Skip to main content

Privacy Policy

Last updated: 21 August 2026

Privacy Policy

Last updated: 21 August 2026 Effective from: 6 August 2026


1. Who we are

This Privacy Policy explains how BOB O JOB LTD ("bob-o-job", "we", "us", "our") collects, uses, stores, and shares personal data when you use the bob-o-job platform — our website at www.bob-o-job.com, our customer and jobber mobile apps, and related services (the "Service").

Data controller: BOB O JOB LTD 5th Floor, 167-169 Great Portland Street, London, W1W 5PF Company number: 17231669 — registered in England and Wales.

Privacy contact: privacy@bob-o-job.com

We are registered with the UK Information Commissioner's Office (ICO) under registration number ZC167574.

2. Scope of this policy

This policy applies to:

  • Customers — people who post jobs and hire service providers through the Service.
  • Jobbers — service providers offering cleaning, gardening, handyman, dog-walking, general tasks, and events/hospitality services through the Service.
  • Visitors — anyone browsing our website or apps without an account.

Where processing differs between customers and jobbers, we say so. It covers our website and both mobile apps (customer and jobber).

3. What personal data we collect

3.1 Information you give us

When you create an account (customers and jobbers):

  • Name
  • Email address
  • Phone number
  • Password (stored only as a securely hashed value — we never see or store your actual password)
  • Profile photo (optional)
  • Postcode and/or address; saved addresses ("home", "work", etc.) including their map coordinates

When you become a jobber, additionally:

  • Identity verification data — a government-issued photo ID (passport or driving licence), photographed live and checked by Stripe Identity on our behalf (see Sections 5 and 8). There is no selfie and no face matching. We receive the verification result; Stripe holds the document image under its own policy.
  • Qualifications, certifications, and supporting documents you upload
  • Vetting and compliance records — your interview record, references, your declared right-to-work route (and, for share-code checks, your Home Office share code, stored encrypted), and the outcome of any compliance checks we carry out or record (with an expiry date where the check has one) — including a basic DBS check (criminal record) (see Section 5)
  • Equipment you can provide, skills, service categories, service area, and availability windows
  • A short bio (free text)
  • Bank/payout details — collected and held by Stripe Connect; we do not see or store them
  • Tax-reporting data required by the UK Reporting Rules for Digital Platforms: your date of birth, your primary address, your taxpayer type, and a tax identifier — your National Insurance number or Unique Taxpayer Reference (UTR), or your company registration number and VAT number if you operate through a business. Your National Insurance number and UTR are stored encrypted and are disclosed to HMRC as described in Sections 4, 7.3 and 10.

When you post a job (customers):

  • Job description, category, and any free-text details (which may contain personal information you choose to include)
  • The job location — address, postcode, and precise latitude/longitude
  • Scheduling preferences
  • Photos relevant to the job (e.g. "before" photos)
  • Optionally, one short video of the job (up to 15 seconds), recorded in the app or chosen from your photo library. It records sound as well as picture, so it may capture your voice, and the voices of anyone nearby. It is optional — you never have to add one — and you can remove it. Who can see it is set out in Section 7.1
  • Budget/price preferences
  • Payment card details — entered directly into Stripe; we never see or store your full card number or CVV (see Section 8)

When you communicate or transact through the Service:

  • Messages exchanged between customers and jobbers (in-app chat, dispute chat)
  • Reviews, ratings, and endorsement tags you leave or receive
  • Support enquiries, and the content of conversations with our in-app help assistant (which uses OpenAI — see Section 7; please don't include sensitive personal details you don't need to)
  • Dispute correspondence and any evidence photos you upload
  • During a job: check-in codes and "after" photos used as proof of completion

3.2 Information we collect automatically

Device, technical, and security data (all users):

  • IP address, browser type/version, operating system, device type, language, and time zone
  • A device "fingerprint" (a one-way hashed signature) and a device-session record each time you sign in
  • Activity logs of key actions, and (for jobbers) a record of job acceptances including time and a coarse area — used for security, fraud prevention, and platform integrity
  • Pages/screens visited and features used

Location data:

