Skip to main content

Privacy Policy

Last updated: 5 July 2026

Privacy Policy

Last updated: 5 July 2026 Effective from: 5 July 2026


1. Who we are

This Privacy Policy explains how BOB O JOB LTD ("bob-o-job", "we", "us", "our") collects, uses, stores, and shares personal data when you use the bob-o-job platform — our website at www.bob-o-job.com, our customer and jobber mobile apps, and related services (the "Service").

Data controller: BOB O JOB LTD Brooms Farm, Upwick Green, Ware, Hertfordshire, SG11 2JX Company number: 17231669 — registered in England and Wales.

Privacy contact: privacy@bob-o-job.com

We are registered with the UK Information Commissioner's Office (ICO) under registration number ZC167574.

2. Scope of this policy

This policy applies to:

  • Customers — people who post jobs and hire service providers through the Service.
  • Jobbers — service providers offering cleaning, gardening, handyman, dog-walking, general tasks, and events/hospitality services through the Service.
  • Visitors — anyone browsing our website or apps without an account.

Where processing differs between customers and jobbers, we say so. It covers our website and both mobile apps (customer and jobber).

3. What personal data we collect

3.1 Information you give us

When you create an account (customers and jobbers):

  • Name
  • Email address
  • Phone number
  • Password (stored only as a securely hashed value — we never see or store your actual password)
  • Profile photo (optional)
  • Postcode and/or address; saved addresses ("home", "work", etc.) including their map coordinates

When you become a jobber, additionally:

  • Identity verification data — a government-issued photo ID and a live selfie, collected and checked by Stripe Identity on our behalf (see Sections 5 and 8). We receive the verification result; Stripe holds the underlying documents and biometric data under its own policy.
  • Qualifications, certifications, and supporting documents you upload
  • Vetting and compliance records — your interview record, references, your declared right-to-work route (and, for share-code checks, your Home Office share code, stored encrypted), and the outcome and expiry of any compliance checks we carry out or record — including DBS (criminal record), sanctions, and politically-exposed-person screening (see Section 5)
  • Equipment you can provide, skills, service categories, service area, and availability windows
  • A short bio (free text)
  • Bank/payout details — collected and held by Stripe Connect; we do not see or store them
  • Tax-reporting data required by the UK Reporting Rules for Digital Platforms: your date of birth, your primary address, your taxpayer type, and a tax identifier — your National Insurance number or Unique Taxpayer Reference (UTR), or your company registration number and VAT number if you operate through a business. Your National Insurance number and UTR are stored encrypted and are disclosed to HMRC as described in Sections 4, 7.3 and 10.

When you post a job (customers):

  • Job description, category, and any free-text details (which may contain personal information you choose to include)
  • The job location — address, postcode, and precise latitude/longitude
  • Scheduling preferences
  • Photos relevant to the job (e.g. "before" photos)
  • Budget/price preferences
  • Payment card details — entered directly into Stripe; we never see or store your full card number or CVV (see Section 8)

When you communicate or transact through the Service:

  • Messages exchanged between customers and jobbers (in-app chat, dispute chat)
  • Reviews, ratings, and endorsement tags you leave or receive
  • Support enquiries, and the content of conversations with our in-app help assistant (which uses OpenAI — see Section 7; please don't include sensitive personal details you don't need to)
  • Dispute correspondence and any evidence photos you upload
  • During a job: check-in codes and "after" photos used as proof of completion

3.2 Information we collect automatically

Device, technical, and security data (all users):

  • IP address, browser type/version, operating system, device type, language, and time zone
  • A device "fingerprint" (a one-way hashed signature) and a device-session record each time you sign in
  • Activity logs of key actions, and (for jobbers) a record of job acceptances including time and a coarse area — used for security, fraud prevention, and platform integrity
  • Pages/screens visited and features used

Location data:

  • Jobbers: when you go "online", the jobber app sends a single precise GPS snapshot of your location so we can match you to nearby jobs. While you are en route to a job, the app streams your precise GPS location continuously so the customer can track your arrival and ETA. Because we offer background location, this streaming can continue when the app is in the background or your screen is locked while you are travelling to or carrying out a job — your device shows the system background-location indicator while this is happening. Background location is off until you turn it on: you affirmatively consent to it through a separate in-app prompt, and you can revoke that consent at any time in your device settings. We do not collect your location when you are offline. If you turn location off you won't be able to receive proximity-based jobs.
  • Customers: the job location you enter (address + coordinates), and the live location shown to you during a booking is the jobber's, not yours.

