Privacy Policy

Last updated

This policy describes information handled for Fact Sheet Desk (factsheetdesk.forage.bot), operated by Jobbot Inc, organised in Delaware, USA. Jobbot Inc is responsible as controller for its own website, customer relationship, billing, and support information. Contact factsheetdesk@forage.bot about privacy or your rights.

1. Information we collect

  • Contact information you provide, such as an email address and any name supplied with your request.
  • Order and transaction information including purchases, amounts, payment identifiers, delivery and refund status, and receipt details. Browser card payments use Stripe Checkout; do not send card numbers or security codes in product forms or support messages.
  • Institution details and program totals such as the institution's name, location names and addresses, phone number and website, its federal student aid status and loan figures, where students can obtain the job, salary and calculation lists, the cancellation disclosure text, each program's name, length and total charges, the per-program, per-location, per-year counts computed from the roster (students who began, graduates, students available for graduation or employment, graduates employed, exam takers and passes, salary-band counts), the number of coverage findings by rule, and the email address you give for delivery. The student roster itself is read and checked in your browser and is not sent to us: no student name, contact detail, employer or salary reaches our servers.
  • Service records including submitted requests, generated outputs, preferences, delivery status, and access or usage records where the feature uses them. Free previews can also involve processing.
  • Support and feedback including messages, optional contact details, and submitted attachments. The feedback widget also sends page context such as the URL, title, viewport, user agent, and session identifier. Avoid including private information in URLs or unnecessary attachments.
  • Technical records such as IP address, request path, referrer, user agent, timestamps, errors, and diagnostic information generated when our hosting or other providers handle requests.
  • Site-visit and attribution records associate pages and referring links or campaigns with a random browser identifier. The identifier can be attached to an order to attribute a purchase to a visit. These records are pseudonymous, not anonymous: they can be linked to other information, including a purchase or identifying message.

2. How we use information

  • To provide requested features, produce and deliver outputs, maintain access, and handle support, payments, and refunds.
  • To send service messages, respond to enquiries, and provide optional communications you request. Where offered, optional mail preferences are separate from essential service and billing notices.
  • To diagnose errors, prevent fraud and abuse, protect the service, and understand visits, usage, and which channels lead to purchases.
  • To keep necessary business records, resolve disputes, and meet legal obligations.

We do not sell personal information or share it for cross-context behavioural advertising. We do not use third-party analytics services or cross-site advertising trackers on this site.

If your organisation supplies information about other people for us to process on its behalf, its responsibilities and ours depend on the service and applicable data-processing agreement. This notice does not replace a required agreement or give either party permission to process information unlawfully. Contact us before submitting material that requires contractual safeguards not already agreed.

3. Important submission rules

Fact Sheet Desk is designed for California private postsecondary institutions preparing their School Performance Fact Sheets and annual-report figures. Provide only what is needed for the requested feature and what you are authorised to provide. If required information is omitted, we may be unable to provide that feature.

  • Do not send student records to us by email, through the feedback form, or in a support message. The product never needs them on our side; the roster check runs in your browser.
  • Do not put Social Security numbers or ITINs in the roster. The roster template has no column for them and the product does not use them.
  • Submit institution details only for a school you are authorised to act for.
  • Do not send payment card details except through Stripe Checkout.

Submission restrictions are not a claim that every prohibited detail is automatically detected or removed. They do not reduce our obligations under applicable privacy law.

4. Service providers

The following providers support the relevant features. Information shared depends on the operation, not every provider receives every submission.

  • Stripe processes payments, checkout, billing records, and refunds under its applicable terms and privacy notice.
  • Vercel hosts the website, functions, and stored records or artifacts.
  • Resend handles outbound service and support email.
  • Migadu hosts incoming support email and mailbox records.
  • Neon hosts the shared database for visit attribution and, where used, developer-account and API usage records.
  • GitHub holds internal support and issue records. Messages and relevant metadata may be copied into private issues. Support and technical investigation may involve automated assistance; omit unnecessary sensitive material from support requests.

Additional feature-specific recipients are described in this policy and the portfolio provider inventory at forage.bot/security. A payment provider or an integration you choose may also act independently under its own notice. Our use of a provider does not remove our own duties.

Information may also be disclosed as necessary for lawful requests, legal claims, security, or a business reorganisation, with the protections and notices required by applicable law. Sharing or publication features make selected material available to their intended recipients or link holders as described by the product. A recipient can keep a separate copy.

5. Legal bases where EEA/UK law applies

  • Contract for processing necessary to provide a service requested by the individual, including delivery and related support.
  • Legitimate interests in security, fraud prevention, troubleshooting, and operating the business, where not overridden by individual rights. An organisation's contract does not by itself supply this basis for every person whose data it submits.
  • Legal obligation for required accounting, tax, and other legal records.
  • Consent where required for a particular use or storage technology. A privacy notice or use of the site alone is not that consent.

