LateFee Privacy Policy
Effective July 24, 2026
LateFee sends payment reminders and applies late fees for invoices in your connected Jobber account. This policy explains what data we handle, why, and what your choices are. Short version: we process the minimum Jobber data needed to chase overdue invoices for you, we don't sell data, and we don't use tracking or advertising cookies.
Our two roles
- For your account (the business connecting Jobber), we decide how data is processed to provide the service — we act as the data controller.
- For your clients' data(the people your invoices are addressed to), we process only on your instructions to run reminders and fees on your behalf — we act as your service provider / processor. If one of your clients contacts us about their data, we'll refer them to you and assist you in responding.
What we collect
- From Jobber, via OAuth: your account ID and business name; client names and email addresses; invoice numbers, amounts, balances, statuses, and due dates. We request only the scopes needed to read invoices/clients and create fee invoices.
- OAuth tokens: stored encrypted (AES-256-GCM) and used only to call the Jobber API for your account.
- Activity records: which reminders and fees were sent, queued, approved, or dismissed, and when.
- Billing: handled by Stripe. We store your Stripe customer and subscription identifiers and status; we never see or store card numbers.
- Cookies: a single signed session cookie to keep you logged in. No analytics, advertising, or cross-site tracking cookies.
How we use it
Only to operate LateFee: syncing invoice state, sending reminder emails as your business name to your clients, creating fee invoices you've enabled or approved, showing you the dashboard, billing your subscription, and keeping the service secure. We do not sell or rent personal information, we don't use your data to train anything, and we don't send marketing to your clients — every email to them is a transactional reminder sent on your instruction.
Who we share it with (subprocessors)
- Vercel — application hosting (United States).
- Supabase — Postgres database hosting (United States).
- Resend — reminder email delivery.
- Stripe — subscription billing.
- Jobber — the source system we read from and write fee invoices to, under your OAuth authorization.
Each receives only what its function requires. We may also disclose data if the law requires it. Data is stored in the United States; by using LateFee from elsewhere you consent to that transfer.
Security
OAuth tokens are encrypted at rest; all traffic uses TLS; the database runs under a least-privilege role isolated to LateFee's schema; inbound webhooks from Jobber and Stripe are signature-verified; dashboard sessions use signed, HTTP-only cookies. If we learn of a breach affecting your data, we'll notify you without undue delay and meet any legally required notification timelines.
Retention and deletion
We keep your data while your Jobber account is connected. Disconnect the app from Jobber (or email us) and we'll delete your connection, tokens, invoice records, and activity history within 30 days, except records we must keep for legal or billing compliance.
Your rights
You can request a copy, correction, or deletion of your data at any time at the email below. Depending on where you live (e.g. the EU/UK under GDPR, California under CCPA/CPRA), you may have additional statutory rights, including complaint to a supervisory authority; we honor these requests regardless of location. We never discriminate for exercising them.
Not for children
LateFee is a business tool and is not directed at anyone under 18; we don't knowingly collect children's data.
Changes
If we materially change this policy we'll notify connected accounts by email or in the dashboard before the change takes effect. The effective date above always reflects the current version.
Contact
Privacy questions or requests: tgoc99@gmail.com