JobSmart Privacy Policy
How JobSmart handles field-service records, synchronization, bookings and invoices.
This policy explains JobSmart's local workspace, connected services, public pages, documents and privacy choices in plain language.
Overview
Blue Sparrow is a solo developer based in India and operates JobSmart for solo technicians and independent field-service businesses. This policy explains what the mobile app, synchronization service, public booking pages, hosted invoices, support and email tools, purchase services and notifications handle. JobSmart applies data-minimisation, transparency, purpose-limitation, security and rights principles supported by the EU General Data Protection Regulation and other applicable privacy requirements.
JobSmart is local-first and connected, not local-only. An app-private local database supports offline work, while an authenticated JobSmart account synchronizes supported records with the JobSmart API. A technician or their business generally decides why customer, contact, site, photo, signature, invoice and payment information is entered or shared. That technician or business is normally responsible for an appropriate basis, notices, accuracy, retention and recipient choices for those professional records. Blue Sparrow handles connected copies to provide JobSmart and separately determines how account security, service operations, purchases, analytics and support information are handled.
Data we handle
Depending on the features used, JobSmart may handle:
- Google and Firebase account information such as a user identifier, email address, display name, profile image, sign-in provider and authentication metadata.
- Business profile information such as trading name, technician name, phone, service types, business and service-area addresses, derived coordinates, hours, timezone, currency, tax and pricing settings, booking slug, logo and document branding.
- User-configured payment destinations such as an account-holder name, IBAN, BIC, UPI identifier, PayPal profile or provider-created payment link. JobSmart does not need a bank password, one-time code or customer payment-card number.
- Customer, contact, site and billing information such as names, company, phone, email, addresses, access notes, recipient preferences and references.
- Booking and work information such as service type, reported problem, arrival note, requested and confirmed schedule, recurrence, status, technician notes, diagnosis, work performed, warranty terms, duration, line items, taxes, totals and cancellation or payment state.
- Before-and-after photos, optional branding images, customer and technician signatures, local file paths, upload state and related file metadata.
- Generated invoices and job reports, including PDF content, invoice identifiers, storage keys, hashes, delivery state, attachment size, email recipient and provider message identifiers.
- Manual payment records and payment-request activity, including amount, currency, method, reference, note and broad action type. JobSmart records payments reported by the technician but does not collect or settle customer funds.
- Public booking information submitted without an app account, including contact details, service address, issue, arrival note, requested schedule and a confirmation reference.
- Booking-link attribution such as a broad sharing channel, app entry point, campaign labels and referring host. Limited attribution may be held in browser session storage, stored with the resulting booking and used for app or website analytics.
- Notification information such as an app-generated device identifier, platform, app version, timezone, permission state and Firebase Cloud Messaging token. The backend encrypts active push tokens and also stores a non-reversible fingerprint for registration control.
- Google Play and RevenueCat product, transaction, receipt, subscription and entitlement information. Blue Sparrow does not receive full payment-card details.
- Support and feedback information deliberately submitted by a signed-in user, including account and reply email, account name, subject, message, optional rating, request identifier, delivery state and provider records.
- Operational information such as synchronization cursors, conflict and queue state, idempotency records, request and security logs, delivery attempts, timestamps and deletion evidence.
- Firebase Analytics events for selected booking-link publication actions in the app. Public booking pages can also send limited landing and submission events to Google Analytics when a measurement identifier is configured. These events use broad channel and entry-point values rather than customer names, addresses, invoice amounts or payment destinations.
JobSmart removes Android advertising-identifier permission and does not build a cross-app advertising profile. Firebase Crashlytics is included as a dependency but no active Crashlytics error handler was found in the audited app startup. Camera capture or image selection occurs only when a user chooses it. JobSmart does not need contacts, SMS content, call history, microphone recordings or continuous device location for its current features.
How we use data
Information is used as reasonably necessary to:
- Authenticate the technician and associate the intended local and connected workspace with that account.
- Provide customers, contacts, sites, bookings, schedules, work records, photos, signatures, invoices, reports, payment tracking and exports.
- Synchronize supported records, recover from conflicts and send queued photos or invoices when connectivity returns.
- Publish selected business information and receive service requests through a booking page.
- Create temporary hosted invoice links and deliver booking, confirmation, invoice, support or feedback email.
- Register enabled notifications and alert a technician to relevant booking activity.
- Validate purchases, restore access and synchronize limited subscription or VIP entitlement state.
- Understand how booking links are published and reached, subject to the analytics configuration and controls described here.
- Protect accounts and services, prevent abuse, maintain reliability and meet applicable operational requirements.
Blue Sparrow does not sell or rent personal information and does not use JobSmart records for targeted advertising.
Storage and residency
The mobile working copy uses SQLite and app-private files on the device. The current local database is not protected by application-level encryption, so device security and a strong screen lock matter. Android cloud backup and device-transfer extraction are explicitly disabled for the app's root, files, databases and preferences.
Supported account, business, customer, site, booking, work, payment, delivery and event records synchronize to PostgreSQL. Selected photos and invoice PDFs can be uploaded to JobSmart-controlled file storage. Blue Sparrow-controlled connected JobSmart content is intended to remain in European Union infrastructure, subject to verification of the live production location, offsite backup region, retention jobs and deployment configuration. This is a qualified infrastructure commitment, not a claim that every JobSmart-related datum stays exclusively within the EU.
