Privacy

How we handle your information

We are a cleaning company, not a data business. We collect what running the service actually requires, we keep access to it narrow, and we tell you plainly what happens to it. This page describes what we do today.

Version 1.0 · This edition: June 24, 2026

01Who we are and what this covers

Elysium Home Solutions LLC ("Elysium", "we", "us") operates this website and the cleaning service booked through it. This policy covers the information we handle when you visit the site, request a cleaning, create an account, communicate with us, pay us, or receive service.

It does not cover sites and services we do not operate. Where we link to one, its own privacy notice applies - see Third-party links.

02Information you give us

When you request a cleaning you give us the details needed to price and carry it out: your name, email address, phone number, the service address, home size, number of bathrooms, cleaning type, add-ons, how often you want service, a preferred date and time, and any notes you choose to add.

An unconfirmed request is handled differently from a booking. Submitting the form creates a request, not a customer record. Until you confirm it through the link we email you, the personal details in that request are stored encrypted and are used only to evaluate and confirm the request. The system separately keeps the facts it decided itself - the calculated price and its inputs, the requested time slot, whether the address fell inside our service area, and the outcome of our security screening - so we can answer a duplicate submission or a support question without decrypting anything.

Once you confirm, the booking becomes a customer record: a contact (you), an account, and a property (the address we clean). Those records persist so we can serve you again, honour a guarantee, handle a claim, and keep accurate business books.

03Information collected automatically

Like any website, ours receives technical information from your browser as you use it. In practice that means:

  • Network and request data - your IP address, the pages and endpoints you requested, timestamps, HTTP status, and a per-request identifier we generate so a support question can be traced to the right log line.
  • Browser and device data - the user-agent string your browser sends, and, if you turn on browser notifications, the push subscription your browser issues for that device.
  • Local storage in your browser - we use cookies and browser storage for things that make the site work: your signed-in session, a cross-site request forgery token, a workspace preference, and, on the field-report screens our team uses, an offline queue. We do not run third-party advertising or cross-site tracking on this site.

Security check. Public forms - booking submission, sign-in link requests, password resets, and account signup - are protected by Cloudflare Turnstile, a human-verification check. Running it means your browser interacts with Cloudflare, which receives technical signals about that interaction. We receive only the verdict.

Addresses. Address autocomplete and address resolution use Google Maps Platform. When you type an address into the booking form, the text you type is sent to that service to return suggestions and to resolve a precise location, and we cache resolved results for a bounded period so we do not repeat lookups.

04Account and sign-in information

An Elysium account is one identity that can be used by customers and by our own staff, with different access. We hold:

  • Your email address, which identifies the account.
  • A password, if you set one, stored only as a strong one-way hash. We cannot read your password, and we do not send it to anyone.
  • One-time email links and codes, stored only as a keyed digest with a short expiry, and single-use.
  • A Google connection, if you use one. We receive a stable identifier for your Google account and your email address once Google has verified it, and we store the link between that identifier and your Elysium account. We do not receive your Google password.
  • Passkeys, if you create one. The private half never leaves your device. We store only the public credential data the standard requires - a credential identifier, a public key, a signature counter, and the transports your device reports.
  • Sessions. Your browser holds an opaque session token; our database stores only a keyed digest of it, along with when the session was created, how it was authenticated, and when it was last used.
  • Sign-in attempts. We record sign-in attempts and their outcome, with the IP address and email involved, to slow down guessing attacks and to investigate account takeover. Failed attempts are recorded in a separate table from our general history.

05Property access information

If you give us a door code, gate code, alarm information, lockbox code, or private entry instructions, we treat that as our most sensitive customer data.

  • It is encrypted at rest, and if the encryption key is unavailable the system refuses to show it rather than falling back to anything readable.
  • It is not included in ordinary customer lists, search results, or the read models most screens use.
  • It is revealed deliberately, by someone whose role permits it, rather than displayed by default.
  • Each reveal is recorded - who looked, when, and for which property. The code itself is never written into that record, into logs, or into a web address.

