Privacy Policy
Last updated: 28 July 2026
This policy explains how TIBRA ENTERPRISE LTD ("Homaroo", "we", "us") collects, uses and protects personal data when you use the Homaroo website and the Homaroo Engineer app. It covers customers who book services, the engineers who carry them out, and other people whose details a customer may give us (such as a property occupant).
Who we are
The data controller is TIBRA ENTERPRISE LTD (company number 16915407), registered at Office 16117, 182–184 High Street North, East Ham, London, England, E6 2JA. For any privacy question or to exercise your rights, contact us at [email protected]. We are registered with the UK Information Commissioner's Office (ICO) under registration number 00014843698.
The information we collect
Depending on how you use Homaroo, we may collect:
- Account & contact details - your email address (used to sign in), name and phone number. We use passwordless sign-in, so we never collect or store a password.
- Booking details - the service address (address, city and postcode), the appointment date/time, and the information you enter about the job: property type, appliance details (e.g. boiler make/model/age, fuel type), symptoms or error codes, access notes, selected add-ons, and any free-text notes.
- Occupant details - if you arrange a booking for someone else (e.g. a tenant), the name and - if you provide them - the email address and UK mobile number you give us for them, so we can send the scheduling link by email or text message.
- Engineer onboarding information - for engineers: a profile (bio, services, coverage), a customer-facing selfie, and verification documents (a government ID such as a driving licence or passport, a Gas Safe registration card, and public liability insurance).
- Location data - see "Location" below.
- Job records - job reports, work performed, safety notes and photographs taken at the property during a job; and, after a job, any rating and review a customer leaves.
- Device & technical data - for the engineer app, a push-notification token for your device; and standard technical data (such as IP address and device/browser type) that is processed when you connect to our site and its providers.
- Records of your bookings and payments - the amounts, our commission and engineer payout, and the status/history of each booking.
We do not collect or store your payment card details ourselves. Payments are handled by our payment provider: you enter your card details directly with them, and we receive only a payment confirmation and limited transaction information (such as the amount and outcome) - never your full card number.
How and why we use it (lawful bases)
Under UK GDPR we rely on the following lawful bases:
- To provide the service (performance of a contract) - creating your account, taking and managing bookings, matching jobs to engineers, sharing the details each party needs to complete a job, and handling reviews.
- Legitimate interests - verifying and vetting engineers, keeping the platform safe and trustworthy, preventing and investigating fraud or misuse, resolving disputes, and improving our service. You can object to processing based on legitimate interests (see "Your rights").
- Consent - sharing your live location and sending push notifications rely on the permissions you grant on your device, which you can withdraw at any time in your device settings.
- Legal obligation - keeping financial/tax records and meeting health-and-safety obligations for gas and related work.
Identity documents
Engineer verification documents (ID, Gas Safe card, insurance) and selfies are used only to confirm identity and eligibility to work. A government ID may incidentally contain more sensitive information; we ask you not to provide more than is needed, we store these files privately (see "How we protect your data"), and only administrators can access them for verification. A customer only ever sees an engineer's verified selfie - never their ID or other documents.
Location
When an engineer taps "on my way", the engineer app shares that engineer's live location with the customer for that job so the customer can see they're on the way and roughly when they'll arrive. On Android this uses a foreground service (with an ongoing notification) so it keeps working while the app is in the background; we do not request "all-the-time" background-location access. Live location is stored only while the engineer is en route and is deleted automatically once the journey ends. Sharing is one-directional - the customer's device location is never shared with the engineer. Separately, we use a postcode look-up service to turn a booking's postcode into an approximate area so engineers can see how near a job is.
What customers and engineers see about each other
- Before an engineer accepts a job, they see only what's needed to decide: the service, date/time, payout, the postcode, and the job description you entered. They do not see your name, street address, access notes or contact details.
- After an engineer accepts, they see the full address, access notes and your contact details so they can carry out the job.
- The customer sees the assigned engineer's name, rating, jobs completed and verified selfie, and their live location while en route.
Who we share data with
We do not sell your data. We use a small number of trusted providers ("processors") to run the service:
- Cloud database and storage providers - our database, sign-in system and file storage.
- Hosting providers - running and delivering our website and app back-end.
- Push notification services - delivering push notifications to the engineer app (your device token plus the job-offer summary).
- Email and text-message delivery providers - sending our emails and texts, such as sign-in codes, booking updates, occupant scheduling links and appointment reminders (the relevant email address or mobile number, and the message content).
- Payment providers - processing payments. Your card details are entered with and handled by the payment provider; we do not store them.
- Postcode look-up services - validating postcodes and approximate geocoding.
- Web font and map providers - loading web fonts (which involves your browser contacting the font provider), and opening map/directions links or map views (which shares the relevant location with the map provider).
We also share data where required by law, or to establish, exercise or defend legal claims (for example, in a dispute or investigation).
International transfers
Some of our providers may process data outside the UK. Where they do, we rely on appropriate safeguards - such as UK "adequacy" regulations or the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses - so your data receives an equivalent level of protection. Contact us for details.
How long we keep it
We keep personal data only as long as we need it. Live location is deleted as soon as a journey ends. When an account is deleted (see below) we delete the personal information associated with it, except where we must keep it: records of completed jobs and payments are retained for as long as the law requires (typically up to 6 years for tax and accounting), and we may keep information needed for safety, disputes, fraud prevention or an ongoing investigation. Where practical we remove or anonymise personal identifiers in anything we retain.
How we protect your data
- All data is encrypted in transit (HTTPS).
- Access to every record is restricted by row-level security so people can only see data they're entitled to; administrator access is limited and controlled.
- Uploaded files (IDs, selfies, job photos) are held in private storage and are only ever served through short-lived, expiring links - never public.
- Sign-in is passwordless (one-time email codes), so there is no password to be lost or stolen.
Your rights
Under UK GDPR you have the right to: access your data; correct it; erase it; restrict or object to processing; data portability; and withdraw consent (e.g. turn off location or notifications) at any time. To exercise any of these, email [email protected]. You can also request deletion of your account at any time via our account deletion page. If you're unhappy with how we handle your data, you can complain to the ICO at ico.org.uk.
Cookies & analytics
We don't use advertising or ad-tracking, and we don't sell your data.
We use a third-party product to see how our website and app are used, so we can improve them. The data is held in the EU. We honour your browser's "Do Not Track" setting, and you can email [email protected] to opt out at any time.
We store your sign-in session in your browser's (or the app's) local storage so you stay logged in, and we use a single non-identifying cookie to remember an interface preference. Web fonts are loaded from a third-party font provider as noted above.
Children
Homaroo is not intended for, or directed at, anyone under 18, and we do not knowingly collect data about children.
Changes to this policy
We may update this policy from time to time. We'll change the "last updated" date above and, where changes are significant, let you know.
Contact us
Questions about this policy or your data? Email [email protected] or write to TIBRA ENTERPRISE LTD at the registered address above.