← Back to Job Holster

Privacy Policy

Last updated: September 6, 2026

Job Holster ("Job Holster," "we," "us," "our") is operated by Jobholster LLC, a company registered in Missouri, United States. This policy explains, in plain language, what data the Job Holster mobile and web app ("the app") collects, why we collect it, who we share it with, and the choices you have. Questions? Email [email protected].

The short version

Who the data belongs to

Job Holster is a tool for tradespeople to track their own jobs and clients. Much of what you enter (your clients' names, phone numbers, addresses, photos, and notes) is personal information about other people. You are responsible for having a lawful basis to store that information; you act as its controller, and we process it on your behalf to provide the app.

What we collect and why

Who we share data with

We share data only with service providers ("processors") who handle it on our behalf under contract, solely to run the app:

ProviderWhat they handle
SupabaseCloud database, authentication, sign-in, and synced workspace storage
CloudflareApp hosting / CDN, relaying AI requests through our proxy, mobile-app voice-memo transcription through Cloudflare Workers AI, and the anti-spam check on the public job request form (Cloudflare Turnstile)
Your browser's speech providerLive voice transcription on supported web browsers, only when you choose it
PostHogProduct analytics tied to a random account ID, without client content
SentryCrash diagnostics so we can fix bugs
RevenueCat, with Apple & GoogleSubscription processing and billing
StripeProcesses deposit and invoice payments a customer makes on a shared pay page; we never receive full card or bank details
ResendAccount, team-invitation, and job-request notification email delivery
BigDataCloudIf you turn on photo location tagging: turning a photo's coordinates into a place name (reverse geocoding)
Anthropic (Claude)Third-party AI: extracting job details from content you choose to analyze, and reading incoming job requests for businesses that have AI turned on (details below)
Intuit / QuickBooksIf you connect QuickBooks: adding customers you choose or finding an existing matching customer (details below)
Apple, GoogleSign in with Apple / Google (if you use it) and App Store / Google Play subscription billing

Sharing with AI providers. Anthropic receives personal data when you choose an AI text or screenshot action, and when a job request comes in to a business that has AI turned on. Both happen only after that workspace has agreed to the in-app AI notice, and neither happens at all while AI is off. Under Anthropic's commercial terms, API customer content is not used to train its models. Anthropic's standard API retention policy says inputs and outputs may be retained for up to 30 days, subject to documented legal, safety, feedback, and customer-setting exceptions. In the mobile apps, Cloudflare receives voice audio only when you choose transcription. Cloudflare states in its Workers AI data policy that customer content is not used to train models without explicit consent. On supported web browsers, the browser vendor's own speech-service terms apply to live transcription. You can turn AI off in Settings → Setup & advanced → Privacy.

Connecting QuickBooks (Intuit). If you connect QuickBooks, the customer contact details you choose to send are shared with Intuit so Job Holster can create that customer or find an existing customer with the same display name. Job Holster does not update an existing customer, create invoices, or change your books. The connection starts only after you authorize it through Intuit's sign-in, and you can disconnect it at any time. Intuit processes the data under its own privacy policy.

We do not sell your data and we are not a data broker. We may disclose data if required by law or to protect rights and safety. The providers listed above process data on our behalf under contract, in the United States and other countries; where required, appropriate safeguards apply. You can request more detail about any provider at [email protected].

What we do not collect

Access controls limit workspace data to signed-in members of that workspace. Teammates you invite can see shared jobs and records allowed by their role. People outside the workspace cannot access them through the app.

Cookies and local storage

The app uses your browser's localStorage to cache your data for offline access and to remember your sign-in session. It does not set tracking cookies. If you sign out and clear browser data, the local cache is removed.

Deleting your account

You can permanently delete your account from inside the app. Go to Settings → Setup & advanced, open Account settings, choose Delete my account, type the confirmation phrase, and confirm. If you are the only owner of a workspace with other members, the app requires you to remove those members or arrange a transfer first. A solely owned workspace without other members is deleted with its data. If you belong to someone else's shared workspace, your membership is removed, but shared records may remain available to that workspace. Account deletion clears the local cache on the device where you complete it; clear Job Holster data separately on any other device if needed. If you can no longer access the app, see our account-deletion page for an email-based request process. Aggregated, non-identifiable analytics events and security logs may persist for a limited time.

Data retention

We keep your account and content until you delete them. Soft-deleted rows are kept for 30 days before being permanently purged, so accidental deletions can be undone. Disaster-recovery backups taken by our cloud database provider are retained according to that provider's standard backup window and then deleted.

Approved estimates. An approval is kept as part of the business's record of that job, for as long as they keep the job, because it is the evidence the work was agreed to. If the business edits an estimate after it was approved, the version you approved and your approval of it are kept alongside the new one rather than overwritten, for the same reason. A business can turn a link off at any time, which stops it being viewable.

Job request forms. A request nobody has acted on yet keeps its photos for 60 days, and then the photos are deleted automatically. A request the business dismisses is kept for 30 days so they can undo that, and then it is deleted automatically. If the business adds the request to their jobs, what you sent becomes part of that job's records and is kept like the rest of their work until they delete it.

Security

Data is encrypted in transit using HTTPS/TLS. Access controls at the database layer restrict workspace data to authorized members. No system is perfectly secure, but we take reasonable measures to protect your information.

The spam check on job request forms. Because a request form is a public page that anyone with the link can open, it runs an automated check to tell a real person from a bot before it will accept a submission. That check is Cloudflare Turnstile, and running it sends your IP address, your browser's user-agent, and similar technical signals about your browser to Cloudflare, which processes them for us. It usually asks you to do nothing at all. It does not read what you typed into the form, and it is not used to profile you or to advertise to you. Cloudflare sets out what Turnstile collects and why in its Turnstile Privacy Addendum. This check runs on the web form only; the iPhone and Android apps do not use it.

Your rights and choices

Children

Job Holster is a business tool and is not intended for anyone under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us data, contact us and we will delete it. A business's job request form asks people to be 18 or older before sending a request, because asking for work on a property is a step towards a commercial arrangement.

Changes to this policy

We may update this policy. If it materially changes, we'll update the "Last updated" date above and surface a notice in the app on next sign-in.

Contact

Jobholster LLC, Missouri, United States. Privacy questions: [email protected]. General support: [email protected].