Privacy Policy
Effective August 8, 2026
Homematch is operated by peak intelligence AG, Im Langacher 42, 8805 Richterswil, Switzerland. This policy describes how we handle data on homematch.ch and in the Homematch app. It complies with the Swiss Data Protection Act (DSG). Homematch is intended for persons aged 18 and older. We do not knowingly collect data from minors.
What We Collect
Account data — When you sign up, we need your email address, a username, and a password. You can add information commonly required for rental applications — personal details, employment, residence history, household composition, and so on. This data stays private until you submit an application to a landlord. You can change it at any time.
Phone number — We collect and verify your phone number via SMS. Verification serves account security and ensures that landlords can reach you when needed. Your number is only shared with landlords you actively apply to.
Documents — You can upload documents to support rental applications (identification, proof of income, references, etc.). These are stored securely and only shared with landlords you send a contact request to.
Usage data — We observe how you interact with listings — what you view, save, and share — so our recommendation engine can learn your preferences and suggest better matches.
Communication data — Messages you send and receive through the platform are stored on our servers. This includes messages between you and landlords or agencies, as well as system notifications. Read receipts are tracked so both parties can see when a message has been read.
Reference checks — If you use the reference check feature, we contact your employer or previous landlord on your behalf to verify the information you provided. If you complete a reference link, we collect your full name, capacity, answers and declaration, and the submission time. We also store the IP address, browser identifier, language, request ID, and security-check result to prevent abuse and preserve an auditable record of the submission. The substantive results are made available to the person concerned and, for a submitted rental application, the responsible agency or landlord. Technical verification data is used only for security, abuse prevention, and audit purposes.
Technical data — Standard server logs: IP address, browser, operating system, device type, referrer, and timestamp.
Contact form — If you reach out through our contact form, we collect your name, email address, and message.
Authentication — We support email/password, Google, and Apple sign-in. Your session is managed with secure HttpOnly cookies. On mobile, your credentials are stored in encrypted device storage.
Payment data — When you use a paid feature, your payment information is processed directly by Stripe. We do not store credit card numbers or bank details on our servers. We only receive a reference ID, payment status, and basic transaction information from Stripe.
Mobile App
The Homematch app may request the following device permissions, each only when needed for a specific feature:
- Camera — For profile photos and scanning QR codes.
- Photo library — To upload profile photos and documents.
- Location — To show your position on the map and display nearby properties. We do not track your location in the background.
- Contacts — To suggest contacts when inviting household members. Contact data is not uploaded to our servers.
- Calendar — To add viewing appointments to your calendar.
- Notifications — For push notifications about new messages, application updates, and property recommendations.
- Biometrics — To secure access to account settings via Face ID or fingerprint.
Push notifications are delivered through Firebase Cloud Messaging. We store a device token to deliver notifications. You can disable notifications in your device settings at any time.
What We Don't Collect
- No TikTok Pixel, no sharing with data brokers
- No marketing cookies once you object — a single switch under Privacy settings stops them permanently
- No data purchased from third-party brokers or credit agencies
- No background location tracking
- We never sell your data. We share nothing with advertisers beyond what the Marketing category below covers — and turning it off ends that too
Cookies & Local Storage
We keep cookies to a minimum:
- Auth cookies — HttpOnly session cookies for authentication. Required for the platform to work.
- Token expiry — A cookie that stores when your session expires, used to keep you logged in automatically.
- Language preference — Stores whether you use German, English, French, or Italian.
- Consent cookie — Stores for one year whether you accepted or declined marketing cookies, so we don't have to ask again on every visit.
- Meta Pixel (Facebook/Instagram) — Active by default, with a right to object. Meta recognises your browser again (cookies
_fbpand_fbc) so we can show you Homematch ads on Facebook and Instagram and measure which ad led to an enquiry. Under Swiss law (revDSG, Art. 45c TCA) we inform you and give you the right to refuse — prior consent is not required. If you turn off the Marketing category under Privacy settings, the pixel stops loading immediately and no further data is sent to Meta. We do not send Meta any email addresses, phone numbers or names. - Google Ads — Active by default, with a right to object. Google recognises your browser again so we can show you Homematch ads on other websites (retargeting) and measure which ad led to an enquiry. Under Swiss law (revDSG, Art. 45c TCA) we inform you and give you the right to refuse — prior consent is not required. If you turn off the Marketing category under Privacy settings, the Google tag stops loading immediately and no further data is sent to Google.