Google, Firebase, RevenueCat, Google Play, notification, mail, analytics, anti-abuse, map and user-selected services may process limited information in other regions. Blue Sparrow support access may occur from India when needed to answer a request or operate the service.
Synchronization uploads and exports
JobSmart keeps a local working copy and transfers supported changes through authenticated API requests. Queues can retain pending records, image paths, invoice paths, retry state and error information until an upload succeeds, is removed or local data is cleared. Synchronization can be delayed, interrupted or conflict with a newer server record, so review important work after reconnecting.
Before-and-after photos selected for synchronization can be uploaded to the booking's server storage. Invoice PDFs are uploaded when a connected invoice workflow requires them. Job report PDFs may instead remain local or be copied into a queued customer email; they are not represented as a permanent hosted report page in the audited public API.
CSV exports, PDF files, email attachments, QR images, payment requests and files shared through another app are ordinary copies. They may contain customer, address, work, signature, invoice or payment information and are controlled by the chosen destination or recipient after sharing. Deleting JobSmart cannot retrieve a delivered copy.
Public pages and invoice links
A technician can publish a stable booking page under their chosen business slug. It can display the technician or company name, phone, business address or service-area information, logo, services, hours, pricing context and map status. The page is designed to be publicly discoverable and does not require a customer account. A customer submission creates a booking for the technician. Ordinary server logs may process network and browser information, and Turnstile may process an abuse-check token when configured.
JobSmart can create a signed hosted invoice URL that expires after seven days. Anyone holding a working URL can open the selected invoice without signing in until the link expires or the underlying invoice changes or is removed. Hosted invoice pages include search no-index and no-follow instructions, but a recipient can still download, forward or capture the PDF. Treat each URL as confidential and verify the intended recipient before sending it.
Retention and deletion
Local records remain until edited, deleted, cleared with app controls or removed with app storage. Synchronized records, uploads, invoices, notification and email queues, analytics, support information, security logs, subscription evidence and operational backups remain while reasonably needed for the feature, service integrity, applicable records or a verified deletion process. No fixed production period is promised where live retention and backup evidence has not been verified.
The in-app account-deletion flow requires recent Google authentication. It first asks the JobSmart API to remove the connected account. The API attempts to remove booking upload folders and invoice files, records a deletion tombstone, removes the subscription mirror and deletes the user row; database relationships then remove associated customers, contacts, sites, bookings, push registrations, aliases, events, payment records and queued messages. File removal is best effort and can fail independently. The app then clears local tables and attempts to remove local files, preferences and the Firebase Authentication identity before signing out.
Deletion tombstones, subscription-delivery receipts, limited security or administrative evidence, protected backups, provider records, already delivered email and recipient or exported copies can have separate lifecycles. Google Play and RevenueCat purchase records are not removed by the app flow, and deleting an account does not cancel a Google Play subscription. Contact [email protected] if any step fails or if app access is unavailable.
Security
JobSmart uses proportionate safeguards including authenticated HTTPS requests, per-user data checks, app-private local storage, Android backup exclusion, encrypted server-side push tokens, signed expiring invoice links, upload validation, idempotency controls, rate limits and deletion tombstones that block delayed entitlement events from recreating an account.
Public booking pages, recipient-held invoice links, exports and user-supplied payment destinations require careful handling. Protect the device, Google account, PDFs, public URLs and payment instructions. No device, transmission, local file or connected service can be guaranteed completely secure.
Your rights
Depending on location and applicable exceptions, a person may have rights to access, correct, receive, delete, restrict or object to processing of personal information and withdraw consent where consent is the basis. A person may contact a local data-protection authority. Applicable protections can include the EU and UK GDPR, India's Digital Personal Data Protection framework, US state privacy requirements, Brazil's LGPD, Canadian requirements and comparable rules elsewhere.
Users can edit many records, export supported booking data, manage notifications and start account deletion. A customer or contact whose information was entered by a technician should normally contact that technician or business first; Blue Sparrow will assist a verified account or respond directly where required. Email [email protected] with JobSmart in the subject. Proportionate identity verification may be requested.
Children and minors
JobSmart is intended for business and professional account operators and is not directed to children. A technician should not enter a child's information unless genuinely needed for an appropriate service purpose with the notices, permissions and safeguards required where the child lives. Do not place unnecessary child information in booking notes, photos, signatures, reports, invoices or public submissions. Contact [email protected] with a concern.
International transfers
Blue Sparrow-controlled connected content is intended for EU infrastructure subject to the verification described above. Google, Firebase, RevenueCat, Google Play, notification, mail, analytics, anti-abuse, map and user-selected providers may process limited information elsewhere. Where required, Blue Sparrow and providers use appropriate contractual, adequacy or other lawful mechanisms with data-minimisation and security measures. EU users retain EU GDPR protections across necessary regional boundaries.
Changes
This policy may change when JobSmart, its providers or applicable requirements change. Material updates will be presented in the app or at https://bluesparrow.dev where appropriate, and the updated date will be revised.
Contact
For privacy questions, rights requests or deletion follow-up, email [email protected]. For general help, email [email protected]. Information is available at https://bluesparrow.dev.