Privacy Policy
How JobTill collects, uses, and protects information when you use our service.
1. Scope
This policy covers the JobTill website (jobtill.com), the JobTill web application at app.jobtill.com, and any JobTill mobile applications. JobTill is a business-to-business field-service CRM operated by Cornerstone Digital Group LLC ("we", "us", "JobTill"). Our customers are service businesses ("Tenants"); a Tenant's employees and customers may interact with the service.
2. Information we collect
From Tenants and their users
- Account information: name, email address, business name, role, phone number.
- Authentication data: hashed passwords, session tokens, login timestamps, IP address.
- Business data you enter into JobTill: clients, contacts, locations, jobs, quotes, invoices, photos, checklists, recurring agreements, notes, expenses, and related work product. This data belongs to your Tenant.
- Payment metadata: when your customers pay invoices through JobTill via Stripe Connect, we receive payment confirmation metadata. Card numbers are handled by Stripe and never stored on JobTill servers.
- Bank account and transaction data (via Plaid): if your Tenant connects a business bank account to JobTill's Bank Feed feature, we receive account details (institution name, account name, type, and masked account number) and transaction data (date, amount, merchant description, and category) through Plaid Inc. Your online banking credentials are entered directly with Plaid and are never received or stored by JobTill. The access token that authorizes the connection is stored only in encrypted form (AES-256-GCM).
- Device data when using mobile apps: device identifier (for push notifications), approximate location (only when you enable navigation features), camera access (only when you upload a photo).
From visitors to jobtill.com
- Standard server logs: IP address, browser type, pages viewed, referring URL, timestamp.
- Cookies: session and preference cookies only. No advertising trackers.
3. How we use information
- To provide, maintain, and improve the JobTill service.
- To process payments through Stripe.
- To import and categorize bank transactions into your Tenant's expense records when you connect a bank account. Bank data is used solely for your Tenant's own bookkeeping — never for advertising, credit decisions, cross-Tenant analysis, or sale to third parties.
- To send transactional email (quotes, invoices, account notifications) via Resend.
- To send push and in-app notifications related to your work.
- To comply with legal obligations and enforce our Terms of Service.
We do not sell personal information. We do not use your business data to train third-party AI models.
4. Subprocessors
We use the following third-party services to operate JobTill:
- Supabase — database, authentication, file storage.
- Vercel — web hosting and content delivery.
- Stripe — payment processing (Stripe Connect for Tenant client payments; Stripe Billing for JobTill subscriptions).
- Plaid — bank account connectivity and transaction data retrieval for the Bank Feed feature. By connecting a bank account, you also grant Plaid the right to process your information as described in the Plaid End User Privacy Policy.
- Resend — transactional email delivery.
- Google Maps / Routes API — navigation and drive-time estimation in the field app.
- Apple Push Notification service / Firebase Cloud Messaging — mobile push notifications.
Each subprocessor processes information solely to provide its service to us.
5. Data retention
We retain Tenant data for as long as the Tenant maintains an active account. On account closure, Tenant data is retained for 30 days to allow for restoration, then deleted within 60 days unless we are required by law to retain it longer. Backups are deleted on a 30-day rolling basis.
Bank feed data is retained only while the bank connection is active. If you disconnect a bank account, JobTill revokes the connection at Plaid, and deletes unreviewed imported transactions; transactions you already converted into expense records are retained as part of your Tenant's financial records. All bank feed data — connections, tokens, accounts, and imported transactions — is deleted when a Tenant account is deleted.
6. Your rights
- Access and correction: Tenants can access and edit their data through the JobTill admin interface at any time.
- Deletion: Users may delete their own account from within the JobTill app under Settings → Account. If a Tenant Owner deletes their account and is the last remaining administrator, the entire Tenant workspace will be scheduled for deletion.
- Export: Money reports, invoice and quote PDFs, and CSV exports are available from the admin dashboard.
- Questions or requests: contact us at the email below.
7. Security
JobTill enforces multi-tenant isolation at the database level (row-level security policies), encrypts data in transit (HTTPS), and relies on Supabase and Stripe to encrypt data at rest. Bank connection access tokens are additionally encrypted at the application layer with AES-256-GCM before storage. Service-role credentials are kept server-side and never exposed to the browser.
8. Children
JobTill is a business product not directed at children under 13. We do not knowingly collect information from children.
9. Changes
We may update this policy from time to time. Material changes will be communicated to Tenants by email. The "Last updated" date at the top of this document reflects the most recent revision.
10. Contact
Questions about this policy: hello@jobtill.com
Cornerstone Digital Group LLC d/b/a JobTill