Broom — Privacy Policy
Last updated: 2 September 2026 Effective date: 1 September 2026
1. Who we are
Broom ("Broom", "we", "us", "our") operates the Broom mobile application and related services (the "Service"), a marketplace that connects customers who need home cleaning and related services with independent service providers and cleaning companies.
- Legal entity: GURZ LTD, a company registered in England and Wales
- Registered address: 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
- Data controller contact: info@beclairiz.com
For the purposes of applicable data-protection law, Broom is the controller of the personal data described in this policy, except where we act as a processor on behalf of a cleaning company for that company's own staff-management records.
2. Scope
This policy applies to everyone who uses the Service, including:
- Customers who book services;
- Individual service providers who offer services;
- Companies (company administrators) and their staff / team members;
- Visitors who create an account but do not transact.
It covers the Broom app on iOS and Android and our backend at
api.beclairiz.com. It does not cover third-party services that
have their own privacy policies (see Section 7).
3. Personal data we collect
3.1 Data you provide
| Category | Examples | Who it applies to |
|---|---|---|
| Account & identity | Name, email address, phone number, password (stored hashed), gender, profile photo, chosen role(s) | All users |
| Provider profile | Bio, years of experience, languages spoken, certifications, specializations, service-area location (latitude/longitude) and radius, city/country | Providers, companies |
| Identity verification (KYC) | Government ID images, selfie / liveness check, verification status | Providers (and company admins where required) |
| Booking details | Service type, property details you enter (room count, approximate size, presence of pool/garden, etc.), address and geolocation of the job, scheduled date/time, notes, reference photos or video you attach, provider preferences | Customers |
| Payment data | Card details are collected and stored by our payment processor (Stripe), not by Broom; we retain payment metadata such as amount, currency, last 4 digits, brand, transaction status, and payout status | Customers, providers, companies |
| Payout / banking data | Bank or Stripe Connect account details for receiving payouts, withdrawal requests | Providers, companies, staff |
| Communications | Messages you send through in-app chat, support tickets and their contents, ratings and written reviews | All users |
| Company / staff records | Staff schedules, leave, salary payment records, performance data | Companies (we process on their behalf), staff |
3.2 Data collected automatically
| Category | Examples |
|---|---|
| Device & app data | Device model, operating system version, app version, language, time zone, crash and diagnostic logs |
| Location data | Precise device location when you grant permission — used to set a provider's service area, find nearby jobs/providers, show a job's location on a map, and support live location during an active job. You can disable this in your device settings; some features will not work. |
| Usage data | Screens viewed, features used, bookings created, approximate interaction timestamps |
| Push notification token | A Firebase Cloud Messaging (FCM) token so we can send you notifications |
| Connection data | IP address, and session/authentication tokens |
3.3 Data from third parties
- Identity verification results from our KYC provider (Persona).
- Payment and payout status from Stripe.
- Geocoding results (turning coordinates into a place/city name) from the device's geocoding service and map provider.
We do not knowingly collect data from children. The Service is intended for users aged 18 and over.
4. How we use personal data and our legal bases
| Purpose | Legal basis (GDPR-style) |
|---|---|
| Create and manage your account; authenticate you | Performance of a contract |
| Match customers with providers/companies and facilitate bookings | Performance of a contract |
| Process booking payments, commissions, refunds, and provider payouts | Performance of a contract; compliance with legal obligations |
| Verify provider identity (KYC) and prevent fraud | Legal obligation; legitimate interests (trust and safety) |
| Enable in-app messaging, reviews and support | Performance of a contract; legitimate interests |
| Send transactional notifications (booking status, messages, payments) | Performance of a contract |
| Send service updates or marketing (where permitted) | Consent, or legitimate interests where allowed; you can opt out |
| Provide AI-assisted price estimates | Performance of a contract / legitimate interests |
| Operate blocking, reporting and content moderation, and keep the Service safe | Legitimate interests; legal obligation |
| Maintain security, debug, and improve the Service | Legitimate interests |
| Comply with law, enforce our Terms, resolve disputes | Legal obligation; legitimate interests |
Where we rely on consent (e.g. precise location, marketing), you may withdraw it at any time without affecting prior processing.
Automated processing
Broom uses an automated dispatch/matching engine to route booking requests to providers, and an AI model to generate price estimates. These do not produce legal or similarly significant effects on you without a human in the loop; final acceptance of a job is made by a provider, and you can contact support to query any estimate or match.