On your mobile device: we store your login token in the device's secure keystore, your push-notification token, and small preference flags. We register a push-notification token so we can send you job and account notifications.

Cookies and similar technologies (website): strictly-necessary cookies (sign-in/session, security) are always on; analytics cookies (PostHog) are set only if you accept them in our cookie banner. See Section 14 and our separate Cookie Policy.

3.3 Information from third parties

  • Identity verification result from Stripe Identity (pass/fail and related metadata)
  • Payment and payout status from Stripe
  • Fraud/risk signals from Stripe where applicable
  • Basic profile information (name, email, profile photo) from Google if you choose to sign in with Google

3.4 Automated illegal-content (CSAM) scanning of uploaded images

To keep the platform safe and to meet our duties under the Online Safety Act 2023, images you upload (such as job photos) are automatically checked for known child sexual abuse material (CSAM) before they are stored. We do this in a privacy-preserving way: a non-reversible "perceptual hash" of the image is generated on our own servers, and only that small irreversible hash — not the image itself — is checked against the industry hash list operated by Microsoft (PhotoDNA Cloud). This is a hash match against known illegal images; it does not "look at", classify, or describe your photo. If an image matches, the upload is refused, the file is securely quarantined, and we report it to the appropriate authorities (see Section 7.3). See Sections 7.2 and 9 for the processor and transfer details.

4. How we use your personal data, and our lawful basis

Under UK GDPR we must have a lawful basis for each use of your data:

PurposeData usedLawful basis
Create and run your accountName, email, phone, password hash, profileContract (Art. 6(1)(b))
Verify jobber identity and trustworthinessID document, selfie, verification result, documentsExplicit consent + substantial public interest (Art. 9) for the biometric check; Contract; Legal obligation where applicable
Jobber vetting and compliance checks (right to work, DBS, sanctions/PEP screening, interviews, references)Right-to-work route and share code (encrypted), check outcomes and expiry dates, interview and reference recordsLegal obligation (right to work); Legitimate interest in a safe marketplace; for criminal-offence (DBS) data, DPA 2018 Schedule 1 conditions (employment/safeguarding and substantial public interest)
Match customers with jobbers; run the marketplaceJob details, location, category, availability, tier, ratingsContract
Process payments and payoutsTransaction details; card data and bank details (held by Stripe); tax infoContract; Legal obligation (tax/AML)
Report jobber (seller) data to HMRC under the digital-platform reporting rulesName, date of birth, address, tax identifier (NI number / UTR / company / VAT), consideration paid and fees withheldLegal obligation (Art. 6(1)(c)) — Finance Act 2023 / SI 2023/817, the UK Reporting Rules for Digital Platforms
Live location tracking and ETA during a jobPrecise GPS (jobber)Contract; Legitimate interest in safety and ETA accuracy
Send service emails/notifications (confirmations, receipts, password resets, dispute/job updates)Email, push token, transaction detailsContract
Send marketing and timing/seasonal emailsEmail, preferences, categories used, general areaConsent — opt-in, with one-click unsubscribe in every email
Website product analyticsPseudonymised usage events (PostHog)Consent (cookie banner)
Operate the platform reliably; server-side analytics, error monitoring, rate-limiting, fraud and abuse prevention, trust-and-safetyAccount, device, IP, location/behaviour logsLegitimate interest in platform integrity, security, and safety
Automated jobber reliability scoring and suspensionCancellation/behaviour historyLegitimate interest / Contract — see Section 6
Resolve disputesMessages, transaction history, photos, location/timingContract; Legitimate interest in fair resolution
Customer support and the in-app help assistantContact details, messages, recent-job context (sent to OpenAI)Contract; Legitimate interest
Scan uploaded images for known illegal content (CSAM) and report matchesUploaded image → irreversible perceptual hash; match metadataLegal obligation (Online Safety Act 2023) and substantial public interest in safeguarding children (Art. 9(2)(g); DPA 2018 Sch. 1)
Comply with legal obligationsAs requiredLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have weighed the impact on your rights and consider the processing necessary and proportionate; you can object (Section 11). Where we rely on consent, you can withdraw it at any time without affecting prior processing.

