Privacy Policy
Last updated: August 13, 2026
This policy describes how Homewise Connect (“Homewise”, “we”) collects, uses and protects the information of providers who use the Homewise mobile app and of the end customers whose lead data is distributed through the platform.
1. Who we are
Homewise is a lead distribution platform connecting customers who requested residential services in the United States to registered providers. We are not a consumer marketplace - the end customer does not use the app, and their personal data is passed on to providers only after a lead is claimed.
2. Data we collect
2.1. From the provider (app user)
- Account: name, email and/or mobile phone (E.164), password (stored as a bcrypt hash). The provider creates their own account on the site or in the app and adds their phone number when completing registration, at which point they consent to the SMS described in the SMS messaging program.
- Profile: optional photo (Supabase Storage), base address and coverage radius in miles, service types offered.
- Approximate location: derived from the base address the provider supplies (no continuous device tracking).
- Usage data: leads viewed and claimed, statuses the provider updates; credit history.
- Technical identifiers: push notification token (Expo), IP and user-agent on authentication events.
- First app launch: the first time the app opens, before any account exists, it sends a random identifier the app generated for that installation, along with the platform and app version. It carries no device identifier and no advertising id, and we do not keep the IP address. We use it for one thing: to know how many people install the app and never finish signing up. If that person later creates an account, the record is linked to it; if they delete their account, the link is removed and the record stays anonymous.
2.2. From the end customer (lead)
Leads are collected through Facebook Lead Ads forms, authorized integrations and the form on Homewise's own site. We collect:
- The customer's name, phone and email.
- ZIP code, requested service type, description, urgency, estimated value.
This data is shared only with the up to 3 providers who claim the lead. Before claiming, a provider sees only the service type and ZIP code - phone and email are released only after credits are spent.
3. How we use the data
- To authenticate and identify the provider.
- To distribute leads within the provider's coverage area.
- To send operational communications: verification codes (2FA, password recovery), push notifications and SMS (new lead, low balance, support message, lead expiring) and support channel messages. Recurring SMS are only sent for the categories you turned on - see the SMS messaging program.
- For end customers: to send a single feedback request by SMS after a service is completed.
- To prevent fraud and platform abuse.
- To comply with legal and tax obligations.
4. Who we share it with
- Providers who claimed a lead receive the end customer's contact data.
- Payment processors (Stripe): process credit purchases on the web. We do not store card numbers.
- Infrastructure providers: Resend (transactional email), Twilio (SMS), Expo (push), Supabase (database + image storage), Mapbox (geocoding), Render (hosting), Sentry (error monitoring). Each one processes data only within the scope of the service it provides.
- Zapier: relays incoming leads from Meta into our systems.
We do not sell personal data to third parties.
5. SMS messages
Mobile opt-in data and consent are never shared with, sold to, or rented to third parties or affiliates for marketing or promotional purposes. The phone number you provide is used only to deliver the messages you authorized.
We use Twilio exclusively as the technical sending carrier. We send account SMS (login/2FA codes, security alerts), operational notices you can turn on and off (new lead in your area, low balance) and, for end customers, a single review request after the service is completed. Frequency varies, and message and data rates may apply from your carrier.
You can opt out at any time by replying STOP to any message, or turn each category off under Profile → Notifications. Reply HELP for help. The full program details are on the SMS messaging program page.
6. Cookies, analytics and advertising
On Homewise's public site (the marketing pages aimed at the end customer), we use cookies for two purposes:
- Strictly necessary: they keep the session, the chosen language and browsing security. They are essential to the site and cannot be turned off.
- Analytics (Google Analytics 4): we use Google Analytics to understand how visitors find and use the site and to measure the effectiveness of our campaigns. Measurement cookies (such as
_ga) are only written after your consent: we show a notice and Google Analytics stays disabled until you accept. Declining does not affect your use of the site in any way. - Advertising (Meta Pixel and Conversions API): when you accept optional cookies, we may load the Meta Pixel and use cookies such as
_fbcand_fbpto measure conversions. Separately, when you submit a request that came from a Meta ad, the explicit acceptance on the form authorizes Homewise to send the event through the Conversions API. We may include campaign, ad-set and ad identifiers, plus normalized, hashed contact data such as email and phone, and the technical identifiers needed for matching. We do not send the project description, the street address or the contact preference.
If you decline optional cookies, we neither load the Meta Pixel nor create Meta cookies. We may still keep campaign parameters present in the URL for our own internal reports. The Conversions API event is only sent when you also accept the explicit disclosure on the form submission. Declining cookies does not affect your use of the form.
Google and Meta act as processors of this measurement data. Learn more in Google's privacy policies and Meta's privacy policy. The authenticated areas (the provider app and the admin panel) use no analytics cookies.
7. Retention
We keep data while the account is active. When a provider deletes their account in the app, we anonymize the personal fields (name, email, phone, photo) and keep only the operational records needed for legal and tax auditing (credits purchased, claims, transactions). Session and notification tokens are deleted immediately.
8. Your rights
At any time, you can:
- Access and update your profile data in the app.
- Delete your account through the in-app flow (Profile → Delete my account).
- Request a copy of your data at any time in the app (Profile → Privacy → Export my data). In line with the CCPA and the LGPD, we generate a compressed file with your personal data and provide a download link valid for 24 hours.
- File a complaint with the competent authority. Use the contact channel below.
9. Children
The service is intended for professionals of legal age. We do not knowingly collect data from anyone under 18.
10. Changes to this policy
We may update this policy from time to time. Substantive changes will be announced in the app before they take effect. The date at the top of this page reflects the current version.
11. Contact
Privacy questions or requests: [email protected].