Skip to content
Limpela
Become a founder

This page is also in

Limpela Privacy Policy

Last updated 2026-09-23

This policy explains what personal information Limpela collects, why we collect it, who helps us handle it, and the choices you have. Limpela is run by Harmony AI Technologies ("Harmony", "we" or "us").

It covers our website at limpela.com, the Limpela app at limpela.app, the crew app, and the quote and invoice links that businesses send to their clients.

This policy takes effect on September 23, 2026.

1. Our two roles

Limpela is used by cleaning businesses. We handle personal information in two different ways.

Inside Limpela, each company has its own workspace. In the app, only the people a company invites can see its data. Our service providers, and the people at Harmony who run Limpela, can also access it when needed to run, support or secure the service.

  • For the business. A business's clients, properties, jobs, quotes, invoices, payments and crew time records belong to that business. The business decides what goes in and why. We process this information on its behalf, as its service provider. If you are a client or crew member of a business that uses Limpela, that business is responsible for your information, so please contact it first. We will help it respond.
  • For ourselves. We are responsible for the accounts of people who sign in, our customers' billing, the forms on our website, and technical logs.

2. What we collect

We collect only what Limpela needs to work:

  • Launch list. If you join the launch list, we collect your email, company name, crew size, language and the page you signed up from. We use it to send one email on launch day.
  • Contact form. If you ask us to call you, we collect your name and email, and, if you give them, your phone, company name, crew size and message. We also record your language. We use it only to get back to you about Limpela.
  • Account details. When you sign up or accept an invitation, we collect your email address, name, preferred language and your role in the business. Our sign-in provider stores your password in a protected (hashed) form. If sign-in with Google or Apple is offered and you choose it, we receive your email and basic profile from them.
  • Invitations. When a business invites someone, we store that person's email address, the role, who sent the invitation and when it expires. The record stays after the invitation is used, revoked or expired.
  • Billing details. When a business buys a plan, Stripe collects the card and billing details. We send Stripe the business name and the email of the person who checks out. We keep the Stripe customer and subscription references, the plan, its status and its renewal date. We also check the email you sign up with against Stripe, so we can match your payment to your new account and fill in your name and email on the sign-up form. We never see or store full card numbers.
  • Business settings. The business name, colors, contact email, phone and address, invoice and quote settings, tax rate and currency, and a logo if you add one.
  • Client and property records. Names, emails, phone numbers, notes, tags, how the client found the business, property addresses and map locations, and notes about pets, parking and access. Access notes can hold door codes, alarm codes and key locations, so we limit who can see them.
  • Work records. Jobs, schedules, checklists, quotes, invoices and payment records, such as the method, amount, date and a check number or Venmo or Zelle reference. Records also show which team member created, recorded, approved or completed them.
  • Crew records. The jobs each crew member is assigned to, the checklist items they complete, and their time entries with clock-in and clock-out times and location. See the location section below.
  • Imports. When a business imports clients from a CSV file, we keep the clients it imports, the file name, the number of rows and who imported it. We do not keep the file itself.
  • Assistant usage. For each assistant request, we record who made it, which AI model answered, how much text was processed, how many lookups it made, the cost and how long it took. We also count how much of the monthly allowance each business has used. We do not store the questions or the answers.
  • Technical logs. Our hosting provider logs each request, such as the IP address, browser type, page and time. Our sign-in provider keeps a log of sign-in activity, such as the time and IP address. While email sending is not turned on, our logs record the sender, recipient and subject of each email the app would have sent, but not the message.

3. How we use information

We use personal information to:

We do not sell personal information. We do not share it for advertising. We do not use analytics or advertising trackers. We do not build profiles of people. We do not use your data to train AI models, and we set the AI gateway to use only model providers that do not train on it.

  • Run Limpela: sign-in, invitations, the language of the app, scheduling, the crew app, quotes, invoices, client links and the assistant
  • Show a business's name and contact details on its quotes, invoices, client links and emails
  • Check whether a clock-in or clock-out happened at the job address
  • Take payment for plans and keep access in line with the subscription
  • Count assistant use against the plan's monthly allowance, and measure the assistant's cost and speed
  • Answer contact requests and send the one launch email
  • Undo a client import when a business asks for it
  • Keep Limpela secure, fix problems and follow the law

4. Location data from the crew app

The crew app asks for the phone's location only when a crew member taps Clock in or Clock out, and only on that crew member's device. It does not track location in the background or between those taps.

The phone's browser asks for permission first. Limpela does not show its own notice before that. If the crew member says no, or the location is not available, the shift is still recorded, without a location.

