The Job Planner holds information that matters to your business and your customers: names, addresses, site access notes, certificates and invoices. This page explains, in plain English, how we protect it. We're a small, owner-run business, so we've focused on the controls that make the biggest difference, and we're open about what we do and don't do.
How your data is protected
Encryption
- In transit: every connection to the website and app uses HTTPS (TLS). Unencrypted connections aren't accepted.
- At rest: our database provider, Neon, encrypts the stored data and its backups.
- Passwords: stored only as a one-way scrypt hash. Nobody — including us — can see your password.
- Card payments: handled entirely by Stripe. Card numbers never touch our systems.
Keeping each company's data separate
Every record belongs to one company, and every request is checked against the company of the person signed in. Every time we change the software, automated tests check that one company can't see or change another company's data.
Signing in
- Two-factor authentication (2FA) with an authenticator app is available to every user. Account owners can require it for the whole team.
- Rate limiting slows down and blocks repeated failed sign-in attempts and other abuse.
- Sessions expire after 30 days, and signing out ends your session straight away.
- Roles (owner, office and engineer) control what each person can see and do.
Monitoring and records
- An audit log records sign-ins and security events with timestamps. We keep it for two years so problems can be investigated.
- Security headers on every page help protect against common web attacks such as clickjacking and cross-site scripting.
Keeping software up to date
We use automated dependency updates, so security fixes to the open-source components we rely on are picked up and tested promptly.
Backups and recovery
Our database provider keeps backups with point-in-time restore, so we can recover data to a moment before a problem happened. Backups of deleted data roll off within 30 days.
Keeping only what we need
A daily clean-up automatically deletes data once it's passed its retention period — for example expired sessions, old rate-limit records, website assistant questions after 90 days, and message text after 12 months. The full schedule is in our privacy notice.
The field app on phones
To work without signal, the field app keeps the day's jobs and any unsent changes on the engineer's phone. Unsent changes are removed once they've synced, and the app's saved screens are wiped when the engineer signs out. We recommend phones used for work have a screen lock. On a shared phone, clear the site data for The Job Planner in the browser settings when someone stops using it. See our cookie and storage policy.
Trusted providers
We use established providers for hosting, the database, payments, email, SMS and AI, each under a written contract with data protection terms. See the sub-processors list.
AI features
AI features send only the details needed for the task to our AI provider, Anthropic, whose commercial terms say it may not train models on that data. Nothing an AI drafts is saved until a person has checked it. See our privacy notice.
Our approach
Our information security management is designed around the principles of ISO/IEC 27001:2022, the international standard for managing information security — covering risk assessment, access control, supplier management, backups and incident response. We're not certified to ISO/IEC 27001 and don't claim to be.
If something goes wrong
If there's a security incident that affects your data, we'll:
- act immediately to contain it and limit the harm;
- tell affected customers without undue delay, with what we know and what we're doing about it;
- report it to the Information Commissioner's Office (ICO) within 72 hours where the law requires, and help you meet your own reporting duties for your customers' data (see our Data Processing Addendum);
- learn from it and fix the cause.
Things you can do
- Turn on two-factor authentication, and require it for your team.
- Remove users as soon as they leave your business.
- Give people only the access they need.
- Use a screen lock on phones and tablets used for work.
- Export your data regularly and keep copies of records you're legally required to hold.
- Be wary of emails asking you to sign in or pay — we'll never ask for your password.
Reporting a security issue
We welcome reports from security researchers and customers. If you think you've found a vulnerability in The Job Planner:
- Email privacy@localhost with "Security" in the subject line.
- Our contact details are also published in machine-readable form at /.well-known/security.txt, following RFC 9116.
- Please include what you found, where, how to reproduce it, and the impact you think it has.
What we ask of you
- Only test against your own account, or a free trial account you've created for the purpose. Never access, change or delete another company's data. If you come across other people's data by accident, stop, don't keep a copy, and tell us.
- Don't run tests that could harm the service or other users — no denial-of-service, spam, or automated scanning at high volume.
- No social engineering or phishing of our customers or suppliers, and no physical testing.
- Give us a reasonable time to fix the problem before telling anyone else about it. We'll agree a disclosure date with you.
What you can expect from us
- We'll acknowledge your report within 5 working days and keep you updated on progress.
- We'll let you know when the issue is fixed and, if you'd like, credit you publicly.
- If you've acted in good faith and followed this policy, we won't take legal action against you or report you to the authorities.
No bug bounty
We're a small business and don't run a paid bug bounty programme. We're genuinely grateful for responsible reports, and we'll say thank you — but we can't offer payment.
Questions about security, or need information for your own supplier checks? Email privacy@localhost.