Privacy Policy
Privacy policy
Jig — Privacy Policy
The short version
- Jig is business software. Most of what is in it is your company's project data, which you control — not data we collect for our own purposes.
- We do not sell personal information, do not share it for advertising, and do not use your project data to train AI models.
- No advertising and no cross-site tracking. The only cookie is the one that keeps you signed in; our marketing site uses a cookieless page-view counter (see §6).
- Jig is for US customers only. Your data is stored in the United States.
- Our operators can reach your data through the database console, as with any hosted software. We would rather say so than imply otherwise.
- You can export or delete your data yourself, at any time.
1. Two different roles, and which one you are in
Jig by SideKick, LLC, a Wyoming limited liability company, operates Jig at jigitup.com.
We are the business (controller) for information about people who visit our site and about the account owners and users who sign up for Jig. This policy governs that.
We are the service provider (processor) for everything our customers put into their projects — including information about their employees, clients, subcontractors, suppliers and workers. We process that on the customer's instructions.
If your information is in a Jig project because a contractor put it there, that contractor is who to contact. We will refer you to them and help them respond. We will not change their records on a third party's request.
2. What we collect
About your account. Name, business email, company, role, and a session. Your password is held by our authentication provider, hashed. We never see or store your password — the application passes it once to the provider and keeps nothing.
Your project data. Projects, schedules, budgets, pay applications, RFIs, submittals, punch lists, daily logs, files, photographs, certified payroll entries, and directory entries for clients and trade partners.
About people your customers enter. This is the larger category and most of it is not about you:
- trade partners — company, contact name, phone, email, licence number and expiry, certificate of insurance expiry, W-9 status
- clients — name, contact, phone, email, address
- workers on certified payroll — name, work classification, hours, wage rates and deductions, for prevailing-wage jobs, plus an identifying number
- daily logs — who was on site, visitors, inspections
- photographs, which may show identifiable people
On every file and photo upload we record: a timestamp, a device label, the uploader's name, and — only if the account has switched it on — GPS coordinates.
Billing. When billing is live, it is handled by Stripe. We will receive the last four digits of the card, the brand, expiry, billing country and postal code, and whether the charge succeeded. Full card numbers and security codes never reach our systems. As at this version, billing is not yet integrated and no payment has been taken.
Usage. IP address, browser and operating system, pages viewed, timestamps, and actions taken — from server logs.
Communications. Emails, support requests and feedback you send us.
If your account connects an outside service — currently QuickBooks Online, Procore, or Autodesk Build, at your own choice and initiation — see §4a.
What we are designed not to hold, and what you must not upload
Jig has no field anywhere for a Social Security number, a government ID number, a financial account number, or health information, and the Acceptable Use Policy prohibits uploading them.
This matters most for certified payroll. Jig holds payroll at the level that goes on the weekly transmittal — name, classification, hours, rates, deductions, and an identifying number such as the last four digits of a Social Security number. Federal rules prohibit full Social Security numbers and home addresses on that transmittal (29 C.F.R. § 5.5(a)(3)(ii)(A)). Your full payroll register — the one that does contain Social Security numbers and addresses — belongs in your payroll system, not in Jig.
Photo location tagging
If an account switches on geotagging, Jig records the location of the person taking each photograph. That is usually a field worker.
- It is off by default.
- It is an account-level setting, controlled by the account holder.
- The browser asks the device holder's permission before any location is read.
- The account holder is responsible for telling their workers. Several states require written notice before electronic monitoring of employees.
- If a user clicks a set of coordinates, Jig opens them in Google Maps, which sends the job's location to Google.
3. How we use it
| Purpose | Examples |
|---|---|
| Run the Service | Accounts, hosting projects, invitations, reports, exports |
| Billing | Subscriptions, invoices, dunning, tax records |
| Support | Answering questions, troubleshooting, restoring data |
| Security | Detecting intrusion, rate limiting, investigating misuse |
| Improving the product | Fixing bugs, deciding what to build |
| Required notices | Service, security and billing notices, and renewal reminders the law requires |
| Marketing, only if you opt in | Product news |
| Legal | Complying with law, responding to lawful requests, defending claims |
We do not sell personal information, share it for cross-context behavioural advertising, use your project data to train machine learning models, or make automated decisions about you with legal or similarly significant effects.