Special-category information and other restricted data may require additional legal conditions. A submission instruction is not a substitute for those conditions.

6. Retention and deletion

  • An order record (delivery email, institution details, program totals, order status, payment identifiers, and when the documents were last viewed or downloaded) and the generated documents are kept in private storage so you can download them again and rebuild them for the same reporting year. No automatic deletion period applies yet; email us to have an order deleted.
  • When an order is refunded, its generated documents are deleted. The order record is kept as a transaction record.
  • Support messages and technical records are kept for as long as their purpose, open issues and security needs require. We do not promise a fixed log or mailbox expiry.

Accounting and transaction records may need to be retained for statutory periods even when product data is deleted. Retention decisions also consider the sensitivity of the information, continuing service needs, legal claims, and applicable deletion duties. This is not permission to keep information indefinitely where law requires its removal.

Cancelling billing, unpublishing a page, expiring a link, deleting a stored artifact, and deleting an account are different actions. An action on our service does not necessarily erase downloaded copies, delivered email, backups, payment records, or data held independently by a recipient or provider. Ask us about the scope of a deletion request; legal exceptions do not justify keeping unrelated product content.

7. Your rights and choices

Depending on the law that applies, you may request access, correction, deletion, restriction, or a portable copy of your personal information; withdraw consent without affecting earlier lawful processing; and exercise applicable opt-out rights. You may use an authorised agent where law permits. Email factsheetdesk@forage.bot with enough context to locate the information. Do not send identity documents unless a proportionate verification method has been arranged.

Right to object

Where EEA/UK law applies, you may object to processing based on legitimate interests on grounds relating to your situation, and to direct marketing at any time. Optional-message unsubscribe controls, where offered, do not prevent you from making a wider privacy request.

Verification, exceptions, response deadlines, and appeals are governed by applicable law. If we refuse a request, you may ask for the reason and appeal where available by contacting the address above. You may complain directly to your local supervisory authority or other competent regulator; contacting us first is not a prerequisite. Exercising a privacy right does not remove consumer rights or justify unlawful discrimination.

8. Cookies and browser storage

The first-party "vid" cookie contains the random attribution identifier described above. It is scoped to this site, is read by our servers rather than page scripts, and has a two-year expiry when set. It is used for visit and purchase attribution, not just essential delivery. Other storage used by a particular feature is described below.

The fact sheet builder saves your questionnaire answers (program lengths, licence-exam and placement settings, institution details) in this browser's local storage under the key factsheetdesk:answers:v1, so you do not have to type them again next time. Roster rows are never saved there. Clearing site data in your browser removes them. The feedback widget keeps a random session identifier in session storage for the length of the browser session.

You can remove or block cookies and local storage in your browser settings. Removing storage may reset preferences or access saved on that device; it does not delete server records or cancel billing. First-party storage is not automatically exempt from consent requirements. This notice is not a consent control and does not replace any choice required by applicable law.

Stripe Checkout operates on Stripe's domain and may use its own cookies or similar technologies under Stripe's privacy practices.

9. Security and access links

The service uses HTTPS for web traffic and managed hosting and processing providers. No transmission or storage method is completely secure. Some products use signed or hard-to-guess links rather than a login; anyone holding such a link may be able to access the associated content or controls. Keep private links and credentials private. Contact us about unintended access. Security-incident obligations, including any required notices, remain governed by applicable law.

10. International processing

Jobbot Inc is based in the United States. Providers may process information there and in other countries with different privacy laws. The provider inventory identifies their published locations and terms, not a guarantee that all data stays in one country. Where a transfer needs a legal safeguard, that requirement must be satisfied separately; using this site does not waive it. Contact us for information about the arrangements applicable to your data and any available safeguard copy.

11. Children and intended audience

Fact Sheet Desk is for institutions, not for children or for students acting on their own. A school's roster can describe students of any age, and it is processed only in the browser of the person using the product; it is not sent to us. If you believe a student's information has reached us, contact factsheetdesk@forage.bot.

12. Changes to this policy

The revision date identifies when this notice changed. Material changes require the notices and, where applicable, permission required by law. Posting a revised notice does not retroactively authorise a new, incompatible use of information already collected.

Student records and the roster

The roster you upload is read and checked in your browser. Only the totals listed in section 1 are sent to us when you order, and the per-student coverage list stays on your computer. Because student records do not reach us, we do not hold, correct or delete them; your school remains responsible for its own records and for any duty it has under student-privacy law.

13. Contact

For privacy questions or requests, email factsheetdesk@forage.bot.