Legal

Privacy Policy

Last updated: 17 September 2026 · Effective: 20 July 2026

This policy explains how Jobdeck ("we", "us", "our"), a product of Taylored Electrical Group Pty Ltd (ABN 49 689 808 633), based in New South Wales, Australia, handles personal information in the Jobdeck mobile app, the web dashboard at portal.jobdeck.com.au, and the marketing site at jobdeck.com.au. We handle personal information in line with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).

Two different roles. If you run a business on Jobdeck, we collect information about you and your team directly, as described in this policy — we are the ones responsible for that data. If your business stores information about your own customers in Jobdeck (names, addresses, phone numbers, job photos, signatures), we are acting as a service provider on your behalf — your business is the entity responsible for that data, and Jobdeck processes it on your instructions. If you are one of your customers, or anyone else a Jobdeck-using business holds information about, the business itself is who to contact first; if you can't reach them, contact us and we will help.

What we collect

Location sharing, Track My Arrival, and shift records

Because location is the most sensitive thing the app can collect, here is everything it covers, in one place. If you employ people, this is also the feature set referenced by the workplace-surveillance notice in our Terms of Service.

Date and place on a photo

A business can turn on a setting that prints the date, the time and where a photo was taken onto the site photo itself. It is printed into the picture rather than hidden in the file, because a date that only exists in a hidden field is stripped out by most email and messaging apps. This makes it permanent, so the setting is deliberately narrow:

Messages between your crew

Jobdeck has a Chats screen where people who work at the same business can message each other, one to one or in a group. It is separate from the messages you send customers, and it only ever reaches people in your own business.

Your business's own customer data, and other people you tell us about

If you run a business on Jobdeck, you will typically store information about people who never signed up to Jobdeck themselves — your own customers, your subcontractors, and anyone who interacts with your business through the app. In every case, we are a data processor for this information, not the data controller — you decide what to collect and why, and we process it on your instructions to run the software. This includes customers (names, phone numbers, addresses, job notes, photos, signatures), crew you invite, subcontractors (including licence, insurance and white-card compliance documents you upload against them), people who fill in your public enquiry or booking form, invoice comment authors and customer-form signers, suppliers (via the invoice inbox, when a supplier forwards an invoice to your business's unique inbox address), and anyone named in a chat message or a site diary entry, as free text your crew writes.

Customer forms and portal links (a liability waiver, a job update, an invoice payment link) are sent to a one-off email address you supply. Not every link expires: links to sign a contract, a customer form, or a subcontractor compliance checklist are time-limited and single-purpose, but a customer's own portal link, and a job's status page and arrival-map link, do not expire or rotate on their own — a customer who forwards their portal link has shared it until the business closes it. A business can invalidate and reissue any of these links at any time from the customer's or the job's own record, which immediately stops the old link working.

If a business that uses Jobdeck holds your details — because you're a customer, a subcontractor, or you filled in one of their forms — the business is responsible for that information and is who to contact first. If you can't reach the business, contact us at support@jobdeck.com.au and we will help.

Financial and billing data

Jobdeck has two separate money flows, handled differently. Your Jobdeck subscription is billed through Stripe — we never see or store your card details, and we store only your Stripe customer/subscription reference, plan tier and billing status. Your customers' payments to you are different: if you connect your own Stripe or Square account, a customer paying an invoice pays directly into your account, not ours. We never see or store card numbers for these payments, take no cut, and never hold your customers' funds. If you haven't connected your own account, there is no card-payment option at all for your invoices — we never silently fall back to a shared account.

Accounting integrations

If you connect Xero, MYOB or QuickBooks, we push your customer and invoice records to your own account with that provider, on your instruction, so your books stay in sync. The OAuth tokens that let us do this are encrypted at rest (AES-256-GCM) and are never shared with anyone else. You can disconnect at any time.

