Privacy Policy
Last updated: June 14, 2026 · Effective: June 14, 2026
Short version: We collect only what we need to run the Service. We never sell your data. You can delete your account and data at any time — in the app or by emailing us.
This Privacy Policy explains how JDMarket ("we", "us", "our") collects, uses, stores, and protects personal information when you use the Service. By using JDMarket, you agree to the practices described here. Because we serve users in Canada, the United States, the United Kingdom, the European Union, Australia, and other countries, this policy is designed to meet Canada's PIPEDA, the EU and UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and comparable laws. Where a specific law gives you additional rights, those rights apply to you.
Information We Collect
| Category | Data collected | Required? |
|---|---|---|
| Account | Username, email address, hashed password | Yes |
| Notifications | Mobile push token & device platform (for app alerts); Telegram chat ID (if you connect Telegram) | Optional |
| Location | Approximate location (city/country) derived from your IP address; and, only if you grant permission in the mobile app, your device's precise location. Used solely to localize your searches — never for advertising. | Optional / Automatic |
| Usage | Saved searches, watch/alert configurations, alert history, AI filter prompts, saved favorites | Yes (core feature) |
| Billing | Stripe customer ID, subscription status, plan type. Full card details are never stored by us. | Paid plans only |
| Technical | IP address, browser/device type, server access logs | Automatic |
We do not collect any Facebook login, password, cookies, or session from you. For JDMarket Alerts, no Facebook account of yours is involved at all. The only Facebook-sourced data we process is the public Marketplace listing content described in Section 6.
How We Use Your Information
- To create and manage your account and authenticate you.
- To run your saved searches, alerts, and AI filtering on your behalf.
- To deliver the notifications you have configured by mobile push and, optionally, Telegram.
- To send transactional emails (email confirmation, password reset, billing receipts).
- To process payments and manage your subscription via Stripe.
- To enforce plan limits (daily search/alert limits, number of watches).
- To detect and prevent fraud, abuse, or security incidents.
- To improve the reliability and performance of the Service.
- To comply with legal obligations.
We do not: sell or rent your personal information, share it with third parties for their own advertising or marketing, or use your data to train AI models.
Legal Basis for Processing
Where the GDPR or UK GDPR applies, we rely on the following lawful bases (Article 6); where PIPEDA applies, we rely on your consent and our reasonable business purposes:
- Contract (Art. 6(1)(b)): creating and managing your account, processing payments, and running the searches and alerts you set up.
- Legitimate interests (Art. 6(1)(f)): retrieving public listing data, security monitoring, fraud prevention, and improving the Service — balanced against your rights and freedoms.
- Consent (Art. 6(1)(a)): optional features such as precise device location and Telegram notifications, which you can withdraw at any time.
- Legal obligation (Art. 6(1)(c)): keeping billing and tax records and responding to lawful requests.
Data Storage & Retention
Your data is stored on servers located in Toronto, Canada (DigitalOcean), using PostgreSQL with connection pooling. All connections use TLS encryption in transit.
- Account data: retained while your account is active, or until you delete it.
- Search runs & alert history: your search run history is automatically trimmed to your most recent runs, and your delivered alerts are kept as a rolling recent history in your in-app inbox.
- Public listing data: the listings we retrieve are stored to power matching and alerts, and are refreshed or replaced as your searches run; stale listings are periodically removed. We do not retain this operational data longer than needed to provide the Service.
- Access logs: retained for up to 30 days for security purposes.
- Billing records: retained as required by applicable tax and financial regulations (typically up to 7 years).
- Deleted accounts: when you delete your account, your personal data — including saved searches, alerts, favorites, and push tokens — is removed within 30 days, except records we are required to keep by law (such as billing/tax records).
Third-Party Services
We use the following sub-processors and third-party services to operate JDMarket:
| Provider | Purpose | Data shared |
|---|---|---|
| Stripe, Inc. | Payment processing & subscription management | Email, name, billing address, payment method (processed directly by Stripe) |
| DigitalOcean | Cloud infrastructure & hosting (Toronto region) | All data stored on their servers |
| Resend | Transactional email delivery | Your email address and email content |
| Cloudflare | DNS, DDoS protection, CAPTCHA (Turnstile) | IP address, browser fingerprint (for CAPTCHA only) |
| Expo (Expo Application Services) | Mobile push-notification delivery | Push token and notification content |
| Google Firebase Cloud Messaging | Android push-notification delivery | Android push token |
| ipwho.is | Approximate geolocation from IP | Your IP address (to derive city/country) |
| Decodo | Proxy infrastructure used to retrieve public listings | No user personal information is shared |
| Telegram | Notification delivery (optional) | Listing data sent to your Telegram chat (only if you connect Telegram) |
We share personal information only with the sub-processors listed above to operate the Service, or where required by law. We do not sell your personal information, and we do not share it with third parties for their own advertising or marketing. Each sub-processor has been selected for its privacy and security standards.