Both the Google tag and the Meta Pixel are active by default until you object. Turn the Marketing category off under Privacy settings and both stop immediately and permanently.
Measurement from our own servers (Meta Conversions API). Alongside the browser pixel, our server reports a small number of events to Meta — that a visit became an engaged visit, that a listing was bookmarked, that an enquiry was sent. This exists because ad blockers stop the browser pixel, and without it we cannot tell which advertising actually works. What we send is limited to the _fbp and _fbc cookies the Meta Pixel itself set in your browser, your browser's user agent, the event name, and the listing concerned. We never send your email address, phone number, name, or any account identifier — hashed or otherwise — and an event with no Meta cookie is discarded rather than sent. When you turn off the Marketing category, these cookies are deleted, and with them this reporting stops.
We also use Vercel Analytics and Speed Insights — these do not use cookies and do not collect personal data.
A random session ID is stored temporarily in your browser (not a cookie) to batch analytics events. It is deleted when you close the tab.
On mobile, credentials are stored in encrypted device storage. Chat history is cached locally so you can read messages offline.
How We Use Your Data
We use your data to operate the platform, manage your account, suggest listings through our recommendation engine, facilitate communication between you and landlords, process rental applications, verify references, deliver push notifications, improve the product, prevent abuse, and meet legal obligations.
Legal Basis
We process your data on the following grounds:
- Contract performance — We process account data, profile data, documents, communications, and payment data to provide our platform and enable rental applications.
- Consent — For phone number verification, the newsletter, reference checks, and optional device permissions (location, contacts, camera, etc.) we obtain your explicit consent. You can withdraw it at any time. Marketing cookies (Google Ads, Meta Pixel) run on the notice + right-to-object basis described under Cookies above.
- Legitimate interest — We process usage data for the recommendation engine, technical logs for security and debugging, and analytics data for product improvement on the basis of our legitimate interest.
- Legal obligation — We retain certain data when legally required to do so (e.g. accounting retention obligations).
Profiling & Personalisation
Homematch suggests listings based on your profile, your stated preferences, and how you use the platform. Because that involves drawing conclusions about you automatically, it counts as profiling under Swiss law, and here is what it actually does.
From the last eight weeks of your activity — which listings you opened, how long you stayed, what you saved, shared or enquired about, and what you marked as not interesting — we estimate what you appear to want for individual attributes such as rent, size or noise: a rough target, how tolerant you seem to be around it, and how confident we are. Recent activity counts for more than older activity. These estimates re-rank the listings we show you. They are not a decision about you, they are not shared with landlords or agencies, and nothing about your profile is scored for suitability or creditworthiness — we do not rank applicants for agencies.
Your control over it. In the app you can pin your own values for an attribute, and you can dismiss any individual attribute we have learned — a dismissed attribute stops influencing what you see and is not learned again. To be straightforward about the limit: there is currently no single switch that turns personalisation off entirely. If you want that, ask us and we will do it manually.
Signup risk check. When an account is created we calculate a risk score from technical signals — the network the request came from, whether the email domain is a disposable one, the country of the phone number, browser characteristics and signup frequency. It produces a low/medium/high flag for our operations team. It never blocks or rejects a signup by itself; a person decides. The record is deleted when you delete your account.
Artificial Intelligence
We use AI in three places, and in two of them personal data is involved. We would rather name them than describe AI in the abstract:
- Listing texts — descriptions and image suggestions are generated from the listing's own content. No personal data.
- The assistant our agency customers use — when a landlord or agency uses it to work through their enquiries, it can read the applicant messages in that conversation and the applicant's name. So if you send an enquiry, your message and name can be processed by the AI provider on the agency's behalf.
- Booking emails — when a reply about a viewing appointment comes in by email, the message text is analysed to detect the proposed appointment automatically.
The provider is OpenAI. We do not use your data to train anyone's models, and no decision with legal or similarly significant effect on you is made automatically — the profiling described above ranks listings, and the signup risk flag is reviewed by a person.
