Legal

Privacy Policy.

How The Concierge collects, uses and protects information across the website, mobile app, customer portal, API and connected services.

Summary

Last updated: 9 August 2026.

The Concierge is designed to bring account, household, planning, smart-home, health, notification and Butler assistant features into one account. We collect the information needed to create and secure your account, provide the features you choose to use, sync your devices, send notifications, support you, improve reliability and meet legal obligations.

We do not sell personal data. Optional integrations, such as health, music, smart-home, camera, email, payment or hiring services, are only used where they are connected by you, an authorised account user or an authorised team member.

Who We Are

This policy applies to The Concierge website, Concierge Home mobile app, customer portal, API, notify forms, support channels, admin tools, hiring portal and related services operated for Concierge Home.

For privacy questions, account requests or data-rights requests, contact privacy@conciergehome.co.uk.

Data We Collect

Account and identity data: name, email address, phone number where supplied in the mobile registration flow, password hash, account id, verification status, verification tokens, accepted terms/GDPR timestamps, profile picture URL, home name, membership/status labels and account role.

Login and security data: access tokens, session state, remember-me cookies, login history, password reset or change events, email verification events, API request metadata, IP address where logged for security or notify forms, device and browser details where supplied in support or IT workflows.

Household and preference data: home name, location label, weather location, latitude and longitude when device location is enabled, temperature/currency/measurement units, week-start preference, calendar visibility, theme, appearance mode, app icon, accessibility settings, onboarding progress, dashboard widgets and notification channel preferences.

Planning and daily-life data: calendar events, shifts, roles, locations, rates and overtime rates, tasks, reminders, notes, shopping lists, meal plans, ingredients, recipe links, vehicles, registration numbers, MOT/tax/insurance dates and household utility meter readings or reminders.

Butler assistant data: Butler briefings, messages, prompts, replies, action history, completed actions, speech/audio requests, transcriptions and cached speech output. Butler may use your account, home, calendar, task, shopping, meal, weather, news, smart-home, vehicle and health context to answer requests and carry out supported actions.

Health data: if enabled, daily health summaries from Apple Health or Health Connect, including date, steps, distance, active energy, sleep minutes, workouts, exercise minutes, stand hours, heart-rate summary, source provider and update time. We treat health data as sensitive and use it only for app features you enable.

Notification and device data: installation id, push token, push provider, device name, platform, app version, enabled status, notification outbox events, delivery status and notification categories such as shifts, calendar events, tasks, shopping, meals, meter readings and Butler briefings.

Smart-home, security and integration data: rooms, devices, scenes, device names, device types, provider ids, supplier device ids, local discovery data, capabilities, online/offline state, last-seen time, power/brightness/temperature/lock state, favourite state, camera locations, doorbell status, motion timestamps, privacy-mode status and whether recording remains active. Optional provider tokens may be stored encrypted server-side for connected suppliers such as Tuya/Smart Life, Home Assistant, Ring, Imou, Google Home or music providers.

Support, operations and admin data: customer portal requests, support messages, email replies, data export/deletion requests, subscription/order/download/security records, internal notifications, audit logs and operational metrics. Admin and employee tools may process work email, job title, department, manager, employment status, leave, payroll-change, document, training, IT ticket, device, audit and Google Workspace data for authorised staff workflows.

Hiring data: candidate name, email, application details, right-to-work confirmation, consent records, documents selected or signed, vacancy stage history, interview or offer actions, manager notes, provisioning plans and onboarding details where a candidate progresses through Concierge Hire.

Payments and finance data: plan, subscription, order, refund and payment status data. Payment card processing is handled by payment providers such as Stripe; we should not store full card numbers. Internal finance tools may process business banking or transaction data where a business account is connected.

Website and marketing data: notify-list email addresses, form submissions, social-post planning data, campaign records and basic analytics or communication preferences where enabled.

How We Use Data

We use personal data to create and secure accounts, verify email addresses, provide the mobile app and website, sync account data, display dashboards, operate Butler, send notifications, process customer requests, provide support, manage subscriptions, handle hiring, administer internal systems and comply with law.

We use location and weather preferences to show local weather and relevant dashboard information. We use health summaries only to show health views, goals and trends. We use smart-home and security data to show device status, run scenes, operate supported devices and hide camera views when privacy mode is enabled. Privacy mode hides live and thumbnail views in Concierge while keeping recording active where the connected provider or device continues to record.

Butler uses account context to answer questions and perform supported actions. Where AI providers are used, requests may include the minimum context needed to produce a relevant answer or transcription. Butler must not be used as a substitute for medical, legal, financial, emergency or safety-critical advice.

Lawful Basis

Where UK GDPR or similar laws apply, we rely on contract where processing is needed to provide the service, consent for optional choices such as some notifications, health, location, marketing or connected-provider access, legitimate interests for service security, reliability, support and improvement, and legal obligation where records must be kept for compliance, tax, employment or dispute purposes.

Sharing

We share data only as needed to run the service, support you or comply with law. This may include hosting and database providers, email and Google Workspace services, payment providers, push notification providers such as Expo/Apple/Google, AI services such as OpenAI for Butler features, weather/news providers, connected smart-home or camera providers, music providers, hiring and internal administration services, professional advisers and authorities where legally required.

Third-party integrations may also process your data under their own terms and privacy notices. You should review those notices before connecting an integration.

Security

We use access controls, hashed passwords, authenticated API requests, server-side secrets, encrypted storage for supported provider tokens, limited public responses for sensitive token fields, audit logs and operational monitoring. No system can be guaranteed completely secure, so you must keep your password and devices safe and tell us quickly if you suspect misuse.

Retention

We keep account and service data while your account is active or while needed to provide the service. We may keep limited records afterwards where required for security, legal, tax, dispute, fraud-prevention, employment or regulatory reasons. Butler messages, notification events, logs, backups and connected-provider records may have different retention periods depending on operational need and legal requirements.

You can request export or deletion through the customer portal or by contacting support. Some information may need to be retained where the law requires it or where it is needed to establish, exercise or defend legal claims.

Your Rights

Depending on where you live, you may have rights to access, correct, export, delete, restrict or object to processing of your personal data, and to withdraw consent where processing is based on consent. You may also have the right to complain to the UK Information Commissioner's Office or your local supervisory authority.

You can update many account details in the app or customer portal. For formal requests, email privacy@conciergehome.co.uk. We may need to verify your identity before acting on a request.

Children

The Concierge is not intended for children to create accounts without appropriate parental, guardian or household-owner involvement. Household members or guests should only be added where the account holder has authority to do so.

Changes

We may update this policy as The Concierge changes. If the changes are material, we will take reasonable steps to notify users through the website, app, email or customer portal.