When a location is shared, we store the latitude, the longitude, the accuracy the phone reports, and whether the point was inside the area around the job address. We store this with the time entry. Limpela does not keep a copy on the phone.

The owner, admins and managers of the business can access the time entries, including the stored location. Crew members can see their own. The office screens show whether the clock-in was at the job, not the point on a map.

Time entries are kept as payroll history, even after a crew member leaves the business. Businesses that use Limpela are responsible for telling their crew about location at clock-in and clock-out.

5. The AI assistant

Owners, admins and managers can ask the assistant about their business. To answer, we send the request through Vercel AI Gateway, a service run by Vercel, to an AI model provider. Today the assistant can use models from Z.ai, OpenAI and Anthropic. If the chosen model cannot answer, the gateway may send the request to an OpenAI model instead. Each request can include:

The assistant does not receive access notes, pet or parking notes, client notes, crew locations or time entries, payment references, your team's email addresses or other business settings.

Anything you type is sent too, so do not type sensitive details the assistant does not need.

We do not store the conversation. It stays in your browser and is cleared when you reload the page. We keep only the usage record described above.

We set the gateway to use only model providers that do not train on the requests. We have not asked for zero data retention, so the gateway and the model providers may keep requests for a time under their own terms, for example to check for abuse.

Some of the companies that make or host these models, or that run parts of the gateway, may process requests outside the United States.

If your plan lets you connect your own AI provider account, such as your own OpenRouter key, requests made with that key go to that provider under your own agreement with it.

  • The business name, today's date, the business's time zone and the reply language
  • The recent messages in the conversation, up to the last 24
  • Records the assistant looks up to answer, for example the schedule (times, client names, street address and city, service, crew names and status), client contact details (name, email and phone), open invoices (number, client, amounts, status and due date), and the details of a quote you ask it to draft
  • An internal ID for the business

7. Service providers we use

We use other companies to run Limpela. They handle personal information for us, only to provide their service. Today they are:

We may add or change providers. When we do, we will update this list.

  • Vercel: hosts the website and the app, runs our server code, keeps request logs, and runs Vercel AI Gateway for the assistant.
  • Supabase: our database and sign-in service. It stores the product data described in this policy and sends sign-in emails, such as confirmation, sign-in link and password reset emails.
  • Stripe: payments for Limpela plans and the billing portal.
  • Stripe Connect: if a business owner connects a Stripe account to get paid, Stripe collects the owner's identity and bank details, and we send Stripe the owner's email, the business name and an internal ID. If card payments on invoices are turned on for that business, Stripe collects the client's card details, and we send Stripe the invoice number and amount.
  • AI model providers (today Z.ai, OpenAI and Anthropic), reached through Vercel AI Gateway: power the assistant. They receive only the assistant data described above.
  • An email delivery provider (Resend), when email sending is turned on: sends invitations, quotes and invoices in the business's name. It receives the recipient, the subject and the message, which includes the link.
  • US Census Bureau geocoder: when a property is added by hand, we send its street address, city, state and ZIP code to find its map location. No name or account details are sent.
  • Google Maps: when you tap a map link, Google receives the address and your device's details, under Google's own privacy policy.
  • Google or Apple sign-in: only if it is offered and you choose it.
  • A team notification tool, if we connect one: receives each new contact form request (name, email, phone, company, crew size and message) so we can call you back.

8. Other times we share information

Beyond the providers above, we share personal information only:

  • Within the business you work with or buy from. For example, a business sees its crew's time entries, and a client sees the quote or invoice sent to them.
  • When the law requires it, such as a valid court order.
  • To protect people, our customers or Limpela from fraud, abuse or harm.
  • As part of a merger, sale or reorganization of our business. The new owner would have to follow this policy.
  • With your permission.

9. Cookies and browser storage

Limpela uses only a few cookies. Each one is needed for the service to work or to remember a choice you made. We do not use advertising or analytics cookies, and we do not load tracking scripts from other companies.

You can block or delete cookies in your browser settings. If you block the sign-in cookies, you will not be able to sign in.

  • Sign-in cookies (their names start with sb-): keep you signed in on limpela.app, and help complete sign-in by email link or with Google or Apple. They can last up to 400 days, and they are removed when you sign out.
  • org: remembers which of your companies is open on limpela.app. It lasts one year and is removed when you sign out.
  • locale: remembers the language you picked. It is set only if you pick one, and lasts one year.
  • locale-bar: remembers that you closed the language bar. It lasts one year.
  • theme: stored in your browser, not as a cookie. It remembers light, dark or system mode.
  • Stripe sets its own cookies on its own payment pages.

10. How long we keep information

We keep information while it is needed for the purposes in this policy, or as long as the law requires.

