Legal

Privacy Policy

Last updated August 7, 2026

This policy explains how Jobspar collects, uses, and shares the information that identifies you or your customers — contact details, job notes and photos, payment data processed through Stripe, and basic usage logs. The text is standard SaaS boilerplate and has not been reviewed by an attorney; please read it as a starting point.

1. What this policy covers

This Privacy Policy explains how Jobspar ("we", "us", or "our") collects, uses, and shares information about you — and about the customers whose data you put into the Service — when you use the Jobspar website, the Jobspar application, and the Jobspar admin dashboard (together, the "Service"). It covers both the trades contractor who creates an account and the contractor’s own customers whose contact details, photos, invoices, or messages are uploaded into the Service by that contractor.

2. Information we collect

Account & sign-in. When you create an account we collect your name, email address, password (stored as a salted hash — we never see the plaintext), and the trade you run. A session cookie keeps you signed in while you use the Service.

Contact records. Every business contact you create in the Service — a job lead, a past customer, a vendor — is stored as a contact record with the fields you provide (name, phone number, email address, postal address, trade-specific details, and any free-form notes you add). The contractor who created the record owns it; Jobspar does not share your contact records with any other contractor.

Photos uploaded for AI measurement. When you attach a photo to a quote or job, the file is downscaled in your browser (see src/lib/client-photo-downscale) before it is sent to us. We receive the downscaled image and any labels you add. The photo is processed by a vision-capable large-language-model subprocessor solely to extract measurements you then review — Jobspar does not view or label the photo ourselves, and the photo is not used to train any third-party model.

Invoice and estimate records. Line items, totals, status, customer link, payment-link history, and the timeline of edits and sends for every invoice and estimate you create, send, or save as a draft.

Payment transaction metadata via Stripe. When you accept a customer payment through the Service, Stripe returns the metadata we need to record the transaction — amount, currency, status, the card brand and last four digits, the Stripe customer ID, and (for subscriptions) the Stripe subscription ID. Jobspar never sees the full card number, the CVC, or the card expiry date; those remain with Stripe.

Email and SMS thread content used to draft replies. When the Service triages your inbound mail or SMS and drafts a reply on your behalf, it stores the inbound message text, the contact metadata it was sent from, and the AI-drafted outbound draft you reviewed before sending. The thread content is kept so that you can audit what went out under your business name, and so that the Service can continue drafting replies in the same context.

Marketing form submissions. If you fill out a Contact form or a Get-a-quote form on the Jobspar website before creating an account, we collect your name, email address, phone number, and the message body so that we (or the contractor the lead was sent to) can respond.

Basic server logs. Every request to the Service writes a line to our logs containing the requesting IP address, the user agent, the request path, and the timestamp. Logs are used to operate, secure, and debug the Service.

Cookies and similar storage. See the Cookies section below.

3. How we use your information

Run the Service — authenticate you, store and surface your business data, draft replies, render the admin dashboard, and keep a contractor’s records isolated from any other contractor’s records.

Run Stripe for billing. We pass the minimum payment details Stripe needs to charge your customer and return the metadata we record against the invoice. Jobspar does not directly process card data.

Deliver messages you have asked us to send. When you approve an AI-drafted email or SMS, the Service delivers it to the recipient under your business name.

Route message content to our LLM subprocessor so it can produce a draft reply. The subprocessor receives only the inbound message and the context needed to draft a reply in the same customer relationship; details are listed in the Subprocessors section.

Operate, secure, debug, and improve the Service — including monitoring for abuse, investigating support requests, and patching defects.

Send account, security, and billing notices to you. Marketing email is opt-in and every message includes an unsubscribe link.

4. Who can access your information

Only the logged-in contractor. Jobspar’s design is single-tenant per contractor: the contact records, photos, invoices, estimates, drafts, thread content, and payment records of one contractor are not visible to any other contractor or to anyone else signed into the Service. We never aggregate your customer list with another contractor’s.

We do not sell, rent, or license contractor or customer data to third parties for advertising, lead generation, or resale.

Authorized subprocessors receive only the minimum needed to perform one specific function on your behalf — for example, Stripe receives only the data needed to run a charge, and the LLM subprocessor receives only the inbound message it was asked to help draft a reply for. The full list is in the Subprocessors section.

Jobspar staff with production access. A small number of named operators can reach production data to debug issues and fulfil data-deletion and export requests, and only under least-privilege access with audit logging. Vendors and contractors outside that group do not have standing production access.

Legal disclosures. We will share information only when we believe in good faith that disclosure is required by law, regulation, valid court order, or to protect the safety of Jobspar, our users, or others — and only the minimum required to satisfy the request.

5. Cookies & local storage

Jobspar uses a small set of functional cookies and browser storage: the session cookie that keeps you signed in (issued by our authentication provider), a preference cookie that remembers your chosen light or dark theme, and a short-lived local-storage key that remembers the last draft you were editing so you can come back to it. We do not place advertising cookies, and we do not use third-party analytics cookies today. Blocking cookies in your browser will break sign-in and other core parts of the Service.