How We Retrieve Listings & Seller Data
JDMarket Alerts. For the managed service, our own servers retrieve publicly visible Facebook Marketplace listings on your behalf, through rotating IP addresses (proxy infrastructure). No Facebook account, login, cookies, or session of yours is used. The mobile app communicates with our servers over HTTPS; it does not record keystrokes or take screenshots.
Legacy Desktop Agent. If you use the optional Desktop Agent, it runs on your own computer and uses your own logged-in browser session, which stays entirely on your device. The Agent does not transmit your Facebook credentials, cookies, or session to our servers — it sends back only the public listing data it is instructed to retrieve.
Listing data about third parties. To provide alerts, we collect and store publicly visible information from Marketplace listings — such as the item title, price, description, photos, listing link, and the approximate location shown on the listing. This information can relate to the people who posted those listings (sellers), who are not our users and have not provided it to us directly. We process it under our legitimate interest (GDPR Article 6(1)(f)) in operating a listings-alert service, and we rely on the Article 14(5)(b) exemption from individually notifying each seller, because doing so would involve disproportionate effort. We keep this data only as long as it is useful for matching and alerts. If you are a seller and want listing information about you removed or no longer processed, contact [email protected] and we will action your request.
Cookies & Tracking
On the website, we use a single session cookie to keep you logged into the JDMarket dashboard. This cookie is:
- Set only after you log in.
- HttpOnly and Secure — it cannot be accessed by JavaScript and is only sent over HTTPS.
- Deleted when you log out or when your session expires.
In the mobile apps, we do not use cookies; your session is kept with a token (JWT) stored securely on your device and removed when you log out or delete your account.
We do not use advertising cookies, cross-site tracking, or third-party web analytics (e.g. Google Analytics), and we do not build advertising profiles or use fingerprinting. Cloudflare Turnstile (our CAPTCHA provider) may set a short-lived cookie on login and registration pages for bot detection only. The mobile push system (Expo / Firebase Cloud Messaging) uses a device/installation identifier to deliver notifications to your device — used only for notifications, never for advertising.
Data Security
We implement reasonable technical and organizational measures to protect your personal data, including:
- All data in transit encrypted via TLS 1.2/1.3 (HTTPS).
- Passwords stored as bcrypt hashes — we never store plaintext passwords.
- Database access restricted to internal services only — not publicly accessible.
- Regular automated backups with point-in-time recovery.
- DDoS protection via Cloudflare.
However, no method of electronic transmission or storage is 100% secure. In the event of a data breach that poses a risk to you, we will notify affected users and the relevant authorities as required by law (including, where applicable, within 72 hours under the GDPR).
Your Rights
Depending on where you live — Canada (PIPEDA), the EU & UK (GDPR), California (CCPA/CPRA), and elsewhere — you have some or all of the following rights:
- Access / Know: request a copy of, or information about, the personal data we hold about you.
- Correction: request correction of inaccurate or incomplete data.
- Deletion / Erasure: delete your account and associated personal data — directly in the app (Settings → Delete account) or by emailing us.
- Portability: request an export of your data in a machine-readable format, where technically feasible.
- Object / Restrict: object to, or ask us to restrict, certain processing based on our legitimate interests (GDPR Art. 21).
- Withdraw consent: turn off optional features (precise location, Telegram, push notifications) at any time in your settings or device settings.
- Opt out of sale/share (California): we do not sell or share your personal information as those terms are defined by the CCPA/CPRA, and you may limit the use of sensitive personal information.
- Non-discrimination: we will not discriminate against you for exercising your rights.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days (or the period required by your local law). You also have the right to complain to your data-protection authority — the Office of the Privacy Commissioner of Canada, your EU national authority, the UK ICO, or the California Privacy Protection Agency.
International Data Transfers
Your data is primarily stored and processed in Canada (Toronto), which the European Commission recognizes as providing an adequate level of data protection. Some of our sub-processors (such as Stripe, Cloudflare, Resend, Expo, and Google) are based in the United States. Where we transfer the personal data of EU, UK, or other protected users to those providers, we rely on recognized transfer mechanisms — such as the Standard Contractual Clauses, the UK International Data Transfer Addendum, or the EU-US Data Privacy Framework — together with each provider's own safeguards.
We select sub-processors that provide contractual guarantees for the protection of personal data transferred internationally.
Children's Privacy
The Service is not directed at individuals under the age of 18, and we do not knowingly collect personal information from anyone under 18 (or under the digital-consent age set by local law, such as the GDPR and COPPA). If we become aware that we have inadvertently collected data from a minor, we will delete it promptly. If you believe a minor has created an account, please contact us at [email protected].
Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will notify you by email or by posting a prominent notice within the Service at least 14 days before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
Contact & Data Controller
For any privacy-related questions, requests, or concerns, please contact us:
- Email: [email protected]
- Website: jdmarket.cc
- Data controller: JDMarket, operated by Amine Hamane, 5905 boulevard du Quartier, Suite 1003, Brossard, Quebec J4Z 0R7, Canada — [email protected].
- EU / UK users: you may also contact your national data-protection authority or the UK ICO. Any appointed EU/UK Article 27 representative will be listed here.
- Canada: Office of the Privacy Commissioner — www.priv.gc.ca