5. Special category and criminal-offence data

Biometric data (jobbers). Verifying a jobber's identity involves biometric processing — matching the selfie to the ID document — which is a special category of data under Article 9 UK GDPR. We rely on:

  • Your explicit consent (Art. 9(2)(a)), given at jobber onboarding, and
  • Substantial public interest (Art. 9(2)(g)) in preventing fraud and keeping a public-facing marketplace safe (Data Protection Act 2018, Schedule 1, Part 2).

The biometric matching is performed by Stripe Identity; Stripe holds the documents and biometric data under its own retention policy. We receive only the result. We do not use facial recognition for any other purpose.

Criminal-offence data (jobbers). Where a DBS (criminal record) check is carried out for a jobber, or a jobber uploads a DBS certificate, we record the outcome and expiry of that check (not the underlying certificate content beyond what is needed to verify it). This is criminal-offence data under Article 10 UK GDPR; we process it under the conditions in Schedule 1 of the Data Protection Act 2018 for employment-and-safeguarding and substantial-public-interest purposes — keeping people safe when a jobber works in their home. We also screen or record screening against sanctions lists and politically-exposed-person (PEP) lists where appropriate. Check outcomes are visible only to our vetting team and are never shown to other users.

6. Automated decision-making and profiling

We want to be transparent that the platform uses some automated processing:

  • Jobber reliability score (human decision on suspension). We calculate a "reliability score" for jobbers, reduced only when a jobber cancels a job they had already committed to. If the score falls below a set threshold, the account is flagged for review by a member of our team — it is not suspended automatically. A person looks at the recent cancellations and decides whether to pause the account. If we do suspend: (a) we notify you with the reason, your score, and the threshold; (b) you can appeal in the app (the "Appeal a suspension" page) or by email, and the appeal is reviewed by a different person, who can reinstate you; and (c) you always have the data-protection right to contest the outcome and obtain human intervention.
  • In-chat contact-detail filter. To prevent off-platform circumvention and protect personal data, messages sent through in-app chat are automatically scanned for contact details (phone numbers, email addresses, addresses, links, social handles). A message containing them is blocked with a warning; after three blocked attempts the account is suspended automatically. If this happens to you, you can contest the decision and ask for human review at support@bob-o-job.com or privacy@bob-o-job.com, and a member of our team will review it and can reinstate your account.
  • Profiling for safety and fraud prevention. We analyse device, IP, location, and behavioural signals to detect fraud and abuse and to keep users safe. This profiling supports human decisions and does not, on its own, produce legal or similarly significant effects on you.
  • Matching. Our engine recommends jobbers to customers, but a human (the customer, or the jobber accepting) makes the final booking decision.

7. Who we share your personal data with

We share personal data only where necessary, and never sell it or share it for third-party marketing.

7.1 Between users

  • Customers see a matched jobber's name, photo, ratings/reviews, tier, approximate location, and live location/ETA during the job.
  • Jobbers see the customer's first name, the job details (description, address at booking, photos), and the customer's rating of them.
  • Reviews and ratings are public to other users.

7.2 Service providers (sub-processors)

We use the processors below, each under (or to be under) a written data-processing agreement. International transfers are covered by the UK IDTA / EU SCCs and supplementary safeguards (Section 9).

