Privacy and data security

Customer accounts, terms acceptances, reservations and audit records are stored in PostgreSQL. Payment-card data is not stored by JDR.

10. Privacy and data security

The system may store:

  • Customer name
  • Contact information
  • Property address
  • Reservation information
  • Supervisor information
  • Service notes
  • Uploaded photographs
  • Payment and refund references
  • Communications
  • Terms acceptance records

Intended data-protection principles

  • Data minimization
  • Role-based access
  • Secure transmission
  • Password protection
  • Limited employee access
  • Audit trails
  • Account deactivation when an employee leaves
  • Incident reporting
  • Reasonable retention periods
  • Secure deletion where applicable

Payment-card information is processed securely by the authorized payment provider and is never stored in the JDR application database.

Current application controls

The application implements the following controls. Infrastructure encryption in transit and database backups must also be enabled and verified during the Neon and Render deployment.

  • Hashed passwords
  • Role-based permissions
  • Expiring signed sessions
  • Rate limiting
  • Restricted web origins
  • Security response headers
  • Audit logs
  • Employee account deactivation
  • PostgreSQL persistence