Privacy Policy
Effective March 3, 2026
Homematch is operated by peak intelligence AG, Im Langacher 42, 8805 Richterswil, Switzerland. This policy describes how we handle data on homematch.ch and in the Homematch app. It complies with the Swiss Data Protection Act (DSG). Homematch is intended for persons aged 18 and older. We do not knowingly collect data from minors.
What We Collect
Account data — When you sign up, we need your email address, a username, and a password. You can add information commonly required for rental applications — personal details, employment, residence history, household composition, and so on. This data stays private until you submit an application to a landlord. You can change it at any time.
Phone number — We collect and verify your phone number via SMS. Verification serves account security and ensures that landlords can reach you when needed. Your number is only shared with landlords you actively apply to.
Documents — You can upload documents to support rental applications (identification, proof of income, references, etc.). These are stored securely and only shared with landlords you send a contact request to.
Usage data — We observe how you interact with listings — what you view, save, and share — so our recommendation engine can learn your preferences and suggest better matches.
Communication data — Messages you send and receive through the platform are stored on our servers. This includes messages between you and landlords or agencies, as well as system notifications. Read receipts are tracked so both parties can see when a message has been read.
Reference checks — If you use the reference check feature, we contact your employer or previous landlord on your behalf to verify the information you provided. We store the verification status and related contact details.
Technical data — Standard server logs: IP address, browser, operating system, device type, referrer, and timestamp.
Contact form — If you reach out through our contact form, we collect your name, email address, and message.
Authentication — We support email/password, Google, and Apple sign-in. Your session is managed with secure HttpOnly cookies. On mobile, your credentials are stored in encrypted device storage.
Payment data — When you use a paid feature, your payment information is processed directly by Stripe. We do not store credit card numbers or bank details on our servers. We only receive a reference ID, payment status, and basic transaction information from Stripe.
Mobile App
The Homematch app may request the following device permissions, each only when needed for a specific feature:
- Camera — For profile photos and scanning QR codes.
- Photo library — To upload profile photos and documents.
- Location — To show your position on the map and display nearby properties. We do not track your location in the background.
- Contacts — To suggest contacts when inviting household members. Contact data is not uploaded to our servers.
- Calendar — To add viewing appointments to your calendar.
- Notifications — For push notifications about new messages, application updates, and property recommendations.
- Biometrics — To secure access to account settings via Face ID or fingerprint.
Push notifications are delivered through Firebase Cloud Messaging. We store a device token to deliver notifications. You can disable notifications in your device settings at any time.
What We Don't Collect
- No Meta Pixel, TikTok Pixel, or Google Ads tracking
- No retargeting or marketing cookies of any kind
- No data purchased from third-party brokers or credit agencies
- No background location tracking
- We do not sell or share your data with advertisers
Cookies & Local Storage
We keep cookies to a minimum:
- Auth cookies — HttpOnly session cookies for authentication. Required for the platform to work.
- Token expiry — A cookie that stores when your session expires, used to keep you logged in automatically.
- Language preference — Stores whether you use German, English, French, or Italian.
- Firebase Analytics — Sets cookies to measure site usage. IP anonymization is enabled, data sharing and Google Signals are disabled.
We also use Vercel Analytics and Speed Insights — these do not use cookies and do not collect personal data.
A random session ID is stored temporarily in your browser (not a cookie) to batch analytics events. It is deleted when you close the tab.
On mobile, credentials are stored in encrypted device storage. Chat history is cached locally so you can read messages offline.
How We Use Your Data
We use your data to operate the platform, manage your account, suggest listings through our recommendation engine, facilitate communication between you and landlords, process rental applications, verify references, deliver push notifications, improve the product, prevent abuse, and meet legal obligations.
Legal Basis
We process your data on the following grounds:
- Contract performance — We process account data, profile data, documents, communications, and payment data to provide our platform and enable rental applications.
- Consent — For phone number verification, the newsletter, reference checks, and optional device permissions (location, contacts, camera, etc.) we obtain your explicit consent. You can withdraw it at any time.
- Legitimate interest — We process usage data for the recommendation engine, technical logs for security and debugging, and analytics data for product improvement on the basis of our legitimate interest.
- Legal obligation — We retain certain data when legally required to do so (e.g. accounting retention obligations).
Recommendation Engine
Homematch uses a recommendation engine to suggest rental listings based on your profile, preferences, and how you use the platform. The more you interact with listings, the better the suggestions become. This is a search aid, not an automated decision that affects your rights.
Third-Party Services
We work with the following providers to operate the platform:
- Microsoft Azure — Cloud infrastructure, database hosting, and file storage. Microsoft Ireland Operations Limited (Ireland).
- Google (Firebase) — Authentication, analytics, push notifications, and feature flags. Google Ireland Limited (Ireland), sub-processor: Google LLC (USA).
- Vercel — Website hosting and privacy-friendly web analytics. Vercel Inc. (USA).
- Resend — Email delivery for contact form, notifications, and newsletters. Resend Inc. (USA).
- Mapbox — Map rendering and address search in the mobile app. Mapbox Inc. (USA).
- HERE Technologies — Geocoding and location services. HERE Global B.V. (Netherlands).
- Twilio — SMS delivery for phone number verification. Twilio Inc. (USA).
- Supabase — Database and backend services. Supabase Inc. (USA).
- Stripe — Payment processing. Stripe Payments Europe Ltd. (Ireland), sub-processor: Stripe Inc. (USA). Payment data is processed directly by Stripe and not stored on our servers.
- Apple — Sign in with Apple. Apple Distribution International Ltd. (Ireland).
- Sentry — Error tracking and diagnostics. Functional Software Inc. (USA).
- OpenStreetMap — Map tiles on the website, routed through our own server. OpenStreetMap Foundation (UK).
Some of these providers are located in the USA. Where required, we use standard contractual clauses to ensure adequate data protection.
Newsletter
If you subscribe, our emails may contain tracking pixels to measure open rates. Every email includes an unsubscribe link.
Data Retention
We retain your data as long as we need it for the purposes described above, or as required by law. When you delete your account, your data is marked for deletion and permanently removed after a transition period — unless we are legally required to retain it.
Security
All traffic is encrypted via TLS. Authentication uses HttpOnly cookies on web and encrypted device storage on mobile. Forms have rate limiting and spam protection. All input is validated and sanitized. You can view active sessions and revoke them individually. On mobile, account settings are additionally protected by Face ID or fingerprint.
Your Rights
Under Swiss law, you can:
- Request information about what data we hold about you
- Have incorrect data corrected
- Request deletion of your data
- Receive a copy of your data in a portable format
- Object to processing, in particular for marketing purposes
- Withdraw consent at any time
Contact us via our contact form or email us at info@homematch.ch. We may need to verify your identity before processing your request.
You can also file a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC).
Changes
We may update this policy. The version on this page is always the current one.
Contact
peak intelligence AG
Im Langacher 42, 8805 Richterswil, Switzerland
info@homematch.ch / info@peakintelligence.ch