ProcessorPurposeLocation
Vercel Inc. — incl. Vercel BlobWebsite hosting; storage of uploaded files (avatars, documents, job photos)US (EU edge) — SCCs
Railway CorpBackend/realtime server hostingUS — SCCs
Neon Inc.Primary database (Postgres)EU (London, eu-west-2)
UpstashRedis — rate-limiting (keyed on IP) and geo-matchingUS/EU — SCCs
Stripe Payments Europe LtdPayments, Stripe Identity (ID verification), Stripe Connect (jobber payouts), fraud preventionIreland (EU); some processing in US — SCCs
Resend Inc.Transactional and marketing email deliveryUS — SCCs
TwilioMasked phone calls between customers and jobbers, where enabledUS — SCCs
Mapbox Inc.Maps, geocoding, routing/ETAUS — SCCs
OpenAIAI help assistant and job-description assistance (text you submit + recent-job context; and, for some features, photos you submit for analysis). Submitted via the API, which OpenAI does not use to train its models.US/EU — SCCs
AnthropicDrafting suggested replies to support tickets, for our support team only — the content of your support ticket and relevant account context is submitted via the API (which Anthropic does not use to train its models); a person reviews every draft before anything is sent to youUS — SCCs
Postcodes.ioUK postcode lookup — converts a postcode you enter to map coordinates; no account details are sentUK
Microsoft (PhotoDNA Cloud)Known-illegal-content (CSAM) detection — we send only an irreversible hash; the image itself is never transferred (see Section 3.4)US — SCCs
PostHog Inc.Product analytics (website, with consent; and server-side, for platform operation)EU region (eu.posthog.com)
Sentry (Functional Software Inc.)Error and performance monitoring (we minimise personal data sent)EU ingest
Google LLCSign in with Google (only if you choose it)EU/US — SCCs
Expo / Apple Push Notification service / Google Firebase Cloud MessagingMobile push-notification deliveryUS — provider terms

Webhook signatures are verified via Svix. (Where our codebase references other vendors, e.g. legacy Google Maps keys, those services are not in active use.)

7.3 Legal and safety disclosures

We may disclose personal data to comply with a court order or lawful request; to enforce our Terms or protect our rights; to prevent or investigate fraud, illegal activity, or threats to safety; or in connection with a corporate transaction, under confidentiality and with appropriate notice.

HMRC (digital-platform reporting). Where you earn through the platform as a jobber, we are legally required to report your details to HM Revenue & Customs under the UK Reporting Rules for Digital Platforms (see Section 4): your name, date of birth, address, tax identifier (National Insurance number / UTR, or company / VAT number), and the consideration paid to you and fees we withheld in each reporting period (a calendar year). Reports are made annually. This reporting is a legal obligation and cannot be opted out of; your National Insurance number / UTR are held encrypted and are included only in the report to HMRC.

Illegal-content reporting. Where our scanning (Section 3.4) detects, or our team confirms, child sexual abuse material or other illegal content, we report it and preserve the necessary evidence for the appropriate bodies — in the UK the Internet Watch Foundation (IWF) and the National Crime Agency (NCA/CEOP), and where applicable the National Center for Missing & Exploited Children (NCMEC). We do not notify the person who uploaded the content where doing so could prejudice an investigation.

8. Payment data

Card details are entered directly into Stripe on our website and apps and sent straight to Stripe. We never see or store your full card number, CVV, or bank/payout details. Stripe is an independent controller for the payment data it processes — see https://stripe.com/privacy.

9. International data transfers

Some processors are outside the UK/EEA (mainly the US). Where personal data is transferred internationally we rely on the UK International Data Transfer Agreement (IDTA) / EU Standard Contractual Clauses, adequacy where it applies, and supplementary measures (encryption in transit and at rest). Your core data store (Neon) is in the EU (London); analytics (PostHog) and error monitoring (Sentry) use EU regions. For illegal-content scanning (Section 3.4) the only thing transferred to the US is an irreversible hash, never the image. We carry out data protection impact assessments for higher-risk processing (identity verification, live location tracking, and illegal-content scanning).

10. How long we keep your personal data

Data categoryRetention
Active account dataWhile your account is open, then deleted/anonymised (we retain only what law requires — below)
Transaction/financial records6 years (HMRC)
Jobber tax-reporting data (NI number / UTR / company / VAT, date of birth, address)encrypted at rest; retained ~6 years (tax-record retention), then scrubbed; National Insurance number and UTR held encrypted
Identity verification recordsheld by Stripe under its policy; our verification result up to 5 years (AML good practice)
Jobber vetting and compliance-check records (right to work, DBS outcome/expiry, sanctions/PEP, interview and reference records)while you provide services through the platform, and afterwards only as long as the law requires (right-to-work records: duration of engagement + 2 years)
Messages and supportretained while relevant to your account or an open dispute
Disputes and safety incidentsup to 6 years after resolution
Device, IP, location, and behavioural logs (device sessions, activity logs, job-acceptance logs)deleted after 12 months (365 days)
Email-delivery logs365 days
Webhook/payment event records90 days
Push-notification delivery logs365 days
In-app notificationsread notifications deleted after 90 days; unread kept until read or until you delete your account
Illegal-content (CSAM) reports and quarantined materialretained as a legal/safeguarding record; quarantined material is deleted only when law enforcement confirms it is no longer needed
Marketing subscriptionuntil you unsubscribe
Completed-job recordsanonymised after 90 days; deleted after 6 years
Website analytics (PostHog)per our PostHog configuration
Backupsoverwritten on a rolling cycle (typically ~35 days; at most 90 days)

