Skip to content

Privacy Policy

This policy explains what personal data Homjo collects, why, and what your rights are. It is written in plain English and describes what the software actually does. The controller is Homjo Networks Limited, registered in Ireland under Company Number 815338. Data-protection requests: privacy@homjo.com. Homjo is not required to appoint a Data Protection Officer and has not appointed one; the founder handles data-protection requests personally.

1. What we collect

Account and profile. Your email address, and — if you add them — your name, avatar, address, language, city, where you moved from, and business details. A verified phone number is required before you can post a listing: it confirms you are a real person, and it is never shown to other members unless you switch on phone sharing for a particular listing. You can sign in with Google or Apple, by email link, or by a code sent to your phone. Signing in with a provider shares your provider ID, email and profile photo with us. Phone verification stores your number and the fact that it was verified.

Identity verification (optional). If you choose to verify your identity, Stripe Identity checks your identity document and a selfie. Stripe processes and holds those images; Homjo stores only a reference to the verification session and its result (verified or not). We never see or store your document.

What you post. Listings, requests, offers and estimates (including the amounts you enter), bookings, ratings you give and receive, reports, invoices and quotes you create in the app, and messages you exchange with other users. Messages are private to the conversation participants; Homjo staff do not read them except where required to investigate a report.

Location. Public listing pins are fuzzed by up to 150 metres; your exact address is stored separately and visible only to you. Services request locations are fuzzed by up to 250 metres before anything is stored for display — the exact point you set is never shown to others.

Usage. Page views, searches, and product events (for example "listing saved"), used to understand what works. For visitors who are not signed in, we store a salted hash of the IP address — never the address itself. Search text is truncated and the filters you used are recorded by name.

Payments. If you buy a plan or a Boost on the website, Stripe processes the payment. Homjo never sees your card number — we store only your Stripe customer reference, plan and billing status. In the iOS app, Apple bills the purchase and RevenueCat, our purchase-management processor, tells us what was bought, renewed, cancelled or refunded; we store the plan and billing status, the Apple transaction reference and, for a Boost, which listing it was bought for — never your Apple payment details. RevenueCat receives your Homjo account id so the purchase can be matched to your account; it is listed in our sub-processor register.

Tax reporting (DAC7). Homjo is not a "reporting platform operator" under the EU DAC7 rules (Council Directive 2021/514, Taxes Consolidation Act 1997 Part 38 Chapter 3A): the platform only lists and connects — it never records an agreed price, takes payment between users, or knows what was finally paid (estimates and budgets shown in the app are indicative and are not consideration). We therefore do not collect tax identifiers from users and do not report anyone's income to Revenue. If that ever changes, this policy will say so before any such collection begins.

Derived signals. From your activity Homjo computes internal figures such as a trust score, an activity level and a churn-risk estimate. They are used to understand the platform and to spot abuse. They are not shown to other users and do not change your access to any feature.

Connect age confirmation. Connect (flatmate, carpool, services and talent profiles) is for adults. When you confirm you are 18 or over, we record the time and the IP address you confirmed from, as evidence of the declaration. This is the one place Homjo stores an IP address rather than a hash.

County waitlist. If Homjo has not launched in your county and you ask to be notified, we store the email address you give us, the county, and — if you pick one — what you'd use Homjo for. This is a separate consent-based list held by MailerLite: you confirm by email before anything is sent to you, and every message carries a one-click unsubscribe. It is used for nothing but telling you when that county opens.

Attribution. If you arrive via a marketing link, the campaign tags and referring page are kept in your browser and saved only if you sign up.

People who are not users. Two kinds of personal data reach Homjo about people without an account. If you report content and give your name and email, we keep them with the report. If Homjo holds a listing for a local provider with their written permission (see How Listings Get Onto Homjo), we store the provider's name, a reference to where their permission is filed, the dates it runs, and any takedown or takeover request they make. Providers are told this when we ask for permission.

We do not use advertising trackers, we never sell your data, and we never share it with advertising networks. To see how the site is used we rely on aggregate, cookieless web analytics from our hosting provider, Vercel: page views, referrers, country, device and browser type, with nothing stored in your browser and no profile of you built. That is the only third-party analytics on Homjo.

2. Why we process it (legal bases)

  • Running the service you signed up for (contract): account, listings, messaging, bookings, offers, payments, notifications you enabled.
  • Legal obligations: content-moderation records and statements of reasons (Digital Services Act), tax and accounting records, responding to data-subject requests.
  • Legitimate interests: keeping the platform safe (moderation, rate limiting, fraud prevention, trust and churn signals), first-party product analytics, error monitoring, and defending legal claims. You can object at privacy@homjo.com.
  • Consent: optional things you switch on, like push notifications, saved-search alerts, identity verification, the Connect age declaration and the county waitlist. Withdraw any time in settings, or via the unsubscribe link in any waitlist email.

3. Automated processing

Listings and images are screened before publication using a deterministic keyword filter, AI-assisted review, and image scanning — including screening against Irish Equal Status Acts discrimination patterns. When a check finds an unambiguous problem, the listing is hidden automatically until a person reviews it. Profile bios, offers and Provider Studio content are checked the same way; messages and requests are checked for warning signs but never blocked.

