Facility-approved placement
CleanScan tags are intended to be placed only where the facility, operator, brand, or corporate reviewer approves the location, copy, and use case.
CleanScan creates a shared operational record for cleaning contractors and the facilities they serve. This page summarizes how we approach member reporting, data custody, photo proof, physical tag placement, and security review.
CleanScan tags are intended to be placed only where the facility, operator, brand, or corporate reviewer approves the location, copy, and use case.
Anonymous reporters can submit feedback tied to the tag they scanned. They do not get dashboard access or the ability to browse facility records.
Facility, contractor, worker, and portal views are separated by account roles, organization membership, and location-level authority.
Locker rooms, restrooms, showers, changing areas, pools, schools, and healthcare areas require extra review before tags or photo workflows are enabled.
CleanScan is designed around a facility-level operational record. Tags, zones, reports, cleaning activity, and proof are tied to the relevant facility and are visible only through configured organization, contractor, worker, and portal access.
A contractor can operate inside a client facility when it has scoped authority to do so. A facility can review the records it is authorized to see. CleanScan hosts and processes the service so those records can be routed, secured, retained, and made available to approved users.
| Tag and zone | Used to route the report to the correct facility area. |
|---|---|
| Issue category or rating | Used to summarize what needs attention. |
| Optional description | Used only when the reporter adds context. |
| Optional contact information | Used for acknowledgements or follow-up when provided. |
| Device and request data | Used for security, diagnostics, rate limiting, and abuse prevention. |
Public reporters do not need to create an account. Public reporting can be enabled only for facility-approved zones and should not be used as an emergency, life-safety, harassment, or general member-monitoring channel.
CleanScan is not designed to collect images of people, nudity, minors, medical information, private activity, or other sensitive personal content. Facilities should disable or avoid photo workflows in locker rooms, restrooms, showers, changing areas, saunas, pools, healthcare areas, schools, and any location with heightened privacy expectations.
Facility teams can review which zones are approved for member reporting, which zones are staff-only, and whether proof should be a note, scan event, or photo. For sensitive spaces, tags can be placed outside the area, inside only where approved, or omitted entirely.
| Supabase | Authentication, Postgres database, storage, Edge Functions, and real-time infrastructure. |
|---|---|
| Vercel | Hosting, deployment, and application delivery for CleanScan web properties. |
| Stripe | Subscription billing, payment processing, and customer billing portal. |
| Telnyx | Operational SMS alerts and SMS webhook handling for opted-in recipients. |
| Supabase Auth SMS provider | Phone one-time passcodes for authentication. |
| Formspark | Marketing and support form submissions. |
| Sentry | Optional application error monitoring when enabled for an environment. |
| SOC 2 | Not certified today. CleanScan is building toward SOC 2 readiness before pursuing a formal audit. |
|---|---|
| ISO 27001 | Not certified today. ISO may be evaluated later if enterprise or international demand requires it. |
| Security review | Available for facility, corporate, and risk teams through direct review with CleanScan. |
For security review, facility approval, privacy requests, or data custody questions, contact privacy@cleanscan.io.