Today we do not delete information on a fixed schedule. We keep it until you, or the business, ask us to delete it, or until we decide it is no longer needed. We will update this policy when we set fixed periods.

  • Workspace data is kept while the business has an account with us. Businesses can archive clients in the app.
  • Crew time entries are kept as payroll history. When a timesheet is edited, we keep a note of who edited it and the original times.
  • Launch list entries, contact requests, invitations and assistant usage records are kept until they are deleted as described above.
  • The app does not have buttons to delete an account or a workspace, or to export data, yet. We handle these by request through our contact page.
  • Some information stays with our providers after we delete it, such as payment records that Stripe must keep, backups and logs, until their own retention periods end.

11. How we protect information

We take reasonable steps to protect personal information, including:

No system is perfectly secure. If a security incident affects your personal information, we will notify you and others as the law requires.

  • Each company's data is kept separate. Database rules stop one company's records from pointing to another's, and our server checks the company on every request.
  • Access notes, such as door and alarm codes, are shown to a business's owner, admins and managers, and to a crew member only when they have a job at that property today or in the next 7 days.
  • Connections to Limpela use HTTPS, and our providers encrypt stored data on disk.
  • Quote, invoice and invitation links use long random codes. Invitations expire after 7 days and work only for the email address they were sent to.
  • We check that payment messages really come from Stripe before acting on them.
  • If we cannot confirm a subscription, the app pauses instead of opening up. If we cannot check a business's assistant allowance, the assistant stops instead of running without a limit.

12. Where information is stored

Harmony is a US company. Our providers may store and process information in the United States and in other countries. For example, some AI model providers may process assistant requests outside the United States, as described above.

If you use Limpela from outside the United States, your information is transferred to and processed in the United States, where privacy laws may differ from those where you live. Where the law requires safeguards for these transfers, we rely on the data protection terms our providers offer, such as standard contractual clauses.

13. Your choices and rights

Depending on where you live, you may have the right to:

To make a request, use our contact page at https://limpela.com/contact and tell us what you need. We may ask you to confirm who you are before we act. Where the law allows, someone you authorize can ask for you.

Some of these requests cannot be done in the app yet, such as changing your name, deleting your account or getting a copy of your data. We handle them by hand. We will respond within a reasonable time, and within the time the law requires.

If your information is in Limpela because a cleaning business you work with or buy from uses it, please send your request to that business. If you contact us instead, we will help that business respond.

We will not treat you differently for using your rights.

  • Know what personal information we hold about you, and get access to it
  • Correct information that is wrong
  • Delete your information
  • Get a copy in a common, machine-readable format (portability)
  • Object to or limit some uses of your information

14. California residents

If you live in California, California privacy law gives you the rights listed above, including the right to know, delete and correct your information, and the right not to be treated differently for using them.

We collect these categories of personal information: identifiers (such as name, email, phone and IP address), customer records (such as billing references), commercial information (such as the plan bought), internet activity (such as request logs), precise location (crew clock-in and clock-out), professional information (such as a role in a business), and account sign-in details. We collect them from you, from the business that uses Limpela, from Stripe and from your device, for the purposes in this policy. We disclose them for business purposes only to the service providers listed above.

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the past 12 months.

We use sensitive personal information, such as precise location and account sign-in details, only to provide the service, and not to infer anything about anyone.

When we handle information for a business that uses Limpela, we act as that business's service provider.

15. People in the European Union and United Kingdom

Limpela is built mainly for businesses in the United States. If the GDPR or UK GDPR applies to you, these are our legal bases for the information we are responsible for:

You also have the right to object to processing based on our legitimate interests, to ask us to restrict processing, and to complain to your local data protection authority.

For information we process for a business that uses Limpela, that business is the controller and we are its processor.

  • To perform our contract with you, such as providing your account and billing
  • Our legitimate interests, such as keeping Limpela secure, answering contact requests and improving the service
  • To meet legal obligations, such as tax and accounting rules
  • Your consent, where we ask for it, such as for the launch list. You can withdraw it at any time.

16. Children

Limpela is not for anyone under 16. We do not knowingly collect personal information from children under 16. If you believe a child has given us information, contact us and we will delete it.

17. Changes to this policy

We will update this policy when Limpela changes, for example when we add a feature or a provider. The date at the top shows the latest version. If a change is important, we will give notice before it takes effect, for example on our website, in the app or by email.

18. Contact us

Questions or requests about privacy? Contact us through our contact page at https://limpela.com/contact, and say that your message is about privacy.

Limpela is operated by Harmony AI Technologies.

Limpela Privacy Policy · Limpela