Effective date: September 1, 2026 · Replaces the version of August 25, 2026
This Privacy Policy explains how JobCostingApp (the “Service”), operated by Job Costing App LLC (“we”, “us”), collects, uses, and protects information when you use our website and application.
This policy covers two things, and it is worth being clear which is which.
Information about you. When you visit our website or create an account, we collect information about you — your name, email, company, how you use the Service. For that information we are the controller: we decide what to collect and why, and this policy tells you.
Information you enter about other people. When you use the Service you enter information about your workers, your customers, your subcontractors and your suppliers. That information belongs to you and you decide what to do with it. For that information we are a processor (in California, a service provider): we hold it and process it only to provide the Service to you, and only on your instructions. We do not use it for our own purposes, we do not sell it, and we do not use it to train any model. See our Data Processing Agreement, which covers this and applies automatically to every customer — we will countersign a copy on request, write to privacy@jobcostingapp.com.
We do not sell your personal information, and we do not use your business data for advertising.
JobCostingApp is intended for construction businesses in the United States. We do not market the Service in the European Union, the United Kingdom, or elsewhere outside the United States; our pricing is in U.S. dollars, and our features are built around U.S. construction practice. Our website is reachable worldwide, as websites are, but we do not target or knowingly offer the Service to people outside the United States, and we do not monitor anyone’s behaviour outside the United States.
We process your information to provide the Service you have asked for, to meet our legal obligations, to keep the Service secure, and — where the law requires your permission — with your consent.
If you are outside the United States and use the Service anyway, your information will be processed in the United States and in the locations shown on our subprocessors page, under U.S. law.
We share information only with providers that help us run the Service, under contracts that require them to protect it and to use it only for us. We share by category as follows:
We name our providers. The current list, with what each one does, is at jobcostingapp.com/subprocessors. We will post any addition or replacement there at least 30 days before it takes effect, and email business customers who have asked to be notified.
We may disclose information if required by law or to protect our rights, our users, or the public. If we receive a legal demand for a customer’s data, we will tell that customer unless we are legally prohibited from doing so.
Reading your receipts and invoices. The Service includes a receipt scanner. When you photograph, upload or email a receipt or invoice, our server sends that image or PDF to Google’s Gemini API, an artificial intelligence service, which reads it and returns the vendor, date, amounts, tax and line items as text. We store the extracted information in your account, and we keep the service’s raw response for up to 30 days so we can investigate errors, after which it is deleted.
Answering your Help chat questions. The Service includes an in-app Help chat. When you type a question there, our server sends the text of your question, together with the relevant excerpts from our own Help articles, to Google’s Gemini API — the same AI service used for the receipt scanner above, under the same paid-tier arrangement. The Help chat only answers using our own Help content: it is instructed to cite the article it used, and to say plainly when our Help content does not cover your question rather than guessing.
What we have arranged with Google. We use a paid tier of the Gemini API under terms which provide that content we submit is not used to train Google’s models. Google processes the content to return a result and under its own retention terms for that service.
What is not sent. The requests are made server to server. Your IP address, your browser and your device information are not sent to Google as part of this. For the receipt scanner, only the image or document you chose to scan, and the text of the request, are sent. For the Help chat, only the text of the question you typed and the relevant excerpts from our own Help articles are sent — never your account data, projects, invoices or any other business information.
Information about other people on a receipt. Receipts sometimes contain information about people who are not you — a name at a supplier, a delivery address, a customer’s job address. We process that only to extract the fields the feature needs, we do not use it for any other purpose, and we do not use it to train anything. If you upload a document, you are telling us you have the right to.
Turning it off. Both the receipt scanner and the Help chat are optional, used only when you choose to scan a document or type a question. If you use neither, nothing is sent to any AI service. These are the only two AI features in the Service that send data to a third party; if we add another, we will update this section and tell you before it is switched on.
The Service can connect to accounting software such as QuickBooks Online. If you connect one, the data you choose to sync is sent to that provider at your direction, and from that point their privacy policy applies to it as well as ours. We only send what the integration requires and only while it is connected. You can disconnect at any time from within the Service; disconnecting stops future syncing but does not remove data already sent.
Our servers are located in the United States (Arizona) and our backups in the United States (Boston, Massachusetts). Our providers may process data in other locations, as shown on our subprocessors page — a content delivery network, for instance, necessarily operates from many countries. Where a transfer requires a legal mechanism, we put an appropriate one in place. If you are a business customer and need this in writing, see our Data Processing Agreement.
We keep your data while your account is active. Items you delete go to a Recycle Bin for 40 days and can be restored during that window; after 40 days they are permanently deleted. When you close your account, we delete or anonymize your data within a reasonable period, except where retention is required by law.
