Privacy Policy

    Effective: April 22, 2026

    This Privacy Policy describes how WeCr8 Solutions LLC d/b/a JobLine.ai ("JobLine") collects, uses, discloses, and safeguards personal information in connection with jobline.ai and the JobLine platform.

    1. Information We Collect

    • Account data: name, email, password hash, organization, role, profile photo.
    • Operational data: shift handovers, work orders, NCRs, queue items, station assignments, KPIs.
    • ERP data (read-through): processed in-memory only, not persisted to our database for ITAR/FedRAMP-sensitive customers.
    • Talent / GCA / OAP data: resumes, machine experience, test attempts, certificates, mentor sign-offs.
    • Billing data: tokenized payment methods (Stripe), billing email, invoices. Card numbers never touch our servers.
    • Device & usage: IP, browser, OS, timestamps, page paths, feature interactions, error logs.
    • Cookies & similar: see Cookie Policy.

    2. How We Use Information

    • Provide, maintain, secure, and improve the Service.
    • Process transactions and send transactional emails (via Resend).
    • Power AI planning context (read-through, in-memory; never used to train third-party models).
    • Detect fraud, abuse, and unauthorized access.
    • Comply with legal obligations and enforce our Terms.

    3. Legal Bases (EEA / UK)

    Contract performance, legitimate interests (security, product improvement), consent (marketing/non-essential cookies), and legal obligation.

    4. Sharing

    • Sub-processors: Lovable Cloud (Supabase) for hosting/database, Stripe (payments), Resend (email), Google (Analytics + Consent Mode v2 when consented), AI Gateway (Google/OpenAI models for AI Assistant).
    • Within your organization: data is shared per role-based access and RLS policies.
    • Public profiles: only operators who opt-in to public visibility on /talent/:username; contact info remains masked.
    • Legal: when compelled by valid legal process or to protect rights, safety, and security.
    • We do not sell personal information.

    5. ITAR & Export-Controlled Data

    ITAR-flagged organizations operate in read-through mode; controlled technical data is not copied into our commercial database. Access is gated behind the US-Person Declaration. For workloads requiring CMMC Level 2+, contact compliance@jobline.ai for self-hosted/GovCloud deployment terms.

    6. Data Retention

    • Account & operational data: retained for the life of the subscription + 30 days.
    • Audit logs: 24 months.
    • Issued certificates: indefinitely (so verification links remain valid), unless revoked.
    • Backups: rolling 30-day window.

    7. Security

    Row-Level Security on every table, encryption in transit (TLS 1.2+) and at rest (AES-256), MFA enrollment gates, audit logging, principle-of-least-privilege RLS, and database triggers enforcing state-machine and persistence-mode invariants.

    8. Your Rights

    Subject to applicable law (GDPR, UK GDPR, CPRA/CCPA, PIPEDA, others) you may request access, correction, deletion, portability, restriction, or objection. EU/UK residents may lodge a complaint with their supervisory authority. Email privacy@jobline.ai — we will respond within 30 days.

    9. International Transfers

    Data is processed in the United States. Where data is transferred from the EEA/UK, we rely on Standard Contractual Clauses or equivalent safeguards.

    10. Children

    The Service is not directed to children under 16. We do not knowingly collect data from minors.

    11. Changes

    Material changes will be announced via in-app notice or email at least 14 days before taking effect.

    12. Contact

    WeCr8 Solutions LLC · privacy@jobline.ai · DPO inquiries: dpo@jobline.ai