You can ask us to remove stored access information at any time; we will then need another way in for future visits.

06Payments

Card payments are processed by Stripe, our payment provider. Your card details are entered on Stripe's own payment page and are handled by Stripe, not by us - we do not receive or store your full card number. What we keep is the record of the obligation and its outcome: the amount, currency, status, timestamps, the provider's identifiers for the checkout session and payment, and the events the provider sent us.

Where you pay through one of the direct methods we publish, we record that a payment was received, its amount, and the method. An operator who records a manual payment is identified in our internal history.

We also keep the events our payment provider sends us so that a repeated or delayed message cannot double-charge you or silently change a settled payment.

07Offers, job reports, photos, and video

Offers. If we send you a personal quote link, we store the quote, what it covers, the prices we froze into it, and when it expires. The link itself is a secret: we keep only a one-way digest of it, so a lost link is replaced rather than looked up.

Job reports. The professional assigned to your visit may complete a report - what was done, notes, and time on site - and may attach limited photos or short video of relevant work areas for quality assurance, service verification, training, safety, insurance, or claim documentation.

Job media is stored on our own systems, not in a public bucket, and is reachable only through an authenticated, permission-checked route. It is used internally, for the purposes above. We do not sell it, and we do not publish it as marketing without asking you first. Tell us if you would prefer no photos in a particular room, or none at all, and we will note it on your booking.

08Communications, and the difference that matters

There are two kinds of message, and we treat them differently.

Transactional messages come with the service: booking confirmations, the confirmation link itself, reminders, changes, receipts, and answers to something you asked. They are part of delivering what you booked, so they are not something you unsubscribe from while the booking exists.

Marketing messages, if we send them, are optional. Every one carries a way to opt out, and opting out never affects your service.

We deliver messages by email and, where you have opted in, by text message and browser notifications. Our operations staff also receive internal alerts about work in progress. We keep a record of what was sent, to which channel, and whether it was delivered, so we can tell you honestly whether a message actually went out.

09Text messages

Text messaging is separate from every other permission, and it is opt-in. We record your consent, when it was given, and the disclosure version it was given against; messages are sent through our SMS provider, Twilio, which receives the phone number and message content in order to deliver it.

Reply STOP to any message to stop texts; we record the opt-out and suppress that number. Reply START to opt back in, or HELP for help. Message frequency varies. Standard message and data rates from your carrier may apply. Stopping texts does not cancel your booking - we will use email instead.

10How we use information

  • To deliver the service - price a request, decide whether an address is in our area, hold and confirm a time, schedule the visit, assign a professional, and carry out the cleaning.
  • To communicate with you about your booking and to answer your questions.
  • To take payment and keep accurate financial records.
  • For quality and claims - to run our guarantee, review a complaint, and document a claim.
  • For safety and security - to protect our customers, our people, and our systems, and to prevent fraud and abuse.
  • To run and improve the business - understanding demand, capacity, and where the service falls short.
  • To meet legal and tax obligations.

We do not sell your personal information, and we do not share it with third parties for their own advertising.

11Security screening and fraud prevention

Public booking requests are screened before they become bookings. That screening looks at signals such as how many requests are arriving from one address, phone number, email address, or network, how quickly a form was filled in, and whether an address can be resolved at all. The outcome is recorded as a set of stable reason codes and a risk result, so an operator can see why a request was held for review without reading through the request itself.

We also apply rate limits and a human-verification check on public forms. These measures exist to keep slots, our calendar, and our people available to real customers.

12Who we share information with

We share only what a given recipient needs, and only for the purpose below.

