We use cookies for analytics (PostHog, Google Analytics) and to show Instagram posts. They stay off until you choose. Read our Privacy Policy.

Privacy Policy

Effective date: 2026-09-28. Last updated: 2026-10-05

This Privacy Policy explains how Jewgo LLC ("Jewgo," "we," "us," or "our") collects, uses, shares, and retains personal information when you use the Jewgo Biz app, merchant storefronts and business dashboard, and the Jewgo Biz websites, and related services (the "Service"). It does not cover jewgo.app's marketing site, which has its own short privacy section at jewgo.app/privacy, or Jewgo Account, which has its own Privacy Policy covering the shared sign-in identity. Capitalized terms not defined here have the meaning given in our Terms of Service. When you submit a quote request, booking, order, or payment through a storefront, we disclose the information needed to complete it to the relevant merchant and to the payment providers identified in § 11.

1. Information We Collect

Account Information

  • Name and display name
  • Email address
  • Phone number (if you add one for contact)
  • Profile photo and bio
  • Authentication identifiers from Google or Apple Sign In (if used)
  • Sign-in credentials and one-time authentication codes are handled by Jewgo Account, not by Jewgo Biz. See the Jewgo Account Privacy Policy for information about those data.

Your Jewgo Account

You sign in to Jewgo Nav, Jewgo Biz, and Jewgo Card with one Jewgo Account, operated by Jewgo LLC at auth.jewgo.app. Your Jewgo Account holds your sign-in identity (your email address, password hash, and Google or Apple Sign In identifiers). Each Jewgo product keeps its own profile and activity, linked to that one identity. A display name or profile you set in one product is not copied to the others. Jewgo Account has its own Privacy Policy covering that shared identity; this policy covers Jewgo Biz's own profile, storefront, and activity data.

Platform Activity

  • Merchant storefronts you create or manage (business profile, products, services, photos, hours, service areas, contact details, and storefront health recommendations)
  • Marketplace activity such as reviews, saved businesses, quote requests, bookings, orders, invoices, payment activity, refunds, promotions, and reports
  • Customer and merchant messages sent through storefront lead threads and related commerce features
  • Dashboard and analytics activity for storefronts you manage
  • Identity-verification materials you submit for merchant or ownership review (such as business documents or government ID, where requested)

Location Data

  • Device GPS or IP-derived location, used with your permission to show nearby businesses and personalize marketplace discovery
  • If you set a default location in your profile, we store it on your account so we can personalize search results until you change or remove it
  • The most recent map-browse location may be stored on your account to resume sessions
  • You can clear stored locations at any time from Settings or by deleting your account

Device, Network & Usage Data

  • Device type, operating system, app version, and locale
  • App interactions, screen views, and performance metrics
  • Server log data, including request paths, timestamps, and error traces
  • IP address, and a coarse country/region derived from it, captured during sensitive actions (such as a business claim, a lead, or a storefront submission) for fraud prevention and security auditing. Sign-up and sign-in are handled by Jewgo Account (see "Your Jewgo Account" above); Biz's own historical sign-up-IP field is a leftover from before that move, is no longer written for any current sign-up, and is deleted along with the rest of your account data if you delete your account.
  • Push notification tokens (if you opt in)

Promotions & Sweepstakes

Jewgo Biz does not currently host sweepstakes or contests and does not collect sweepstakes-entry data. Merchant storefronts may offer discounts, specials, or other promotions; these are not sweepstakes and may be subject to their own terms. If Jewgo itself offers a sweepstakes or contest in the future, its own published Official Rules will describe exactly what entry information is collected and how long it is retained, and we will update this Policy before it launches.

Payment Information

Merchant plan subscriptions and other in-app purchases are billed by the Apple App Store or Google Play Store, with RevenueCat supporting subscription management; Stripe is not used to bill a merchant plan subscription. Stripe Connect processes customer-to-merchant payments through storefronts (including quotes, bookings, invoices, and checkout), and Stripe Checkout may process a one-time merchant fee where one is offered. Jewgo does not directly collect or store full payment card numbers. We receive subscription or payment status, transaction identifiers, amounts, refund/dispute status, and renewal dates needed to operate paid features and payment facilitation.

2. How We Use Information

  • Operate, maintain, and secure the Service
  • Display storefronts and personalize marketplace search and discovery
  • Send transactional notifications (account, security, commerce activity, and storefront updates you opt into)
  • Send marketing communications you have opted into, which you can stop at any time via the unsubscribe link or notification settings
  • Provide dashboard analytics to listing and storefront owners about their own listings
  • Facilitate quotes, bookings, invoices, and payments between customers and merchants where those features are enabled
  • Detect, investigate, and prevent fraud, abuse, and policy violations
  • Comply with legal obligations and enforce our Terms
  • Improve product performance, including aggregated analytics

3. Sharing Information

We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under California law.