6. How & where your data is stored

Database. Your account, contacts, invoices, estimates, drafts, and thread metadata live in a PostgreSQL database managed for us by our platform provider and accessed via Prisma. The database is encrypted at rest by the platform provider and all traffic between the Service and the database is encrypted in transit.

Photos. Each photo is stored against your account record alongside the quote or job it was attached to. We only ever receive the browser-downscaled version; the original full-resolution image stays on your device unless you explicitly upload a full-resolution copy.

Email and SMS thread content. Inbound messages and the AI-drafted outbound replies you have sent are stored against your account record so you can audit what was sent under your business name and so the Service can continue drafting in the same context.

File assets. If you store an attachment through the Service, the file is uploaded through the platform’s R2-backed object-storage proxy and stored under your account’s namespace.

7. How long we keep your data (retention & account deletion)

Active accounts. As long as your account is open, we retain the data needed to run the Service for you — contacts, invoices, estimates, photos, drafts, thread content, and payment metadata — indefinitely.

Account deletion from the dashboard. You can close your account from the Account page in the dashboard. Once you do, the records attached to your account — contacts, photos, invoices, estimates, drafts, and thread content — are hard-deleted within 30 days. Records we must keep longer for tax, accounting, or lawful-records-request reasons (for example, settled Stripe transactions) are retained only as long as the law requires and then deleted.

Photos and business records. Photos and contract records (invoices, estimates) are deleted on the same timeline as the account.

Anonymized usage. We may retain anonymized or aggregated usage statistics after account deletion, but those statistics cannot be tied back to you or your customers.

Marketing form submissions. Submissions sent to us before you created an account (Contact / Get-a-quote) are retained until the lead is resolved or for up to 24 months, whichever comes first.

8. Your rights — export & hard delete

Export your data. From the Account page in the dashboard, open "Export my data" to download a full export of your business data — contacts, invoices, estimates, photo metadata, and thread content. Any contractor can run this export at any time; the export belongs to you.

Hard-delete your account. From the Account page, use "Delete account" to close your jobspare account and hard-delete the records attached to it. Hard delete is irreversible — once your account is gone, the records are gone, and we cannot recover them.

Requests the dashboard cannot fulfil. If one of your customers asks you to remove their data, or if you need to request a deletion on the subprocessor side, email jobspar-2@polsia.app with "Privacy" in the subject line. We acknowledge within 30 days and complete the request within 60 days.

Regional rights and non-retaliation. Depending on where you live you may also have the right to access, correct, port, restrict, or object to certain processing, and to withdraw consent where we rely on consent. Exercising any of these rights will never affect the price, features, or treatment you receive from Jobspar.

9. Third-party subprocessors

To run the Service we engage the subprocessors listed below. Each receives only the minimum data needed to perform its function. We update this section before enabling any new subprocessor.

Stripe — payment processing. Stripe receives the data needed to identify the payer, run the charge, and return the transaction receipt. Stripe handles full card numbers, CVCs, and expiry dates; Jobspar receives only the metadata described in section 2 (amount, currency, status, brand and last-4, Stripe customer / subscription IDs).

Email provider — to deliver the emails you approve through the Service. The provider receives the message body and recipient address at the moment of send. Thread content is also stored against your account record as described in section 2.

SMS provider — to deliver the SMS replies you approve. The provider receives the message body and recipient phone number at the moment of send. Thread content is stored against your account record.

LLM API (accessed through the Polsia AI proxy) — to draft the replies and extract measurements from photos. The subprocessor receives the inbound email or SMS body, the photo you attached (downscaled), and the contact context drawn from your own account; the subprocessor is used solely to produce a draft that you then review and edit. No subprocessor input is used to train a third-party model.

Cloud hosting and managed Postgres — to run the Service. The platform hosts the application and the managed PostgreSQL database per contractor, with tenant isolation between contractor accounts.

Analytics. Jobspar does not enable a third-party analytics subprocessor today. If one is enabled in the future it will be added to this section before it is turned on.

10. Children's privacy

The Service is not directed to children under 13 (under 16 in some jurisdictions). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact jobspar-2@polsia.app so we can delete it.

11. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date below is the source of truth and reflects the most recent revision. For material changes we give at least 14 days’ notice by email or by an in-product notice before the change takes effect. Continued use after the effective date means you accept the updated policy.

12. Contact

Questions about this Privacy Policy, requests to export or delete your data, or subprocessor-side deletion requests on behalf of one of your own customers? Email jobspar-2@polsia.app and put "Privacy" in the subject line. We respond within 30 days and complete requests within 60 days.

Questions about this policy? Email jobspar-2@polsia.app and put "Privacy" in the subject line.