Privacy Document

Privacy Policy

Notice published: September 9, 2026 (UTC) · Effective: September 24, 2026 (UTC)

Short version: We use your information to run JDMarket. Optional mobile ad measurement shares identifiers and app and subscription activity with Meta only when you enable it, with tracking permission on iPhone. You can keep it off, change your choice in Settings, or delete your account and data in the app or by emailing us.

This Privacy Policy explains how JDMarket ("we", "us", "our") collects, uses, stores, and protects personal information when you use the Service. By using JDMarket, you agree to the practices described here. Because we serve users in Canada, the United States, the United Kingdom, the European Union, Australia, and other countries, this policy is designed to meet Canada's PIPEDA, the EU and UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and comparable laws. Where a specific law gives you additional rights, those rights apply to you.

1Section 1

Information We Collect

CategoryData collectedRequired?
AccountUsername, email address, hashed passwordYes
NotificationsMobile push token & device platform (for app alerts); Telegram chat ID (if you connect Telegram)Optional
LocationApproximate location (city/country) derived from your IP address; and, only if you grant permission in the mobile app, your device's precise location. Used to localize your searches. Precise device location is not sent to advertising providers. Technical IP addresses may also be processed as described under mobile analytics and optional ad measurement.Optional / Automatic
UsageSaved searches, watch/alert configurations, alert history, AI filter prompts, saved favoritesYes (core feature)
BillingStripe customer ID, or the store identifier for in-app purchases (Apple transaction ID; Google Play purchase token / order ID), subscription status, plan type. Full card details are never stored by us.Paid plans only
TechnicalIP address, browser/device type, server access logsAutomatic
Mobile analyticsInstallation identifiers, app version, device/OS information and app activity, including onboarding and purchase-flow eventsAutomatic; optional Meta ad measurement is controlled separately
Ad measurementMeta anonymous device identifier, app activations, subscription/trial events, product identifiers, purchase values and currency, and app/device context. On iPhone, with tracking permission, this can include the advertising identifier (IDFA), vendor identifier (IDFV) and IP address. Android advertising ID access remains disabled.Optional opt-in in supported mobile app versions

You do not need to connect a Facebook account to use JDMarket. We do not ask for or collect your Facebook login, password, cookies or session. Public listing retrieval (Section 6) is separate from optional Meta ad measurement (Section 7).

2Section 2

How We Use Your Information

  • To create and manage your account and authenticate you.
  • To run your saved searches, alerts, and AI filtering on your behalf.
  • To deliver the notifications you have configured by mobile push and, optionally, Telegram.
  • To send transactional emails (email confirmation, password reset, billing receipts).
  • To process payments and manage your subscription via Stripe, Apple In-App Purchase or Google Play Billing.
  • To enforce plan limits (daily search/alert limits, number of watches).
  • To detect and prevent fraud, abuse, or security incidents.
  • To improve the reliability and performance of the Service.
  • If you opt in to mobile ad measurement, to measure and improve JDMarket advertising, including which ads lead to app activity, trials and paid subscriptions.
  • To comply with legal obligations.

We do not exchange personal information for money or train our own AI models on your data. AI providers process requests under their applicable terms and privacy policies. Optional sharing with Meta for advertising measurement may be considered a “sale” or “sharing” under some privacy laws. You can decline this sharing or withdraw your choice in the app under Settings → Ad measurement.

3Section 3

Legal Basis for Processing

Where the GDPR or UK GDPR applies, we rely on the following lawful bases (Article 6); where PIPEDA applies, we rely on your consent and our reasonable business purposes:

  • Contract (Art. 6(1)(b)): creating and managing your account, processing payments, and running the searches and alerts you set up.
  • Legitimate interests (Art. 6(1)(f)): retrieving public listing data, security monitoring, fraud prevention, and improving the Service — balanced against your rights and freedoms.
  • Consent (Art. 6(1)(a)): optional features such as AI processing, precise device location, Telegram notifications and mobile ad measurement, which you can withdraw at any time.
  • Legal obligation (Art. 6(1)(c)): keeping billing and tax records and responding to lawful requests.
4Section 4

Data Storage & Retention

Your data is stored on servers located in Toronto, Canada (DigitalOcean), using PostgreSQL with connection pooling. All connections use TLS encryption in transit.

