Jewgo Account Privacy Policy
Effective 2026-09-28. This document covers the Jewgo Account identity platform only. Jewgo Nav, Jewgo Biz and Jewgo Card each publish their own Terms of Service and Privacy Policy, linked in the Contact section below.
This Privacy Policy explains how Jewgo LLC ("Jewgo," "we," "us," or "our") collects, uses, shares, and retains personal information through Jewgo Account — the single sign-in service at auth.jewgo.app used by Jewgo Nav, Jewgo Biz and Jewgo Card. It does not cover what a product does with your activity once you are signed in; see that product’s own Privacy Policy, linked in Section 16 below. Capitalized terms not defined here have the meaning given in our Terms of Use.
1. What Jewgo Account Is
You sign in to Jewgo Nav, Jewgo Biz, and Jewgo Card with one Jewgo Account. Your Jewgo Account holds your sign-in identity — your email address, password hash, and any Google or Apple sign-in identifiers you link. Each Jewgo product keeps its own profile and activity, linked to that one identity. A display name or profile you set in one product is not copied to the others.
2. Information We Collect
Account information
- Email address, and a phone number if you add one
- Name, display name, and username
- Profile photo
- Birthday, if you provide one
- A salted password hash (we never store your password in plaintext)
- A one-time sign-in or email-verification code you request, stored as a salted hash until it is used or expires
- Authentication identifiers from Google or Apple Sign In, if you link them
- A two-step verification (TOTP) secret and recovery codes, if you turn on two-step verification
Session and device information
- Active sign-in sessions and the devices/browsers they belong to, so you can see and end them
- IP address, and a coarse country/region/city derived from it, captured for fraud prevention and security during sensitive actions, and at account creation for accounts created through Google or Apple sign-in or through an emailed one-time sign-in code — not for a password signup
Terms acceptance
- Whether and when you accepted our Terms of Use, which version, and (for the audit trail) the IP address and user agent the acceptance came from
Administrative and audit logs
- A record of administrative actions taken on an account (for example, a suspension), for accountability and security review
3. How We Use Information
- Authenticate you and maintain your sign-in session across Jewgo Nav, Jewgo Biz and Jewgo Card
- Operate two-step verification and account-recovery flows
- Detect, investigate, and prevent fraud, abuse, and unauthorized access
- Send account and security notices (for example, a new-device sign-in or a password change)
- Comply with legal obligations and enforce our Terms of Use
4. What Each Product Learns About You
When you sign in to a Jewgo product, Account issues that product a token bound to it (it cannot be used against a different product) carrying only: a stable account identifier, and — only if that product asked for the corresponding permission — your email address, whether that email is verified, your name, your one Jewgo-wide username, and your profile photo. Nothing else in Section 2 is released to a product through this token.
Each product then keeps its own profile and activity on top of that identity, governed by that product's own Privacy Policy — Account does not see or store that activity.
5. Sharing Information
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under California law.
We may disclose information:
- To Jewgo Nav, Jewgo Biz and Jewgo Card, as described in Section 4, when you sign in to one of them
- To the service providers listed in Section 10, acting on our behalf under contractual confidentiality and security obligations
- To comply with law, valid legal process, or to protect rights, safety, and property
- In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections
6. Data Retention
- Account profile
- kept while your Jewgo Account is active; deleted immediately, with no grace period, when you delete your Jewgo Account — except the limited records below, kept after deletion for the reasons stated
- Sessions and devices
- kept while a session is active; an expired or revoked session is deleted within 7 days. Deleted immediately, along with every other session, when you delete your Jewgo Account
- Signup IP and country/region/city
- retained with the account record for fraud and abuse defense (written at account creation for Google, Apple, or one-time-code sign-in — not for a password signup — see Section 2); deleted with the account
- One-time sign-in and email-verification codes
- stored only as a salted hash; deleted within 1 day of expiring if unused, or immediately once used. A password-reset code is deleted within 7 days of expiring if unused
- Terms acceptance records
- kept as an audit trail while your Jewgo Account is active, and deleted with the account — they do not outlive the identity they document
- Data export requests
- a request to export your data is kept for 180 days so you can be shown its status; the exported file itself is deleted within 7 days of being generated
- Administrative audit logs
- kept indefinitely, and not deleted when an account is deleted — this is the record of what an administrator did (for example, a suspension), and its accountability value depends on it surviving the account it concerns. If the account that took the action is itself later deleted, we keep the audit entry rather than refuse the deletion: the reference to that account is removed and replaced with a one-way, non-reversible label, so the entry stays traceable to "the same administrator" without retaining that person's identity or email
- Deletion records
- when you delete your Jewgo Account, we keep a permanent record that it was deleted and a one-way cryptographic hash of the email address or sign-in provider identifier involved — never the email address or identifier itself. This is what stops a deleted identity from being quietly recreated to re-enter a product it was removed from, and it is also how we can confirm a deletion took place if you ask. We also keep, in a separate erasure record, the deleted account's internal identifier and the deletion time, which is the deletion notice a product retrieves in order to erase what it holds for that identity and then acknowledge that it has done so; this erasure record may remain after every product has acknowledged it
- Backups
- backup copies may retain deleted data until they are rotated out under our backup-retention schedule
7. Deleting Your Jewgo Account
Deleting your Jewgo Account permanently deletes the sign-in identity itself, immediately and with no grace period. You are signed out of Jewgo Nav, Jewgo Biz and Jewgo Card everywhere, and Jewgo Account publishes a deletion notice for that identity. Each product is responsible for retrieving that notice and erasing what it holds about you, under that product's own Privacy Policy — Jewgo Account does not reach into a product and erase its data itself, so deleting your Jewgo Account does not by itself erase what a product holds. Not every product retrieves these notices yet; a product that does not will not erase anything because you deleted your Jewgo Account. You can ask any product directly to delete what it holds about you, under that product's own Privacy Policy.
