CleanRev
Features Pricing About Blog
Sign In Join Waitlist
Features Pricing About Blog
Sign In Join Waitlist

Data Protection & Your Financial Data

Last updated: July 12, 2026

Your most sensitive data lives with the processors, not with us

CleanRev helps you run the money side of your cleaning business, but we deliberately keep the most sensitive raw data out of our systems. Card numbers stay with Stripe. Bank login details stay with Plaid. Payroll identity data stays with Gusto. We hold references and encrypted access — not the raw secrets.

1. What CleanRev does NOT store

  • Your full card number or security code (CVC). Card payments are processed directly by Stripe, our PCI-DSS-compliant payment processor, using in-browser tokenization — the card details never reach CleanRev’s servers.
  • Your full bank account number or routing number. Bank connections are handled by Plaid; we receive only a secure access token (stored encrypted) and the last four digits of the account for display.
  • Your employees’ Social Security Numbers. Payroll identity data is held by Gusto, our payroll integration provider; CleanRev receives only aggregated payroll amounts.

2. What CleanRev does store

  • Non-sensitive references and display details: your Stripe / Plaid / payroll customer and account identifiers, and the card brand, expiry, and last four digits needed to show you which payment method is on file. These identifiers are useless without the processor that issued them.
  • Encrypted integration credentials: when you connect a bank feed (Plaid) or payroll (Gusto), the access token that lets CleanRev sync your data is encrypted at rest using AES-256-GCM. CleanRev enforces this encryption — if the encryption key is unavailable, CleanRev refuses to store the token rather than storing it unprotected.
  • Your business’s own financial records: invoices, payments, imported bank transactions, and payroll totals — the bookkeeping data the product exists to manage, isolated per business.

3. Where your most sensitive data really lives

Card details go to Stripe. Bank credentials go to Plaid. Payroll and tax identity go to Gusto. These providers are the systems of record; CleanRev holds references and encrypted access, not the raw secrets.

4. How your data is protected

  • Card tokenization: every payment flow tokenizes card details in your browser through Stripe, so no full card number or CVC is ever received or stored by CleanRev.
  • Encryption at rest: integration credentials (Plaid and Gusto access tokens) are encrypted with AES-256-GCM, enforced fail-closed. Our database host, Neon, additionally encrypts all stored data at rest.
  • Secrets are not in the database: the processor API keys and the encryption key itself are held as platform secrets, not in the application database.
  • Tenant isolation: every financial record carries your business’s identifier and is scoped to your business throughout the application. We are progressively moving that isolation into the database engine itself so it is enforced at multiple layers.

5. Sub-processors

The third parties that process financial or account data on CleanRev’s behalf are listed below. The complete, authoritative sub-processor list — with locations and 30-day change-notice terms — is maintained in our Data Processing Agreement.

Sub-processor Data category processed Purpose
StripeCard data (held by Stripe), Connect KYC & payout bankCard vault, payments, payouts
PlaidBank login credentials, account / transaction dataBank feed & reconciliation (opt-in)
GustoEmployee SSN & payroll (held by Gusto), direct-deposit bankPayroll integration (opt-in)
Neon (PostgreSQL)All application data at rest (encrypted)Primary database
CloudflareAll traffic, compute runtime & object storageHosting, edge, storage
SMTP2GOEmail addresses & message contentTransactional email
TelnyxPhone numbers & SMS contentTransactional SMS
AxiomApplication logs & telemetryObservability
Google WorkspaceBusiness email / opsInternal operations

6. Retention

Financial and tax records (invoices, payment receipts) are retained for up to 7 years to meet tax and accounting law, consistent with the retention terms in our Privacy Policy.

7. Your right to access & erasure

You can request access to, or deletion of, the data we hold about you at any time. When you delete your account, your workspace is deactivated and your data is made inaccessible; records subject to legal retention (such as financial and tax records) are held for the required period and then removed.

To make a data-access, correction, or erasure request, email privacy@cleanrev.io. We respond within 30 days. Your full rights under GDPR (EEA/UK) and CCPA/CPRA (California) are described in our Privacy Policy.

8. Questions

  • Privacy & data requests: privacy@cleanrev.io
  • Security practices: Security page
  • Processor terms: Data Processing Agreement
CleanRev

Run your cleaning business smarter. Scheduling, invoicing, and customer management—all in one place.

Product

  • Features
  • Pricing

Company

  • About
  • Contact

Resources

  • Help Center
  • Blog
  • Status

Legal

  • Privacy Policy
  • Terms of Service
  • Data Protection
  • Accessibility
  • Security

© 2026 CleanRev, Inc. · All rights reserved.

Terms Privacy Refunds Cookies Accessibility Security Do Not Sell My Info

Cookie Preferences

We use essential cookies for authentication and payment processing through Stripe, plus first-party, cookieless analytics you can opt out of. Reject disables the analytics too. View cookie preferences

CleanRev

Pristina · AI Assistant

Leave your email and a CleanRev team member will reach out. Phone is optional.

Join the CleanRev waitlist

Be first in line for early access. Leave your name and email and we'll let you know the moment it opens.

No spam — just one note when early access opens.

You're on the list!

We'll email you the moment early access opens. Thanks for your interest in CleanRev.