We may disclose information:

  • To service providers and sub-processors (see § 11) acting on our behalf under contractual confidentiality and security obligations
  • To merchants when you interact with their storefront (e.g., review, inquire, request a quote, book, order, or pay)
  • Between Jewgo products: your Jewgo Account sign-in identity is available to each Jewgo product you sign in to, so you can use one account across them
  • To other users, in the form of public profile content, storefront content, reviews, and similar content you choose to publish
  • To comply with law, valid legal process, or to protect rights, safety, and property
  • In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections

4. Data Retention

We retain personal information only as long as needed for the purposes described in this policy, including for legal, security, and operational reasons. Indicative retention periods:

  • Account profile while your account is active; deleted within 30 days of account deletion (some records may be retained longer for legal compliance or fraud prevention)
  • Listings, reviews, and public content retained while published; soft-deleted content may be retained for up to 15 days for recovery. If you delete your account, a public review you wrote is anonymized rather than deleted — the rating, text, and any owner reply are kept as part of the business's record, with your name and account link removed
  • Device / session location (GPS) used to show nearby results while location access is active; not kept as a separate long-term history beyond your saved default location and last map-browse location described above
  • Saved default and last-browse map location retained on your account until you clear them in Settings or delete your account
  • Server and security logs up to 90 days, longer where required for incident response
  • Signup IP and country retained with the account record for fraud and abuse defense
  • Transaction, invoice, and refund records retained as needed to operate payments, resolve disputes, and meet tax and accounting obligations; typically up to seven years for merchant billing and payment records
  • Merchant identity-verification materials the submitted documents themselves are deleted 30 days after we decide the review (approve or reject); the fact that a review happened and its outcome are kept for audit without the documents
  • Quote requests and lead conversations quote requests and lead conversations are normally purged 24 months after last activity. A conversation linked to a financial transaction may be retained until the associated financial records are deleted under this policy. When you delete your account, we remove your account link and direct contact fields (name, phone, email) from the conversation; messages may remain and may contain information you included in them
  • Push notification tokens a disabled push token is deleted 90 days after it was disabled
  • Renewal / trial-ending reminder records kept only as long as the related storefront exists; deleted when the storefront is
  • Backups we keep periodic backup copies of our systems on a rolling schedule for disaster recovery; a backup copy may retain deleted data until it is rotated out under that schedule

5. Your Rights

Subject to applicable law, you may:

  • Access your data: request a copy of personal information we hold about you
  • Correct inaccurate information: edit your profile or ask us to update records
  • Delete your account: you can delete your account at any time; deleting it in a Jewgo product permanently erases that product's profile and associated personal data, subject to limited exceptions (legal, fraud, financial records — see Data Retention above). Two exceptions work by removing your identity rather than the content itself: a public review you wrote is anonymized, not deleted (the rating, text, and any owner reply stay as part of the business's record), and messages in a quote-request/lead conversation remain with the business's side of that conversation with your name and account link removed. If you have an active paid plan purchased through the Apple App Store or Google Play Store, deleting your account does not cancel that subscription — billing continues through the applicable store until you cancel it there directly. If a storefront you solely own has a connected Stripe payout account, it is disconnected automatically as part of account deletion. Deleting your Jewgo Biz account does not delete your Jewgo Account, which you may still be using for Jewgo's other products. To delete your Jewgo Account itself, see Jewgo Account's Privacy Policy or contact [email protected]
  • Export your data: receive a copy of your account data in a machine-readable JSON format via the in-app data export feature; we will respond to written requests within 30 days
  • Object to or restrict processing of your personal information
  • Withdraw consent for optional processing (e.g., marketing, push notifications, Share Usage Analytics)

For EU/EEA/UK users, these rights are provided under GDPR Articles 15–22 and the UK GDPR. You may also lodge a complaint with your local supervisory authority.

Where the GDPR or UK GDPR applies, we rely on the following legal bases depending on the activity:

  • Creating and managing your account performance of a contract
  • Providing core platform features (marketplace discovery, storefronts, and commerce tools) performance of a contract
  • Transactional and security notices performance of a contract and, where applicable, legitimate interests
  • Personalizing your experience legitimate interests
  • Analytics and product improvement legitimate interests
  • Fraud detection, abuse prevention, and security legitimate interests
  • Marketing communications consent
  • Complying with legal obligations legal obligation
  • Precise device location (if you enable it) consent
  • Tax, accounting, and regulatory records legal obligation
  • Religion-adjacent inferences (e.g., from use of Jewish community features) where GDPR Article 9 applies: Article 9(2)(e): data manifestly made public by the data subject through voluntary use of the Jewish community features of the Service; and/or Article 9(2)(a): explicit consent where required by law. Exercise GDPR rights (including withdrawal of explicit consent where that is the basis) by contacting [email protected]. See also § 6.