One-off data migration from another system

If you're moving from ServiceM8 or simPRO, you can connect your existing account there and pull your historical jobs, customers and quotes across into Jobdeck as a one-time import. The connection credentials for this are encrypted the same way as the accounting integrations above.

Supplier invoices by email

Each business gets a unique email address (inv-<token>@jobdeck.com.au). Forwarding a supplier invoice to it automatically creates a record in your Purchase Orders. Only emails sent to your business's own unique address are accepted; everything else bounces.

Marketing website analytics

Our marketing site (jobdeck.com.au) and the sign-in and sign-up screens of the web dashboard use Google Analytics 4 to understand how visitors find and use the site, with IP addresses anonymised. Analytics stops the moment you're signed in. No customer data, email address, name or business information is ever sent to Google Analytics, and it is not present anywhere inside the working app itself — only on the public marketing pages and the sign-in/sign-up screens. If you would rather not be counted, any browser content blocker will stop it, and nothing about the site or the product will behave differently.

On your phone (offline storage)

The app is built to keep working on sites with no reception, so some information is also held on the device itself, separately from what's stored on our servers: a copy of jobs you've opened (kept up to 7 days, cleared on sign-out), diary entries, photos, video and other work you've recorded but not yet sent (deliberately not deleted when you sign out, since that would destroy work you haven't sent), unsaved form drafts (discarded after 24 hours), and your sign-in tokens, held in the device's own secure keychain. Anything held on the phone is protected by the device's own passcode or biometric lock. If you share a work phone, sign out before handing it over, and send any pending diary entries first.

What we do not currently do

How we use it

Only to run Jobdeck for you: to create and secure your account, run the core features of the app, process your subscription payment, send transactional emails and push notifications (verification codes, invites, reminders, alerts), respond to support requests, detect and prevent fraud and abuse, meet our own legal and accounting obligations, and understand and improve the product using the limited, anonymised marketing analytics described above. We do not sell your data, and the app itself carries no advertising or tracking SDKs. Jobdeck does not send marketing to its own users — the emails and pushes above are all service messages, not marketing. We do not use your information for any purpose beyond what's described in this policy without asking you first.

Who we share it with (sub-processors)

We use a small set of reputable service providers to run the app. Each only receives the data needed for its function:

ProviderPurposeData involved
Google Analytics (United States)Counting visits to this website, and to the dashboard's sign-in and sign-up screens. Stops once you are signed inPage visited, approximate location, device type. Anonymised IP. No account data, and nothing from inside the app
Cloudflare Email Routing (United States)Receiving email sent to any @jobdeck.com.au address, including support/privacy enquiries and the supplier-invoice inbox address your business can hand to wholesalersThe full email as sent, including attachments, in transit
Cloudflare R2 (Oceania)Stores every uploaded file — photos, signatures, licence and ticket scans, receipts, job documents, letterheads, chat imagesThe files themselves
Neon (Singapore)Database hostingYour account & business data
Railway (United States)Server hosting — runs the application itselfData transiting the app
VercelWebsite hostingWebsite traffic only
ResendTransactional emailRecipient email + message content
Expo (United States), and Apple or Google behind itPush notificationsDevice push tokens and the text of each notification. For a staff chat message that is the sender's name and the first part of what they wrote, on the recipient's own devices only
SentryCrash monitoringDiagnostics + a user ID (never your email)
StripeYour Jobdeck subscriptionYour email, card and billing address, plus your business id, plan and team size. Card details stay with Stripe. We never see or store them.
Square ConnectIf you connect your own Square account, routes your customers' invoice payments to youNothing beyond what's needed to create the payment link
XeroAccounting sync (opt-in, live today)Customers & invoices you push to your own accounting file
MYOB / Intuit QuickBooksAccounting sync — built and available, not yet connectable in productionNone currently
Google / AppleSign-in (opt-in)Your sign-in identity token

Stripe Connect, Google Calendar, and ABR (Australian Business Register) lookup are built into Jobdeck but have no live credentials configured in production — nothing currently flows to them. If we switch any of these on, we will add them here first.

