Jefe Privacy

Privacy Policy

Effective date: May 28, 2026

Last updated: August 23, 2026

Current launch coverage

  • Supabase-authenticated owner, manager, and crew account data
  • Customer, job, contact, quote, invoice, photo, and work-request data
  • Voice-command transcript text and user-recorded voice-note audio or transcripts where voice features are used
  • Stripe-powered invoice, Checkout, Terminal, and Tap to Pay payment flows
  • Push notification tokens and delivery events
  • Product analytics, diagnostics, crash reporting, and operational logs
  • Support, feedback, import, reporting, and account-lifecycle workflows
  • Google Calendar read-only connection, import, synchronization, and deletion workflows

Overview

Jefe helps small field-service businesses manage work, customers, crews, quotes, invoices, payments, and customer communication. This Privacy Policy explains what information Jefe collects, how we use it, and the choices available to account owners, team members, and customers who use Jefe links.

This policy is published at https://getjefe.app/privacy. Store privacy disclosures must be reviewed again whenever shipped SDKs, vendors, permissions, or data flows change.

Information we collect

  • Account and authentication information, such as names, phone numbers, email addresses where used, role, company membership, language, and security metadata.
  • Business profile information, such as company name, address, service area, logo, trades, availability, payment settings, and owner-configured templates.
  • Customer and job information, such as customer names, contact details, addresses, work requests, visits, notes, photos, quotes, invoices, receipts, ratings, referrals, and service history.
  • Voice information when users choose voice features, such as tap-to-talk command transcript text generated by device or platform speech recognition, and user-recorded job or lead voice-note audio, transcripts, translations, and playback artifacts where those features are used. For tap-to-talk voice commands, Jefe does not retain raw command audio by default, but transcript text may be sent to Jefe backend parsers and enabled AI providers.
  • Payment information needed to operate Stripe-powered service-payment flows, including payment status, provider references, connected-account readiness, receipts, and saved-card or autopay authorization metadata if those features are enabled. Jefe does not collect raw card numbers or CVC values.
  • Device, usage, diagnostics, and notification information, such as device identifiers used for push notifications, app interactions, crash data, performance data, request identifiers, and operational logs.
  • Support and feedback information that users choose to send to Jefe, including messages, screenshots or files when provided, and related account context needed to investigate the request.

How we use information

  • Provide the app, authenticate users, route owners, managers, and crew to the right workspace, and keep each company account scoped to its own data.
  • Create and manage jobs, visits, customers, quotes, invoices, payments, reminders, request forms, reports, imports, and related customer-facing links.
  • Transcribe, parse, classify, or translate voice input when users choose voice features, including sending voice-command transcript text to backend parsers and enabled AI providers for field-service command parsing.
  • Operate Stripe Connect, Checkout, Terminal, Tap to Pay, and any separately enabled saved-card or autopay workflows for a company's own service payments.
  • Send or help users send operational communications, including push notifications, owner-approved communication handoffs, payment follow-up drafts where configured, and support responses.
  • Monitor reliability, debug issues, prevent abuse, protect accounts, measure product usage, and improve the app.
  • Comply with legal, tax, accounting, security, platform, and payment-network obligations.

Google Calendar data

When an eligible company owner chooses to connect Google Calendar, Jefe requests read-only access to the owner's calendar list and events. Jefe uses calendar-list metadata to show the calendars available to that owner, then processes event data only from the one calendar the owner selects. The data can include calendar metadata and future-event titles, descriptions, times, recurrence, locations, and creator, organizer, and attendee identity fields such as names, email addresses, Google self markers, and attendee response status. Jefe also securely stores the OAuth credentials needed to keep the selected connection working.

Jefe uses this Google Calendar data only to show the owner a preview, determine whether an event is eligible for import, import selected future work as ordinary Jefe jobs, match an exact and unique active Jefe crew member, and keep untouched future copies synchronized. Jefe never adds, changes, or deletes anything in Google Calendar. An event location may be sent to Google Maps Platform Address Validation or Places only to resolve a service address, subject to Jefe's paid-provider budgets; if enrichment is unavailable, the owner can complete the address manually.

Imported job information is visible to authorized members of the owner's Jefe company. Jefe does not sell Google user data, use it for advertising, or use it to create contacts or users. Jefe's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

An owner can disconnect Google Calendar or request deletion of Calendar import data inside Jefe. Disconnecting removes Jefe's Google credentials and Google-link metadata while preserving ordinary Jefe job copies. The deletion control removes eligible untouched imported copies and unlinks records that Jefe must preserve because they were edited, used for business work, or retained for legal, security, or audit obligations. Temporary setup records and operational evidence expire on bounded schedules described in the product disclosure shown before connection.

Service providers

Jefe uses service providers to host and operate the product. These include infrastructure, database, authentication, storage, payment, notification, analytics, diagnostics, email, app-store, speech-recognition, AI, and support providers. Current core providers include Supabase, Stripe, Expo, Apple, Google, OpenAI, Groq, Resend, Sentry, and PostHog.

We do not sell personal information or use Jefe account data for third-party advertising. Providers process information to help us operate Jefe, protect the service, deliver payments and notifications, and support users.

Payments

Jefe Payments is built on Stripe. Card entry and payment-method setup happen through Stripe-hosted or Stripe-owned components. Jefe stores payment status, provider references, receipts, and authorization records needed to show payment state, support service-payment collection, and recover failed payments.

Jefe does not store raw payment card numbers or CVC values. Account owners should not enter card data into notes, support messages, SMS, email, or other free-form fields.

Notifications and communications

Jefe may use push notifications and in-app surfaces to alert owners, managers, or crew about operational work. Lock-screen notifications are designed to avoid unnecessary customer names, addresses, amounts, or other sensitive detail unless Jefe later updates its privacy review and product rules.

Many SMS flows use owner device handoff, where the owner chooses whether to send the message from their own device. Jefe also sends configured transactional customer emails, such as payment verification and payment recovery or autopay messages, through email providers. If Jefe later sends SMS from Jefe-operated providers, the related compliance and privacy disclosures must be reviewed before launch.

Retention and security

We keep information for as long as needed to provide Jefe, support users, meet legal or accounting obligations, maintain audit history, prevent abuse, and resolve disputes. Some operational logs and temporary records are deleted or archived on shorter schedules.

We use technical and organizational safeguards intended to protect account data, including authentication, role-based access, row-level database controls, encrypted transport, provider security controls, and operational monitoring.

Your choices

  • Account owners can update business profile, customer, job, payment-setting, notification, and team information inside Jefe where the current product provides controls.
  • Some data may need to be retained for legal, security, payment, tax, accounting, or dispute reasons after an account-deletion request.
  • Customers who receive Jefe public links can contact the service business that sent the link, or contact Jefe support if they need help with a Jefe-hosted page.

Contact

For privacy or support questions, contact support@getjefe.app.