Trust & Security
This page is maintained by Job On The Block LLC to answer common questions about how jobontheblock.com handles access, data, and privacy.
It is app-owned editable content — not an independent certification or third-party audit.
Access & authentication
Sign-in uses Google, Apple, or an emailed magic link. We do not accept passwords and we do not use SMS. Account deletion is self-serve with a 30-day grace window before data is purged.
Platform & hosting
The app is built on Lovable and served from edge infrastructure. Application data is stored in our managed cloud database. We describe enabled platform capabilities here; we do not claim any independent certification on behalf of the platform.
Data collection & use
We collect the data needed to run the marketplace: account profile, approximate location for matching, in-app messages, ratings, and payment metadata (we never see full card numbers — Stripe handles those directly). We do not run ads and we do not sell personal information.
Subprocessors & integrations
We use a small set of service providers to operate the product: a managed cloud database for storage and auth, Stripe for payments, Google Maps for places autocomplete and geocoding, an AI gateway plus OpenAI Whisper for voice transcription and matching, and web push for notifications. Each is used only to run the features you see in the app.
Cookies & analytics
We use essential browser storage to keep you signed in and to remember language and dismissed banners. We do not load third-party advertising or cross-site tracking cookies.
Retention & deletion
Account data is retained while your account is active. When you request deletion, your account is immediately deactivated and permanently purged after a 30-day grace period by a daily background job. Some records (such as payment receipts) may be retained longer where required by law.
Privacy requests & Do Not Sell or Share
California residents can submit Do Not Sell or Share requests and exercise other CCPA/CPRA rights. Email help@jobontheblock.com from the address on your account.
Security & vulnerability contact
To report a security issue or suspected vulnerability, email help@jobontheblock.com with the subject line "Security". Please include reproduction steps and avoid testing against other users' accounts.
help@jobontheblock.comAccessibility
We target WCAG 2.1 Level AA across the mobile-first web app and PWA.
Compliance
We do not currently hold SOC 2, ISO 27001, HIPAA, or PCI-DSS certifications, and we do not claim any. Card data is handled by Stripe under its own PCI scope; we never receive full card numbers.
Last reviewed alongside the latest Terms and Privacy Policy update. For anything not covered here, email us — we'd rather answer the question than leave you guessing.