1. Who we are and what this policy covers
TidyupCo, also known as Tidyup & Co., is a cleaning business based in Newmarket, Ontario, Canada. In this policy, ‘we’, ‘us’ and ‘our’ mean TidyupCo. We are responsible for the personal information we collect through our website and booking-request application.
This policy covers tidyupco.ca and www.tidyupco.ca, the on-site booking and quote forms, referral features, and TidyupCo Website Booking, including its private Gmail authorization helper. It explains the information collected, why it is used, where it goes, how it is retained, and the choices available to customers and the Google account owner.
A booking request is not a confirmed appointment. The form does not take payments, create customer accounts, or require customers to sign in with Google. Google authorization is used only by the business owner to connect the business Gmail account.
2. Information we collect
We collect information you provide and limited technical information needed to operate and understand the website. Required fields are identified on the request form. Please provide only details relevant to your cleaning request; do not send payment-card numbers, passwords, government identification, alarm codes, or sensitive medical information.
- Booking and quote requests: your name, phone number, town or city, and selected cleaning service are required. Email address, preferred date and time, property details and other notes are optional or can be left flexible.
- Request context: the page path used to submit the form, a submission identifier, a generated reference, submission time, and a referral code when available. Notes may contain personal information that you choose to include.
- Direct communications: information contained in emails, calls and follow-up messages you send us. If you later arrange a cleaning, you may provide an address and service instructions directly to our team; these are not required by the initial website form.
- Technical and usage information: hosting services can process IP addresses, request URLs, browser and device information, timestamps, and operational logs. Analytics tools can process page visits, referring sources, approximate location, engagement and performance events.
- Referral information: a randomly generated browser referral code, its creation time, and the referral code and time associated with a referral-link visit. These are browser identifiers, not Google account identifiers.
- Owner-only Google authorization: the authorized account email and verified-email status, OAuth authorization credentials, access and refresh tokens, and Gmail API send results. See section 4 for the exact permissions and limits.
3. Why we use this information
We use request details to prepare a quote, discuss the service, check availability, respond by phone or email, and arrange an appointment if you choose to proceed. The email address you optionally provide is used as a reply address so our team can respond to you. A preferred date does not reserve a time slot.
We also use limited information to attribute referrals, identify duplicate submissions, reduce spam and abuse, investigate delivery problems, and measure website usage and performance. Booking analytics record that a request was sent; our custom booking event does not include your name, phone number, email address, free-text notes, or Google authorization tokens.
Submitting a request allows us to handle the information for that request and related service communications. It does not automatically subscribe you to a marketing mailing list. Any new use outside the purposes explained here requires an appropriate basis and, where required, separate consent.
4. Google user data and Gmail permissions
Only the business owner authorizes the business account, tidyupproco@gmail.com. Customers are not asked to connect their Gmail accounts. The private setup helper checks the account email and verified-email status so that an unrelated Google account cannot be connected by mistake. The helper does not create a customer Google profile database.
The gmail.send permission allows the application to send email on behalf of the authorized account. Although Google grants a sending capability, our application uses it only to send booking and quote notifications to the fixed business mailbox, tidyupproco@gmail.com. The notifications contain the details submitted by the customer. The application does not send automatic emails to arbitrary customer-supplied recipients.
The userinfo.email permission is used to check the authorized account email and its verification status during setup. We do not request Gmail inbox-reading, message-listing, message-deletion, contacts, Calendar, Drive, or full-mail permissions. The Gmail integration does not read existing messages or attachments. The owner may independently read and respond to received requests in Gmail.
The refresh token is stored in private server-side configuration and used to obtain short-lived access tokens for sending notifications. Access tokens and Gmail send-result identifiers are processed by the server; they are not intentionally returned to visitors or included in analytics. Customers receive our request reference, not a Gmail access token or mailbox message identifier.
Google-derived account information and authorization data are used only to connect the business mailbox, send the notifications described here, and maintain that connection. They are not used for advertising, profiling, sale, credit decisions, or training artificial-intelligence or machine-learning models. They are not given to another app for an unrelated purpose.
TidyupCo Website Booking's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy and the Google Workspace user data and developer policy, including the Limited Use requirements. People may access Google-derived data only with documented affirmative permission to view the specific information, as necessary for security or an applicable legal obligation, or for internal use of aggregated and anonymized information permitted by those policies. This is not permission for staff to browse Google data for an unrelated purpose.
7. Storage, retention and deletion
Different types of information are held in different places. The request form keeps entries in the current page's memory while you fill it out; it does not save a draft to local storage. The website has no persistent queue that stores a request before email delivery. A delivery failure is shown to you rather than silently retaining the request for a later send.