  • Jobbers: when you go "online", the jobber app sends a single precise GPS snapshot of your location so we can match you to nearby jobs. While you are en route to a job, the app streams your precise GPS location continuously so the customer can track your arrival and ETA. Because we offer background location, this streaming can continue when the app is in the background or your screen is locked while you are travelling to or carrying out a job — your device shows the system background-location indicator while this is happening. On a dog walk, and on a general task where the customer has asked to follow it and you have agreed, this streaming continues for the duration of the task itself and not only while you travel to it — and you can stop that sharing at any time from the job screen. Background location is off until you turn it on: you affirmatively consent to it through a separate in-app prompt, and you can revoke that consent at any time in your device settings. We do not collect your location when you are offline. If you turn location off you won't be able to receive proximity-based jobs.
  • Customers: the job location you enter (address + coordinates), and the live location shown to you during a booking is the jobber's, not yours.
  • Sharing a job with someone else: both customers and jobbers can create a tracking link and send it to someone outside bob-o-job — a family member, a housemate, a friend. Anyone with that link can see the job's progress without logging in. What the link shows, and how to switch it off, is set out in Section 7.4.

On your mobile device: we store your login token in the device's secure keystore, your push-notification token, and small preference flags. We register a push-notification token so we can send you job and account notifications.

Cookies and similar technologies (website): strictly-necessary cookies (sign-in/session, security) are always on; analytics cookies (PostHog) are set only if you accept them in our cookie banner. See Section 14 and our separate Cookie Policy.

3.3 Information from third parties

  • Identity verification result from Stripe Identity (pass/fail and related metadata)
  • Payment and payout status from Stripe
  • Fraud/risk signals from Stripe where applicable
  • Basic profile information (name, email, profile photo) from Google if you choose to sign in with Google
  • Basic profile information (name, and either your email address or Apple's private relay address) from Apple if you choose to Sign in with Apple

3.4 Automated illegal-content (CSAM) scanning of uploaded images

To keep the platform safe and to meet our duties under the Online Safety Act 2023, images you upload (such as job photos) are automatically checked for known child sexual abuse material (CSAM) before they are stored. We do this in a privacy-preserving way: a non-reversible "perceptual hash" of the image is generated on our own servers, and only that small irreversible hash — not the image itself — is checked against the industry hash list operated by Microsoft (PhotoDNA Cloud). This is a hash match against known illegal images; it does not "look at", classify, or describe your photo. If an image matches, the upload is refused, the file is securely quarantined, and we report it to the appropriate authorities (see Section 7.3). See Sections 7.2 and 9 for the processor and transfer details.

This check applies to images only — not to job videos. The technology we use works on still pictures and cannot examine a video, and a job video is uploaded from your device straight to our file storage without passing through our servers, so we never hold it in a form we could check. Two consequences, and we would rather state both than leave either to be assumed:

  • Nothing about your video is analysed, and none of it is sent to any outside company. No hash is generated from it and nothing about it leaves our storage. Where a video is concerned, this section simply does not apply to you.
  • Illegal material in a video is not detected automatically. We rely on the people who can see it telling us: every Jobber who can view a job video has a clearly visible "Report this video" control, and a reported video goes to our safety team, who can remove it permanently and report it onward. Please use it.

We also cannot remove location information from a video the way we do from a photo. When you upload a photo we strip the hidden location data your phone records into it. We cannot do that for a video, for the same reason as above — it does not pass through our servers. Your phone re-encodes the clip when you attach it, which we expect removes that data, but we have not yet confirmed it, and we will not tell you it is removed until we have. If this matters to you, turn off location for the camera in your phone's settings before filming.

4. How we use your personal data, and our lawful basis

Under UK GDPR we must have a lawful basis for each use of your data:

PurposeData usedLawful basis
Create and run your accountName, email, phone, password hash, profileContract (Art. 6(1)(b))
Verify jobber identityA photograph of your passport or driving licence, taken at the time, and the verification resultLegitimate interests (Art. 6(1)(f)) in marketplace trust and fraud prevention. We do not scan or match your face. If the online check will not work for you — a worn document, an ID it does not accept — contact us and a member of our team will check it with you in person instead
Prescribed right-to-work checks on jobbersRight-to-work route, Home Office share code (encrypted, and deleted as soon as the check is done), the evidence of the check, its outcome and any follow-up dateLegal obligation (Art. 6(1)(c)) from 1 October 2026 — the Right to Work Scheme was extended to online matching services by s.48 of the Border Security, Asylum and Immigration Act 2025, so we are required to check and to keep the evidence. See Section 5
Other jobber vetting (DBS, interviews, references)Check outcomes and review dates, interview and reference recordsLegitimate interests (Art. 6(1)(f)) in a safe marketplace — assessed in writing before we rely on it; for criminal-offence (DBS) data, additionally a condition in Schedule 1 of the Data Protection Act 2018 (Part 2, paragraph 10 — preventing or detecting unlawful acts)
Match customers with jobbers; run the marketplaceJob details, location, category, availability, tier, ratingsContract
Process payments and payoutsTransaction details; card data and bank details (held by Stripe); tax infoContract; Legal obligation (tax/AML)
Report jobber (seller) data to HMRC under the digital-platform reporting rulesName, date of birth, address, tax identifier (NI number / UTR / company / VAT), consideration paid and fees withheldLegal obligation (Art. 6(1)(c)) — Finance Act 2023 / SI 2023/817, the UK Reporting Rules for Digital Platforms
Live location tracking and ETA during a jobPrecise GPS (jobber)Contract; Legitimate interest in safety and ETA accuracy
Show job progress on a tracking link the customer or jobber has sharedJob status and timings, jobber first name and photo, borough, and (on a customer's link only) an approximate destinationContract — providing the sharing feature the user asked for; Legitimate interest in the safety of the person being followed
Send service emails/notifications (confirmations, receipts, password resets, dispute/job updates)Email, push token, transaction detailsContract
Email someone who is following a tracking link if the job runs well over its booked timeThe email address they enter on the tracking pageConsent (Art. 6(1)(a)) — they enter their own address and must click a confirmation link before we send anything else; unsubscribe in every email
Send marketing and timing/seasonal emailsEmail, preferences, categories used, general areaConsent — opt-in, with one-click unsubscribe in every email
Website analytics set from your browser or appPseudonymised usage events and a device identifier (PostHog)Consent (cookie banner)
Product analytics. We collect information about how you use BOB O JOB, such as when a job is posted, payment is made or a job is completed. We use this to understand how our service is used, monitor performance, identify problems and improve the product.Product events sent from our own servers, linked to your account ID. No name, email address, phone number, postcode or message content, and IP addresses are not recorded. Not used for advertising.Legitimate interest (Art. 6(1)(f)) in understanding and improving the service
Operate the platform reliably; error monitoring, rate-limiting, fraud and abuse prevention, trust-and-safetyAccount, device, IP, location/behaviour logsLegitimate interest in platform integrity, security, and safety
Remember which advert or link brought you to us, if you accept optional cookiesCampaign tags in the web address, the site you arrived from, and the page you landed onConsent (cookie banner)
Automated jobber reliability scoring and suspensionCancellation/behaviour historyLegitimate interest / Contract — see Section 6
Resolve disputesMessages, transaction history, photos, location/timingContract; Legitimate interest in fair resolution
Customer support and the in-app help assistantContact details, messages, recent-job context (sent to OpenAI)Contract; Legitimate interest
Answer your call to our support lineThe number you are calling from and the number you dialled, the time and length of the call, and whether we answered it. We do not record calls and we do not transcribe themContract (Art. 6(1)(b)) where you are calling about your own account, booking or payout; Legitimate interests (Art. 6(1)(f)) in operating a support line people can actually reach, including for callers who are not users
Scan uploaded images for known illegal content (CSAM) and report matchesUploaded image → irreversible perceptual hash; match metadataLegal obligation (Online Safety Act 2023) and substantial public interest in safeguarding children (Art. 9(2)(g); DPA 2018 Sch. 1)
Comply with legal obligationsAs requiredLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have weighed the impact on your rights and consider the processing necessary and proportionate; you can object (Section 11). Where we rely on consent, you can withdraw it at any time without affecting prior processing.