5. Sharing personal data
We share personal data only as described here:
- With the other side of a booking. When a booking is made, the customer and the assigned provider/company/staff see the information needed to perform the job — name, profile photo, job address and location, scheduled time, contact through in-app chat, and any notes/photos attached to the booking.
- With companies about their staff. A company administrator can see their staff members' profile, schedule, leave, salary payments and performance within the Service.
- With service providers acting for us (processors):
- Stripe — payments, cards, payouts, Stripe Connect onboarding.
- Persona — identity verification (KYC).
- Google Firebase — push notifications (Firebase Cloud Messaging).
- OpenAI — AI price-estimate generation. Details are sent from our backend to OpenAI's model; the app does not contact OpenAI directly, and inputs are not used to train OpenAI's models.
- Google Maps Platform — displaying maps, and geocoding/reverse-geocoding to resolve coordinates into place names.
- Cloud hosting / infrastructure provider — hosting the Broom backend
(
api.beclairiz.com).
- For legal reasons — to comply with law, court orders or lawful requests; to enforce our Terms; to detect or prevent fraud, security or technical issues; or to protect the rights, property or safety of Broom, our users or the public.
- In a corporate transaction — if Broom is involved in a merger, acquisition, financing or sale of assets, personal data may be transferred, subject to this policy.
We do not sell personal data.
6. International transfers
Our providers (Stripe, Google/Firebase, Persona, OpenAI, hosting) may process data outside the United Kingdom and the European Economic Area, including in the United States. Where required, we put in place appropriate safeguards — such as the UK International Data Transfer Agreement / Addendum, the EU Standard Contractual Clauses, or transfers to a country covered by a UK or EU adequacy decision. Contact us for details.
7. Third-party services
The Service integrates with the following, each governed by its own privacy policy:
- Stripe — https://stripe.com/privacy
- Persona — https://withpersona.com/legal/privacy-policy
- OpenAI — https://openai.com/policies/privacy-policy
- Google / Firebase / Google Maps Platform — https://firebase.google.com/support/privacy and https://policies.google.com/privacy
8. Data retention
We keep personal data for as long as your account is active and as needed to provide the Service, then:
- Account deletion — recovery window: when you request deletion, your account is deactivated immediately and enters a 30-day recovery window during which you can sign back in to cancel. After 30 days the deletion is permanent and irreversible.
- Account and profile data: deleted or anonymised within 90 days of the deletion request (i.e. within roughly 60 days of the recovery window closing), unless we must keep it longer.
- Booking, payment and payout records: retained for 6 years to meet UK tax, accounting, anti-fraud and dispute-resolution obligations.
- KYC records: retained for the period required by applicable law and our verification provider's requirements (typically up to 7 years).
- Chat and support messages, and abuse reports: retained for 24 months, then deleted.
- Diagnostic logs: retained for up to 90 days.
9. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- delete your data ("right to be forgotten");
- restrict or object to certain processing;
- data portability;
- withdraw consent;
- lodge a complaint with a data-protection authority — in the UK, the Information Commissioner's Office (ICO), https://ico.org.uk; in the EU/EEA, your local supervisory authority; in the US, your state Attorney General where applicable.
How to exercise them: in the app, use Profile → Account settings (edit profile, notification settings) and the account-deletion request flow, or email info@beclairiz.com. We will respond within the period required by law (generally 30 days, or 45 days for US state privacy requests). We may need to verify your identity first.
Deleting your account deactivates it immediately and starts a 30-day recovery window; after that the deletion is permanent and your profile and personal data are removed or anonymised within 90 days of the request. Some records are retained longer as described in Section 8. Full step-by-step instructions are at https://beclairiz.com/account-deletion.
10. Security
We use encryption in transit (HTTPS/TLS), hashed password storage, scoped access tokens, and access controls. Card data is handled by Stripe (PCI-DSS). No method of transmission or storage is completely secure; we cannot guarantee absolute security. If a breach affects your data, we will notify you and the relevant authority as required by law.
11. Notifications and marketing
- Transactional push notifications (booking status, new messages, payments) are part of the Service. You can turn categories off in Notification settings or in your device settings.
- Marketing communications are sent only where permitted; every marketing message includes an opt-out.
12. Changes to this policy
We may update this policy. If changes are material we will notify you in the app or by email before they take effect. The "Last updated" date shows the current version.
13. Contact us
- Privacy / data-protection enquiries: info@beclairiz.com
- Support: support@beclairiz.com
- Post: GURZ LTD, 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