  • Account data: retained while your account is active, or until you delete it.
  • Search runs & alert history: your search run history is automatically trimmed to your most recent runs, and your delivered alerts are kept as a rolling recent history in your in-app inbox.
  • Public listing data: the listings we retrieve are stored to power matching and alerts, and are refreshed or replaced as your searches run; stale listings are periodically removed. We do not retain this operational data longer than needed to provide the Service.
  • Access logs: retained for up to 30 days for security purposes.
  • Billing records: retained as required by applicable tax and financial regulations (typically up to 7 years).
  • Deleted accounts: when you delete your account, your personal data — including saved searches, alerts, favorites, and push tokens — is removed within 30 days, except records we are required to keep by law (such as billing/tax records).
5Section 5

Third-Party Services

We use the following sub-processors and third-party services to operate JDMarket:

ProviderPurposeData shared
Stripe, Inc.Payment processing & subscription management (website checkout)Email, name, billing address, payment method (processed directly by Stripe)
Apple Inc.Apple In-App Purchase — payment processing & subscription management (iPhone)No user personal information is shared by us; Apple returns a transaction ID and subscription status
Google LLCGoogle Play Billing — payment processing & subscription management (Android)No user personal information is shared by us; Google returns a purchase token / order ID and subscription status
RevenueCatIn-app subscription validation, entitlements and lifecycle reporting; optional Meta integrationJDMarket account identifier, purchase/transaction data, subscription status and device/app context. When ad measurement is enabled, attribution identifiers and subscription events are forwarded to Meta. Privacy policy
OpenRouter and model providers, including DeepSeek and OpenAIAI query assistance, rule drafting, assistant replies and listing filteringSearch text, filter rules, assistant messages and relevant listing titles, prices, descriptions and approximate listing locations. Assistant requests can include watch and account context such as city and notification preferences. Requests route through OpenRouter and its model providers, or directly to OpenAI as a fallback. OpenRouter privacy policy; OpenAI privacy policy.
Meta PlatformsOptional mobile advertising measurement and campaign improvementThe ad measurement data listed in Section 1, shared by the Meta SDK and RevenueCat. Meta may match it with information it holds to measure advertising. We do not supply search criteria, listing contents, precise location, email addresses or phone numbers to this integration. Privacy policy
DigitalOceanCloud infrastructure & hosting (Toronto region)All data stored on their servers
ResendTransactional email deliveryYour email address and email content
CloudflareDNS, DDoS protection, CAPTCHA (Turnstile)IP address, browser fingerprint (for CAPTCHA only)
Expo (Expo Application Services)Mobile push-notification deliveryPush token and notification content
Google Firebase Cloud MessagingAndroid push-notification deliveryAndroid push token
Google Firebase AnalyticsMobile app analyticsApp installation identifiers, device/app information and automatically collected app activity
ipwho.isApproximate geolocation from IPYour IP address (to derive city/country)
DecodoProxy infrastructure used to retrieve public listingsNo user personal information is shared
TelegramNotification delivery (optional)Listing data sent to your Telegram chat (only if you connect Telegram)

AI permission. Supported mobile versions explain external AI processing and ask for permission before sending an AI request or saving an AI-filtered watch. Permission covers future AI requests and automatic filtering. We keep the notice version and grant/withdrawal timestamps with your account. Older watches also require this permission before new external AI processing. You can turn AI processing off in Settings → Privacy · AI processing. This account-wide choice applies on all devices and to automatic filtering. Watches that require AI retain their saved criteria and wait for permission; basic features that do not need AI remain available. A network connection is required to save this choice to your account. Withdrawal stops new provider requests after it is recorded, but cannot recall requests already sent. Do not put private contact details into search rules or assistant messages. Ad measurement is a separate choice.

We share information with these providers to operate the Service, for optional advertising measurement as described here, or where required by law. These providers process information under the applicable service terms and their own privacy policies. Meta is an advertising partner; it is not used to retrieve listings through your personal Facebook account.

6Section 6

How We Retrieve Listings & Seller Data

JDMarket Alerts. For the managed service, our own servers retrieve publicly visible Facebook Marketplace listings on your behalf, through rotating IP addresses (proxy infrastructure). No Facebook account, login, cookies, or session of yours is used. The mobile app communicates with our servers over HTTPS; it does not record keystrokes or take screenshots.

Listing data about third parties. To provide alerts, we collect and store publicly visible information from Marketplace listings — such as the item title, price, description, photos, listing link, and the approximate location shown on the listing. This information can relate to the people who posted those listings (sellers), who are not our users and have not provided it to us directly. We process it under our legitimate interest (GDPR Article 6(1)(f)) in operating a listings-alert service, and we rely on the Article 14(5)(b) exemption from individually notifying each seller, because doing so would involve disproportionate effort. We keep this data only as long as it is useful for matching and alerts. If you are a seller and want listing information about you removed or no longer processed, contact [email protected] and we will action your request.

