Paperless Job Card is operated by [Your Company Legal Name], registration number [registration number], of [registered address] (“we”, “us”, “Paperless Job Card”). You can reach us at [support email].
From your account: your name and email address.
From job cards created through the service: the client's name, phone number and site address; the client's email address if provided for sending a copy of the signed card; a GPS location, captured once, only at the moment a signature is captured, to evidence where the card was signed; photographs attached to the job; signatures, stored as vector path data rather than images; and an app-generated installation identifier (never a hardware identifier such as an IMEI or serial number).
Solely to provide the job card service: creating and managing job cards, producing a signed PDF record of completed work, emailing that record to the client and to your company's own notification addresses when you turn that on, and applying your company's branding, tax and job-numbering configuration. We do not sell personal information, and we do not use it for advertising.
If you use Paperless Job Card through a company account, that company is the responsible partyfor the personal information captured on its job cards (its clients' details), and we act as its operator— we process that information only on the company's instruction, and we maintain the security safeguards required by POPIA section 19. Our written commitments to each company as operator are set out in our Terms of Service.
Paperless Job Card's infrastructure (database, authentication and file storage) is hosted by Supabase in the European Union. Because this involves transferring personal information out of South Africa, our Terms of Service include your company's consent to that transfer, as POPIA section 72 requires. The European Union has its own comprehensive data protection framework; whether that independently satisfies POPIA's adequacy requirement (rather than relying on consent alone) is one of the specific questions for attorney review noted above.
Once both parties have signed a job card, it becomes an immutable business record. We retain signed job cards for five years, matching SARS's record-keeping requirement, even if the technician who created the card or the company that owns it later requests deletion — POPIA section 14(1) permits retention where required by law. Draft (unsigned) cards and accounts are deleted as described below.
Every account has a Delete My Account option (Settings → Account in the mobile app, or Settings in the web console).
For a technician or supervisor: your access is revoked immediately and your name is removed from your profile. Job cards you already created or signed stay on your company's record, for the reason in section 6.
For a company admin: this begins deleting your entire company's account — all job cards, team members and settings — after a 30-day retention window, and revokes your own access immediately. Contact us within that window if you want to cancel the deletion.
If your personal details appear on a job card as a client (not as an account holder), requests to access, correct or delete that information should go to the company that issued the job card — they are the responsible party for it. If you hold a Paperless Job Card account, use the deletion option above, or contact us directly at [support email].
All data in transit is encrypted (TLS). Data at rest is scoped by Row Level Security policies enforced by the database itself, not just by application code — a company can only ever read its own data, regardless of what a client application requests. Photographs and logos are stored in private buckets and served only via short-lived signed URLs.
Supabase (database, authentication, file storage) and Resend (delivering the signed-card emails you or your company choose to send). Both process data only as needed to provide their part of the service to us.
Paperless Job Card is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 18.
If this policy changes materially, we'll update the date at the top and, for company admins, note it in the admin console.
Questions about this policy or a data subject request: [support email].