  • The people who serve you. The professional assigned to your visit receives what is needed to do the job: the address, the scheduled time, the scope of work, relevant notes, and - where the role requires it - access information.
  • Service providers who operate parts of our platform: our payment provider (Stripe), our email delivery, our SMS provider (Twilio), our address and mapping provider (Google Maps Platform), the network and security layer in front of our site (Cloudflare), and push delivery services operated by your browser vendor. Each receives only the data its function requires.
  • Professional advisers and insurers where a claim, a dispute, or a legal question makes it necessary.
  • A successor, if the business is ever sold or reorganised - in which case this policy, or a notice at least as protective, continues to apply.

14How long we keep information

We keep information for as long as it serves the purpose it was collected for, and then for as long as we are required or reasonably need to keep it - for tax and accounting, for the period in which a claim could still be brought, and for security investigation.

In practice:

  • Customer and booking records are kept while you are a customer and for a reasonable period afterwards.
  • Unconfirmed requests and their encrypted contents are short-lived; automated housekeeping removes expired and abandoned ones.
  • Operational side data - sign-in attempts, notification windows, cached address lookups, screening events, and internal diagnostic logs - is bounded by automatic cleanup rather than kept indefinitely.
  • Records of access to protected customer data are kept for 24 months, because their whole purpose is to answer a question after the fact.
  • Financial records are kept for the period tax and accounting rules require.

There are exceptions, and we would rather say so than pretend otherwise. Where information is subject to a legal hold, an open claim, a dispute, or an active investigation, we keep it until that ends, even if ordinary deletion would otherwise have applied. Backups are also replaced on a cycle rather than edited, so information can persist in a backup for a period after it is removed from live systems.

15How we protect information

  • Access is limited by role. What a person can see and do is decided by permissions attached to their role, not by who they know, and sensitive customer data is limited to roles that need it.
  • Access is limited to authorised business purposes. Using customer information for anything other than the Elysium purpose it was granted for is a breach of our Ethics & Conduct standard.
  • Meaningful access to protected data is recorded, so we can answer who reached what, and why, after the fact.
  • Sensitive values are encrypted at rest - access codes and the contents of unconfirmed requests among them - and the system fails closed rather than showing plaintext when a key is unavailable.
  • Secrets stay secret. Passwords, session tokens, one-time links, and access codes are never written into our logs, our internal history, or a web address.
  • Transport is encrypted between your browser and our systems.

No system is perfectly secure, and we will not tell you otherwise. What we can say is that these are the controls we actually run, and that we treat a weakness in them as a defect to fix rather than a risk to accept.

16Your choices and privacy requests

You can:

  • ask what personal information we hold about you and get a copy of it;
  • ask us to correct information that is wrong or out of date;
  • ask us to delete information we no longer need;
  • ask us to remove stored property access information;
  • opt out of marketing at any time, and stop text messages by replying STOP;
  • turn off browser notifications from your browser or from your account.

Where a privacy law gives you a right we have not listed, we will honour it as that law requires. Email [email protected] and tell us what you want; we will respond within the time the applicable law allows, and we will not treat you differently for asking.

Some information we cannot delete on request - a financial record we are required to keep, or evidence relevant to an open claim or investigation. Where that applies, we will tell you what we kept and why.

17Verifying a privacy request

Before we act on a request about personal information, we need to be reasonably sure the request is really yours - otherwise the request itself becomes a way to reach someone else's data. We normally verify by sending a one-time link or code to the email address on the account, and we may ask you to confirm details we already hold. We ask only for what verification requires, and we do not use what you provide for verification for anything else.

An authorised agent may act for you if you confirm the authorisation directly with us.

19Children

Our service is for adults. We do not knowingly collect personal information from children under 13. If you believe a child has given us information, contact us and we will delete it.

20Changes to this policy

We may update this policy. When we do, this page gets a new edition and the version and date at the top change with it; earlier editions stay available at their own permanent addresses. Where a change is significant, we will make that clear.

21Contact us

Questions about privacy, or want to make a request? Reach out any time:

Mailing address
Elysium Home Solutions LLC, 3400 Cottage Way, Ste G2 #35721, Sacramento, CA 95825