5. Special category and criminal-offence data

Identity documents (jobbers) — and what we do not do. Verifying a jobber's identity means photographing a passport or driving licence, which our provider Stripe Identity checks for authenticity. The document is photographed at the time rather than uploaded from your camera roll, which is what stops someone using a picture of somebody else's ID.

We do not run a face scan. There is no selfie step and no comparison of your face against the photo on your document, so this processing does not involve biometric data and no special-category condition applies to it. (Until 17 August 2026 this section said we did — that was wrong, and it described a check the product has never performed. If we ever do enable a face match we will ask for your explicit consent first, in terms that name it, and you will be able to refuse and use the manual route with no disadvantage.)

If the online check will not work for you, we will do it in person. Some documents are refused by automated checks for reasons that have nothing to do with the person holding them — wear, an unusual format, a camera that will not focus. Tell us and an administrator will check your document with you at your interview. It costs nothing and makes approval no less likely.

Stripe holds the document image and the verification result; we receive the outcome, the date and a session reference, and we do not download the image. Stripe acts partly as our processor and partly as an independent controller for some of its own fraud-prevention purposes, which means some requests about that data have to go to Stripe — tell us and we will point you the right way. We set our own deletion timetable with Stripe rather than leaving it to their default.

An automated result never decides anything on its own. If the check fails, a person reviews it. You will not be refused access to the platform by software alone.

Criminal-offence data (jobbers). Jobbers apply for their own Basic DBS (criminal record) check at GOV.UK and show us the original certificate at their vetting interview. We record the certificate number, its issue date, the outcome, and our decision — never the content of any disclosure. Where a copy of the certificate is taken so that an administrator can check the date against the document, that copy is automatically destroyed within six months; the record of the check remains. A Basic certificate does not expire; we ask jobbers to obtain a fresh one every 24 months. This is criminal-offence data under Article 10 UK GDPR, processed under Schedule 1, Part 2, paragraph 10 of the Data Protection Act 2018 (preventing or detecting unlawful acts) — keeping people safe when a jobber works in their home. Check outcomes are visible only to our vetting team, are recorded against access-controlled accounts, and are never shown to other users. A criminal record is not an automatic bar; where something is disclosed we carry out an individual assessment.

Right-to-work information (jobbers). From 1 October 2026 we are required by law to carry out a prescribed right-to-work check before a jobber can accept work, and to keep the evidence — the Right to Work Scheme was extended to online matching services like this platform by section 48 of the Border Security, Asylum and Immigration Act 2025. What that means for you:

  • We use the Home Office online right to work checking service with a share code you give us, or check your documents directly. We delete the share code as soon as the check is complete — it is a temporary credential, not the evidence.
  • We keep the evidence of the check for as long as you provide services through the platform and for two years afterwards. That period is set by the Home Office, not chosen by us.
  • If your permission to work is time-limited we record a follow-up date and re-check before it passes. We will warn you well ahead of it, and you will be unable to accept jobs if a required re-check is missed.
  • Because this is required by law, the Article 21 right to object does not apply to it (see Section 11). Your other rights are unaffected, and you can tell us at any time if you think information used in the check is wrong.

We check everyone, not a selected few — selective checking in practice tracks nationality, and it is both unlawful and something we have no wish to do.

6. Automated decision-making and profiling

We want to be transparent that the platform uses some automated processing:

  • Jobber reliability score (human decision on suspension). We calculate a "reliability score" for jobbers, reduced only when a jobber cancels a job they had already committed to. If the score falls below a set threshold, the account is flagged for review by a member of our team — it is not suspended automatically. A person looks at the recent cancellations and decides whether to pause the account. If we do suspend: (a) we notify you with the reason, your score, and the threshold; (b) you can appeal in the app (the "Appeal a suspension" page) or by email, and the appeal is reviewed by a different person, who can reinstate you; and (c) you always have the data-protection right to contest the outcome and obtain human intervention.
  • In-chat contact-detail filter (human decision on suspension). To prevent off-platform circumvention and protect personal data, messages sent through in-app chat are automatically scanned for contact details (phone numbers, email addresses, addresses, links, social handles). A message containing a phone number or an email address is not delivered, and we tell you why so you can rephrase and send it again. The other kinds we look for are not blocked. If the same thing happens repeatedly the pattern is flagged for review by a member of our team — the account is not suspended automatically, and a person decides whether any action is warranted. If we do suspend: (a) we notify you with the reason; (b) you can appeal in the app or by email, and the appeal is reviewed by a different person, who can reinstate you; and (c) you always have the data-protection right to contest the outcome and obtain human intervention. You can ask for human review at any time at support@bob-o-job.com or privacy@bob-o-job.com.
  • Profiling for safety and fraud prevention. We analyse device, IP, location, and behavioural signals to detect fraud and abuse and to keep users safe. This profiling supports human decisions and does not, on its own, produce legal or similarly significant effects on you.
  • Matching. Our engine recommends jobbers to customers, but a human (the customer, or the jobber accepting) makes the final booking decision.

