Clear limits on the data NeatRound handles.
This policy covers the NeatRound website, web product, and technician app. NeatRound is in controlled pre-launch testing, and this policy will receive legal review before commercial launch.
Scope
NeatRound is washroom service software for businesses managing recurring service rounds. This policy applies to information handled through NeatRound and its public website. A customer business may also have its own privacy notice for the workforce, customers, sites, and contacts it manages in NeatRound.
NeatRound is not designed for health records, government identifiers, payment-card details, children's data, biometric identifiers, or unrelated sensitive information. Users should not enter that material into notes, uploads, or support messages.
Our role
A customer business generally decides why its customer, site, unit, technician, and service information is entered and used. NeatRound processes that operational information to provide the service. NeatRound separately determines how limited account, security, billing, abuse-prevention, and service-operation information is used to run and protect the platform.
Data we handle
- Account data: email address, display name, organisation membership, role, authentication state, and security events.
- Operational data: customers, contacts, sites, locations, serviceable units, schedules, rounds, service outcomes, issues, optional issue photos, proof records, and invoice-ready work.
- Device and service data: an app-scoped installation identifier, sync state, timestamps, and bounded error or security events needed for offline work and service reliability.
- Support data: information a person chooses to include when contacting NeatRound for help.
- Website data: ordinary request data such as IP address, browser details, requested page, timestamp, and security signals processed by our hosting provider.
NeatRound does not sell personal information, run advertising trackers, create cross-site profiles, continuously track technician location, or use customer operational data to train general-purpose AI models by default.
How we use data
- Provide accounts, tenant-isolated workspaces, offline field workflows, service records, proof, and invoice preparation.
- Authenticate users, enforce permissions, prevent abuse, investigate security events, and protect service integrity.
- Deliver transactional messages and respond to requested support.
- Meet accounting, dispute, legal, and contractual obligations.
- Diagnose and improve product reliability using minimised operational signals rather than customer content.
Required service messages are separate from marketing. NeatRound will not send optional marketing messages without an appropriate choice and unsubscribe process for the recipient's region.
Providers and international processing
NeatRound uses Supabase for database, authentication, and private file infrastructure; Vercel for application and website hosting; and Resend for transactional email. These providers process only the information needed for their service and may process it in the United States or other countries where they operate.
NeatRound reviews provider access, data location, security, and contractual safeguards before production use. New providers that materially change personal-data handling require a privacy and security review before activation.
Security
NeatRound uses encryption in transit, provider encryption at rest, tenant isolation at the database and application layers, deny-by-default permissions, private file access, audit records, rate limits, and restricted support access. The mobile app keeps offline business data in an encrypted device database designed to be excluded from device backup.
No system is risk-free. Anyone who believes they have found a security issue should contact hello@neatround.com without including customer data, passwords, access codes, or exploit details in the first message.
Retention and deletion
NeatRound keeps data only for a defined service, security, support, accounting, dispute, or legal purpose. Raw bulk-import files are short-lived and scheduled for deletion after processing. Routine application logs have a 30-day engineering baseline; security records may be kept longer where needed to investigate and prevent abuse. Backups expire through a rolling recovery schedule.
When a customer organisation ends service, its operational data enters a controlled export and recovery period before hold-aware deletion. Individual account deletion removes the person's login and access across organisations. Historical service, proof, invoice, and audit records may keep a pseudonymous identifier or neutral Former member label where the business record must remain understandable.
The exact period for some business and security records depends on the customer agreement, legal requirements, active disputes, and approved retention schedule. See account deletion for the self-service process and what happens to associated data.
Your choices and rights
Depending on location and context, a person may have rights to access, correct, export, object to, restrict, or delete personal information, or complain to a privacy regulator. A customer business may need to handle requests about operational data it controls; NeatRound will assist that business where required.
To make a request, email hello@neatround.com. NeatRound may need to verify identity and authority before disclosing or changing information. There is no fee for an ordinary request, though the law may permit limits for manifestly unfounded or excessive requests.
Children
NeatRound is a business service and is not directed to children. Accounts are provided through customer organisations for authorised workforce use.
Changes to this policy
NeatRound will update the effective date and publish material changes here. Where a change materially affects active accounts, NeatRound will also provide an appropriate in-product or service notice before the change takes effect where required.
Contact NeatRound
Privacy questions, requests, or complaints can be sent to hello@neatround.com. Include the minimum information needed to identify the request. Do not send passwords, authentication codes, site access instructions, or customer files by email.