Skip to content
Legal

Privacy Policy for Online Applications

All Legal Policies

Effective September 8, 2026

1. What this policy covers

This policy explains what information Jones & DeMille Engineering (“JDE,” “we,” “us”) collects when you use one of our online applications, why we collect it, and who we share it with.

It applies to:

  • civiclinQ
  • Any other public-facing application JDE hosts that links to this policy

We operate some of these applications on behalf of a city, county, or special service district. When you submit information through one of those applications, you are also giving that information to the agency. This policy describes what JDE does with it. What the agency does with it is governed by the agency’s own rules and by public-records law. Our corporate website, jonesanddemille.com, has its own privacy policy and the terms in that policy are not applicable to this policy.

2. Information you give us

We collect the information you enter, including:

  • Your name, mailing address, email address, and phone number
  • Business and license information, such as a contractor license number or business name
  • Property and project information, including addresses, parcel numbers, and site details
  • Files you upload, such as plans, permit documents, photographs, and supporting records
  • Account credentials, when an application requires you to sign in
  • Payment information, when you pay a fee through an application. When you pay a fee, your card details are entered with and handled by our payment processor, Stripe, under Stripe’s privacy policy. JDE does not receive or store your full card number.

We ask only for the information needed to process your submission, and where a form requests a sensitive identifier, it tells you why.

3. Information collected automatically

When you use one of our applications, our systems and our hosting providers record:

  • Your IP address, and the general geographic area it indicates
  • Your browser type, operating system, and device characteristics
  • The pages you open, the actions you take, and when you take them
  • Referring pages and error messages

We use cookies and similar browser storage to keep you signed in, remember your preferences, and keep the application working. We do not use advertising cookies, and we do not sell your information.

4. How we tell people from bots

We use automated tools to tell the difference between a person and a bot, and to block automated abuse of our applications. This protects the accuracy of the records our clients rely on.

To do this, our applications use Google Firebase App Check together with Google reCAPTCHA. These services collect technical signals from your browser or device — including your IP address, browser and device characteristics, and how you interact with the page — and score how likely it is that a real person made the request. Google processes this information on our behalf under its own terms. You can read Google’s privacy policy at policies.google.com/privacy.

We use these signals only to protect our applications and the information in them. We do not use them for advertising, we do not use them to build a profile of you, and we do not sell them.

If an automated check blocks you by mistake, contact us using the information in Section 12 and we will help you finish your submission.

5. How we use your information

We use the information we collect to:

  • Process and route the applications, reports, and requests you submit
  • Communicate with you about your submission
  • Collect fees
  • Operate, maintain, secure, and improve our applications
  • Prevent fraud, abuse, and automated attacks
  • Meet our legal, contractual, and public-records obligations

We do not sell your personal information, and we do not use it for targeted advertising.

6. Automated and AI-assisted features

Some of our applications use automated or AI-assisted features to help process what you submit — for example, checking a form for completeness or summarizing an uploaded document. Where we use these features, we select vendors and plans that do not use the content you submit to train AI models, and we configure those services accordingly. AI-assisted output is not guaranteed to be accurate or complete. You are responsible for reviewing and verifying any AI-generated result before you rely on it, and for the accuracy of what you submit through our applications.

7. Who we share information with

The agency the application serves. When you submit through an application we operate for a city, county, or district, your submission goes to that agency. The agency decides how it is used, retained, and disclosed.

Service providers. Companies that host, secure, or support our applications — including cloud hosting, email delivery, abuse prevention, and payment processing (Stripe). They may use your information only to perform services for us.

Others, when required. When you direct us to, when the law or a court order requires it, or when we need to protect the rights and safety of people who use our applications.

We do not sell your personal information, and we do not share it for advertising.

8. Public records

Information you submit to a government agency through one of our applications may become a government record. In Utah, those records are governed by the Government Records Access and Management Act (GRAMA) and by the agency’s own records policy, which decide what is public and what is protected.

Send records requests, and requests to correct or remove a record, to the agency that received the submission. We will help you find the right contact.

9. How long we keep information

Information you submit through an application stays in that application so the agency we serve can use it, for as long as our agreement with the agency requires. Most submissions become that agency’s record — we hold them on its behalf and do not delete them on our own. Send corrections and removal requests directly to the agency (see Section 8); if requested, we will help you find the right contact for your specific agency.

Where we hold personal information in our own right, such as an account you created with us, you can ask us to remove it at any time and we will, unless we are required to keep it.

We keep backups of our systems for 30 days, solely for disaster recovery. Information removed from a live application may remain in a backup until it ages out and is overwritten.

10. How we protect information

We encrypt information in transit, limit who inside JDE can see what, log access to our systems, and review those systems regularly. No system is perfectly secure and we cannot promise otherwise, but we handle the information you give us with the same care we give our own. If a security incident compromises your personal information, we will notify you and the affected agency as required by applicable law.

11. Your choices

You may ask us to:

  • Tell you what personal information we hold about you
  • Correct information that is wrong
  • Delete information, where we are not required to keep it
  • Give you a copy of what you submitted

Email privacy@jonesanddemille.com. We will respond within 45 days. If your request concerns a submission made to a government agency, we will point you to that agency, because the record is theirs.

We do not knowingly collect information from children under 13. If you believe a child has given us information, contact us and we will delete it.

12. Changes and contact

We will update this policy as our applications change. We will post the updated version with a new effective date and note material changes on the application itself.

Questions about this policy:

Jones & DeMille Engineering
1535 S 100 W, Richfield, UT 84701
privacy@jonesanddemille.com