Privacy Policy

Last Updated: September 9, 2026

1. Introduction

QuickJHA ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit quickjha.com or use our safety document creation services.

2. Merchant of Record & Payment Data Handling

Payment Security & Merchant of Record Notice:

All payments and financial transactions are processed securely by our Merchant of Record, Paddle.com Market Ltd (or Paddle Payments Limited). QuickJHA does not store or process payment card numbers, CVVs, or sensitive financial data on our servers. All payment data is handled directly by Paddle in compliance with PCI-DSS Level 1 security standards.

3. Information We Collect

We collect information that you provide directly when creating an account or using our generator:

  • Account & Identity Data: Name, email address, company name, and authentication details (e.g. Google OAuth profile data).
  • Project & Safety Document Data: Project names, task descriptions, hazard details, control measures, and PPE selections entered during document creation.
  • Technical & Device Data: IP address, browser type, operating system, referral URLs, and pages visited on QuickJHA.
  • Transaction Metadata: Order IDs, purchase amounts, and document unlocking statuses provided by Paddle.

4. How We Use Your Information

We use the collected information for the following purposes:

  • To generate, format, and deliver your customized JHA, AHA, and JSA safety documentation.
  • To verify account access, authentication, and document ownership.
  • To process payments, fulfill orders, and issue invoices via Paddle.com.
  • To send essential transactional notifications, invoice receipts, and customer support responses.
  • To improve our AI safety models and platform user experience.
  • To detect, prevent, and address technical errors or security threats.

5. Data Sharing & Third-Party Processors

We do not sell, rent, or trade your personal information. We only share information with trusted third-party service providers necessary to operate QuickJHA:

  • Paddle.com: Merchant of Record and payment gateway handling order processing, tax compliance, and payment verification.
  • Google OAuth / Socialite: Secure third-party authentication provider.
  • Email Delivery Infrastructure: Used to send invoice confirmations and safety review updates.

6. Security Measures

We implement robust technical and organizational security measures to safeguard your information:

  • 256-bit SSL/TLS encryption for all data in transit across HTTPS.
  • Secure HTTP-only cookies and Content Security Policy (CSP) headers.
  • Restricted database access and password hashing using bcrypt.
  • Full PCI-DSS compliance via Paddle for financial transactions.

7. Your Privacy Rights (GDPR & CCPA)

Depending on your location, you have the following rights regarding your personal data:

  • Right to Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate account details.
  • Right to Erasure ("Right to be Forgotten"): Request full deletion of your account and associated documents.
  • Right to Data Portability: Receive your safety documents and data in a structured, standard format.

To exercise any of these rights, please email us at info@quickjha.com.

8. Data Retention

We retain your account and document data for as long as your account remains active or as needed to provide our services. You may request account deletion at any time by contacting support.

9. Contact Information

For privacy inquiries, data deletion requests, or security questions, please contact us: