Legal
Privacy Policy
The short version
- Spanner stores your customers, jobs, quotes, invoices and job photos on your device. You do not need an account to use it.
- If you enter a business email in the app, we may keep a device-bound copy of that data on our servers (keyed to this install). That copy is for operating the service and future product features; it is not the same as Pro restore or the desktop portal. The email is stored as an unverified claim until you sign in with a code.
- If you subscribe to Pro and sign in with a six-digit code sent to your email, you unlock restore on any phone and the web portal at portal.spanner.pro. That verified copy is encrypted in transit and at rest by Cloudflare. We can access it to run the service.
- For your customers’ personal data in any cloud copy, you are the controller and Spanner is your processor. See the Data Processing Addendum.
- We do not run advertising or third-party analytics SDKs in the app.
- Optional on-device reminders (jobs today, overdue invoices, due-back dates) are scheduled on your phone only. They are not push notifications and nothing is sent to our servers for them. You can turn them off in Settings.
- We use Firebase App Check (Apple App Attest / Google Play Integrity) so only genuine installs of the app can call our API. App Check tokens are short-lived and do not include your job or customer data.
- Subscriptions are processed by Apple or Google. We never see your card details.
- Uninstalling the app removes the copy on that phone. To delete a cloud copy, use Delete account in Settings, or email josh@spanner.pro from the address you signed in with (or the business email on the device-bound copy). A Pro subscription is cancelled separately in the App Store or Play Store.
Who we are
Spanner is built and run by one person: Josh Mason, an independent developer based in the United Kingdom, trading as Spanner (“I”, “we”, “us”).
ICO registration: ZC243782.
Contact address: Unit 82701, PO Box 92, Cardiff, CF11 1NB, United Kingdom.
Contact: josh@spanner.pro.
On the Apple App Store and Google Play the listing is titled Spanner: Jobs & Quotes (pro.spanner.ios / pro.spanner.android).
Controllers and processors
| Data | Who decides why it is processed | Spanner’s role |
|---|---|---|
| Your sign-in email, sessions, Pro entitlement, App Check tokens, support mail you send us | Spanner | Controller |
| Your customers’ names, phones, emails, addresses, job notes, quotes, invoices, and job photos you upload | You (the trader) | Processor when a cloud copy exists — see the DPA |
| Your business profile and bank details you enter for PDFs | You decide what to store; we hold a copy if a cloud copy exists | Processor for the cloud copy; you remain responsible for what you put on quotes and invoices |
| Purchase receipts and store billing | Apple / Google (and RevenueCat for entitlement checks) | We receive entitlement status only |
If you put someone else’s personal data into Spanner, you need a lawful basis to do so. We do not contact your customers.
What data the app handles
| Data | Where it lives | Purpose |
|---|---|---|
| Customer details (name, phone, email, address) | Your device; our servers if a cloud copy exists | Jobs, quotes, invoices, call and directions |
| Jobs, quotes, invoices and line items | Your device; our servers if a cloud copy exists | Running the day’s work and producing PDFs |
| Job photos | Your device; our servers if a cloud copy exists | Evidence on the job |
| Business profile (name, address, logo, bank details) | Your device; our servers if a cloud copy exists | Branding quotes and invoices |
| Email address | Our servers when you enter a business email (claim) or sign in for Pro | Identifying a device copy; sending sign-in codes for Pro restore |
| Subscription status | RevenueCat and the app store you use | Unlocking Pro features |
| Local reminder schedules | Your device only | Morning nudges for jobs, overdue invoices and due-back work |
| Device location (optional) | Reverse-geocoded on the device via Apple or Google’s address lookup, then stored only on your device (and our servers if a cloud copy exists) | One-tap fill of a customer address from where you are standing. Coordinates are sent to the platform geocoder to turn them into a postal address; we do not store the coordinates. |
| Home-screen widget | Your device | Next job title and amount owed, so you can see the day without opening the app. Job titles can appear on a home screen (and, on iOS, a lock screen). |
| App Check attestation | Firebase (Google) briefly, then discarded | Confirming the request came from the real Spanner app |
Customer phone numbers and addresses are stored only if you enter them.
Cloud copies
Device-bound copy (business email)
When you enter a business email in the app, we may create a cloud copy of your customers, jobs, quotes, invoices, photos and business profile, keyed to this install. The email is stored as an unverified claim (we have not proved you control that inbox). That copy is not available on the desktop portal and is not a multi-device restore until you take the Pro sign-in steps below.