4. Who we share it with
Service providers. Supabase (database and file storage), Cloudflare (hosting, DNS, network), Resend (transactional email — password resets, notifications), and Stripe (once billing is live). Each is under contract to protect the data and use it only to provide services to us. A full, current subprocessor list is available on request at contact@jigitup.com and will be published here as it is finalized.
4a. Integrations you choose to connect
Jig can connect to outside services at your own request — it never connects on its own. Today that means QuickBooks Online (Intuit), Procore, and Autodesk Build. When you connect one:
- You authorize the connection directly with that provider, through their own sign-in screen — Jig never sees or stores your QuickBooks, Procore or Autodesk password.
- We store an encrypted access token for that connection, readable only by our server-side systems, never by your browser or anyone else's.
- What is exchanged depends on the connection. QuickBooks: job costs and vendor bills sync in, invoices sync out, only for the company and cost-code mappings you set up, and only after you review and approve a sync — nothing commits automatically on the first sync. Procore and Autodesk Build: Jig reads project records you've mapped (RFIs, submittals, punch items, change order packages, model/account data) to display them; Jig never writes back to Procore or Autodesk Build.
- You can disconnect at any time, in Jig's own settings. Disconnecting revokes our access token with that provider immediately.
- Each provider has its own privacy policy governing how it handles the data on its side — this policy covers what Jig itself does with the connection.
We will add other integrations only with the same pattern: your explicit connection, a revocable token, and a plain description here of what is exchanged.
Collaborators you invite. When you invite a subcontractor or client into a project, they see what you granted them. That is the product working as intended and it is your decision.
Others in your organisation. Everyone holding a licence in your organisation can see your organisation's projects.
Legal and safety. To comply with law, enforce our terms, or protect rights and safety. Where we are legally permitted, we will tell the affected customer before disclosing their data.
A business transfer. If we are acquired or merge, information may transfer. We will give notice and the acquirer will be bound by commitments no less protective.
Never: we do not sell your information and we do not rent or trade contact lists.
5. Where it lives, and for how long
Location. United States. The database and files are with Supabase, US region. Hosting, DNS and network are Cloudflare, whose global edge may process request metadata outside the US.
Files and photographs are in a private storage bucket. There is no public URL. A download link is minted for a single request when you ask for one, and it expires.
Retention:
| Data | Kept |
|---|---|
| Your data while the subscription is active | For as long as it is active |
| After a subscription ends | Read-only, available to you for at least 12 months from the end of the period you paid for plus 3 days, then eligible for deletion with 30 days' notice |
| Deletion you request | Within 45 days, except records we must keep |
| OSHA 300 Log, 300A, 301 | 5 years after the end of the calendar year covered (29 C.F.R. § 1904.33) |
| Certified payroll, prevailing-wage work | 3 years after all work on the prime contract completes (29 C.F.R. § 5.5(a)(3)) |
| BABA self-certifications | 5 years |
| Billing and tax records | 7 years |
| Encrypted backups | 30 days, then purged on rotation |
| Server and security logs | 90 days |
| Email delivery logs | 30 days (our email provider's retention) |
| Support correspondence | 3 years |
| Auto-renewal consent records | 3 years, or 1 year after the contract ends, whichever is longer |
Where a protected record cannot be separated from the project containing it, we keep the whole project until that record's retention period expires.
6. Cookies and tracking
We use one kind of cookie: the one that keeps you signed in, plus the technical state the browser needs for that session.
Our marketing site uses a cookieless page-view counter (Cloudflare Web Analytics) for aggregate traffic and approximate visitor location; it sets no cookies, runs no cross-site tracking, and identifies no individual visitor. We use no advertising cookies and no tag manager, and the application itself remains cookie-based only for sign-in.
We do not currently respond to Do Not Track. We honour Global Privacy Control signals as opt-out requests where they apply.
