Legal

Privacy Policy

Last updated: August 7, 2026 · This policy is part of our Terms of Service. See also the Payments, Cancellations & Refunds Policy.

1. Who we are and what this covers

CheckedOut ("CheckedOut", "we", "us") operates trycheckedout.com — a platform where short-term-rental hosts and property managers ("Hosts") find, hire, schedule and pay cleaning and maintenance professionals ("Pros"), and manage their own teams. This policy explains what personal information we collect, why, who sees it, how long we keep it, and the choices you have. It applies to the website, the web app, and every communication we send. It does not apply to third-party sites we link to.

We are based in Ontario, Canada, and comply with the Personal Information Protection and Electronic Documents Act (PIPEDA). We honour equivalent access, correction and deletion requests from users in any region, including under U.S. state privacy laws for our American users.

2. Two roles: platform and workspace processor

For your own account (profile, login, marketplace activity) we decide how data is handled and this policy governs directly. Inside a Host's workspace — team rosters, schedules, time-clock entries, wage settings — the Host controls that data and what it's used for; we process it on the Host's behalf to provide the tools. If you are an employee or worker whose employer uses CheckedOut, your employer is responsible for how it uses your work records, and questions about pay, hours or employment records should go to them first. We still apply every safeguard in this policy to that data.

3. What we collect

Account data — name, email address, phone number, password (stored only as a salted bcrypt hash — we cannot read it), avatar if you upload one, language preference, and business details you choose to add (company name, address, tax registration numbers).

Profile data (Pros) — headline, skills, service area, hourly rate and its currency, and anything you choose to publish on a public profile page. Ratings and review counts are computed from real reviews left on completed jobs.

Work data — listings and property details, job postings, bids and offers, jobs and their statuses, schedules, checklists and form submissions, messages sent through the platform, reviews, time-clock entries, invoices and payment records. This is the product: if you use CheckedOut to run work, the record of that work lives here.

Evidence data — photos uploaded on jobs, each with a server-recorded timestamp, and the device's location coordinates when granted (see section 4). This record is deliberate: it is what protects both sides when there is a dispute, a damage claim, or an insurance question.

Payment data — processed by Stripe, Inc. Full card numbers and bank credentials never touch our servers. We store only what we need to show you your own records: card brand and last four digits, invoice amounts, fee breakdowns, payout amounts and statuses.

Technical data — IP address, browser type, device type, pages visited and actions taken, and server logs. We use this for security (detecting account takeover attempts), debugging, and understanding which features are used.

Communications — support emails, and the content of messages you exchange with other users through the platform (which both participants can see, by design).

4. Location data — exactly when and what

We collect device location only at specific work moments, and only when the device grants permission:

· Clock in / clock out — a single coordinate captured at the moment of punching, so a Host can verify on-site attendance. Not continuous tracking: we never record location between punches, off shift, or in the background.
· Job photo capture — coordinates attached to evidence photos where granted, so the photo can prove where it was taken.

Location records are visible to you and to the workspace (Host, admins and managers) the work was performed for. Declining location permission never blocks you from working; punches and photos are simply recorded without coordinates, and the workspace can see that they were.

5. How we use information

To provide the service — matching postings with Pros, scheduling, messaging, notifications about your work, generating invoices, computing wages from time-clock data where a Host uses that feature, processing payments through Stripe, and producing evidence exports. To keep the platform safe — fraud prevention, enforcement of the Terms, and defending legal claims. To improve the product — aggregate, de-identified usage analysis. To communicate — transactional emails about jobs, payments and account security, and (separately, with unsubscribe) product updates.

We do not sell personal information. We do not rent it. We do not use your photos, messages or work records for advertising, and we do not train advertising systems on them.

6. Who sees what

People on the same job — a Host sees the Pro's submitted photos, checklists, times and messages for that job; a Pro sees the property information needed to do the work (address, access notes, checklists). Within a workspace — owners, admins and managers see their team's work data, schedules, time-clock entries and (where configured) wage information; access can be narrowed with groups and per-resource permissions. Public profiles — show only what a Pro chooses to publish, plus earned ratings. Service providers — companies that process data under contract with us, currently: Stripe (payments and payouts), Vercel (application hosting), our managed database provider, and our transactional email provider. Each receives only what its function requires. Legal — we disclose information when a law, court order or government demand requires it, or when necessary to protect someone's safety; where lawful, we tell you first. Business transfer — if CheckedOut is acquired or merges, data transfers with the business under this same policy.

7. Cookies

We use a small number of first-party cookies: co_session (signed login session — essential), co_display_currency (your CAD/USD display preference, kept one year), and short-lived cookies that make forms and redirects work. We do not use third-party advertising cookies or cross-site trackers. Blocking essential cookies will prevent login from working.

8. Retention

Financial records (invoices, payment records, fee breakdowns) — kept at least seven years, as Canadian tax and accounting rules require. Job evidence (photos, timestamps, location points, checklist runs) — kept for the life of the account plus any period needed for open disputes, claims or limitation periods, because its whole purpose is to be available when a question arises later. Messages and work data — kept while the account is active. Server logs — rotated within 90 days. When you delete your account, personal data outside those legal-hold categories is deleted or irreversibly anonymized within 30 days; records a Host workspace controls (e.g. your employer's payroll exports) follow the workspace's retention.

9. Security

All traffic is encrypted in transit (TLS). Passwords are hashed with bcrypt. Sessions are signed server-side tokens. Payment credentials live exclusively with Stripe, a PCI-DSS Level 1 certified processor. Production data access is limited to people who need it to operate the service, and is logged. No system is perfectly secure; if a breach ever creates a real risk of significant harm, we will notify affected users and the Privacy Commissioner as PIPEDA requires, without unreasonable delay.

10. Your rights and choices

You can access what we hold about you, correct anything inaccurate, export your data in a portable format, delete your account, and withdraw consent for optional collections (like location) at any time going forward. Marketing emails always contain an unsubscribe link; transactional emails about your jobs and payments are part of the service. To exercise any right, email support@trycheckedout.com from your account address — we verify identity, answer within 30 days, and never charge for it. If you are unsatisfied with our answer, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or your local authority.

11. Where data lives

Our infrastructure providers store and process data in Canada and the United States. Wherever it is processed, the same contractual safeguards and this policy apply. By using CheckedOut you consent to this cross-border processing; note that data stored in a country is subject to that country's lawful-access rules.

12. Children

CheckedOut is for adults conducting business. You must be at least 18 (or the age of majority where you live) to hold an account. We do not knowingly collect information from minors; if you believe a minor has an account, contact us and we will remove it.

13. Changes

When this policy changes, the new version is posted here with a new date. If a change meaningfully reduces your rights or expands what we collect, we notify account emails before it takes effect. Continued use after the effective date means the updated policy applies.

14. Contact

Privacy questions and requests: support@trycheckedout.com · legal notices: legal@trycheckedout.com. CheckedOut, Toronto, Ontario, Canada.