JobWall (“JobWall”, “we”, “us” or “our”) provides customer portal software for businesses that use ServiceM8. This Privacy Policy explains how JobWall collects, uses, stores, discloses and protects information when a business connects JobWall to its ServiceM8 account and when administrators, staff and customers use JobWall.
JobWall is an independent software product and is not operated by ServiceM8.
1. Our role
A business that connects its ServiceM8 account to JobWall remains responsible for the personal information it collects and manages through its business operations and ServiceM8 account.
For information obtained from ServiceM8 and processed to provide JobWall to that business, JobWall generally acts as a service provider or data processor on behalf of the connected business. For information necessary to operate JobWall itself, such as administrator account information, platform security records, support communications and service usage information, JobWall may be responsible for that information in accordance with applicable privacy laws.
2. Information we receive from ServiceM8
When a business connects JobWall using ServiceM8 OAuth, JobWall may access and process ServiceM8 information required to provide enabled JobWall features. Depending on the features used and permissions granted, this may include:
- ServiceM8 account and business identifiers;
- business name, address, country and account information;
- customer company records and customer contact names, email addresses and phone numbers;
- ServiceM8 job identifiers and job numbers;
- job category, status, service address and scheduling or completion information;
- job information required for JobWall functionality;
- quotes, invoices, reports, documents, photographs and attachment metadata that are eligible for JobWall functionality;
- ServiceM8 Asset information, including asset type, name, location, configured fields and related service history;
- ServiceM8 staff identifiers associated with actions performed through JobWall; and
- information required to deliver customer service requests into the connected business's ServiceM8 workflow.
JobWall only accesses ServiceM8 information within the permissions authorized through the ServiceM8 OAuth connection. Each connected business has its own ServiceM8 OAuth connection.
3. Customer documents and photos
JobWall does not automatically make a quote, invoice, document, attachment or photo visible to a customer merely because that information exists in ServiceM8.
Supported files remain private from the JobWall customer portal until an authorized staff member explicitly chooses to make the file available through the JobWall Job Card interface. The business may revoke that publication at any time. JobWall rechecks publication status when protected documents are accessed so revoked files are no longer available through the customer portal.
The connected business is responsible for deciding which documents and information are appropriate to share with its customers.
4. Information collected directly by JobWall
JobWall may collect information directly when administrators, staff or customers use the service, including:
- email address, first name and last name;
- authentication and login information;
- customer portal membership information;
- company administration information;
- service requests submitted through JobWall;
- service address and preferred service timing included in a request;
- company branding and portal configuration;
- customer-facing document names selected by staff;
- support requests and communications; and
- records of actions performed within JobWall.
JobWall uses emailed one-time codes for customer and administrator authentication. Authentication codes are stored as protected hashes rather than reusable plaintext passwords.
5. Usage and operational information
JobWall records limited operational information required to operate, secure and maintain the service. This may include login times, session activity, feature activity, audit records, synchronization status, errors and aggregate usage information.
JobWall may maintain aggregate activity information for purposes such as determining active users and overall product usage. JobWall is designed to use aggregate platform analytics rather than exposing unnecessary customer-private activity to JobWall platform administrators.
6. How we use information
JobWall uses information to provide and operate the customer portal; authenticate users and administrators; identify the correct connected business and customer account; display authorized job and service-history information; provide documents and photographs selected for customer access; display enabled ServiceM8 Asset information; submit customer service requests; synchronize information with ServiceM8; administer company portal settings; provide technical support; maintain security; diagnose errors; maintain audit records; understand aggregate product usage; comply with legal obligations; and protect JobWall, connected businesses and users.
JobWall does not sell personal information to advertisers and does not use ServiceM8-derived customer information for third-party advertising.
7. Service providers and disclosure
JobWall may disclose or provide access to information only as reasonably necessary to operate the service. This includes service providers used for cloud application hosting, managed database infrastructure, transactional email delivery, security and operational infrastructure, and technical support.
JobWall currently uses infrastructure including Render for application hosting and Resend for transactional email delivery. JobWall also exchanges information with ServiceM8 as necessary to provide the integration requested by the connected business.
