Privacy Notice
Last updated: July 10, 2026
JobToolShed is operated by Job Tool Shed LLC. We are the data controller for information collected through jobtoolshed.com.
Information we collect
- Account info — email and password (hashed) for sign-in, optional display name.
- Business profile — the business details you enter so JobToolShed can personalize your drafts (business name, services, tone preferences).
- Proposal defaults — default warranty, payment terms, exclusions, and similar reusable content you save for use across proposals.
- Customer records — customer details you enter, which may include name, phone, email, and address, so you can organize work in JobToolShed.
- Job records — job titles, addresses, notes, status, and other project details you enter.
- Proposal inputs and outputs — the project details, materials, pricing, scope items, and notes you provide when drafting a proposal/sales pack, and the generated proposal/sales-pack drafts that JobToolShed returns.
- Follow-up pack inputs and outputs — the project details you enter to generate a follow-up pack, and the generated follow-up messages (email, SMS, internal notes).
- Usage data — basic events such as pack created, message copied, so we can improve the product and support you.
- Support submissions — name, email, and message when you contact us through /contact.
- Billing data — handled by Polar, our current merchant-of-record payment provider. We receive a transaction reference and subscription status, not your card details.
- Pre-launch waitlist (historical) — if you joined our pre-launch waitlist, we collected your email address (and optional name, trade, and country). We use it only to send occasional Job Tool Shed product updates and related notices. You can unsubscribe at any time.
How we use information
- To operate the service and generate your proposal and follow-up drafts.
- To send transactional account messages (e.g. password reset).
- To respond to support requests.
- To process payments (via Polar, our current merchant-of-record payment provider) and manage entitlements.
- To monitor abuse and protect the service.
What we send to AI
JobToolShed uses AI model providers to draft proposals, sales packs, and follow-up messages from the project information you enter. We aim to send only what is needed to produce a useful draft:
- JobToolShed does not need your customer's email address, phone number, or full street address to generate a draft, and avoids sending those fields to the AI model where the app can.
- Where practical, customer name may be replaced with a placeholder in the AI prompt; you can paste the real name back in when you send the message.
- Private internal notes are stored with your pack for your reference and are not sent to AI unless they are specifically being used as input to generate a draft.
Who we share with
We share data only with service providers needed to run JobToolShed:
- Our merchant-of-record payment provider (currently Polar) — payment processing, tax handling, and receipts.
- Hosting and database providers — to operate the service.
- AI model providers — to generate proposal and follow-up drafts.
We do not sell your data. We do not share customer-of-yours contact details collected by JobToolShed with any third party for marketing.
Legal basis for processing
We rely on the following legal bases under applicable data protection law (including the UK GDPR and EU GDPR where relevant):
- Performance of a contract — to create and operate your account, generate the proposal and follow-up drafts you request, store your business profile, customer records, jobs, proposals, and follow-up packs, and provide customer support.
- Legitimate interests — to secure the service against fraud and abuse, monitor basic usage events to improve the product, and maintain service reliability. We balance these interests against your rights and expectations.
- Legal obligation — to keep records required for tax, accounting, and compliance with lawful requests from authorities.
- Consent — where we ask for it (for example, optional marketing communications). You can withdraw consent at any time.
Billing-related data is processed by Polar, our current merchant-of-record payment provider, under that provider's own legal bases and privacy notice.
How long we keep information
We keep personal data only as long as we need it for the purposes above, then delete or anonymize it. Typical retention periods:
- Account, business profile, customers, jobs, proposals, and follow-up packs — kept for the life of your account so you can access your records. Deleted within 30 days of account closure, except where we must keep limited records for legal or accounting reasons.
- Support submissions — kept for up to 24 months after the issue is resolved.
- Usage events (e.g. pack created, message copied) — kept for up to 24 months in identifiable form, then aggregated or deleted.
- Security and audit logs — kept for up to 12 months for abuse prevention and incident response.
- Billing records — transaction references and subscription status are kept for up to 7 years to meet tax and accounting requirements. Card details are held by the merchant-of-record payment provider, not us.
- Backups — may persist for up to 30 days after deletion from the live system before being overwritten.
You can request earlier deletion at any time by contacting support; we will honour the request unless we are legally required to keep specific records.
Your choices
- You can request a copy of your account data by contacting support.
- You can request deletion of your account data by contacting support.
- You can cancel a paid subscription through the billing portal in-app.
Security
We use industry-standard practices including encrypted connections, row-level security on user data, and least-privilege server credentials. No system is perfectly secure; please use a strong, unique password.
Contact
Questions about this notice? Reach us through /contact.