If your business adds an accountant seat, that person can view your business's reports and download a financial export (customers, jobs, quotes, invoices, variations and expense claims). The accountant export does not include your crew's licence details, leave records, site photos, or staff chat. Those stay with the business owner and admins.

What we deliberately never send to our error-reporting tool (Sentry)

Our error monitoring is built to explicitly exclude passwords, API keys, auth tokens, full licence numbers, and customer names, emails or phone numbers. Only technical detail needed to diagnose a bug is ever sent.

Overseas disclosure (APP 8)

Where your data actually sits. Your Jobdeck database, which holds your account and all of your business records, is hosted by Neon in Singapore (AWS ap-southeast-1). The servers that run the app, hosted by Railway, are in the United States. The photos, signatures, licence scans and other files you upload are stored separately, on Cloudflare R2 in the Oceania region — not on the application server itself. Our website is served by Vercel from its global network.

Our other providers are located overseas or store and process data overseas, principally in the United States (Resend for email, Sentry for crash-monitoring, Stripe for your subscription, Google and Apple for sign-in, Google Analytics for counting visits to this website, and Expo for push notifications). Xero processes in Australia and New Zealand. Where a provider runs on global infrastructure it may process in another country as well; if that changes materially for any of the providers above, we will update this page.

Before your information goes to an overseas recipient we take reasonable steps to make sure it is handled consistently with the Australian Privacy Principles, including using established providers under contracts that require it. We are accountable for that under APP 8.1, and we are not asking you to waive it. We do not rely on your consent to send your information overseas, because the people whose information is in your account — such as your customers and your crew — never gave us any.

How we store & protect it

We take reasonable technical and organisational steps to protect your information, including: passwords hashed with bcrypt, never stored or logged in plain text; short-lived session tokens, with long-lived refresh tokens stored only as a cryptographic hash; integration credentials (Xero, MYOB, QuickBooks, ServiceM8, simPRO) encrypted at rest with AES-256-GCM; rate limiting on login, registration and password-reset routes; optional two-factor authentication your business can switch on; uploaded files served through time-limited, signed links rather than being publicly accessible; and production deployment refuses to start if critical security keys are left at their development defaults. No system is perfectly secure, and we can't guarantee absolute security of information transmitted to us.

If a data breach occurs that's likely to result in serious harm, we'll notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in line with the Notifiable Data Breaches scheme, without undue delay. If the breach involves information about your customers or your crew, we will tell you first, with enough detail for you to meet your own obligations to them, and we will help you do it.

Who at Jobdeck can read your data

Jobdeck is run by a small team. The people who operate the servers can read the database, and do so only to fix a problem you've reported or to keep the service running. Neon encrypts the database at rest and keeps a 6 hour point-in-time restore window, letting us recover the database to any moment in the last 6 hours if something goes wrong. Uploaded files (photos, signatures, licence scans, receipts and chat images) are stored on Cloudflare R2, an object store separate from our application servers, built to keep multiple copies of every file across different physical locations. We do not hold a security certification and do not claim one.

Keeping & deleting your data

You can delete your own account at any time in the app (Profile → Delete account) or by emailing support@jobdeck.com.au. When you delete your account: every session and device notification token is revoked; your licence/ticket credential photos and any receipt photos you personally uploaded are deleted, files included; your name, email, sign-in identity, phone number and profile photo are scrubbed to a placeholder that can never be signed into again; you're removed from every business you were a member of; any location you'd chosen to share is deleted; and in staff chat, nicknames and blocks involving you are deleted — messages you sent remain visible to the people you sent them to, but with your name removed. Your name stays in the business's activity log, against the actions you took while you were part of it, because those are the business's own records of who did what.

