Last updated: 22 April 2026
Joust Technologies Ltd ("Joust", "we", "us") operates the Joust website and app, including client portal pages that your clients may access via a secure link.
Controller: Joust Technologies Ltd
Contact: contact@withjoust.com
Registered address: [insert registered address]
Account data
Name, email address, password (stored as a secure hash), and authentication and session identifiers (managed via Better Auth).
Workspace and business data
Projects, client records, proposal and contract content, invoice details, payment status, reminder settings, and related metadata.
Time tracking data
Time entries including timestamps, duration, project and task associations, and notes.
Client portal data
Information your clients view or submit through a portal link, such as approvals, signatures, and payment actions, tied to a secure portal token.
Payment data
Payment initiation and status data processed via Stripe and TrueLayer. We do not store full card details or bank credentials — these are handled directly by our payment providers.
Usage and device data
Log data including IP address, device and browser information, and product events used for security, reliability, and service improvement.
| Purpose | Description |
|---|---|
| Providing the service | Creating accounts, storing your projects and documents, generating proposals, contracts and invoices, and running client portal flows |
| Payments and billing | Processing subscription payments via Stripe and open banking payment links via TrueLayer |
| Communications | Sending transactional emails via Resend, such as authentication, invoice reminders, and product notifications |
| Security | Preventing abuse, investigating suspicious activity, and maintaining audit trails for sensitive actions such as signing, approvals, and payment state changes |
| Product improvement | Understanding feature adoption and fixing issues, using aggregated usage data |
We use the following third-party providers to operate Joust:
| Provider | Purpose | Location |
|---|---|---|
| Railway | Cloud hosting and databases | US |
| Stripe | Subscription payment processing | US / EU |
| TrueLayer | Open banking payment initiation | UK / EU |
| Resend | Transactional email delivery | US |
| Better Auth | Authentication and session management | — |
We do not sell your data to third parties. We may disclose data where required by law or to protect the rights and safety of Joust, our users, or others.
Some of our subprocessors process data outside the UK and EU, primarily in the United States. Where this occurs, we rely on appropriate transfer mechanisms, including the UK International Data Transfer Agreement (IDTA) and EU Standard Contractual Clauses (SCCs), as applicable.
| Data type | Retention period |
|---|---|
| Active account data | Retained while your account is open |
| Deleted accounts | Retained for 30 days, then deleted or anonymised |
| Financial records (invoices, payments) | Retained for 7 years to meet UK tax and accounting obligations |
| Audit logs and security events | Retained for 12 months |
| Server logs | Retained for 90 days |
We take reasonable technical and organisational measures to protect your data, including:
No system is completely secure. If you believe your account has been compromised, please contact us immediately at contact@withjoust.com.
Depending on where you are located, you may have the following rights regarding your personal data:
To exercise any of these rights, contact us at contact@withjoust.com. We will respond within 30 days.
If you are in the UK, you may also lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk. If you are in the EU, you may contact your local supervisory authority.
Joust operates as a platform used by freelancers and agencies ("customers") to manage their own clients. When a customer uploads client data to Joust — such as names, email addresses, or payment details — Joust acts as a data processor on that customer's behalf, and the customer acts as the data controller for that data.
Customers are responsible for providing appropriate privacy notices to their own clients and for ensuring they have a lawful basis to share that data with Joust. If you would like a Data Processing Agreement (DPA), please contact us at contact@withjoust.com.
For information about how we use cookies and how to manage your preferences, please see our Cookie Policy.
We may update this policy from time to time. If we make material changes, we will notify you by email or via an in-app notice before the changes take effect. The "Last updated" date at the top of this page will always reflect the most recent version.
Joust Technologies Ltd — contact@withjoust.com