Privacy Policy
Your data is protected with the same standard of care as our services.
The essentials at a glance
Protected data
We collect only what is needed for the account, booking, mission and secure payment.
Secure payments
Protected payment: the provider is paid only after the mission is validated. We never store your card numbers.
Controlled geolocation
GPS is used for the service address and presence proof, never for continuous tracking.
No data selling
Your data is never sold, nor used for third-party targeted advertising.
At MBOACLEAN, trust is at the heart of the service. MBOACLEAN is an integrated platform of cleaning, hygiene and maintenance solutions, operated by CORTEXPO. To ensure quality, mission safety, payment tracking and everyone's protection, we process certain data in a controlled, transparent way, limited to what is strictly necessary. The MBOACLEAN platform, its websites, applications and related services are legally operated by CORTEXPO. The applicable data protection law and the competent supervisory authority depend on the country of the service: both are named in the country annex at the end of this document. This policy explains what data we process, why, with whom, for how long, and your rights and duties.
Account deletion
- You can request deletion of your MBOACLEAN account at any time, without justification.
- From your space: profile section, when the option is available.
- By email: write to contact@mboaclean.com with the subject “Account deletion”.
- Once received, we delete or anonymise the data that is no longer needed.
- Some information may be retained where the law requires it (accounting, tax, payment proof, security or an ongoing dispute).
1. Data controller
- Controller: CORTEXPO SARL AU, operating the MBOACLEAN platform.
- MBOACLEAN is an integrated platform of cleaning, hygiene and maintenance solutions, operated by CORTEXPO.
- Data contact: contact@mboaclean.com.
- The postal address and telephone numbers of the contracting entity depend on the country of the service: they are set out in the country annex at the end of this document.
- For any request about your data, email us with the subject “Data protection”.
2. Data we collect
- Account: name, phone number, email, city, address, language, avatar.
- Authentication: email, password (hashed) and a session token. Creating an account also requires proof that the declared phone number belongs to you: that proof comes either from a one-time code sent to the number or from a signed token issued by the phone verification service. A one-time code by email is added where the security of the space requires it.
- Bookings: requested service, service address, date/time, description, constraints (children, pets, allergies…), and the location's GPS coordinates if you allow it.
- Proof of service: before/after photos and videos, and the provider's GPS presence at check-in/check-out.
- Payment: protected-payment status, payment proof, amounts and commission (we do not store card numbers).
- Messaging: content exchanged within a booking (automatically scanned to detect circumvention attempts).
- Reviews and ratings you leave.
- Technical connection data: IP address, login date, approximate city/country inferred from the IP; device type and security logs.
3. Purposes and legal bases
- Provide the service and perform the contract: account, matching, booking, delivery and follow-up.
- Manage protected payments and commission — contractual necessity.
- Ensure quality, proof of delivery and dispute handling — legitimate interest.
- Prevent fraud and platform circumvention, and secure accounts — legitimate interest and security.
- Comply with our legal, accounting and tax obligations.
- Keep you informed (mission and security notifications); non-essential communications rely on your consent, which you can withdraw at any time.
4. Geolocation
- GPS location is used only for specific purposes: locating the service address at booking, setting the provider's zone at onboarding, and proving on-site presence at check-in/check-out.
- GPS geolocation requires your explicit device permission; you can refuse or withdraw it in settings — booking remains possible by entering the address manually.
- The login city/country is inferred from the IP address (city-level, never the neighborhood) for security and statistics; it does not continuously track your movements.
5. Data sharing
- With the selected provider: information needed for the mission. Your direct contact details are masked until the mission is confirmed, protecting both parties.
- Technical processors acting on our behalf: app hosting (Vercel), API and database (Railway), marketing site (Netlify), secure file storage (AWS S3), phone number verification (Firebase/Google) when that channel is used.
- Competent authorities where required by law.
- We never sell your personal data and do not use it for third-party targeted advertising.
6. Retention
- We keep your data for as long as necessary for the stated purposes, then according to legal obligations.
| Data | Retention period |
|---|---|
| User account | Life of the account; deletion or anonymisation on request, except legal obligations. |
| Bookings & missions | As long as needed for follow-up, customer service, disputes and legal obligations. |
| Payments, invoices, commissions | For the applicable accounting and tax periods. |
| Messages | As long as needed for mission follow-up, security and dispute handling. |
| Photo / video proof | As long as needed for proof of delivery, quality control and disputes. |
| Provider verification | We keep neither a copy nor the number of any ID document: only the outcome of the check, its date and the authorised officer who performed it. |
| Security logs | As long as needed to prevent fraud and secure accounts. |
7. Security
- Protected payment: paying the provider is not triggered by merely receiving a payment; it happens only after the mission is completed and validated, protecting both client and provider.
- Encrypted traffic (HTTPS), strict access control, logging of sensitive admin actions.
- Contact masking and automatic detection of direct-contact attempts in messaging (anti-circumvention).
- As no measure is infallible, please protect your credentials and report any suspicious use.
8. Your rights
- Access: obtain a copy of the data we hold about you.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion of your data, subject to our legal obligations.
- Objection and restriction: object to certain processing based on legitimate interest.
- Withdraw consent: at any time, for processing that relies on it (no retroactive effect).
- Portability: receive your data in a readable format.
- Complaint: refer the matter to the competent supervisory authority of the country of the service. It is named in the corresponding country annex at the end of this document.
- To exercise these rights: contact@mboaclean.com. We reply within legal deadlines and may verify your identity.
9. Your duties
- Provide accurate and up-to-date information (identity, address, actual need).
- Use the platform in good faith: do not circumvent MBOACLEAN to deal or pay directly outside the service.
- Respect other users and providers, and the confidentiality of information received.
- Protect access to your account and do not share it; report any unauthorized access.
- Do not post unlawful, misleading or infringing content.
11. Minors
- The service is intended for adults (18+) able to enter into a contract.
- We do not knowingly collect minors' data; if you believe a minor provided us data, contact us for deletion.
12. International transfers
- Some technical processors may host or process data outside the country of the service.
- In such cases we ensure appropriate safeguards and limit data to what is strictly necessary.
13. App permissions (Android/iOS)
- Location: to set the service address and prove on-site presence — optional and revocable.
- Camera / storage: to attach before/after photo and video proof.
- Notifications: for mission follow-up and security alerts — can be disabled.
- Each permission can be refused or withdrawn in system settings; core use remains possible by entering information manually.
14. Changes
- This policy may change. The last-updated date appears at the top of the page.
- For any material change, we will inform you by an appropriate means.
Country-specific provisions — Morocco
- The provisions below apply only to services booked and performed in this country (Morocco). They do not apply to the other countries where MBOACLEAN operates.
- Contracting entity: CORTEXPO — 62 Boulevard de la Gironde, Appartement 4, 2e étage, Casablanca, Maroc
- Telephone: +212 5 22 54 22 45 · +212 7 11 89 84 38
- Data processing carried out for services in Morocco falls under Moroccan Law No. 09-08 on the protection of individuals with regard to the processing of personal data.
- Competent supervisory authority in Morocco: the CNDP (national data protection authority), with which a complaint may be lodged.
For any data request or complaint: contact@mboaclean.com. The competent supervisory authority depends on the country of the service: see the country annex.