7. Your rights
Depending on where you live you may have the right to know what we collect, get a copy, correct it, delete it, take it elsewhere, opt out of sale or targeted advertising (we do neither), limit the use of sensitive information, and not be treated worse for asking.
How to ask. Email contact@jigitup.com from the address on your account, or use the export and delete tools in the product. We verify identity first. We respond within 45 days and may extend once by another 45 with notice.
If we say no, you can appeal by replying. We respond within 60 days and, if we still say no, we tell you how to contact your state attorney general.
Agents. Someone can ask on your behalf with written authorisation.
If your data is in a customer's project, ask that customer — see §1.
8. Security
- Access control is enforced in the database, not the page. Every table has PostgreSQL row-level security. The rule is the same throughout: you reach a project if you belong to the organisation that owns it, or you were invited to that specific project. Table-level privileges that row-level security cannot reach are revoked from application accounts.
- TLS in transit; encryption at rest for the database and file storage.
- Files and photographs in a private bucket, reachable only through a signed link minted per download.
- Passwords hashed by the authentication provider; we never store them.
- Production access limited to the people who need it.
- A separate staging environment with its own database. Schema changes and deploys go to staging first. An unrecognised hostname falls back to staging, never production — a misconfigured deploy cannot reach live customer data.
- Dependency updates and security patching.
We list only controls we actually operate. No system is perfectly secure and we cannot promise absolute security.
If there is a breach. We will notify affected individuals and, where required, the Arkansas Attorney General and other regulators, within the time the law allows. Arkansas requires notice as expediently as possible and no later than 45 days after discovery, with notice to the Attorney General when more than 1,000 Arkansas residents are affected (Ark. Code Ann. § 4-110-105). Where we hold data for a customer, we notify the customer without undue delay so they can meet their own obligations.
9. Children
Jig is business software, is not directed to anyone under 18, and we do not knowingly collect information from children. Tell us at contact@jigitup.com if you think we have.
10. Jig is for United States customers only
Jig is offered only to customers in the United States. It is operated from the United States, your data is stored in the United States, and we do not market to, or knowingly accept subscriptions from, customers established outside it.
We have not designed Jig to meet the requirements of the EU or UK General Data Protection Regulation, and we make no claim to comply with them. We have not appointed a representative under Article 27 and we do not rely on Standard Contractual Clauses.
If you are outside the United States, please do not create an account. If you do and we notice, we will tell you, give you the chance to export your data, and close the account.
11. Changes
We will post updates with a new date. For material changes we will email account owners at least 30 days beforehand.
12. Contact
contact@jigitup.com · Jig by SideKick, LLC · 30 N Gould St Ste N, Sheridan, WY 82801 · 1-327-324-3111
Appendix — disclosures for California residents
Categories collected in the last 12 months, per Cal. Civ. Code § 1798.100 et seq.
| CCPA category | Collected | Source | Purpose | Sold or shared |
|---|---|---|---|---|
| Identifiers — name, email, IP, account ID | Yes | You, your device | Run the Service, security, billing | No |
| Customer records — name, phone, billing address | Yes | You | Billing, support | No |
| Commercial information — subscription, transactions | Yes | You, Stripe | Billing | No |
| Internet activity — pages, actions, timestamps | Yes | Your device | Security, product improvement | No |
| Professional / employment information — role, company, and on prevailing-wage jobs, classification, hours, wage rates and deductions for named workers | Yes | Your employer, as our customer | Run the Service for that customer | No |
| Geolocation — coarse, from IP; and precise, from photo geotagging where an account enables it | Yes | Your device | Security; and, for geotags, recording where a photo was taken | No |
| Sensitive personal information | Not by design — no field accepts a Social Security or government ID number, and uploading one is prohibited | — | — | No |
| Biometric, genetic, health, education records | No | — | — | No |
We have not sold or shared personal information for cross-context behavioural advertising in the preceding 12 months.
By invitation
Tell us what you build, and we'll show you the job.
Access is by invitation while the pilot runs. It takes a minute, and a person reads every one.
Sign-in opens with your account. Request access and we will send you the link.