Backups. When you delete something it is removed from the live Service immediately, but copies may remain in our backups until each backup expires on its normal rotation, which is currently no more than 30 days. We do not search, restore or otherwise use backups to bring deleted data back into use; a backup is only ever restored as a whole, to recover the Service from a failure. If a restore of that kind happens after your deletion, we re-apply your deletion to the restored system.
Privacy laws give different people different rights depending on where they live. Rather than work out which rights you are legally entitled to, we give the same rights to everyone who uses the Service: to get a copy of your information, to correct it, to delete it, to receive it in a portable format, and to appeal if we say no. How to make a request is in section 7A.
Which privacy laws apply to us. We are a small U.S. company. Some privacy laws apply to us today; others apply only to larger companies and would apply to us if we grow past their thresholds. If a law that applies to you gives you a right we have not listed, tell us and we will honour it.
How to make a request. Email privacy@jobcostingapp.com from the email address on your account, or write to us at the address at the foot of this page. Tell us what you want: a copy of your information, a correction, deletion, or a copy in a portable format.
How we verify you. For a request about your account we verify by matching the email address on the request to the one on the account, and we may ask you to confirm details only the account holder would know. We do not ask for more information than we need, and we do not use verification information for anything else.
How long we take. We acknowledge every request within 10 days and respond within 45 days. If a request is complex we may take a further 45 days, and if we do we will tell you why before the first 45 days are up.
Authorized agents. Someone may make a request on your behalf if they give us written permission signed by you, or a power of attorney. We may still contact you directly to confirm.
If we say no. We will tell you why, in writing. You may appeal by replying to that email with the word “appeal” and any additional information. We will decide the appeal within 45 days and tell you the outcome in writing. If we deny the appeal, you may complain to your state attorney general.
We will not treat you differently for exercising any of these rights. We will not deny you the Service, charge you a different price, or give you a lower level of service.
Requests about other people’s information in your account. If your worker, customer or subcontractor asks us to delete or produce information you entered, we will refer them to you and tell you they asked. We act on such a request only on your instruction, or where the law requires us to act directly.
In transit. All traffic between your browser or device and the Service is encrypted using TLS.
At rest. Data stored on our servers, including backups, is encrypted at rest by our hosting provider.
Passwords. We never store your password. We store only a salted cryptographic hash of it, so nobody — including us — can read it.
Separation between companies. Every record in the Service belongs to a company account, and the application checks on every request that the signed-in user belongs to the company that owns the record. Users of one company cannot see another company’s data.
Access. Access to production systems is limited to the people who need it, which today means the owner of the business. Access to your account data by our team happens only to support you or to investigate a problem, and administrative actions are logged.
Other measures. Forms are protected against cross-site request forgery. Sign-in attempts are rate limited. A web application firewall and DDoS protection sit in front of the Service. We take nightly encrypted backups, stored outside the public web directory.
Our hosting provider. The Service is hosted by Hostinger, which states that it is certified to ISO/IEC 27001:2022. That certification is theirs, not ours, and covers their operations rather than our application.
If we determine that a security incident has resulted in unauthorised access to, or disclosure or loss of, personal information we hold, we will notify affected customers without undue delay, and we will tell you what we know, what we do not yet know, what information was involved, and what we are doing about it. We will update you as we learn more.
For information you entered about your workers, customers or subcontractors, we notify you, because that information is yours and the decision about how and when to tell the people involved is yours to make. We will support you in doing that, and where the law requires us to notify someone directly, we will and we will tell you first. We will notify regulators where the law requires.
We do not promise that an incident will never happen; no one honestly can. We promise to tell you promptly, tell you truthfully, and not to minimise it.
The Service is for businesses and is not directed to individuals under 18. We do not knowingly collect data from children.
We review this policy whenever we add, change or remove a third party that receives visitor or customer data, and at least once a year. The effective date above shows when the current version took effect. A summary of past changes is below, and we keep copies of previous versions — write to privacy@jobcostingapp.com if you need one.
Change log
Job Costing App LLC — privacy@jobcostingapp.com. See also our Contact page.
We do not sell your personal information. We have never sold personal information and we do not share it for cross-context behavioural advertising, as those terms are used in California and other state privacy laws. We do not serve advertising, we do not use advertising or analytics cookies that follow you across sites, and we have no advertising relationships.
Browser privacy signals. Because we do not sell or share personal information and do not track you across sites, there is nothing for an opt-out signal to switch off. We nevertheless honour the Global Privacy Control (GPC) and similar browser signals: if we receive one, we treat it as an instruction not to sell or share your personal information, which we already do not do. We do not respond to older “Do Not Track” browser headers, because there is no common standard for what they require and we do not engage in the tracking they were designed to address.
Other parties collecting information across sites. We do not permit third parties to collect personal information about your online activities over time and across different websites through our Service.