Booking emails and follow-up correspondence are retained in the business Gmail account until manually deleted or handled through its configured retention settings. The booking application does not automatically delete emails after a fixed number of days. Retention should be limited to responding to the inquiry, administering an agreed service, resolving disputes and meeting applicable recordkeeping requirements. You can ask us to delete an inquiry or explain why a particular record needs to be retained.
The request handler temporarily holds hashed client identifiers, request fingerprints, submission IDs and references for rate limiting and duplicate detection. These per-instance records have a 15-minute validity window. Expired records are removed when subsequent requests are processed or when the instance ends; this is not a guarantee of physical deletion at exactly 15 minutes. Hashes are not a claim that the information is fully anonymous.
The owner's refresh token and OAuth client settings remain in private configuration while the Gmail connection is enabled. Short-lived access tokens are used in server memory. To end the connection, revoke the app's Google access and remove its credentials from hosting settings and local credential files. Revoking access does not delete booking emails already in Gmail.
Referral-cookie and browser-storage lifetimes are described in section 6. Hosting logs, provider backups and analytics records follow the providers' retention systems and the applicable account settings; the website does not independently control immediate erasure from every backup. We do not promise a provider retention period that has not been configured and verified. Contact us for help with deletion of information under our control and relevant provider controls.
8. How the application protects information
The public website and Google API connection use HTTPS. OAuth tokens are kept in private server-side configuration, not public pages or client-side environment variables. The Gmail account password is not collected by the application. The owner approves access on Google's own authorization screen.
The booking handler validates submitted fields, restricts request size, checks the request origin, uses a hidden spam-check field, and applies per-instance rate and duplicate guards. Its delivery-error logging is limited to an error category and request reference; it does not intentionally log the submitted name, phone, email, notes or authorization tokens. Hosting providers may separately retain technical request logs.
No internet transmission or storage system is guaranteed to be completely secure. The application is not a secure channel for passwords, payment credentials, medical records or property-entry codes. If you believe information has been exposed or misused, contact our privacy contact using the details below.
9. Processing outside Canada
TidyupCo is based in Ontario, but Google, Vercel and their infrastructure providers may process or store information in other countries, including the United States. The site does not promise Canada-only data residency. Information processed abroad may be subject to that country's laws and lawful access requirements.
Provider privacy information is linked in section 5. Contact us if you have questions about using the online form or need to discuss an alternative way to provide your cleaning details.
10. Your choices and privacy requests
You can leave optional fields blank, avoid including sensitive details, or call us instead of using the form. We need sufficient contact and service information to respond to a request; withdrawing permission to use that information can prevent us from completing the request.
Subject to applicable law, you can ask to access or correct personal information we hold, request deletion, withdraw consent for a use that depends on consent, or ask how your information has been used or disclosed. Email our privacy contact with the subject ‘Privacy request’ and enough context to locate the record, such as a request reference or the email address used. Do not send identification documents unless a proportionate identity-verification step is specifically needed.
We may need to verify that you are entitled to make the request to avoid disclosing another person's information. Some records may need to be retained for legal, contractual, security or dispute-resolution reasons. If a request cannot be fulfilled in full, we will explain the relevant limitation and respond within the time required by applicable law.
The Google account owner can remove the app's access in Google Account connections at any time. This stops future authorized Gmail API use; it does not remove previously delivered email. Removing the private hosting credentials also disables website email delivery. Customers do not have a connected Google account to revoke in this application.
11. Other websites and children
Links to Google reviews, Yelp, Instagram and other outside websites take you to services with their own privacy practices. Visiting those links can disclose information to the service you choose to visit. This policy does not control those services or any information you submit directly to them.
The booking application is intended for people arranging cleaning services, not for children. We do not ask for a child's Google account or intentionally solicit children's personal information. If a child has submitted personal details without appropriate permission, contact us so we can review and address the information.
12. Changes to this policy
We may update this policy when our website, providers or data practices change. The effective and last-updated dates at the top identify the published version. Material changes to how information is used will be explained, and additional notice or consent will be sought where required. An update does not authorize a previously undisclosed use of Google data.
13. Contact us about privacy
Our privacy contact is the TidyupCo business owner. Contact us about access, corrections, deletion, Google authorization, cookies, or a privacy complaint. Please use ‘Privacy request’ in the email subject so it can be identified separately from a cleaning request.
TidyupCo / Tidyup & Co. — Newmarket, Ontario, Canada. Email: tidyupproco@gmail.com. Phone: (647) 793-4973. If your concern is not resolved with us, you may contact the Office of the Privacy Commissioner of Canada or another appropriate authority.
TidyupCo business owner · Privacy contact
