing anonymized bid data across organizations to improve regional pricing benchmarks is off by default and requires an organization’s explicit opt-in. No AI output is used to make an automated decision about hiring, discipline, pay, or termination — flags and recommendations are always reviewed by a human before they affect a real person.
9. Third-party service providers
We use a payment processor to handle billing (no card details reach our servers); a cloud infrastructure provider to host the service, which also delivers our account and notification emails and, where an organization uses text-message onboarding, its SMS messages; and, where an organization has enabled it, an AI provider for bid-pricing assistance under the limits described above. These providers act on our instructions and are not permitted to use the data for their own purposes. Each one is named, with what it processes and where, in our Data Processing Addendum at janisync.com/dpa — which is also the contract that governs our handling of an organization’s data as its processor, and which business customers and their procurement teams should read alongside this policy.
10. Security
Passwords and employee PINs are stored as one-way cryptographic hashes, never in plain text. All traffic is encrypted in transit. Access to a company’s data is restricted to that company’s own owners and employees, enforced on every request.
11. Who we are, and where data is processed
JaniSync is operated from Ontario, Canada and serves customers in the United States. Customer Data is hosted and processed in the United States, on infrastructure located there. As a Canadian organization we are subject to PIPEDA in our own right, and our agreements with US customers are governed by Ontario law as set out in the Terms of Service. If you access the service from outside the United States, your information is transferred to and processed in the United States; where that data originates in the European Economic Area, the United Kingdom or Switzerland, the transfer is made under the Standard Contractual Clauses described in our Data Processing Addendum.
12. Your privacy rights
Depending on where you live, you may have the right to know what personal information we hold about you, request a copy of it, request correction or deletion, and object to or restrict certain processing, and we do not sell personal information or use it for cross-context behavioral advertising, so there is nothing to opt out of on that front. California residents have these rights under the CCPA/CPRA; Canadian residents may exercise similar rights under PIPEDA; and users in the European Economic Area, UK, or Switzerland have rights under the GDPR, including the right to lodge a complaint with a supervisory authority and, per Section 8 above, the right not to be subject to a solely automated decision with legal or similarly significant effects. An organization’s employees should direct requests to their employer as described in Section 7; an organization owner can reach us using the contact details below.
13. Children’s privacy
JaniSync is a business product intended for use by adult employees of a commercial cleaning company and is not directed at children. We do not knowingly collect personal information from anyone under 16.
14. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email or an in-app notice before they take effect.
15. Contact
Questions about this policy, and requests to access, correct or delete your personal information, can be sent to support@janisync.com. You do not need an account to make a request — if you only ever used the public bid calculator, that address is how you ask us to delete what Section 3 describes. We aim to respond within 30 days.