Pro restore and portal
Pro restore is optional. When you subscribe and sign in:
- We send a six-digit sign-in code (and a link) to the email address you enter. The code expires and can only be used once. We store a hashed version of the code and a session token so the app stays signed in.
- Your customers, jobs, quotes, invoices, photos and business profile are stored under that verified email so they can be restored on any device where you sign in with the same email, including the web portal at portal.spanner.pro.
- Data is encrypted in transit (TLS) and at rest by Cloudflare. This is platform encryption, not a lock only you can open: we can access backed-up records to operate the service. Login email is encrypted at application level (AES-GCM). Customer CRM fields and bank details in the backup are stored so the service can sync and render them — they are not end-to-end encrypted.
- Our infrastructure is provided by Cloudflare, Inc. (Workers, D1 database and R2 object storage). Cloudflare processes data on our behalf under its data processing terms. Backed-up data is stored in the European Union.
- Sign-in emails are sent via Cloudflare’s email sending service from
login@spanner.pro. - Processor terms for your customers’ data are in the Data Processing Addendum.
You can sign out at any time in Settings. Signing out leaves the work on this phone. Delete account in Settings wipes this phone and, if you are signed in, the cloud copy — but only after the cloud wipe succeeds. If the cloud request fails, nothing is removed so you can retry. You can also email josh@spanner.pro from the address you signed in with.
On-device storage
The copy on your phone (SQLite database and photo files) is protected by your device lock and OS storage, not by an extra app-level database password. If the phone is lost and unlocked, that copy can be read. Use a device passcode or biometrics, and use Delete account before handing a phone on.
Purchases
Pro subscriptions are sold through the Apple App Store and Google Play. Apple or Google handle payment and hold your billing details. We use RevenueCat to check whether your subscription is active. RevenueCat receives an anonymous app user ID and purchase receipt data from the store; it does not receive your name, email or job data from us. See RevenueCat’s privacy policy for details.
Analytics and tracking
The app does not include third-party analytics, advertising or crash-reporting SDKs. Our servers keep short-lived technical logs (request paths, timestamps, status codes) to operate the service and investigate faults. Firebase App Check may contact Google briefly to attest the device; that attestation is not used for advertising.
This website does not use cookies or analytics.
Legal bases
Where UK GDPR applies and Spanner is the controller (your account email, security, support):
- Contract — providing cloud backup and Pro features you have asked for.
- Legitimate interests — keeping the service secure, preventing abuse, and responding to support requests.
Where Spanner is the processor of your customers’ data, you determine the lawful basis for collecting and using that data. Our processing is on your instructions under the DPA.
Retention
- Data on your device stays until you delete a record, use Delete account in Settings, or uninstall the app.
- Soft-deleted records stay briefly so sync can propagate the delete, then are hard-removed after 30 days on the device and in the cloud backup.
- Backed-up live data is kept while your account exists. Cloudflare D1 may keep a restore point of the database for up to 30 days. Delete account removes the live copy when the cloud request succeeds.
- Sign-in codes expire shortly after they are sent; sessions expire after a period of inactivity.
- Server logs are held in Cloudflare’s Workers Logs for a short rolling window (currently no more than 7 days) and are not exported elsewhere.
- Email josh@spanner.pro and we will action a deletion request within 30 days.
Your rights
You can access, correct, export or delete your data. On-device data can be edited or deleted directly in the app.
To delete the cloud copy and the email account we use for sign-in, use Delete account in Settings, or email josh@spanner.pro from the address you signed in with. We will action a deletion request within 30 days.
If someone whose details you stored contacts us about their data, we will direct them to you as controller where that is appropriate, and help you remove cloud copies we hold as processor.
A Pro subscription is billed by Apple or Google. Deleting your Spanner data does not cancel that subscription; manage or cancel it in your store account.
You also have the right to object to processing, to restrict processing, and to complain to the Information Commissioner’s Office (ico.org.uk) about processing where Spanner is the controller.
Children
Spanner is a tool for people running their own trade and is not intended for anyone under 18.
International transfers
Backed-up records and photos are stored in the European Union. Cloudflare may still process requests from other regions to serve the API. Where data is processed outside the UK, transfers are protected by UK-approved safeguards such as the International Data Transfer Agreement or Addendum.
Changes
We will update this page when our practices change and update the date at the top. Material changes will be flagged in the app.