If you want to leave only one product and keep your Jewgo Account (and your other products), delete your account from inside that product instead — that erases what that product holds for you without touching your identity or your other products.
To delete your Jewgo Account, use the Delete Account page in your Account settings, or contact [email protected]. The administrative audit log, the hashed deletion record, and the erasure record each product retrieves to carry out its own deletion, all described in Section 6, are kept even after deletion, for the reasons stated there; backups that already contain your data age out on their own schedule, also described in Section 6.
8. Your Rights
Subject to applicable law, you may:
- Access your data: request a copy of the personal information Jewgo Account holds about you
- Correct inaccurate information: edit your profile, or ask us to update a record
- Delete your Jewgo Account, as described in Section 7
- Export your data: receive a copy of your Account data in a machine-readable format
- Withdraw consent for optional processing, such as two-step verification you chose to turn on
To exercise any of these rights, contact [email protected]. We will respond within 30 days. We will not discriminate against you for exercising your rights.
If we deny all or part of your request, you may appeal by replying to our decision or emailing [email protected] with the subject "Privacy Request Appeal." We will review the appeal and respond within 30 days. If we deny your appeal, we will explain how to contact the appropriate state regulator.
9. California & US State Privacy Rights
If you are a resident of California, Virginia, Colorado, Connecticut, Utah, or another U.S. state with a comprehensive privacy law, you have the right to:
- Know the categories and specific pieces of personal information we collect, use, and disclose
- Delete personal information we have collected about you, subject to legal exceptions
- Correct inaccurate personal information
- Opt out of the "sale" or "sharing" of personal information: Jewgo Account does not sell or share personal information for cross-context behavioral advertising, but you may still submit a request
- Be free from retaliation for exercising your rights
Categories of personal information collected in the prior 12 months: identifiers (name, email, phone, account ID), internet/network activity (session and device data), and geolocation data (coarse, IP-derived). Disclosed for business purposes to the service providers listed in Section 10. Sources: directly from you, automatically from your device, and from Google or Apple if you link a sign-in provider.
Submit a verifiable request to [email protected]. You may use an authorized agent; authorized agents must provide a signed written authorization from the consumer, and Jewgo may also require the consumer to verify their identity directly with us.
10. Security
- TLS for data in transit; disk-level encryption at rest with our hosting providers
- Salted password hashing (bcrypt); your password is never stored in plaintext and is never visible to us
- Two-step verification (TOTP) available on every account, with recovery codes
- Short-lived access tokens and secure, audience-bound sessions
- Rate limiting and abuse detection on sign-in, sign-up and password-reset paths
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and, where required, regulators without undue delay and within the timelines required by applicable law.
11. Children's Privacy
Jewgo Account is not directed to children under 13 and we do not knowingly collect personal information from children under 13. If a birthday you enter at sign-up or in your profile shows you are under 13, we will not create or update the account. If we otherwise learn that a Jewgo Account belongs to a child under 13 — including if you tell us at [email protected] — we will delete the account and its information, except for the limited records described in Section 6 that are kept after any account deletion, and publish a deletion notice for each product as described in Section 7.
12. International Users & Data Transfers
Jewgo Account is operated from the United States. If you access it from outside the U.S., your information will be transferred to, stored, and processed in the U.S. and other countries where our service providers operate. For transfers from the EU/EEA, UK, and Switzerland, we rely on Standard Contractual Clauses or other lawful transfer mechanisms with our sub-processors.
13. Cookies & Tracking
The Jewgo Account sign-in pages (auth.jewgo.app) set one strictly-necessary cookie to hold your session; it cannot be disabled without signing you out. We do not run advertising trackers or web analytics (such as Google Analytics or PostHog) on these pages. A product you sign in to may use its own cookies and analytics once you land back on it, as described in that product's own Privacy Policy.
14. Service Providers & Sub-processors
We use the following service providers to operate Jewgo Account:
- Cloudflare
- network edge (Cloudflare Tunnel) and DDoS protection for every account; our production configuration uses Cloudflare R2 for object storage to store profile photos. Privacy policy.
- Google Sign-In
- authentication, if you choose to link or sign in with Google. Google privacy policy.
- Apple Sign In
- authentication, if you choose to link or sign in with Apple. Apple privacy policy.
- Resend
- transactional email delivery (sign-in codes, security notices, password reset) — our configured email provider. Resend privacy policy.
- GlitchTip
- self-hosted, Sentry-compatible application error monitoring, used to diagnose failures in the identity service, if and while enabled.
- OpenTelemetry-based observability
- backend telemetry and tracing, exported to a self-hosted collector, if and while enabled. OpenTelemetry project.
- Cloud hosting providers
- for our database, application servers, and backups. Specific providers and DPAs available on request to [email protected].
Each provider processes personal information on our behalf under contractual confidentiality and security obligations and only for the purposes we instruct.
15. Updates to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and provide notice of the change before it takes effect, using the contact or in-product notice appropriate to the change. This policy describes our data practices; it does not replace any consent choice required by law.
16. Each Product’s Own Privacy Policy
This policy covers the Jewgo Account identity only. Each product's own Privacy Policy covers what it does with your activity inside it:
17. Contact & Data Controller
The data controller for personal information processed under this policy is:
- Company
- Jewgo LLC
- Address
- 20401 Northwest 7th Court, Miami Gardens, FL 33169, USA
- Privacy
- [email protected]
- Support
- [email protected]