7. Who we share your personal data with

We share personal data only where necessary, and never sell it or share it for third-party marketing.

7.1 Between users

  • Customers see a matched jobber's name, photo, ratings/reviews, tier, approximate location, and live location/ETA during the job.
  • Jobbers see the customer's first name, the job details (description, address at booking, photos, and the job video if you added one), and the customer's rating of them.
  • A job video is seen more widely than by your matched jobber alone. It is shown to the Jobbers eligible to take your job so they can decide whether to accept it — which means Jobbers who have not yet accepted, and may never accept, can watch it. Every one of them is an identity-verified, right-to-work-checked and DBS-checked Jobber whose account is attributable to them. It is never public, never on a feed, cannot be searched for, and cannot be shared onward through the platform. Our staff can view it if it is reported.
  • Reviews and ratings are public to other users.
  • People outside bob-o-job can be sent a tracking link by either party — they are not users, and what they see is covered separately in Section 7.4.

7.2 Service providers (sub-processors)

We use the processors below, each under (or to be under) a written data-processing agreement. International transfers are covered by the UK IDTA / EU SCCs and supplementary safeguards (Section 9).

ProcessorPurposeLocation
Vercel Inc. — incl. Vercel BlobWebsite hosting; storage of uploaded files (avatars, documents, job photos)US (EU edge) — SCCs
Railway CorpBackend/realtime server hostingUS — SCCs
Neon Inc.Primary database (Postgres)EU (London, eu-west-2)
Amazon Web ServicesOff-site backup storage — nightly copies of the database and uploaded files, so that we can recover your data after a failure, mistake or attack. Backups are encrypted before they are sent, with a key held offline that AWS does not have, so AWS cannot read their contentsUK (London, eu-west-2)
UpstashRedis — rate-limiting (keyed on IP) and geo-matchingUS/EU — SCCs
Stripe Payments Europe LtdPayments, Stripe Identity (ID verification), Stripe Connect (jobber payouts), fraud preventionIreland (EU); some processing in US — SCCs
Resend Inc.Transactional and marketing email deliveryUS — SCCs
TwilioSMS verification of your phone number; our support telephone line — connecting your call and handling the number you call from; masked phone calls between customers and jobbers where enabledUS — SCCs
Mapbox Inc.Maps, geocoding, routing/ETAUS — SCCs
OpenAIAI help assistant and job-description assistance (text you submit + recent-job context; and, for some features, photos you submit for analysis). Submitted via the API, which OpenAI does not use to train its models.US/EU — SCCs
AnthropicDrafting suggested replies to support tickets, for our support team only — the content of your support ticket and relevant account context is submitted via the API (which Anthropic does not use to train its models); a person reviews every draft before anything is sent to youUS — SCCs
Postcodes.ioUK postcode lookup — converts a postcode you enter to map coordinates; no account details are sentUK
Ideal PostcodesUK address lookup — converts a postcode you enter into the list of addresses at it (Royal Mail PAF); no account details are sentUK
CalendlyBooking and managing jobber interview appointments — name, email and appointment timeUS — SCCs
Open-MeteoWeather forecast for a job's location and time — coordinates only, no account detailsEU
Transport for LondonPublic-transport travel times for jobber ETAs — coordinates onlyUK
Microsoft (PhotoDNA Cloud)Known-illegal-content (CSAM) detection — we send only an irreversible hash; the image itself is never transferred (see Section 3.4)US — SCCs
PostHog Inc.Product analytics (website, with consent; and server-side, for platform operation)EU region (eu.posthog.com)
Sentry (Functional Software Inc.)Error and performance monitoring (we minimise personal data sent)EU ingest
Google LLCSign in with Google (only if you choose it)EU/US — SCCs
Apple Inc.Sign in with Apple (only if you choose it)EU/US — SCCs
Expo / Apple Push Notification service / Google Firebase Cloud MessagingMobile push-notification deliveryUS — provider terms

Webhook signatures are verified via Svix. (Where our codebase references other vendors, e.g. legacy Google Maps keys, those services are not in active use.)