These periods are enforced automatically. After the retention period, data is deleted or irreversibly anonymised. Our internal retention schedule (docs/compliance/retention-schedule.md) records the exact period and the mechanism that enforces each one.

11. Your rights

Under UK GDPR you can: access a copy of your data; rectify inaccurate data; erase your data; restrict or object to processing (including direct marketing and legitimate-interest processing); request portability; withdraw consent; and not be subject to a solely automated decision with significant effect (see Section 6 for the suspension review/appeal route).

Download your data (self-service). You can export a copy of the personal data we hold about you at any time from your account settings, or directly from /api/account/export while signed in. The export is a machine-readable JSON file covering your profile, jobs, messages you sent, reviews, saved addresses, payments and payout records, marketing-consent state, and device/session history. It excludes other people's personal data and security details (such as your password, sign-in tokens, and card or bank data, which are held by our payment processor Stripe). This satisfies your right of access and to portability without waiting for a manual response.

To exercise any other right, or if you need data the self-service export does not cover, email privacy@bob-o-job.com. We respond within one month (extendable by two months for complex requests). We may verify your identity first. Most requests are free.

Deleting your account. You can delete your account at any time from the app/website. When you do, we delete your account and associated records from our systems, delete your uploaded files (profile photo, documents, job photos) from our file storage, and instruct Stripe to delete your customer and payout records. Some data may be retained where the law requires it (e.g. transaction records for tax), and Stripe may retain certain data under its own legal obligations. If you are a jobber who has earned through the platform, we are legally required to keep the minimum information needed for HMRC digital-platform reporting (your name, date of birth, address, tax identifier, and the amounts paid to you and fees withheld) for around six years even after your account is deleted; your National Insurance number / UTR remain encrypted during this period and are then erased.

You can also complain to the ICO (https://ico.org.uk/make-a-complaint/ · 0303 123 1113) — though we'd appreciate the chance to help first.

12. Security

Security measures include: encryption in transit (TLS) and at rest; passwords stored hashed with bcrypt; mobile login tokens held in the device's encrypted secure store; role-based access controls; rate-limiting on sensitive endpoints; authenticated, access-controlled links for private documents (e.g. ID/certificate downloads); security headers; and regular dependency patching. No system is perfectly secure; if a breach risks your rights we will notify the ICO within 72 hours where required, and you where the risk is high.

13. Children

The Service is for adults (18+). We do not knowingly collect data from anyone under 18. If you believe a child has provided us data, email privacy@bob-o-job.com and we will delete it.

14. Cookies

Our website uses strictly-necessary cookies (sign-in, session, security — always on) and, only if you accept via our cookie banner, PostHog analytics cookies. The banner lets you accept or reject non-essential cookies, and stores your choice in a first-party consent cookie. You can change your choice at any time via our cookie settings. See our separate Cookie Policy for the full list. Our mobile apps do not currently use advertising trackers.

15. Changes to this policy

We may update this policy. We'll update the "Last updated" date and, for material changes (e.g. new categories of data or new sensitive-data processors), notify you by email. Continued use after a change means you accept the updated policy.

16. Contact

Privacy: privacy@bob-o-job.com Post: BOB O JOB LTD, Brooms Farm, Upwick Green, Ware, Hertfordshire, SG11 2JX ICO: https://ico.org.uk · 0303 123 1113


This Privacy Policy is provided in English; the English version prevails over any translation.

We use essential cookies for sign-in and payments, and optional analytics cookies (PostHog) to improve the site. Privacy Policy · Cookie Policy · Cookie settings