← MowGuard

Privacy Policy

Last updated: July 24, 2026

1. Who we are

MowGuard (the “Service”) is operated by First Penguin Apps (“we”, “us”). We act in two different roles under the EU General Data Protection Regulation (GDPR), depending on whose data is involved:

  • for data about you and your business (your account, settings, and subscription), we are the data controller;
  • for data about your own customers that we process to provide the skip-request feature, you are the data controller and we act as your data processor — see Section 4.

You can reach us at indybouzu0107@gmail.com.

2. What data we process

Your business account data (we are the controller)

When you connect your Jobber account, we receive and store:

  • your Jobber account name and account identifier, and API tokens (encrypted at rest) that let the Service act on your behalf;
  • your account settings: skip-request deadline, reminder timing, fee percentages, timezone, and which job types the feature is enabled for.

When you subscribe to a paid plan:

  • payment is handled by Stripe. Your card details are entered directly on Stripe's payment pages and never pass through or get stored on our servers. We store only your Stripe customer reference, subscription reference, plan, and subscription status.

Your customers' data (you are the controller, we are the processor — see Section 4)

To run the skip-request feature for a job, we receive and store the following about your customer, sourced from your Jobber account:

  • name and email address;
  • service address and the visit/job details tied to it;
  • a permanent, unguessable access token used for their self-service request link (no login or password is used);
  • skip-request history: consecutive skip count, request timestamps, the fee condition they consented to, and the outcome (approved, declined, fee amount) of each request.

The Service uses only strictly necessary cookies: a session cookie that keeps you signed in. We do not use analytics, advertising, or tracking cookies.

3. Why we process it (legal bases)

For your business account data, where we are the controller:

  • To provide the Service — connecting to Jobber, operating the skip-request workflow, and managing your subscription (performance of a contract, Art. 6(1)(b) GDPR);
  • To operate and secure the Service — error logging and abuse prevention (legitimate interests, Art. 6(1)(f) GDPR);
  • To meet legal obligations — bookkeeping and tax records relating to payments (Art. 6(1)(c) GDPR).

For your customers' data, we do not rely on our own legal basis: we process it strictly on your instructions, as your processor, and it is your responsibility to have a lawful basis (typically your contract or arrangement with your customer) for sharing that data with us. See Section 4.

4. Our role as processor for your customers

Where we process your customers' personal data (Section 2) to operate the skip-request feature on your behalf, we commit to:

  • process that data only on your documented instructions — as configured in your account settings and as necessary to run the Service you have subscribed to — and not for our own purposes or those of any other customer;
  • keep it confidential and limit access to personnel and sub-processors who need it to provide the Service;
  • apply appropriate technical and organizational security measures, including encryption of stored access credentials and tenant-level data isolation;
  • use the sub-processors listed in Section 6 to help provide the Service, and remain responsible for their processing of your customers' data;
  • assist you, to the extent reasonably possible, in responding to requests from your customers who wish to exercise their GDPR rights, and in meeting your security, breach-notification, and data protection impact assessment obligations;
  • notify you without undue delay if we become aware of a personal data breach affecting your customers' data;
  • delete your customers' data in line with the retention period in Section 5 after you disconnect the Service, and make it available to you on request beforehand.

These commitments, together with this Privacy Policy, form the data processing terms between you and us for this data; see also Section 7 of the Terms of Service.

5. How long we keep data

  • While your Jobber account is connected, we keep the business account data and customer data needed to provide the Service.
  • If you disconnect the Service from your Jobber account, both your business account data and your customers' data are retained for 30 days (so that reconnecting restores your settings and skip-request history) and then deleted.
  • Records we must keep for accounting or tax purposes are retained for the statutory periods required by applicable law.

6. Who we share data with (processors)

We use the following service providers to run the Service. They process data on our behalf under data-processing agreements:

  • Supabase — database hosting (our database is hosted on Supabase infrastructure, which may be located in the United States);
  • Vercel — application hosting and delivery;
  • Stripe — payment processing and subscription management;
  • Brevo — delivery of reminder, result-notice, and fee-notice emails sent to your customers on your behalf;
  • Jobber — the platform your data originates from and, where applicable, is written back to (visit deletion, invoice creation).

We do not sell personal data, and we do not share it with third parties for their own marketing purposes.

7. International data transfers

Some of our processors store or process data outside the EU/EEA, in particular in the United States (for example, Supabase database hosting, Vercel infrastructure, and Brevo's email delivery infrastructure). Where personal data is transferred outside the EU/EEA, we rely on appropriate safeguards under Chapter V GDPR, such as the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU-U.S. Data Privacy Framework adequacy decision.

8. Your rights

If you are a contractor using the Service, under the GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data rectified;
  • have your data erased (“right to be forgotten”);
  • restrict or object to certain processing;
  • receive your data in a portable format.

To exercise these rights, contact us at indybouzu0107@gmail.com. You also have the right to lodge a complaint with a supervisory authority — in Sweden, the Swedish Authority for Privacy Protection (IMY, imy.se) — or with the authority in your country of residence.

If you are a customer of a business using the Service and wish to exercise your rights over your own data (email, address, or skip-request history), please contact that business directly — they are the data controller for that data, as explained in Section 4. We will assist the business in responding to your request.

9. Changes to this policy

We may update this policy from time to time. Material changes will be announced in the app before they take effect. The date at the top of this page shows when it was last revised.

10. Contact

First Penguin Apps · indybouzu0107@gmail.com