This notice explains what personal data we hold, why, who we share it with, how long we keep it and what your rights are. It's written in layers: each section starts with the main point, then gives the detail.
Who we are
The Job Planner is run by Matt Rooney, a sole trader in England trading as "The Job Planner". For the data described in this notice, we are the controller — we decide why and how it's used.
- Address: the address shown on our invoices (available on request)
- Email: privacy@localhost
- ICO registration number: (registration pending)
We're a small business, so we haven't appointed a Data Protection Officer (the law doesn't require one for a business like ours). Privacy questions come straight to the owner at the email above.
Who this notice covers
This notice covers:
- Website visitors — anyone browsing our website, using the website assistant or sending us an enquiry.
- Account users — the people at our customers' businesses who log in to The Job Planner: owners, office staff, schedulers and engineers, including people on a free trial.
What this notice does not cover: your customers' data
The Job Planner is used by trade businesses to manage their own customers and jobs. When a business puts in details about its customers — names, contact details, addresses, site access notes, photos, signatures, certificates, job notes, quotes, invoices and payment records — that business is the controller and we are its processor. We only use that data to provide the service to that business, on its instructions, under our Data Processing Addendum.
If you're a customer of a business that uses The Job Planner and you have a question about your data, please contact that business first — it decides how your data is used. If you contact us, we'll pass your request on to them (we'll tell you if we do).
What we collect and why
We only collect what we need for a specific purpose. The tables below set out each type of data, what we use it for, and the lawful basis that UK GDPR requires us to have.
If you visit our website
| Data | What we use it for | Lawful basis |
|---|---|---|
| Your cookie choice | Remembering whether you've accepted optional cookies | Legal obligation (to respect your choice under PECR) |
| Your light/dark display choice | Showing the site the way you asked | Legitimate interests (a working, accessible website) |
| Questions you type into the website assistant | Answering your question, and reviewing questions to improve our answers | Legitimate interests (helping visitors understand the product) |
| Enquiries sent through our contact form (name, contact details, message) | Replying to you and, if you ask, setting up a demo or trial | Legitimate interests (responding to people who contact us); steps before a contract if you're asking to sign up |
| Technical data your browser sends (such as IP address and browser type) | Delivering pages securely and protecting the site from abuse | Legitimate interests (running a secure website) |
We don't use analytics tools or advertising trackers, and we don't build profiles of visitors.
If you have an account
| Data | What we use it for | Lawful basis |
|---|---|---|
| Name, email, phone number, role | Creating your login, contacting you about your account, showing who did what on a job | Contract (if you signed up); legitimate interests (if your employer or the business you work with set up your account, so they can use the service they've paid for) |
| Password (stored only as a one-way scrypt hash — we can't see it) | Letting you sign in securely | Contract / legitimate interests (as above) |
| Two-factor authentication secret (if you turn it on) | Checking the codes from your authenticator app | Contract / legitimate interests (keeping accounts secure) |
| Gas Safe or F-Gas registration numbers and expiry dates (optional) | Printing them on certificates and reminding you before they expire | Legitimate interests (producing valid paperwork for your business) |
| Skills and schedule colour | Scheduling the right engineer and showing them on the planner | Legitimate interests (running the service) |
| Sessions and login records (date and time of sign-ins and security events) | Keeping you signed in, spotting suspicious activity, investigating problems | Legitimate interests (security of the service and your data) |
| Visit times recorded by the field app (on my way, arrived, left) | Showing your office where jobs are up to, and recording time on site | Processed on behalf of the business you work for — see "What this notice does not cover" |
| Push notification subscription (if you turn notifications on) | Sending job alerts to your phone or browser | Consent (you switch it on, and can switch it off at any time) |
| Billing details (Stripe customer and subscription IDs, plan, invoices we send you) | Taking payment for your subscription and keeping accounting records | Contract; legal obligation (tax records) |
| Messages you send us and support history | Helping you and keeping a record of what was agreed | Legitimate interests (providing support) |
We don't hold your card details. Card payments go through Stripe, which handles and stores card data under its own security certification.
Emails we send you
We send service emails that you need to use The Job Planner: sign-in links, security alerts, trial and billing reminders, and important changes to the service or these terms. We don't send marketing emails at the moment. If we start, we'll update this notice first, only send them where the law allows, and include a one-click way to opt out in every email.
Where we get your data from
Most of it comes from you. Some comes from:
- the business you work for, if they create your account or add your details (for example your skills or registration numbers);
- Stripe, which tells us whether a payment succeeded;
- Lead Capture AI, which runs our contact form and passes your enquiry to us.
AI features and the website assistant
The Job Planner includes AI features that help draft content — for example turning a customer's phone message into a job, or suggesting a job sheet or quote from the details on file. To do this, the relevant job, site and asset details are sent to Anthropic PBC, which provides the AI model.
- A person always checks. AI drafts are suggestions. Nothing is saved to a job, quote, certificate or invoice until a user has reviewed it.
