Privacy

Last updated 2 August 2026. This describes what the software actually does today, not what it might do later.

The short version. mossbench stores the change orders you create, a record of who approved them, and the access token that lets it write approved work back into your Jobber account. It never sees your card. It sets one cookie, which keeps you signed in. It does not sell anything to anyone, does not run advertising, and does not track you across other websites.

Who is responsible

mossbench is operated by its owner, a sole operator based in the United States. For any privacy question, correction, export, or deletion request, use the contact form. That is the fastest route and it reaches someone who can actually action it.

mossbench is operated with AI automation, including its support replies. This is disclosed on the contact page too. If you would rather a human handles your request, say so and that will be arranged.

What is stored, and why

DataWhy it existsKept for
Jobber access and refresh tokens The whole point of the product: writing approved change orders back into your Jobber job. Requested scopes are limited to clients, quotes and jobs. Until you disconnect or ask for deletion
Your Jobber account ID and business name Identifies your workspace. This is your login — there is no separate password. Until deletion
Change orders — title, reason, line items, quantities, prices, client name, job number The records you create. Until deletion
Approval records — the name typed by the approver, timestamp, IP address and browser user-agent This is the evidence the product exists to produce. A change order you cannot prove was authorised is worth nothing in a dispute. Until deletion
Session cookie (mb_session) Keeps you signed in. Opaque random value, HttpOnly, Secure, SameSite=Lax. Strictly necessary — it carries no analytics. 30 days
Support messages — your message, an optional email address, the country the request came from, user-agent, referring page Answering you, on your private thread link. Until deletion
Pageviews on the home page — page path, the host of the referring site, country, user-agent Knowing whether anyone found the site. No cookie, no IP address, no identifier, no cross-site tracking. The full referring URL is deliberately discarded and only the host kept. 180 days
Billing state — Stripe customer and subscription IDs, plan status Knowing whether your subscription is active. Until deletion; Stripe keeps its own records
Rate-limit counters — a count against your IP address Stopping floods and abuse. 1 hour

Card details

mossbench never receives your card number. Payment happens entirely on Stripe's own hosted checkout page. No card data touches mossbench's servers at any point, by design.

A note about your clients

When you send a change order for approval, the person who approves it has their typed name, the time, their IP address and their browser user-agent recorded. That is personal data about someone who is not you, and it exists specifically so the approval can be proven later. You should assume your client can ask you for a copy of it, and you can obtain it from us at any time.

Who else processes it

ProcessorWhat they handleWhere
CloudflareHosting, storage of everything above, DNS, and email routingGlobal edge network
StripePayments, card data, subscription records, invoicesUnited States
JobberYour own account — mossbench reads and writes through their official API using access you explicitly grantPer Jobber's terms
ResendSending support replies to the email address you optionally give. Active since 2 August 2026.United States

Nothing is sold, rented, or shared for advertising. There is no ad network, no data broker, and no third-party analytics service. mossbench has no commercial interest in your data beyond running the service.

Cookies and tracking

One cookie: mb_session. It is strictly necessary, it keeps you signed in, and it does nothing else. There are no advertising cookies, no third-party cookies, and no cross-site tracking.

The home page counts pageviews without a cookie and without storing an IP address. The contact page is not instrumented at all.

Your rights

Whatever jurisdiction you are in, these are available to you here on request through the contact form:

Requests are answered within one business day and actioned within 30 days at the outside. No charge, and no requirement to explain why.

If you are in the EU or UK

mossbench is aimed at contractors in the United States and Canada and is not marketed in the EU or UK. If you use it from there anyway, the lawful bases are contract (everything needed to deliver the service you signed up for) and legitimate interests (keeping the service secure and rate-limited, and counting pageviews without identifiers). You may object to the latter, and you may complain to your local supervisory authority.

If you are in California

mossbench does not meet any CCPA/CPRA applicability threshold — it is far below $25 million in revenue, handles nowhere near 100,000 California residents' data, and derives no revenue at all from selling personal information. The rights listed above are offered regardless.

mossbench does not sell or share personal information as those terms are defined under California law.

Security

HTTPS everywhere with HSTS. A strict Content-Security-Policy. Secrets stored in an encrypted secret store, never in the codebase. Every request that touches a record verifies the record belongs to the account making the request, server-side. Rate limiting on public endpoints. Backups of stored data, with restores actually tested rather than assumed.

No system is perfectly secure. If personal data is ever exposed, affected users will be told promptly and honestly rather than quietly.

If you have found a security problem, please report it through the contact form. Reports are welcomed, not treated as hostile.

Data location and transfers

Data is stored on Cloudflare's global network and may be processed in the United States and elsewhere. Stripe processes payment data in the United States.

Children

mossbench is a business tool, not intended for anyone under 18, and does not knowingly collect data from children.

Changes

If this policy changes materially, the date at the top changes and active customers are told directly rather than left to notice. A policy that does not match what the software actually does is worse than no policy, so it is updated when behaviour changes, not on a schedule.