1. What Data We Collect
JBHandyMan collects information to operate our website, platform, and services for clients and their end users. The categories of data we collect include:
Information You Provide
- Contact and account information (name, email, phone number)
- Business information, service requirements, and configuration details
- Payment and billing information processed through our payment provider
- Communications with our sales and support teams
- Content you upload or configure within client applications (e.g., customer records, schedules)
Information Collected Automatically
- Device and browser information (user agent, operating system, screen size)
- Network and session data (IP address, timestamps, referring URLs)
- Usage and interaction data on our website and platform
- Application logs, error reports, and performance metrics
- Cookies, pixels, and similar technologies as described below
Information from Third Parties
We may receive information from authentication providers, payment processors, analytics services, and infrastructure vendors that help us deliver and secure our services.
2. Google Analytics
Our website uses Google Analytics (Google tag / gtag.js) to understand how visitors use our site. Google Analytics may collect information such as pages viewed, time on site, approximate geographic region, device type, and referral source.
Google may use cookies and similar identifiers to recognize browsers across sessions. Data collected through Google Analytics is processed by Google LLC and is subject to Google’s Privacy Policy. You can opt out of Google Analytics on websites generally by installing the Google Analytics Opt-out Browser Add-on, or by adjusting your browser cookie settings.
3. Logging
We maintain server, application, and API logs to operate, secure, and troubleshoot our services. Logs may include request timestamps, endpoints accessed, HTTP status codes, error messages, authentication events (without storing passwords), and technical identifiers such as IP addresses and session tokens.
Logs are used for security monitoring, fraud prevention, capacity planning, and incident response. We apply access controls so that log data is available only to authorized personnel and systems with a legitimate need.
4. Diagnostics
We collect diagnostic information when errors or performance issues occur, including stack traces, error codes, request metadata, and environment details needed to reproduce and fix problems. Diagnostic data is used to improve reliability and is not used for advertising purposes.
Where possible, we minimize the personal information included in diagnostic payloads. You should not include sensitive personal data in free-text fields unless required for support.
5. Monitoring
We use monitoring tools—including cloud infrastructure monitoring such as AWS CloudWatch—to track service health, latency, availability, and resource utilization. Monitoring may process aggregated metrics and alerts derived from logs and infrastructure events.
Our website may also use session analytics tools (such as Contentsquare) to understand user experience patterns, including page interactions and navigation flows. These tools help us improve usability and are governed by the respective provider’s privacy terms.
6. Authentication Data
Account authentication for our platform and admin flows may be handled through one or more identity providers, including Amazon Cognito (AWS), Google Identity Services, Firebase Authentication, Google Cloud Identity Platform, and Azure SSO (Microsoft Entra ID). Depending on the sign-in method you use, these services may process authentication data such as email address, username or user ID, password hashes (we do not store plaintext passwords), profile identifiers, multi-factor authentication settings, sign-in timestamps, and session or access tokens.
Authentication data is stored and processed within the infrastructure of the applicable provider according to that provider’s security standards. We use this data solely to authenticate users, manage access, enforce account policies, and protect against unauthorized access. For more information, see the privacy policies of AWS, Google, and Microsoft.
7. Support and Debug Access
When you contact support or when we investigate an issue on your behalf, authorized JBHandyMan personnel may access account, configuration, and usage data necessary to resolve the request. This may include viewing application state, reproducing errors, or temporarily elevating access for debugging.
Debug access is limited to personnel with a business need, is logged where feasible, and is revoked when no longer required. We do not use support access to sell your data or for unrelated marketing purposes.
