Privacy Policy
Last updated: August 2026
JobLock answers the calls you miss, qualifies the caller and hands you a complete job card. That means we handle data about you, about your team, and about the people who call you. This policy explains exactly what we collect, why, who it is shared with, how long it is kept, and the choices you and your callers have.
1. Scope and who this policy applies to
This Privacy Policy explains how JobLock ("JobLock", "we", "us") collects, uses, discloses, stores and protects personal data. It applies to our websites, our web application, our onboarding flow, our call-forwarding and SMS qualification service, our public tradesperson profiles, and any related support channels (together, the "Service").
It covers three different groups of people: (a) tradespeople and businesses who hold a JobLock account ("Customers"); (b) staff members and technicians added to a Customer account ("Team Members"); and (c) end callers whose missed call is captured and qualified by JobLock on a Customer's behalf ("Callers").
For Customers and Team Members, JobLock acts as a data controller. For Caller data captured through a Customer's forwarded line and qualification form, JobLock acts as a data processor on behalf of that Customer, who is the controller of that data.
2. The data we collect
Account and business data: business name, owner name, email address, mobile number, country, service postcode or ZIP, trade type and specialties, company registration and tax identifiers where required by your country, plan selection, and voice greeting recordings you upload.
Team data: name, email, phone number, trade types, role and active status of each Team Member you add.
Telephony data: caller number, the number the call was forwarded from, call identifiers and timestamps, forwarding status, and whether a qualification message was delivered. We do not record the content of voice calls.
Caller-submitted job data: name, phone number, optional email, postcode, issue description, urgency, callback window preference, answers to your custom qualification questions, and any photos the caller uploads.
AI-derived data: summaries, suggested diagnoses, detected specialties, suggested parts and estimated job value ranges generated from the caller-submitted data.
Billing data: plan, subscription status, billing address and payment identifiers held by our payment processor. JobLock never stores full card numbers.
Calendar data: where you connect a calendar, the event identifiers and scheduling data needed to create and update your job appointments.
Technical and usage data: IP address, browser and device type, pages viewed, feature usage, approximate country derived from IP for pricing localisation, error logs and diagnostic events.
Support data: the content of messages you send us through the Help Center or by email.
3. Where the data comes from
Directly from you, when you register, complete onboarding, add team members, configure your lead form, edit your public profile, or contact support.
From your callers, when they reply to a qualification message or complete a qualification form.
Automatically, from your use of the Service (cookies, local storage, server logs).
From our sub-processors, such as telephony metadata from our SMS/voice provider, subscription status from our payment processor, and calendar identifiers from a calendar provider you connect.
4. Why we use it, and our legal bases
To provide the Service (performance of a contract): forwarding missed calls, sending qualification messages, collecting job details and photos, building dispatch cards, scheduling jobs, publishing your public profile and running your dashboard.
To take payment and manage subscriptions (performance of a contract and legal obligation).
To secure the Service, prevent abuse, fraud and spam, and to debug faults (legitimate interests).
To measure and improve the Service, including anonymous or aggregated usage analysis (legitimate interests).
To communicate with you about service changes, incidents, quota limits and support (legitimate interests and performance of a contract).
To send marketing about JobLock features (consent, where required; you may opt out at any time).
To comply with legal, accounting and tax obligations (legal obligation).
5. Automated processing and AI
JobLock uses automated models to summarise a caller's issue, classify urgency, suggest a likely diagnosis from submitted photos and text, and estimate a value range for the job.
These outputs are decision support only. They do not produce legal or similarly significant effects on the caller, they are always presented to a human tradesperson, and no job is accepted, refused or priced automatically without your involvement.
AI outputs can be inaccurate. You remain responsible for verifying a job before quoting or attending. Caller data sent to AI providers is used to generate your result and is not used by us to train public models.
6. Caller data and your responsibilities as a Customer
Caller data captured through your forwarded line is stored in your account and is visible only to your business and to JobLock personnel who need access to operate or support the Service.
As controller of that data you are responsible for: having a lawful basis to contact your callers, telling them how their data is used, honouring their requests, keeping your own privacy notice up to date, and configuring custom qualification questions that do not solicit unnecessary or special-category data (for example health details, financial details or identity documents).
Do not use JobLock to collect special-category personal data or to send marketing messages to callers who have not agreed to receive them.
We process caller data only on your documented instructions, keep it confidential, apply the security measures described below, assist you with data-subject requests where reasonably possible, and delete or return it as described in the retention section.
7. Calls, SMS and messaging consent
JobLock messages a caller only in response to that caller having just called your business line. The message identifies your business and its purpose.