The "legitimate interests" entries in the table above apply only to processing that is not special-category personal data under GDPR Article 9. Religion-adjacent processing that qualifies as special-category data is not grounded in Article 6(1)(f) legitimate interests as its Article 9 basis.

Where we rely on legitimate interests for non-special-category processing, you may object by contacting [email protected]. Where we rely on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights, contact [email protected]. We will not discriminate against you for exercising your rights.

If we deny all or part of your privacy request, you may appeal by replying to our decision or emailing [email protected] with the subject "Privacy Request Appeal." We will review the appeal and respond within the time required by applicable law. If we deny your appeal, we will explain how to contact the appropriate state regulator.

6. California & US State Privacy Rights

If you are a resident of California, Virginia, Colorado, Connecticut, Utah, or another U.S. state with a comprehensive privacy law, you have the right to:

  • Know the categories and specific pieces of personal information we collect, use, and disclose
  • Delete personal information we have collected about you, subject to legal exceptions
  • Correct inaccurate personal information
  • Opt out of the "sale" or "sharing" of personal information: Jewgo does not sell or share personal information for cross-context behavioral advertising, but you may still submit a request
  • Limit the use of sensitive personal information: we use sensitive information (such as precise location) only for the purposes described in this policy and not for advertising
  • Be free from retaliation for exercising your rights

Categories of personal information collected in the prior 12 months: identifiers (name, email, phone, account IDs), commercial information (subscription status), internet/network activity, geolocation data, user-generated content, and inferences drawn from the foregoing. Disclosed for business purposes to the service providers listed in § 11. Sources: directly from you, automatically from your device, from your Jewgo Account, and from authentication providers.

Submit a verifiable request to [email protected]. You may use an authorized agent; authorized agents must provide a signed written authorization from the consumer, and Jewgo may also require the consumer to verify their identity directly with us. Where California law applies, we may require documentation consistent with the CCPA and the California Probate Code for agency. California residents may also request information under California Civil Code § 1798.83 (Shine the Light) at the same address.

Religion-adjacent information: By its nature, Jewgo is a Jewish community marketplace. Your use of the Service (for example, browsing kosher businesses, Jewish-owned storefronts, or Jewish community services on Jewgo) may reveal preferences or affiliations related to religion. We use such information only to operate the Service, personalize discovery, improve the product, and keep the marketplace safe, not for cross-context behavioral advertising. We do not sell personal information or share it for cross-context behavioral advertising as defined under California law. We do not use religion-adjacent information to infer characteristics for advertising. Except as described in this Policy, we do not share religion-adjacent information with third parties beyond our service providers processing data on our behalf.

7. Security

We use a layered set of safeguards, including:

  • TLS 1.2+ for data in transit and disk-level encryption at rest with our hosting providers
  • Sign-in credentials (including password hashing) are managed by Jewgo Account; see its Privacy Policy for its safeguards
  • Short-lived access tokens, secure session cookies (HttpOnly, Secure, SameSite), and CSRF protections for the admin dashboard
  • Role-based access controls and audit logs for administrative actions
  • Rate limiting, abuse detection, and ongoing dependency vulnerability monitoring

No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and, where required, regulators without undue delay and within the timelines required by applicable law (including, where applicable, the 72-hour timeline under GDPR Article 33).

8. Children's Privacy

Jewgo is not directed to children under 13 and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact [email protected] and we will delete the information and the associated account. Jewgo complies with applicable U.S. state children's privacy laws and international equivalents where applicable. Where required by local law (for example, the EU and UK's higher digital age of consent), additional age limits may apply.

9. International Users & Data Transfers

Jewgo is operated from the United States. If you access the Service from outside the U.S., your information will be transferred to, stored, and processed in the U.S. and other countries where our service providers operate. For transfers from the EU/EEA, UK, and Switzerland, we rely on Standard Contractual Clauses or other lawful transfer mechanisms with our sub-processors.

10. Cookies, Analytics & Tracking

On our websites, we use a small number of cookies and similar technologies for the following purposes:

  • Strictly necessary authentication, session management, CSRF protection. These cannot be disabled.
  • Functional remembering your preferences (e.g., theme, language).
  • Analytics aggregate, privacy-respecting usage measurement to improve the product.