7.3 Legal and safety disclosures

We may disclose personal data to comply with a court order or lawful request; to enforce our Terms or protect our rights; to prevent or investigate fraud, illegal activity, or threats to safety; or in connection with a corporate transaction, under confidentiality and with appropriate notice.

HMRC (digital-platform reporting). Where you earn through the platform as a jobber, we are legally required to report your details to HM Revenue & Customs under the UK Reporting Rules for Digital Platforms (see Section 4): your name, date of birth, address, tax identifier (National Insurance number / UTR, or company / VAT number), and the consideration paid to you and fees we withheld in each reporting period (a calendar year). Reports are made annually. This reporting is a legal obligation and cannot be opted out of; your National Insurance number / UTR are held encrypted and are included only in the report to HMRC.

Illegal-content reporting. Where our scanning (Section 3.4) detects, or our team confirms, child sexual abuse material or other illegal content, we report it and preserve the necessary evidence for the appropriate bodies — in the UK the Internet Watch Foundation (IWF) and the National Crime Agency (NCA/CEOP), and where applicable the National Center for Missing & Exploited Children (NCMEC). We do not notify the person who uploaded the content where doing so could prejudice an investigation.

7.4 People you share a tracking link with

Customers and jobbers can create a tracking link for a job and send it to someone who does not have a bob-o-job account. That person is not a user of the Service and we have no relationship with them, so this section sets out exactly what they can see and what we do with anything they give us.

What the link shows. The page is deliberately restricted, and the restriction is applied by our servers on every load — not just hidden in the page:

ShownNever shown
The jobber's first name and profile photoAnyone's surname
How the job is progressing, and how long the jobber has been on site, as elapsed times ("arrived 2 hours ago") rather than clock timesThe address, or the postcode
The borough the job is inThe phone number of either party, the price, or the check-in code
An approximate destination, accurate to about a kilometre — on a customer's link onlyAny destination at all on a jobber's link — a jobber sharing their whereabouts does not reveal where the customer lives
The jobber's live position while they are travelling, and only while it is recentThe jobber's position once they have arrived, or a stale position from a stalled job

A link is a key. Anyone who has the link can open it, including someone it was forwarded to. Only share it with people you trust. Timings are shown as elapsed durations precisely so that a screenshot passed on later does not record when a particular home was occupied.

Switching it off. Whoever created a link can stop sharing it at any time from the app, which makes that link stop working immediately for everyone holding it. Sharing again creates a new link — the old one stays dead. A link also stops showing live location as soon as the job ends; for a week afterwards it shows only how long the visit took, and after that nothing.

Customers and jobbers share separately. A customer's link and a jobber's link are different links showing different things. Neither party can see, or switch off, the other's.

If someone gives us their email address on that page. They can ask to be emailed if the job runs well over its booked time. We rely on consent: we send one confirmation email and do nothing further unless they click the link in it, so an address entered by somebody else never receives anything but that single message, and ignoring it is a complete opt-out. If they do confirm, they get one alert about that job and nothing else — no marketing, and the address is not added to any list, not used to build a profile, and not shared with the customer or the jobber. Every message carries a one-click unsubscribe, and the address is deleted with the job's other personal data (Section 10). If you believe someone entered your address without your agreement, email privacy@bob-o-job.com and we will delete it.

8. Payment data

Card details are entered directly into Stripe on our website and apps and sent straight to Stripe. We never see or store your full card number, CVV, or bank/payout details. Stripe is an independent controller for the payment data it processes — see https://stripe.com/privacy.

