Privacy Policy
immoClaire is currently offered as a closed or internal test. Test environments may be reset or wiped without notice. Do not upload real identity documents, genuine payslips, or other sensitive personal documents while the app is in testing. Use fictional or redacted test data only.
1. Who we are
The data controller for immoClaire is IRONBLOOM BV, based in Belgium.
Contact for privacy matters: contact@ironbloom.be.
This Privacy Policy applies to the immoClaire mobile application
(Android and iOS), package / bundle ID
com.immoclaire.app, and the backend services that support
it.
2. What data we collect
We collect only the data needed to operate the rental matching service. Categories below reflect what the current product actually stores and transmits.
2.1 Account and authentication
- Email address
- Password (stored only as a one-way cryptographic hash)
- Account role (renter, landlord, or admin)
- Session / refresh tokens and a limited device identifier derived from the User-Agent string of the device that signed in
2.2 Profile
- Display name, first name, last name
- Phone number (optional)
- Bio and profile photo (avatar)
- Preferred language and notification preferences
2.3 Search preferences
- Filters you set: price range, cities, property types, number of bedrooms, and commute-related preferences
2.4 Property and listing data (landlords)
- Full address, postal code, city, country, and map coordinates that you enter when creating a listing (these are landlord-supplied address fields — the app does not access device GPS)
- Listing title, description, rent, deposit, and photos
- Visit availability preferences
2.5 Behaviour and matching
- How you interact with listings (like, dislike, or pass) and expressions of interest, including any optional free-text message to a landlord
- A non-binding match score used only to help rank listings in your feed. This scoring does not produce legal or similarly significant effects about you
2.6 Messaging
- Message content and related metadata exchanged between renters and landlords (for example listing references or proposed visit times)
2.7 Visit scheduling
- Visit appointments, notes you or the other party add, and post-visit decisions or rejection reasons
2.8 Documents and media
- Verification documents you choose to upload to the secure vault (for example payslips or identity documents). During testing, please do not upload real documents — see the notice above
- Listing photos and profile avatars
- Media is stored in S3-compatible object storage. Image processing strips EXIF / GPS metadata from uploaded photos before they are served
2.9 Security and audit logs
- Technical logs related to document access and security events, which may include IP address and User-Agent
2.10 Data we do not collect
- We do not use advertising identifiers, analytics SDKs, crash reporters, or marketing trackers in the current app build
- We do not sell personal data and we do not share it with advertisers
- The app does not request device location (GPS) permissions; map tiles are fetched from OpenStreetMap when you view a map
3. Why we process your data (purposes and legal bases)
- Contract performance — creating and managing your account, listings, messaging, visit scheduling, and search preferences so the service works as you expect
- Consent — uploading verification documents to the vault; you can delete individual documents and withdraw consent by removing them or deleting your account
- Legitimate interests — securing the service, preventing abuse, and maintaining audit trails. You may object to processing based on legitimate interests as described in section 8
4. Who receives your data
Your data is handled by:
- Our hosting infrastructure — application servers hosted on a Hetzner VPS under our control
- Object storage — S3-compatible storage for photos and vault documents
- OpenStreetMap — when you open a map in the app, tile requests are made to OpenStreetMap tile servers, which receive your device IP address in the ordinary course of loading map tiles
- Other users of the service — landlords and renters you interact with see the profile and listing information you choose to share through the product (for example messages, interests, and listing details)
We do not use third-party analytics, advertising, payment, SMS, or crash-reporting providers in the current release.
5. International transfers
Primary application data is processed in the European Economic Area (our Hetzner infrastructure). If object storage or map tile providers process data outside the EEA, we rely on appropriate safeguards required by applicable law (for example Standard Contractual Clauses where relevant).
6. How long we keep your data
- Account, profile, listings, messages, preferences, and related records are kept for as long as your account remains active
- When you request account deletion, we schedule deletion with a 30-day grace period during which you can cancel the request in the app. After that window, associated account data is deleted, subject to limited retention needed for security, fraud prevention, or legal obligations (for example audit logs)
- Individual vault documents can be deleted by you at any time; the stored file is removed from object storage when you delete the document
- During the testing phase, datasets may also be reset as part of development (see the notice at the top of this page)
7. Security
We use industry-standard measures appropriate to the sensitivity of the data, including TLS encryption in transit, hashed passwords, authenticated API access, and malware scanning of vault uploads. No method of transmission or storage is completely secure; please use a strong unique password and avoid uploading real identity documents during testing.
8. Your rights (GDPR)
If you are in the EEA or UK, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data (“right to be forgotten”)
- Restrict or object to certain processing
- Receive a portable copy of data you provided to us
- Withdraw consent where processing is based on consent
To exercise these rights, email contact@ironbloom.be or use the in-app account deletion flow (Profile → Delete Account). You can also request deletion via our account deletion page.
You also have the right to lodge a complaint with the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit): www.dataprotectionauthority.be (also known as APD / GBA).
9. Children
immoClaire is intended for adults seeking or offering rental housing. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
10. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will change when we do. For material changes we will provide additional notice in the app or by email when reasonably practicable. Continued use of the service after an update constitutes acknowledgment of the revised policy.
11. Contact
Questions about this Privacy Policy or your personal data: contact@ironbloom.be.