Privacy & Data Protection Policy
Effective date: September 30, 2026
1. Commitment to Privacy
Warning: Undefined variable $bizLegalName in /home/cleaucaz/secure.clean-service.online/public/privacy.php on line 18
respects your privacy. This policy explains how we collect, store, and process your personal information in connection with our storefront, invoices, and customer accounts.
2. Information We Collect
We collect personal information necessary to deliver services and fulfill billing:
- Contact details: Name, email address, company name, billing address, and phone number.
- Order records: Purchased products, transaction IDs, invoice histories, and coupon redemptions.
- Account credentials: Secure cryptographic password hashes (Argon2id).
- Technical data: IP addresses, user agents, and security audit log entries.
3. Payment Information & PCI SAQ A Architecture
We do not collect, process, or store full credit card numbers, CVV security codes, or bank account credentials on our infrastructure. All payment method fields are rendered by Stripe via encrypted iframes directly into your web browser. Stripe transmits an obfuscated token (e.g. pm_...) along with non-sensitive display metadata (card brand, expiration month/year, and last 4 digits) for display in your account portal.
4. Third-Party Service Providers
We share data exclusively with trusted third-party sub-processors strictly for transaction processing and operational delivery:
- Stripe, Inc. - Payment processing, fraud detection (Stripe Radar), and subscription lifecycle.
- SMTP Mail Delivery - Transactional order confirmations and account verification.
5. Data Retention & Rights
We retain billing transaction logs for accounting and legal audit compliance (typically 7 years). You have the right to request access to your personal data, request correction of inaccurate records, or request account closure by contacting
Warning: Undefined variable $supportEmail in /home/cleaucaz/secure.clean-service.online/public/privacy.php on line 48
.
6. Security Measures
We employ modern industry standards including TLS 1.3 encryption in transit, Argon2id password hashing, strict CSRF token validation, Content-Security-Policy enforcement, and real-time brute-force rate limiting.