The short version: we don’t sell your data.

We only collect what we need to build, ship, and support Sortd™. We never sell or share it with third parties for marketing or promotion. Reply STOP to any SMS and we stop.

Effective 2026-06-16 · JNS RE Holdings LLC (Automate Boring)

01 · Who we are

Automate Boring is a brand operated by JNS RE Holdings LLC. We ship Sortd™, a SaaS platform for Amazon DSP (Delivery Service Partner) owners. Sortd helps DSP customers run compliance, scheduling, HR, hiring, performance, and device management workflows.

The data controller for this site is JNS RE Holdings LLC. Contact us at automateboringai@gmail.com.

02 · What we collect

From people visiting this marketing site, we collect only:

That’s the full list. No cookies beyond what Next.js needs to render the page. No third-party trackers. No fingerprinting. No retargeting pixels.

03 · How we use it

04 · What we never do

Opt-in data and phone numbers collected for SMS are never sold or shared with third parties for marketing or promotional purposes.

05 · SMS (10DLC) terms

When you check the SMS consent box on a lead form, you agree to the following language verbatim — we store which version of this string you saw, along with the date and time:

“By checking this box, you agree to receive automated operational SMS messages from Sortd™, operated by JNS RE Holdings LLC (Automate Boring). Message frequency varies. Msg & data rates may apply. Reply STOP to opt out.”

You can reply STOP at any time to opt out. You can reply HELP to get contact info. We use a 10DLC-registered Twilio campaign; message and data rates may apply.

06 · Device Management (Sortd Device Management)

Our role. Sortd Device Management is an Enterprise Mobility Management (EMM) module that lets our business customers — Amazon Delivery Service Partners (“DSPs”) — manage the company-owned Android phones they issue to their own delivery associates. These are company-owned, business-only devices locked to approved work apps (non-work apps are blocked).

What device data we read. For an enrolled company-owned device, we read only the following categories of operational and compliance data:

  1. Device identifiers — and enrollment identity, used to uniquely reference the device.
  2. Device model and brand — manufacturer, model, and brand.
  3. Enrollment and compliance status — the device’s overall enrollment and compliance state.
  4. Applied policy — the policy currently applied to the device.
  5. Installed-application inventory — the full list of applications present on the device, including apps that have been removed, used to confirm required work apps are installed and non-work apps are not.
  6. Device settings status — security-relevant device settings, for example encryption and whether the device meets policy.
  7. Software information — operating-system version, security-patch level, and related build/software details.
  8. Hardware and system status — hardware status and system properties, for example device build and configuration values.
  9. Memory (and storage) information — memory and storage capacity and usage at the device level.
  10. Display information — display/screen characteristics of the device.
  11. Network information — device-level network status and connectivity information. This does not include the contents of the driver’s communications.
  12. Power-management events — device-level power events such as boot, shutdown, and battery state changes.

This is the complete set of categories we read. We do not enable additional reporting beyond what is listed here.

Remote lock and wipe. Because these are company-owned devices, the DSP customer can, through the console, remotely lock a device and remotely wipe (factory-reset) a device. These actions are used for lost, stolen, or offboarded devices. They are guarded by an explicit confirmation step and are strictly scoped to the customer’s own enterprise; a customer can never lock or wipe a device belonging to another customer.

What we do NOT access. The Android Management API does not expose, and we do not collect, read, or store, any of the following:

Because the device is locked to approved work apps, it is not intended to hold personal data. We see that a work app is installed; we do not read personal content.

Retention and use. We process the categories above only to provide the Device Management service to the DSP customer — enrolling devices, applying and verifying policy, managing required work apps, reporting compliance, and performing lock/wipe at the customer’s direction. We retain this operational state while the device is enrolled and as needed for the customer’s records and our legal obligations; we delete or de-identify it on a defined schedule after a device is unenrolled or a customer’s account is closed, unless longer retention is required by law. We do not sell device data and do not use it for advertising. We act on the instructions of the DSP customer, who is the controller of its drivers’ device data.

Consent and notice. Before a device is enrolled, the DSP customer is required to present each driver with a managed-device notice describing this access and the lock/wipe capability. The customer separately authorizes this access in its Device Management agreement with us.

Note on category mapping. The 12 categories above map exactly to the 12 categories enumerated in the “Data processed by the service” section of our Device Management Terms; both lists are identical in content and order.

Not legal advice. This section describes our data practices for the Device Management module and is not legal advice. DSP customers are responsible for their own compliance with applicable employment, privacy, and notice laws, including obtaining any employee consents required where they operate.

07 · Your rights

You can email automateboringai@gmail.com to:

If you’re a California resident, the CCPA gives you additional rights. We honor them. No fee, no retaliation.

08 · Data retention

Lead form submissions are retained until you ask us to delete them or until the underlying business purpose expires (typically 36 months for prospect data, longer if you become a customer). SMS opt-outs are retained indefinitely because we have to remember not to text you.

09 · Where we store it

Data lives in Supabase (PostgreSQL) in the United States. Our infrastructure is hosted on Vercel (marketing site) and Railway (application). All transport is TLS. Sensitive columns use row-level security.

10 · Changes to this policy

We’ll update this page if we change what we collect or how we use it. The effective date at the top of the page reflects the latest revision. Material changes will also be communicated directly to active customers.

11 · Contact

Questions? Complaints? Want to invoke one of the rights above? Email automateboringai@gmail.com. A human will reply within two business days.