Privacy and data security
Customer accounts, terms acceptances, reservations and audit records are stored in PostgreSQL. Payment-card data is not stored by JDR.
10. Privacy and data security
The system may store:
- Customer name
- Contact information
- Property address
- Reservation information
- Supervisor information
- Service notes
- Uploaded photographs
- Payment and refund references
- Communications
- Terms acceptance records
Intended data-protection principles
- Data minimization
- Role-based access
- Secure transmission
- Password protection
- Limited employee access
- Audit trails
- Account deactivation when an employee leaves
- Incident reporting
- Reasonable retention periods
- Secure deletion where applicable
Payment-card information is processed securely by the authorized payment provider and is never stored in the JDR application database.
Current application controls
The application implements the following controls. Infrastructure encryption in transit and database backups must also be enabled and verified during the Neon and Render deployment.
- Hashed passwords
- Role-based permissions
- Expiring signed sessions
- Rate limiting
- Restricted web origins
- Security response headers
- Audit logs
- Employee account deactivation
- PostgreSQL persistence