8. Subprocessors
We use trusted third-party service providers (“subprocessors”) to host, operate, and improve our services. These providers process personal data on our instructions and under contractual obligations. Current categories of subprocessors include:
- Cloud infrastructure: Amazon Web Services (Hosting, Cognito, API Gateway, Serverless, CloudWatch, WAF, CloudFront; AI infrastructure including AWS Trainium, AWS Inferentia, Amazon SageMaker AI HyperPod, and EC2 accelerated compute for AI/ML; AI and machine learning services including Amazon Bedrock, Amazon Bedrock AgentCore, Amazon SageMaker AI, Amazon Nova, Amazon Q, Amazon Comprehend, Amazon Comprehend Medical, Amazon Rekognition, Amazon Transcribe, Amazon Polly, Amazon Textract, Amazon Lex, Amazon Kendra, Amazon Personalize, Amazon Translate, Amazon Forecast, Amazon Fraud Detector, Amazon CodeGuru, Amazon DevOps Guru, Amazon Augmented AI (A2I), Amazon Lookout for Metrics, Amazon Lookout for Equipment, Amazon Lookout for Vision, AWS Deep Learning AMIs, AWS Deep Learning Containers, AWS Entity Resolution, and related AWS AI/ML tooling)
- Google services: Google LLC and its affiliates, including Google Analytics (website measurement); Google Cloud Platform services such as Cloud Functions, Cloud APIs, and related infrastructure used to run backend workflows; Google Fonts and other Google-hosted assets loaded by our website; and other Google APIs integrated into our products where applicable
- Microsoft services: Microsoft Corporation and its affiliates, including Azure Database services (e.g., SQL Database, Cosmos DB, and related data stores); Azure Functions and other serverless compute; Azure Messaging Services (e.g., Service Bus, Event Hubs, Notification Hubs); Azure AI and Machine Learning services; Azure Containers (e.g., Container Instances, Kubernetes Service); Azure DevOps and related CI/CD tooling; Azure IoT services; Azure Media Services; and other Microsoft Azure or Microsoft 365 APIs integrated into our products where applicable
- Payments: Stripe and Authorize.Net (payment processing and fraud prevention)
- Analytics and UX: Session and experience analytics providers (e.g., Contentsquare)
- Content delivery: CDN providers for static assets and media
- Communications: Email and messaging providers used for transactional and support communications
We may update subprocessors as our stack evolves. Material changes affecting how we process your data will be reflected in updates to this policy. Third-party services are also subject to their own privacy policies, including Google’s Privacy Policy and Microsoft’s Privacy Statement.
9. Retention
We retain personal information only for as long as necessary to provide services, meet legal obligations, resolve disputes, and enforce our agreements. Retention periods vary by data type:
- Account and contract data: retained for the duration of your relationship plus a reasonable period thereafter
- Payment records: retained as required for accounting, tax, and fraud-prevention obligations
- Logs and diagnostics: typically retained for a limited rolling period unless needed for an active investigation
- Analytics data: retained according to each analytics provider’s configuration and our internal policies
When data is no longer needed, we delete or anonymize it using commercially reasonable methods.
10. Security Posture
We implement technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. Our security posture includes:
- Encryption of data in transit (TLS) and encryption at rest where supported by our infrastructure
- Authentication and access controls, including AWS Cognito for identity management
- Least-privilege access for employees and production systems
- Monitoring, logging, and alerting for suspicious or anomalous activity
- Regular review of dependencies, configurations, and security practices
- Contractual security requirements for subprocessors handling personal data
No method of transmission or storage is completely secure. If you believe your account has been compromised, contact us immediately.
11. Rights Requests
Depending on your location, you may have rights regarding your personal information, including:
- Access to the personal information we hold about you
- Correction of inaccurate or incomplete data
- Deletion of personal information, subject to legal and contractual exceptions
- Portability of data you provided in a structured, commonly used format
- Restriction or objection to certain processing activities
- Withdrawal of consent where processing is based on consent
To submit a rights request, email us at hello@jbhomeassembly.com with the subject line “Privacy Rights Request” and describe the right you wish to exercise. We may need to verify your identity before fulfilling a request. We will respond within the timeframe required by applicable law.
If you are a resident of the European Economic Area, United Kingdom, or California, additional rights and complaint mechanisms may apply under GDPR, UK GDPR, or CCPA/CPRA. We do not sell personal information as defined under the CCPA.
12. How We Use Information
We use collected information to:
- Provide, maintain, and improve our services
- Authenticate users and manage access
- Process payments and manage billing
- Communicate with clients about services and updates
- Provide customer support and technical assistance
- Monitor performance, detect abuse, and protect security
- Comply with legal obligations and enforce our terms
13. Information Sharing
JBHandyMan does not sell personal information. We share data only with subprocessors described above, with your consent, when required by law, or in connection with a merger, acquisition, or asset sale with appropriate safeguards.
14. Cookies and Tracking
Our website uses cookies and similar technologies for authentication, analytics, and user experience measurement. You can control non-essential cookies through your browser settings. Disabling cookies may affect certain site features.
15. Children’s Privacy
Our services are not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13.
16. Policy Updates
We may update this Privacy Policy from time to time. Material changes will be communicated through our website or direct notification. Continued use after the effective date constitutes acceptance of the updated policy.
17. Contact Us
For questions about this Privacy Policy or to exercise your rights, please contact us at:
Email: hello@jbhomeassembly.com