Service providers are permitted to process information only for the services they provide to JobWall and are expected to protect that information appropriately. We may also disclose information when reasonably necessary to comply with law, legal process or regulatory requirements, protect rights or security, investigate fraud or abuse, or respond to an emergency.
If JobWall or substantially all of its business is acquired, reorganized or transferred, information may be transferred as part of that transaction subject to applicable privacy obligations.
8. Data storage and security
JobWall production information is stored in a tenant-scoped PostgreSQL database so records belonging to one connected business are separated from records belonging to other businesses. ServiceM8 OAuth access and refresh tokens are encrypted at rest.
JobWall also uses measures including tenant-isolated data access, protected authentication sessions, hashed login codes and session tokens, rate limiting, browser origin protections, HTTPS, hardened security headers, HSTS, secure document access controls, audit logging and separate access controls for the JobWall Owner Dashboard.
No method of electronic transmission or storage can be guaranteed to be completely secure, but JobWall uses reasonable technical and organizational safeguards appropriate to the nature of the information processed.
9. Data retention
JobWall retains information for as long as reasonably necessary to provide the service to the connected business, maintain the ServiceM8 integration, provide security and audit functionality, meet legal obligations and resolve disputes.
When a business disconnects or terminates JobWall, information no longer required to provide the service may be deleted or anonymized in accordance with JobWall's operational and legal requirements. Some information may remain temporarily in backups, security records or service-provider systems according to normal backup and retention cycles.
JobWall may retain limited records where required for legitimate security, fraud-prevention, accounting, dispute-resolution or legal purposes.
10. Data accuracy
Much of the customer, job and asset information displayed by JobWall originates from the connected business's ServiceM8 account. Customers who believe ServiceM8-derived information is incorrect should ordinarily contact the business that provides their service so the underlying business record can be corrected. Where information is maintained directly by JobWall, users may contact JobWall for assistance.
11. Privacy rights
Depending on applicable law and jurisdiction, individuals may have rights relating to their personal information, including rights to request access, request correction, request deletion, object to or restrict certain processing, withdraw consent where processing is based on consent, request portability of certain information, and make a complaint to an applicable privacy regulator.
Because JobWall often processes customer information on behalf of a connected ServiceM8 business, a request relating to the business's customer records may need to be handled by that business. JobWall will reasonably assist connected businesses with valid privacy requests where required.
12. Responsibilities of connected businesses
Businesses using JobWall are responsible for having appropriate authority to connect their ServiceM8 account to JobWall; complying with applicable privacy laws governing their customers and staff; ensuring information contained in ServiceM8 is collected lawfully; managing staff authorization to use JobWall; deciding which customer documents and photos are appropriate to publish; responding to customer privacy requests where the business is responsible for the information; and promptly disconnecting or restricting access when access is no longer appropriate.
13. International processing
JobWall and its service providers may process or store information in countries other than the country in which a business or individual is located. Where required by applicable law, JobWall will use appropriate safeguards for international processing or transfer of personal information.
14. Essential cookies and sessions
JobWall may use cookies or similar browser storage that are necessary for authentication, session management, security and operation of the service. JobWall does not use these essential technologies for third-party behavioral advertising.
15. ServiceM8
JobWall integrates with ServiceM8 through ServiceM8's authorized developer interfaces and OAuth authentication. Use of ServiceM8 itself remains subject to ServiceM8's own terms and privacy practices.
Disconnecting JobWall from ServiceM8 prevents JobWall from continuing to use the OAuth connection to access new ServiceM8 information, subject to information JobWall may lawfully retain as described in this Policy.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to JobWall, legal requirements, security practices or service providers. The current version will be published on the JobWall website with its effective date. Material changes may also be communicated to connected businesses where appropriate.
17. Contact us
Questions, privacy requests or concerns about JobWall may be directed to:
JobWall
Email: support@jobwall.app
Website: jobwall.app
Where a request relates primarily to information maintained by a particular service business, we may direct the individual to that business so the request can be handled by the organization responsible for the underlying customer information.
