Trust & Security

How we protect your data

This page is maintained by ReadyGuest to answer common security and privacy questions about Flip Fairy. It describes practices and controls that are enabled in the app today. It is not an independent certification or audit report.

Access & authentication

  • Sign-in is required to view listings, bookings, or cleanings. Public marketing pages do not expose customer data.
  • Email/password and Google sign-in are supported through our managed authentication provider.
  • Owner and cleaner roles are stored server-side and enforced through database row-level security — not by the browser.
  • Each cleaner only sees listings and tasks an owner has explicitly assigned to them.

Data we collect

  • Account: name, email, and authentication identifiers.
  • Listings: property name, address, timezone, checklist, and the iCal URL you paste.
  • Bookings: check-in and check-out dates synced from your Airbnb (or other iCal) feed. We do not ingest guest names, contact information, or payment details.
  • Cleanings: task status, completion timestamps, notes you add, and which cleaner completed the work.
  • Billing: Stripe customer and subscription identifiers for owners on a paid plan. Card numbers are handled by Stripe and never touch our servers.

How your data is protected

  • All traffic to and from the app is served over HTTPS.
  • Database row-level security policies scope every read and write to the owner who created the record, plus the cleaner(s) they have assigned.
  • Cleaners can update only the task fields they need (status, checklist progress, notes); they cannot re-point a task to a listing they do not service.
  • Cleaner email addresses are visible only to owners who currently have that cleaner assigned to one of their listings.
  • Server-side privileged functions are not callable by anonymous (signed-out) users.

Email & notifications

We send transactional emails to remind cleaners and owners about upcoming and overdue cleanings. Every email includes an unsubscribe link, and suppressed addresses are excluded from future sends.

Subprocessors

  • Lovable Cloud (Supabase): application database, authentication, and server functions.
  • Stripe: subscription billing and payment processing for owner plans.
  • Resend: transactional email delivery.
  • Airbnb / iCal providers: read-only calendar feeds you choose to connect.

Retention, deletion & contact

Owners can remove listings, bookings, and cleaning records from inside the app at any time. To request account deletion or to ask a privacy question, email chris@ripstopbytheroll.com. To report a suspected security issue, please use the same address with "Security" in the subject line.

This page reflects the app as configured today and may evolve as features change. It is editable content maintained by the app owner; nothing on this page should be read as a formal compliance certification.