9. International data transfers

Some processors are outside the UK/EEA (mainly the US). Where personal data is transferred internationally we rely on the UK International Data Transfer Agreement (IDTA) / EU Standard Contractual Clauses, adequacy where it applies, and supplementary measures (encryption in transit and at rest). Your core data store (Neon) is in the EU (London); analytics (PostHog) and error monitoring (Sentry) use EU regions. For illegal-content scanning (Section 3.4) the only thing transferred to the US is an irreversible hash, never the image. We carry out data protection impact assessments for higher-risk processing (identity verification, live location tracking, and illegal-content scanning).

10. How long we keep your personal data

Data categoryRetention
Active account dataWhile your account is open, then deleted/anonymised (we retain only what law requires — below)
Transaction/financial records6 years (HMRC)
Jobber tax-reporting data (NI number / UTR / company / VAT, date of birth, address)encrypted at rest; retained ~6 years (tax-record retention), then scrubbed; National Insurance number and UTR held encrypted
Identity verification recordsheld by Stripe under its policy; our verification result up to 5 years (AML good practice)
Right-to-work check — the evidence of the check, its outcome and any follow-up datewhile you provide services through the platform and two years afterwards. That period is required by the Home Office, not chosen by us. Your share code is deleted as soon as the check is complete
DBS records (certificate number / issue date / outcome / our decision) and other vetting records (interview, references)while you provide services through the platform, and afterwards only for a limited period: 6 months after your engagement ends. If we turn down your application, we keep the DBS record for 6 months from that decision and no longer. Any copy of a DBS certificate, and the form you signed, are destroyed once we have finished checking the details against them and in any event within 6 months; the record of the check remains for the periods above. If you delete your account, the certificate copy and number are deleted straight away and only a minimal record of the check survives to the deadline above
Job photos and any job video you attacheddeleted when the job is anonymised after 90 days, and immediately if we remove one following a report
Messages and supportretained while relevant to your account or an open dispute
Records of calls to our support line (the number you called from, the number you dialled, the time and how long the call lasted)held by our telephony provider, Twilio, under its own retention policy. We do not record or transcribe calls, and we keep no separate copy of them in our own systems
Records of masked calls between you and your jobber (which job the call related to, which of you started it, whether it connected, and when)kept with the job and deleted when the job is deleted. We do not record or transcribe these calls either, and the record does not contain either phone number
Disputes and safety incidentsup to 6 years after resolution
Device, IP, location, and behavioural logs (device sessions, activity logs, job-acceptance logs)deleted after 12 months (365 days)
Email-delivery logs365 days
Webhook/payment event records90 days
Push-notification delivery logs365 days
In-app notificationsread notifications deleted after 90 days; unread kept until read or until you delete your account
Illegal-content (CSAM) reports and quarantined materialretained as a legal/safeguarding record; quarantined material is deleted only when law enforcement confirms it is no longer needed
Tracking links you have sharedstop working when you switch sharing off, and stop showing live location as soon as the job ends; the link itself is deleted when the job is anonymised after 90 days
Email address of someone following a tracking linkuntil they unsubscribe, or the job is anonymised after 90 days — whichever is first
Marketing subscriptionuntil you unsubscribe
Completed-job recordsanonymised after 90 days; deleted after 6 years
Product and website analytics (PostHog)set by PostHog, not by us — retention of these events is not configurable on our current plan. The events themselves contain no name, email address, phone number, postcode or message content, and IP addresses are not recorded.
Backupsencrypted copies are taken nightly and kept off-site. A backup can be restored from for 35 days, after which it is superseded and permanently destroyed — always within 90 days of being taken. When something is deleted from the live service, it stops appearing in new backups immediately and is gone from the older ones within the same window

These periods are enforced automatically, with one exception we would rather state than gloss: the analytics row above is held by PostHog on their own schedule, which we cannot set. After the retention period, data is deleted or irreversibly anonymised. Our internal retention schedule (docs/compliance/retention-schedule.md) records the exact period and the mechanism that enforces each one.

11. Your rights

Under UK GDPR you can: access a copy of your data; rectify inaccurate data; erase your data; restrict or object to processing (including direct marketing and legitimate-interest processing); request portability; withdraw consent; and not be subject to a solely automated decision with significant effect (see Section 6 for the suspension review/appeal route).

