Privacy Policy
JACK App Inc., United States and Canada
Effective date: August 1, 2026
JACK App Inc. (“JACK App”, “we”, “us” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose and protect personal information when you use the JACK App construction management platform (the “Service”) in the United States and Canada.
We handle personal information in line with the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together the “CCPA”); the comprehensive consumer privacy laws of other U.S. states (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana, and other states as their laws take effect); the federal Personal Information Protection and Electronic Documents Act (“PIPEDA”) in Canada; and Canadian provincial privacy laws (including Quebec Law 25 and the personal information protection Acts of British Columbia and Alberta). This policy is intended to apply to residents of all U.S. states and Canadian provinces whose privacy laws apply to us.
1. Key terms
~Personal information means information that identifies, relates to, or could reasonably be linked to a particular individual or household.
~Sensitive personal information is a subset (for example government identifiers or precise geolocation). We do not seek it and ask that you not upload it to the Service.
~Customer Data means the data you and your users upload to or create in the Service, such as contacts, estimates, budgets, invoices, schedules, photos and project records.
2. Information we collect
Depending on how you use the Service, we collect:
~Identifiers and contact data: name, business name, mailing address, email address and phone number.
~Commercial and account data: your subscription, billing details and transaction history.
~Order and delivery data: for physical products, the name and delivery address for your safety sign orders.
~Customer Data: the content you and your authorized users enter into the Service.
~Onboarding and migration data: data imported from your existing software and, where you choose, login credentials for that software (see section 4).
~Internet and device data: IP address, device and browser type, and usage data collected through cookies and analytics.
~Support records: your communications with our support, training and implementation teams.
3. How we collect it
We collect information directly from you when you enquire, subscribe or use the Service; automatically through cookies and analytics; and sometimes from third parties or public sources to improve and tailor our products.
4. Onboarding, data import and access to your existing software
When you onboard, you may give us data to set up your account and ask us to import or migrate data from your current software. To do this, you may choose to give us login access to that other platform. Where you do, you represent that you are authorized to share the data and grant the access, and that you have any consents needed from the individuals involved.
We use this access and data only to import and set up your account. We do not mine, profile or sell the data, and we do not keep your third-party login credentials longer than needed to complete the work. You remain responsible for the accuracy and legality of the data you provide.
5. Support login access
The Service includes a Support Access feature that lets our implementation, training and support staff sign in to your account to help you. It is enabled by default and you can disable or re-enable it at any time in your account settings.
We use Support Access only for onboarding and setup, training, and support and troubleshooting. When our staff use it, we do not export your data, access your account for purposes you have not asked us to help with, or use it for marketing, advertising, data mining or profiling.
Support Access may be provided by our staff located overseas, including support and implementation staff in the Philippines engaged through an agency, who are bound by confidentiality and data protection obligations.
6. How we use information
We use information to provide, maintain, secure and improve the Service; set up accounts and deliver onboarding, training and support; process payments; communicate with you; perform analytics and internal administration; send marketing where permitted; and meet legal obligations.
We use artificial intelligence tools to help provide, secure and improve the Service. We do not use AI to make automated decisions that produce legal or similarly significant effects about individuals without human involvement.
If you connect an external AI tool or agent to your account, including through a connection that uses the Model Context Protocol, that tool can access personal information in your account to read and write data as you direct. You choose and control which tools you connect, and you can disable the connection at any time. Those tools are third-party services governed by their own privacy terms, and personal information may be sent to the AI provider you choose.
7. How we disclose information
We disclose information to service providers and contractors (for example hosting, IT, payment and analytics providers), to professional advisers, and where required or permitted by law. We do not sell or “share” personal information as those terms are defined under the CCPA and comparable state laws, and we do not use or disclose sensitive personal information beyond the purposes those laws permit. We use Stripe to process card payments; Stripe handles your card details, and we do not store your full card numbers. When you order physical safety signs, we share your name and delivery address with our third-party printing and shipping provider to fulfil your order.
8. Your privacy rights
California residents (CCPA/CPRA)
If you are a California resident, you have the right to:
~know and access the personal information we have collected about you;
~delete personal information, subject to exceptions;
~correct inaccurate personal information;
~opt out of the sale or sharing of personal information;
~limit the use and disclosure of sensitive personal information; and
~not be discriminated against for exercising your rights.
We respond to verifiable requests within 45 days, and may extend once by a further 45 days (90 days total) with notice. You may use an authorized agent, and we may need to verify your identity. Where feasible, we provide access data in a portable, machine-readable format. To make a request, contact us (see section 13).
Residents of other U.S. states
If you live in another U.S. state with a comprehensive privacy law, you generally have similar rights to confirm whether we process your personal information, access it, correct it, delete it, obtain a portable copy, and opt out of targeted advertising, the sale of personal information and certain profiling. Where your state law provides one, you may also appeal a refused request. We respond within the timeframe your state law requires, usually 45 days. To make a request, contact us (see section 13).
Canadian residents (PIPEDA)
If you are in Canada, you may request access to the personal information we hold about you, ask us to correct it, and withdraw consent to our use of it (subject to legal or contractual limits). We respond within the timeframes required by PIPEDA and applicable provincial law.
9. How we keep it secure
We use reasonable administrative, technical and physical safeguards to protect information, including access controls, encryption in transit, firewalls and staff training. No system is completely secure, so we cannot guarantee absolute security. Customer Data is hosted primarily in the United States and Australia.
10. Data breaches
United States: If a breach affects your personal information, we notify affected individuals and regulators as required by applicable state breach-notification laws, without unreasonable delay. Under the CCPA, California residents may have a private right of action for certain breaches caused by a failure to maintain reasonable security.
Canada: If a breach of security safeguards creates a real risk of significant harm, we report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible, and we keep records of breaches as PIPEDA requires.
11. Data retention and deletion
We keep personal information only as long as needed for the purposes described here, usually for the life of your relationship with us and a reasonable period afterwards, unless a longer period is required by law. We then delete or de-identify it. On account termination we handle Customer Data in line with our Terms of Service.
12. Cookies, analytics and your choices
We use cookies and analytics tools such as Google Analytics to understand and improve website use. You can block or remove cookies in your browser. We honor recognized opt-out preference signals, such as Global Privacy Control, where required by law. Our Service is intended for businesses and is not directed to children under 16. If you receive SMS messages from us, our separate SMS Terms and Conditions also apply.
We also use a session recording tool (Hotjar) that captures how users interact with the Service, such as clicks, navigation and page activity, so we can find bugs and usability problems. We configure this tool to mask or exclude sensitive data, and we use the recordings only to diagnose and improve the Service, not to identify you or for marketing.
13. Contact us
Email: helpdesk@jackapp.io
Mailing address (United States): JACK App Inc., 9595 Six Pines Drive, Building 8, 2nd Floor, Suite 8210, The Woodlands, TX 77380, USA
Contact (Canada): Same as the United States above.
14. United States and Canada: key differences

15. Changes to this policy
We may update this policy from time to time. The current version is always available on our website, with the effective date shown at the top.
16. Contact
JACK App Inc.
Email: helpdesk@jackapp.io
Head office: 2002 Timberloch Pl Suite 200, The Woodlands, TX 77380
Website: jackapp.io/us/