- Not used to train AI. Anthropic's commercial terms say it "may not train models on Customer Content from Services" (Anthropic Commercial Terms of Service). Anthropic's own privacy centre explains the exceptions (such as feedback you choose to submit to Anthropic directly), which don't apply to how we use its service.
- No automated decisions about you. We don't use AI, or any other automated process, to make decisions that have legal or similarly significant effects on anyone.
The website assistant is an AI chat on our public pages. It tells you it's an AI. It answers from facts we've published about the product. We log the questions people ask — without your IP address — so we can improve our answers, and we delete them after 90 days. Your conversation is also kept in your browser for the length of your visit and is cleared when you close the tab. Please don't type personal details into it.
Who we share data with
We don't sell personal data and we don't share it for other companies' marketing.
We use a small number of trusted service providers ("sub-processors") to run the service — for hosting, the database, payments, email, SMS, AI features and push notifications. Each one only gets the data it needs to do its job, under a written contract. The full list, with what each receives and where, is on our sub-processors page.
We may also share data if the law requires it (for example a valid request from HMRC or the police), to protect our rights or others' safety, or with a buyer if the business is ever sold — in which case this notice would continue to apply to your data.
International transfers
Some of our providers are based in, or access data from, the USA. When personal data leaves the UK, we make sure it stays protected in one of these ways:
- UK adequacy regulations — for example the European Economic Area, which the UK recognises as providing adequate protection, and the "UK–US data bridge" (the UK Extension to the EU–US Data Privacy Framework), which covers US companies that have certified to it. See the ICO's guide: How does the UK Extension to the EU-US Data Privacy Framework work?
- Standard contracts approved for UK use — the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, backed by a transfer risk assessment. See the ICO's international transfers guidance.
Our sub-processors page shows which safeguard applies to each provider. You can ask us for more detail at privacy@localhost.
How long we keep data
We keep data only as long as we need it, and we run an automatic clean-up every day.
| Data | How long we keep it |
|---|---|
| Your account details | While your company's account is open |
| Sign-in sessions | 30 days, then deleted by the daily clean-up |
| One-time sign-in tokens | 7 days after they expire |
| Rate-limit records (used to block repeated failed attempts) | 7 days |
| Audit log (sign-ins and security events) | 2 years |
| Message logs (emails and texts sent through the service) | Message text removed after 12 months; the record that a message was sent (who, when, delivery status) kept for 2 years |
| Website assistant questions | 90 days |
| Contact form enquiries | 24 months after our last contact with you |
| Trial or lapsed accounts that are never closed | 6 months, then deleted |
| Our own billing and accounting records | As long as tax law requires — for a sole trader, at least 5 years after the 31 January filing deadline for the tax year (GOV.UK) |
When a company closes its account, we delete its data from our live database straight away. Copies in our database provider's backups roll off within 30 days. Before closing, account owners should use the export tool to download any records they need to keep — HMRC generally expects businesses to keep financial records for 5 to 6 years. Stripe keeps its own payment records under its privacy policy.
How we protect your data
In short: encryption in transit and at rest, strict separation between companies' data (checked automatically every time we release changes), hashed passwords, optional two-factor authentication, rate limiting, audit logs and regular backups. Read more on our security page.
If a data breach puts your rights at risk, we'll tell you without undue delay, and we'll report it to the ICO within 72 hours where the law requires.
Your rights
Under UK GDPR you have the right to:
- access — get a copy of the personal data we hold about you;
- rectification — have inaccurate data corrected or incomplete data completed;
- erasure — have your data deleted, where there's no good reason for us to keep it;
- restriction — ask us to pause using your data while a concern is sorted out;
- portability — receive data you gave us in a machine-readable format, or have it sent to another provider;
- objection — object to us using your data on the basis of legitimate interests (we'll stop unless we have a compelling reason), and object at any time to direct marketing;
- withdraw consent — where we rely on consent (such as push notifications or optional cookies), you can withdraw it at any time. This doesn't affect what we did before.
How to use them. Email privacy@localhost and tell us what you'd like. We may need to check your identity first. We'll respond within one month; if a request is complex we can extend this by up to two more months, and we'll tell you why within the first month. There's normally no charge.
Tools in the app. Account owners can export all their company's data (JSON, plus invoices as CSV) and close the account from the settings page. You can update your own profile at any time. For requests from your own customers, the app lets you export or anonymise an individual customer's records.
Complaints
If you're unhappy with how we've handled your data, please tell us first at privacy@localhost. We'll acknowledge your complaint within 30 days, look into it properly, keep you updated and tell you the outcome without undue delay.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK regulator for data protection: ico.org.uk/make-a-complaint.
Children
The Job Planner is a business tool and our website is aimed at businesses. We don't knowingly collect data from children.
Changes to this notice
We'll update this notice when our services or the law change. The date at the top shows when it was last updated. If we make a change that significantly affects how we use account users' data, we'll email account owners before it takes effect.
Related: Cookie and storage policy · Terms of service · Data Processing Addendum · Sub-processors · Security