On the Jewgo Biz website, analytics and non-essential third-party embeds (such as PostHog, Google Analytics, and embedded social content) do not load until you consent through the cookie banner; strictly necessary cookies load regardless, since the site cannot function without them. If your browser sends a Global Privacy Control (GPC) signal, we treat it as an opt-out and do not load non-essential analytics or embeds, without requiring a separate banner interaction.

In our mobile apps, we use Firebase Analytics and PostHog for optional product analytics (we may send the same or overlapping event data to both services to measure and improve the Service). We use Firebase Crashlytics for crash reporting. Share Usage Analytics is off until you turn it on under Settings → Privacy; when it is off, we disable optional product analytics collection from these providers on your device. Crashlytics may still run so we can detect and fix crashes. Separately from on-device analytics, our own servers record operational events about storefront activity — such as a subscription changing state, a payment settling, or a business accepting a connection request. These server-side events are recorded against the business, not against you as an individual, and do not include message content, contact details, or addresses. Because they describe the operation of a storefront rather than your use of the app, they are not controlled by the Share Usage Analytics setting. You can also manage cookies through your browser settings; we honor Global Privacy Control (GPC) signals where applicable. Deleting your account does not automatically erase analytics events already sent to PostHog or Firebase Analytics under an identifier tied to you; email [email protected] and we will request deletion of your analytics profile from these providers.

11. Service Providers & Sub-processors

We use the following categories of service providers to operate Jewgo:

  • Cloudflare CDN, image storage (R2), and DDoS protection. Privacy policy · DPA.
  • Firebase (Google) push notifications, optional product analytics via the Firebase SDK, crash reporting, remote configuration. Firebase privacy · Google Cloud DPA.
  • PostHog optional product analytics, screen and funnel measurement, and related product metrics via the PostHog SDK when Share Usage Analytics is on; and server-side operational analytics about storefront activity (subscription state, payments, connection-request acceptance) sent from our backend, keyed to a business rather than an individual and not affected by that setting. PostHog privacy policy · PostHog DPA.
  • Google Sign-In & Google Maps authentication, mapping, geocoding. Google privacy policy.
  • Apple Sign In authentication for iOS users. Apple privacy policy.
  • Stripe one-time merchant fees (Stripe Checkout, where offered) and Stripe Connect payment processing, invoicing, and related payment operations for eligible storefront transactions. Stripe does not bill merchant plan subscriptions — those are billed by the Apple App Store or Google Play Store. Stripe privacy policy · Stripe DPA.
  • RevenueCat / Apple App Store / Google Play Store subscription and in-app purchase management and payment processing. RevenueCat privacy · Apple privacy · Google privacy.
  • Resend transactional and marketing email delivery. Resend privacy policy.
  • Sentry application error monitoring and performance tracing. Sentry privacy policy.
  • OpenTelemetry-based observability backend telemetry and tracing, exported to a self-hosted collector. OpenTelemetry project.
  • Cloud hosting providers for our database, application servers, and backups. Specific providers and DPAs available on request to [email protected].

Each provider processes personal information on our behalf under contractual confidentiality and security obligations and only for the purposes we instruct. Business customers requiring a Data Processing Addendum (DPA) may contact [email protected].

12. AI Features (Coming Soon)

We are developing optional AI-assisted features (for example, a community-focused chat assistant and AI-powered discovery aids). These features are not yet generally available to users. We are publishing this section in advance so it is clear how data will be handled when the feature launches. Before any AI feature is generally available, we will update this Privacy Policy (including the Service Providers list in § 11, retention specifics, and any new legal bases or choices) and advance the effective date, with any additional notice required by law.

  • AI features will be powered by one or more third-party large-language-model providers, which will be added to the Service Providers list above when the feature ships.
  • If you choose to use an AI feature, the messages and prompts you send may be transmitted to the LLM provider strictly to generate a response.
  • We may store chat sessions and any preferences or memories you opt into, for a limited retention period to operate and improve the feature. Specific retention windows will be disclosed here at launch.
  • AI features are entirely optional. You are not required to use them, and you can disable them in Settings when they ship.
  • Personal information collected through AI features is handled under the same protections described in this policy, including your rights of access, correction, and deletion.

13. Updates to this Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and provide notice before the change takes effect, using the contact or in-product notice appropriate to the change (for example, in-app or by email). This Policy describes our data practices; it does not replace any consent choice required by law.

14. Contact & Data Controller

The data controller for personal information processed under this policy is:

Version 2026-09-28