Callers can stop messages at any time by replying with a standard opt-out keyword; opt-outs are honoured by our messaging provider and recorded against that number.
Message and data rates may apply to the caller depending on their mobile plan. Delivery depends on carrier networks and is not guaranteed.
Call forwarding is enabled by you on your own handset with a carrier code, and can be cancelled at any time with the corresponding cancellation code.
9. International data transfers
JobLock operates internationally and some sub-processors are located outside your country, including outside the UK, the EEA and Switzerland.
Where we transfer personal data out of the UK/EEA we rely on an adequacy decision, the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, together with additional technical and organisational safeguards where appropriate.
You may request further information about the safeguards used for a specific transfer through the Help Center.
10. Security
Data is encrypted in transit using TLS and is stored on access-controlled cloud infrastructure. Access to production data is restricted to personnel who need it, is authenticated, and is logged.
Account access is protected by password and one-time email verification. You are responsible for keeping your credentials confidential and for the actions of Team Members you add.
No system is perfectly secure. If a personal data breach affecting your data occurs, we will notify affected Customers and, where required, the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it.
11. How long we keep data
Account and business data: for as long as your account is active, then up to 90 days after closure to allow recovery and dispute resolution.
Job, call and caller data: for as long as your account is active, unless you delete individual records sooner. Photos are deleted together with the job record they belong to.
Billing and tax records: for the period required by applicable accounting and tax law, typically six to ten years.
Support correspondence: up to 24 months after the request is closed.
Security and diagnostic logs: typically up to 12 months.
Backups are rotated on a fixed cycle, so deleted data may persist in encrypted backups for a short period after deletion from the live system.
12. Your rights
Subject to your location and applicable law, you may have the right to: access a copy of your personal data; correct inaccurate data; delete data; restrict or object to processing, including profiling; withdraw consent at any time without affecting prior processing; receive your data in a portable format; and not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
Requests can be made through the Help Center from inside your account, or by contacting us using the details in the Contact section. We will respond within one month, and may extend by two further months for complex requests, telling you why.
We may ask you to verify your identity before acting on a request. We do not charge a fee unless a request is manifestly unfounded or excessive.
If you are a caller and want your data removed, contact the tradesperson whose line you called — they control that record — or contact us and we will forward your request to them.
You may complain to your local supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk).
13. Regional disclosures
UK and EEA (UK GDPR / GDPR): the legal bases we rely on are listed above. Where we rely on legitimate interests we have carried out a balancing assessment, available on request.
California (CCPA/CPRA): in the past 12 months we have collected the categories of data listed above for the business purposes listed above. We do not sell or share personal information as those terms are defined by the CPRA. California residents may request to know, delete or correct their personal information, may limit the use of sensitive personal information, and will not be discriminated against for exercising these rights. Requests can be made through the Help Center.
Canada (PIPEDA): you may challenge our compliance with our privacy obligations by contacting us; you may also complain to the Office of the Privacy Commissioner of Canada.
Australia (Privacy Act / APPs) and New Zealand (Privacy Act 2020): you may request access to and correction of your personal information, and complain to the OAIC or the New Zealand Privacy Commissioner respectively.
Norway, Sweden and the Netherlands: the GDPR applies as implemented locally; your supervisory authority is Datatilsynet, IMY and the Autoriteit Persoonsgegevens respectively.
15. Third-party services and links
The Service integrates with third-party providers such as telephony and messaging networks, payment processing, calendar providers, and job-management and accounting tools you choose to connect. Those providers process data under their own privacy policies and terms.
Connecting an integration authorises JobLock to exchange the data needed for that integration to work; disconnecting it stops future exchange but does not retroactively delete data already shared with that provider.
Our site may link to external websites we do not control and are not responsible for.
16. Public tradesperson profiles
If you publish a public profile, the content you enter — business name, photos, services, prices, service areas, credentials, opening hours and reviews — becomes publicly accessible and may be indexed by search engines.
Do not publish personal data about third parties without their permission, and do not publish reviews you have not been authorised to display.
You can unpublish your profile at any time from your dashboard. Search engine caches may retain a copy for some time after unpublishing.
17. Children
The Service is a business tool intended for adults. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
18. Changes to this policy
We may update this policy to reflect changes to the Service, our sub-processors or the law. The "last updated" date at the top always reflects the current version.
Where changes are material, we will notify account holders by email or by a notice inside the Service before the changes take effect. Continuing to use the Service after that date means you accept the updated policy.
19. Contact us
For any privacy question, data-subject request, or to ask for details of our sub-processors or transfer safeguards, contact us through the Help Center inside your account.
Please include enough detail for us to identify your account or the record concerned, so we can respond accurately.