Some limits are applied automatically with no review at the time: posting limits (5 listings per hour, 20 per day), plan quotas, the offer allowance, and the 30-day listing expiry. They apply identically to everyone on a plan.

A moderation decision can always be appealed to a human — from the notice in your dashboard or at appeals@homjo.com. We do not make decisions by automated means alone that produce legal or similarly significant effects on you. Details of every AI feature are in the AI Usage Disclosure.

4. Who we share data with

We use a small set of service providers (sub-processors) to run Homjo — hosting, transactional email, the county-waitlist mailing list, SMS, payments and identity verification, maps, AI moderation and translation, and error monitoring. The current list, what each receives, and where they process it is published at Sub-processors. Some are in the United States and process data under the EU Standard Contractual Clauses or the EU–US Data Privacy Framework; the list says which.

If you sign in with Google or Apple, that provider learns that you signed in to Homjo, under its own privacy policy. If you choose Apple's "Hide My Email", Apple gives us a relay address instead of yours and forwards our emails to you. Facebook sign-in is not offered today; if we switch it on, the same applies and this page will say so.

We share data with public authorities only where the law requires it — on a valid legal request, which we check before we answer. Requests from authorities go to dsa@homjo.com.

5. How long we keep it

  • Your account and content: for as long as you have an account.
  • Search logs and session logs: 6 months.
  • Product events: 24 months.
  • Image-moderation records: 12 months.
  • AI-generated cover images you did not use: 90 days. Older images are removed the next time your image album is opened.
  • Re-engagement reminders: 90 days after they are sent. Message-email throttle records: 30 days.
  • Accounts inactive for 3 years: we email a warning, and erase the account 30 days later if you don't sign back in.
  • Some records are kept longer where the law requires it or where they are the evidence that we did something: statements of reasons and appeal decisions under the DSA, illegal-content notices, the register of data-subject requests, payment records for tax purposes, and records of a provider's takedown or takeover request. When you delete your account, these are de-identified rather than deleted (see Section 6).

Deletion timers run automatically every night.

6. Your rights

You have the right to access, rectify, export, and erase your data, to restrict or object to processing, and to withdraw consent. Two of these are self-serve:

  • Export: Profile → Settings → Your Data → "Download my data" gives you a machine-readable copy of your data immediately, as a single JSON file with a readme explaining each part. It does not include your photos themselves (email us for those), sign-in logs held by our authentication provider, other people's messages to you, or moderation notices you already received. A notice email is sent to your address whenever an export happens, so you'd know if someone else did it. Exports are rate-limited.
  • Erasure: deleting your account in Profile → Settings permanently erases your profile, listings, bookings, offers, messages, ratings given and received, documents, and uploaded images. This is a full erasure, not a deactivation. A short list of records is kept in de-identified form because we are obliged to keep them or because they protect other people: moderation and appeal records, illegal-content notices you filed, the data-request register entry recording the erasure itself, and aggregate platform events. The county waitlist is a separate list — unsubscribe from any of its emails to leave it.

You can also object to the trust and churn signals described in Section 1. That is not self-serve: email privacy@homjo.com and we will stop computing them for you or explain why we cannot.

For anything else, email privacy@homjo.com. We respond within one month (GDPR Art. 12(3)) and aim for 15 working days. You can complain to the Irish Data Protection Commission (dataprotection.ie) at any time.

7. Where data lives

Homjo's database and file storage are hosted in the EU (Ireland). Our server-side functions run on our hosting provider's network and read from and write to that Irish database. Some providers process data in the US under EU-approved safeguards — the sub-processor list says which.

8. Messages we send you

  • Transactional: new messages, offers, booking updates, rating prompts, moderation notices, plan and Boost events, and the export-security notice. Four categories have an off switch in Settings: new messages, offers, saved-search alerts, and booking reminders and rating prompts. The rest always send — booking requests, confirmations, declines, cancellations and no-shows, moderation notices, plan and Boost lifecycle emails, and the export-security notice. They cannot be switched off because each one is a record of something that has already happened to you or your listing.
  • Welcome: one email when you finish creating your account, confirming it is set up and showing what you can do on Homjo. It is sent once and never repeated, so there is nothing to switch off.
  • Saved-search alerts: optional; switch them all off with one setting, or pause one search from the link in its email.
  • Marketing: only the county waitlist, which you join and confirm separately.
  • We use email, and SMS or push notifications where you have enabled them.

9. Security and breaches

Access to personal data is restricted by database-level rules and logged. If a breach is likely to put your rights at risk, we will tell you without undue delay and notify the Data Protection Commission within 72 hours as GDPR Art. 33 requires. Security reports: security@homjo.com.

10. Children

Homjo is for adults. You must be 18 or older to use it. We do not verify age at sign-up; creating an account is your confirmation that you are 18 or over, and Connect asks you to confirm it explicitly. If we learn that an account belongs to someone under 18 we delete it.

11. Changes and language

When this policy changes, the version and date below change with it. Material changes will be announced in the product. This policy is published in English; if a translation differs, the English version applies.

Version 1.7 · Effective 20 August 2026 · Updated 4 September 2026 · privacy@homjo.com