Objecting — how it works in practice, for the two jobber checks. These are worded separately because the answers genuinely differ:

  • DBS and our other vetting rest on our legitimate interests, so you can object on grounds relating to your particular situation. We will consider your objection and the reasons for it. We will stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is required for the establishment, exercise or defence of legal claims. If an objection is upheld and the vetting cannot lawfully be completed, we may be unable to approve or continue your access to the platform — but that outcome is decided on your individual facts, and an objection is never treated as though you had withdrawn your application.
  • The prescribed right-to-work check is processed because it is necessary to comply with our legal obligations, and the Article 21 right to object does not apply to processing on that basis. You may still exercise the other data-protection rights that apply in the circumstances, and you may contact us if you believe information used in the check is inaccurate or has been handled unlawfully.

Asking us to delete your right-to-work records. We will consider any erasure request and act on it — this data is not simply exempt. We delete anything that is no longer needed for the legal obligation, keep only the evidence the Home Office requires us to hold, and tell you what we have kept, why the law permits it (Article 17(3)(b)) and the date it will be deleted.

Download your data (self-service). You can export a copy of the personal data we hold about you at any time from your account settings, or directly from /api/account/export while signed in. The export is a machine-readable JSON file covering your profile, jobs, messages you sent, reviews, saved addresses, payments and payout records, marketing-consent state, and device/session history. It excludes other people's personal data and security details (such as your password, sign-in tokens, and card or bank data, which are held by our payment processor Stripe). This satisfies your right of access and to portability without waiting for a manual response.

To exercise any other right, or if you need data the self-service export does not cover, email privacy@bob-o-job.com. We respond within one month (extendable by two months for complex requests). We may verify your identity first. Most requests are free.

Deleting your account. You can delete your account at any time from the app/website. When you do, we delete your account and associated records from our systems, delete your uploaded files (profile photo, documents, job photos) from our file storage, and instruct Stripe to delete your customer and payout records. Some data may be retained where the law requires it (e.g. transaction records for tax), and Stripe may retain certain data under its own legal obligations. If you are a jobber who has earned through the platform, we are legally required to keep the minimum information needed for HMRC digital-platform reporting (your name, date of birth, address, tax identifier, and the amounts paid to you and fees withheld) for around six years even after your account is deleted; your National Insurance number / UTR remain encrypted during this period and are then erased.

You can also complain to the ICO (https://ico.org.uk/make-a-complaint/ · 0303 123 1113) — though we'd appreciate the chance to help first.

12. Security

Security measures include: encryption in transit (TLS) and at rest; passwords stored hashed with bcrypt; mobile login tokens held in the device's encrypted secure store; role-based access controls; rate-limiting on sensitive endpoints; authenticated, access-controlled links for private documents (e.g. ID/certificate downloads); security headers; and regular dependency patching. No system is perfectly secure; if a breach risks your rights we will notify the ICO within 72 hours where required, and you where the risk is high.

13. Children

The Service is for adults (18+). We do not knowingly collect data from anyone under 18. If you believe a child has provided us data, email privacy@bob-o-job.com and we will delete it.

14. Cookies

Our website uses strictly-necessary cookies (sign-in, session, security — always on) and, only if you accept via our cookie banner, PostHog analytics cookies. The banner lets you accept or reject non-essential cookies, and stores your choice in a first-party consent cookie. You can change your choice at any time via our cookie settings. See our separate Cookie Policy for the full list. Our mobile apps do not currently use advertising trackers.

15. Changes to this policy

We may update this policy. We'll update the "Last updated" date and, for material changes (e.g. new categories of data or new sensitive-data processors), notify you by email. Continued use after a change means you accept the updated policy.

16. Contact

Privacy: privacy@bob-o-job.com Post: BOB O JOB LTD, 5th Floor, 167-169 Great Portland Street, London, W1W 5PF ICO: https://ico.org.uk · 0303 123 1113


This Privacy Policy is provided in English; the English version prevails over any translation.

We use essential cookies for sign-in and payments, and optional analytics cookies (PostHog) to improve the site. Privacy Policy · Cookie Policy · Cookie settings