Privacy Policy
Effective: April 22, 2026
This Privacy Policy describes how WeCr8 Solutions LLC d/b/a JobLine.ai ("JobLine") collects, uses, discloses, and safeguards personal information in connection with jobline.ai and the JobLine platform.
1. Information We Collect
- Account data: name, email, password hash, organization, role, profile photo.
- Operational data: shift handovers, work orders, NCRs, queue items, station assignments, KPIs.
- ERP data (read-through): processed in-memory only, not persisted to our database for ITAR/FedRAMP-sensitive customers.
- Talent / GCA / OAP data: resumes, machine experience, test attempts, certificates, mentor sign-offs.
- Billing data: tokenized payment methods (Stripe), billing email, invoices. Card numbers never touch our servers.
- Device & usage: IP, browser, OS, timestamps, page paths, feature interactions, error logs.
- Cookies & similar: see Cookie Policy.
2. How We Use Information
- Provide, maintain, secure, and improve the Service.
- Process transactions and send transactional emails (via Resend).
- Power AI planning context (read-through, in-memory; never used to train third-party models).
- Detect fraud, abuse, and unauthorized access.
- Comply with legal obligations and enforce our Terms.
3. Legal Bases (EEA / UK)
Contract performance, legitimate interests (security, product improvement), consent (marketing/non-essential cookies), and legal obligation.
4. Sharing
- Sub-processors: Lovable Cloud (Supabase) for hosting/database, Stripe (payments), Resend (email), Google (Analytics + Consent Mode v2 when consented), AI Gateway (Google/OpenAI models for AI Assistant).
- Within your organization: data is shared per role-based access and RLS policies.
- Public profiles: only operators who opt-in to public visibility on /talent/:username; contact info remains masked.
- Legal: when compelled by valid legal process or to protect rights, safety, and security.
- We do not sell personal information.
5. ITAR & Export-Controlled Data
ITAR-flagged organizations operate in read-through mode; controlled technical data is not copied into our commercial database. Access is gated behind the US-Person Declaration. For workloads requiring CMMC Level 2+, contact compliance@jobline.ai for self-hosted/GovCloud deployment terms.
6. Data Retention
- Account & operational data: retained for the life of the subscription + 30 days.
- Audit logs: 24 months.
- Issued certificates: indefinitely (so verification links remain valid), unless revoked.
- Backups: rolling 30-day window.
7. Security
Row-Level Security on every table, encryption in transit (TLS 1.2+) and at rest (AES-256), MFA enrollment gates, audit logging, principle-of-least-privilege RLS, and database triggers enforcing state-machine and persistence-mode invariants.
8. Your Rights
Subject to applicable law (GDPR, UK GDPR, CPRA/CCPA, PIPEDA, others) you may request access, correction, deletion, portability, restriction, or objection. EU/UK residents may lodge a complaint with their supervisory authority. Email privacy@jobline.ai — we will respond within 30 days.
9. International Transfers
Data is processed in the United States. Where data is transferred from the EEA/UK, we rely on Standard Contractual Clauses or equivalent safeguards.
10. Children
The Service is not directed to children under 16. We do not knowingly collect data from minors.
11. Changes
Material changes will be announced via in-app notice or email at least 14 days before taking effect.
12. Contact
WeCr8 Solutions LLC · privacy@jobline.ai · DPO inquiries: dpo@jobline.ai