Third-Party Services
We work with the following providers to operate the platform:
- Microsoft Azure — Cloud infrastructure, database hosting, and file storage. Microsoft Ireland Operations Limited (Ireland).
- Google (Firebase) — Authentication, analytics, push notifications, and feature flags. Google Ireland Limited (Ireland), sub-processor: Google LLC (USA).
- Google Ads — Retargeting and measurement, active by default with a right to object (see Cookies). Google Ireland Limited (Ireland), sub-processor: Google LLC (USA).
- Meta (Facebook/Instagram) — Retargeting and measurement, active by default with a right to object (see Cookies). Meta Platforms Ireland Limited (Ireland), sub-processor: Meta Platforms, Inc. (USA).
- Vercel — Website hosting and privacy-friendly web analytics. Vercel Inc. (USA).
- Resend — Email delivery for contact form, notifications, and newsletters. Resend Inc. (USA).
- Mapbox — Map rendering and address search in the mobile app. Mapbox Inc. (USA).
- HERE Technologies — Geocoding and location services. HERE Global B.V. (Netherlands).
- Twilio — SMS delivery for phone number verification. Twilio Inc. (USA).
- Supabase — Database and backend services. Supabase Inc. (USA).
- Stripe — Payment processing. Stripe Payments Europe Ltd. (Ireland), sub-processor: Stripe Inc. (USA). Payment data is processed directly by Stripe and not stored on our servers.
- Apple — Sign in with Apple. Apple Distribution International Ltd. (Ireland).
- Sentry — Error tracking and diagnostics. Functional Software Inc. (USA).
- OpenAI — Listing text generation, the agency assistant, and parsing viewing-appointment emails (see Artificial Intelligence above). OpenAI Ireland Ltd. (Ireland), sub-processor: OpenAI, L.L.C. (USA).
- OpenStreetMap — Map tiles on the website, routed through our own server. OpenStreetMap Foundation (UK).
Some of these providers are located in the USA. Where required, we use standard contractual clauses to ensure adequate data protection.
Newsletter
If you subscribe, our emails may contain tracking pixels to measure open rates. Every email includes an unsubscribe link.
Data Retention
We retain your data as long as we need it for the purposes described above, or as required by law.
When you delete your account, we flag it immediately and a purge job removes your profile the same night — in practice within about 24 hours. That deletion is permanent and cannot be undone: your profile, documents, messages, applications, saved searches, sessions and recommendation data are erased outright, not archived.
Three things deliberately outlive the purge, and we would rather say so than imply a clean slate:
- Behavioural events — the record of what was viewed, searched and clicked. It is kept as a historical and audit record and still carries the account identifier it was recorded under, so it is not anonymous.
- Security and audit records — sign-ins, account-security events and the like, kept as evidence.
- Reports filed against you — kept so that someone reported for abuse cannot erase the report by deleting their account. Reports you filed about others are deleted with your account.
Other concrete periods: a data export ZIP is deleted 7 days after we prepare it; the training examples behind our recommendation engine are deleted after 2 years, and are removed immediately if you delete your account.
Security
All traffic is encrypted via TLS. Authentication uses HttpOnly cookies on web and encrypted device storage on mobile. Forms have rate limiting and spam protection. All input is validated and sanitized. You can view active sessions and revoke them individually. On mobile, account settings are additionally protected by Face ID or fingerprint.
Your Rights
Under Swiss law, you can:
- Request information about what data we hold about you
- Have incorrect data corrected
- Request deletion of your data
- Receive a copy of your data in a portable format
- Object to processing, in particular for marketing purposes
- Withdraw consent at any time
Two of these you can exercise yourself, without asking us: delete your account under Settings, and download a copy of your data from the privacy section of the Homematch app — we prepare a ZIP with your account data, applications and uploaded documents, notify you when it is ready, and delete it again after 7 days. The download is not yet available on the website; email us and we will send it.
For anything else, contact us via our contact form or email us at info@homematch.ch. We may need to verify your identity before processing your request.
You can also file a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC).
Changes
We may update this policy. The version on this page is always the current one.
Contact
peak intelligence AG
Im Langacher 42, 8805 Richterswil, Switzerland
info@homematch.ch / info@peakintelligence.ch