← Back to sign in

Privacy Policy

Last updated: 2026-09-11

1. Who we are and scope

This Privacy Policy explains how David Lander, trading as “Jomioz” (“Jomioz,” “we,” “us,” or “our”), collects, uses, and shares personal information when you visit our website (such as jomioz.com), use our marketing pages, join a waitlist, contact us, or use the Jomioz product — including the web app, mobile app, Client Hub, and related services (together, the “Service”). Controller for platform account, billing, security, and marketing-site data: David Lander, trading as “Jomioz”; Tax ID (NIF/NIE): Y8422959M; Address: Calle San Isidro, 2 - La Orotava - Tenerife - Spain; Contact: info@jomioz.com. Jomioz is field-service operations software for service businesses. We serve customers in Europe and the Americas and design our privacy practices to meet applicable laws in those regions, including the EU/UK GDPR and US state privacy laws such as the CCPA/CPRA where they apply. Full imprint details: https://www.jomioz.com/legal. This Policy covers Jomioz as provider of the Service. It does not apply to the privacy practices of Account Owners or of third parties we do not control.

2. Controller vs processor (B2B)

When an Account Owner uses Jomioz to manage its own customers (“End Users”), jobs, estimates, invoices, messages, and related content, that organization is typically the controller (or “business”) of that Customer Data, and Jomioz acts as a processor (or “service provider”) on the Account Owner’s documented instructions. Jomioz is the controller of account, billing, security, and platform administration data. End Users with privacy requests about data in a customer’s workspace should contact that Account Owner first. B2B customers may review or request a Data Processing Agreement (DPA) at https://www.jomioz.com/dpa or info@jomioz.com.

3. Information we process (product-related)

Depending on features you use, we may process: Account Owner and Employee User data (name, work email, company, role, locale); End User and job content (contacts, properties/addresses, schedules, jobs, estimates, invoices, notes, photos, attachments, e-signatures, Client Hub activity); messaging metadata for email and, where connected, SMS/WhatsApp; map/route-related address data; Stripe payment/billing data (no full card numbers stored on Jomioz for reuse); AI prompts/outputs where assistive features are enabled — we do not use Customer Data or those prompts to train third-party foundation models; technical logs (IP, device, diagnostics, auth); PostHog product analytics; and marketing-site analytics/cookies as described below.

4. Europe — legal bases (GDPR)

Where the EU/UK GDPR applies, we rely on: (a) performance of a contract — to run your account, workspace, billing, and the features you use; (b) legitimate interests — security, fraud prevention, service communications, and product analytics that help us keep the Service reliable, balanced against your rights; (c) legal obligation — tax, accounting, and similar duties that apply to us as provider; and (d) consent where required — non-essential marketing-site cookies and optional marketing, which you may withdraw at any time. We do not sell personal information for money.

5. United States privacy (including California)

Categories we may collect as a business: identifiers (name, email, account ID, IP); commercial information (plan, billing, trial activity); internet activity (pages, feature-usage events, cookie/device IDs); approximate location from IP; and inferences from that activity. Sources include you, your organization, cookies after consent, and subprocessors. We do not sell personal information for money. If you accept analytics cookies on our marketing site, we may use Google Analytics, Google Ads, Meta Pixel (Facebook), and Meta’s Conversions API to measure visits, trial clicks, and ad performance. That may constitute “sharing” for cross-context behavioral advertising under the CCPA/CPRA. You can opt out by declining cookies on our banner, by emailing info@jomioz.com with the subject “Do Not Sell or Share,” or by using Google’s and Meta’s opt-out tools (see also https://www.jomioz.com/privacy#dns). Residents of California and similar US states may have rights to know/access, correct, delete, and obtain a portable copy of certain personal information we hold as a business, and to appeal denials where the law provides, without discrimination. Contact info@jomioz.com for data Jomioz controls. For End User data inside a customer workspace, contact that business first.

6. How we use information

We use personal data to provide and operate Jomioz (including jobs, scheduling, documents, Client Hub, payments, and messaging); authenticate users (including optional two-factor authentication); send transactional and security messages; bill subscriptions; detect abuse; meet legal obligations; improve reliability and product quality (including PostHog product-usage analytics); and generate aggregated, anonymized statistics that do not identify individuals.

7. Sharing and subprocessors

We use subprocessors under contracts that restrict their use of data (GDPR Art. 28 where applicable). Depending on enabled features, this may include cloud hosting/databases; file storage (e.g. AWS S3); Google sign-in; Resend (email); Twilio/Meta (SMS/WhatsApp where connected); Stripe (payments); Mapbox (maps); PostHog (analytics); Sentry (errors, where enabled); OpenAI (AI assist); Meilisearch (search); Firebase (push); and marketing-site measurement (Google Analytics, Google Ads, Meta Pixel and Conversions API after cookie consent). We may disclose data if required by law or to protect rights and safety. Current list: https://www.jomioz.com/subprocessors.

8. International transfers (Europe ↔ Americas)

Data may be processed in the EEA, UK, United States, and other countries where we or our subprocessors operate. For EEA/UK transfers to countries without an adequacy decision, we use SCCs (and UK equivalents) plus supplementary measures where needed. Contact info@jomioz.com for workspace-specific details.

9. Cookies and similar technologies

We use strictly necessary cookies for authentication, security, and sessions. PostHog records product-usage events in the Service so we can operate and improve Jomioz. On the marketing site, PostHog and advertising measurement (Google, Meta) run only after you accept cookies. Where non-essential cookies require consent under EU/UK or local law, we will request it. Blocking necessary cookies may break sign-in. Full Cookie Policy (vendors, retention, and how to change your choice): https://www.jomioz.com/cookies.

10. Security and retention

We use TLS in transit, encryption at rest where supported, role-based access, optional two-factor authentication, monitoring, and least-privilege production access. See our Security page. If we become aware of a personal-data breach affecting Customer Data we process for an Account Owner, we will notify that Account Owner without undue delay and provide information reasonably available to help them meet their own obligations. Retention: account and workspace administration data for the life of the account, then typically up to 24 months after closure; Customer Data until the Account Owner deletes it or we complete an instructed deletion/export; billing and accounting records we hold as provider for the period required by tax and accounting law (often six to ten years); support records typically up to 24 months; security logs typically up to 12 months; marketing-site analytics until you withdraw consent or the vendor’s period ends.

11. Your rights

Under GDPR you may have rights to access, rectify, erase, restrict, or port data, object to certain processing, and complain to a supervisory authority (in Spain, the AEPD). US state rights, including Do Not Sell or Share, are in section 5. For organization-controlled workspace data, contact your admin first; otherwise info@jomioz.com. We aim to respond within 30 days (or sooner if law requires). We may verify identity. End Users should contact their Account Owner first for workspace Customer Data.

12. Children

Jomioz is a business service. You must be of legal age in your jurisdiction. We do not knowingly collect data from children under 16 (or under 13 in the US, or the higher age required locally). Contact info@jomioz.com if you believe we have.

13. Changes and contact

We may update this policy and will post the revised version with an updated date; material changes may also be emailed or shown in-product. Privacy, legal, and security: info@jomioz.com. See also our Terms of Service, Security page, https://www.jomioz.com/legal, https://www.jomioz.com/cookies, https://www.jomioz.com/subprocessors, and https://www.jomioz.com/dpa.