Operational records that belong to the business (jobs, invoices, financial and work-health-and-safety records) are kept in anonymised form because a business's history and the law require it. We keep personal information only for as long as we need it for the purposes above, or as the law requires — financial and tax records are generally kept for at least 5 years (as required by Australian tax law) and WHS records for the period required under work-health-and-safety law.

A business owner can delete the entire business, not just their own account. This is irreversible and requires a typed confirmation. It removes essentially everything scoped to that business — jobs, quotes, invoices, customers, photos, chat, the lot — verified by an automated check after the fact that nothing was left behind. Files in storage are deleted as part of the same process.

Requesting your own customer's data be removed. If your business needs to honour a customer's request to be forgotten, Jobdeck has a dedicated erasure tool for that. It replaces every piece of identifying information (name, phone, email, address, notes) with a permanent placeholder, everywhere it appears, while keeping the underlying job numbers, invoice numbers, dollar amounts and dates completely intact so your books and reports still balance. This works whether or not your business is currently paying — erasure only ever removes data, so it's exempt from the read-only lock described below.

If your business stops paying, your account becomes read-only — you can still open and export every job, quote, invoice and report, but you can't add or change anything until you resubscribe. Deleting your own account, deleting the whole business, and running a customer or team-member erasure all keep working, because each of those only removes data.

If your business is locked for non-payment for 12 months with nobody signing in, we will email the owner and every admin 30 days before deleting it and everything in it. Signing in or exporting your data at any point during those 30 days cancels the deletion.

Your rights

Under the Australian Privacy Act, you have the right to access the personal information we hold about you, correct it if it's wrong, ask us to delete or de-identify it (subject to our own legal obligations to retain certain records), and make a complaint if you think we've mishandled your information. For most requests about information held inside a specific business's Jobdeck account, the fastest path is to contact that business directly. If you can't reach them, or your request is about your own Jobdeck sign-in account, contact us at support@jobdeck.com.au and we'll respond within a reasonable time, usually within 30 days. There's normally no charge.

Data export. The Reports export (Reports section, mobile and web) covers your business's books — customers, jobs, quotes, invoices, purchases, payments, PDFs and diary photos — and is available to the business owner and a free accountant seat. It does not include staff chat. The full business backup (Settings → Activity log, web dashboard only) covers every table in the schema, plus PDFs and photos, including staff chat message bodies, and is available to owners and admins only — every download is written to the activity log. Both work at any time, including while the account is locked for non-payment.

Complaints

If you think we've mishandled your personal information, email support@jobdeck.com.au with "Privacy complaint" in the subject. We'll acknowledge your complaint, look into it, and respond, usually within 30 days. If you're not satisfied with our response, you can escalate to the Office of the Australian Information Commissioner (OAIC): oaic.gov.au or 1300 363 992.

Sensitive information

Some information handled by Jobdeck may be considered "sensitive information" under the Privacy Act — in particular, work-health-and-safety incident records can include details about a worker's injury or health. We collect this only where your business's own work-health-and-safety obligations require it, and it's accessible to your business's managers, and to any crew member assigned to the job the incident happened on — not only the worker involved.

Children

Jobdeck is a business tool and isn't intended for anyone under 16. If you employ an apprentice or a worker under 16, do not create a Jobdeck login for them.

Cookies

Our marketing website (jobdeck.com.au) uses cookies associated with Google Analytics to measure site usage — this also runs on the sign-in and sign-up screens of the web dashboard, but stops the moment you're signed in. The Jobdeck app itself (mobile and the working dashboard) does not use advertising or tracking cookies.

Changes

We may update this policy from time to time. If we make a material change to how we handle personal information — including if we ever switch on AI-based processing of your data, text-message delivery of security codes, or a new subprocessor — we will update the date above and, for significant changes, notify account owners directly.

Contact

Privacy questions or requests: support@jobdeck.com.au.

Taylored Electrical Group Pty Ltd (ABN 49 689 808 633), New South Wales, Australia. A postal address is available on request.