7Section 7

Cookies & Tracking

On the website, we use a single session cookie to keep you logged into the JDMarket dashboard. This cookie is:

  • Set only after you log in.
  • HttpOnly and Secure — it cannot be accessed by JavaScript and is only sent over HTTPS.
  • Deleted when you log out or when your session expires.

In the mobile apps, we do not use cookies; your session is kept with a token (JWT) stored securely on your device and removed when you log out or delete your account.

The website does not use advertising cookies or third-party web analytics such as Google Analytics. Cloudflare Turnstile may set a short-lived cookie on login and registration pages for bot detection. Mobile push tokens are used for notification delivery; we do not pass them to the Meta ad measurement integration.

Optional mobile ad measurement. In app versions that support this feature, it starts off. If you choose Allow, the app can share the data described above with Meta directly and through RevenueCat. On iPhone, you must also grant Apple's App Tracking Transparency permission before this tracking starts. Declining does not affect searches, alerts, subscriptions or prices. A Meta anonymous identifier is still an identifier for advertising measurement; it does not make the data anonymous to Meta.

Your choice. Choose Keep off or withdraw consent in Settings → Ad measurement on each device. You can also revoke tracking permission in iPhone Settings. The app checks your permission when it returns to the foreground. Withdrawal stops new app reporting and requests removal of the attribution identifiers used by the RevenueCat integration; a network connection is needed for that request to reach RevenueCat. It does not undo information already delivered. Contact [email protected] for access or deletion requests concerning previously shared data.

8Section 8

Data Security

We implement reasonable technical and organizational measures to protect your personal data, including:

  • All data in transit encrypted via TLS 1.2/1.3 (HTTPS).
  • Passwords stored as bcrypt hashes — we never store plaintext passwords.
  • Database access restricted to internal services only — not publicly accessible.
  • Regular automated backups with point-in-time recovery.
  • DDoS protection via Cloudflare.

However, no method of electronic transmission or storage is 100% secure. In the event of a data breach that poses a risk to you, we will notify affected users and the relevant authorities as required by law (including, where applicable, within 72 hours under the GDPR).

9Section 9

Your Rights

Depending on where you live — Canada (PIPEDA), the EU & UK (GDPR), California (CCPA/CPRA), and elsewhere — you have some or all of the following rights:

  • Access / Know: request a copy of, or information about, the personal data we hold about you.
  • Correction: request correction of inaccurate or incomplete data.
  • Local drafts: Watch drafts are stored on your device for recovery. Account deletion clears that account’s draft and legacy device permission records; interrupted cleanup is retried when the app opens.
  • Deletion / Erasure: delete your account and associated personal data — directly in the app (Settings → Delete account) or by emailing us.
  • Portability: request an export of your data in a machine-readable format, where technically feasible.
  • Object / Restrict: object to, or ask us to restrict, certain processing based on our legitimate interests (GDPR Art. 21).
  • Withdraw consent: withdraw AI processing permission for your account in Settings → AI processing. Turn off optional ad measurement in Settings → Ad measurement on each device. You can also turn off precise location, Telegram and push notifications in app or device settings.
  • Opt out of sale/share (California): optional Meta advertising measurement may qualify as sale or sharing under applicable law. Decline or disable Ad measurement in Settings to opt out. You may also contact us about your rights, including limits on the use of sensitive personal information.
  • Non-discrimination: we will not discriminate against you for exercising your rights.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days (or the period required by your local law). You also have the right to complain to your data-protection authority — the Office of the Privacy Commissioner of Canada, your EU national authority, the UK ICO, or the California Privacy Protection Agency.

10Section 10

International Data Transfers

Your data is primarily stored and processed in Canada (Toronto). Some providers, including Stripe, Apple, Cloudflare, Resend, Expo, Google, RevenueCat, Meta, OpenRouter and AI model providers, process data in the United States and other countries. Applicable transfer safeguards depend on the provider, destination and data involved, including contractual safeguards where required. Contact us for information about safeguards applicable to your data.

We select sub-processors that provide contractual guarantees for the protection of personal data transferred internationally.

11Section 11

Children's Privacy

The Service is not directed at individuals under the age of 18, and we do not knowingly collect personal information from anyone under 18 (or under the digital-consent age set by local law, such as the GDPR and COPPA). If we become aware that we have inadvertently collected data from a minor, we will delete it promptly. If you believe a minor has created an account, please contact us at [email protected].

12Section 12

Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will notify you by email or by posting a prominent notice within the Service at least 14 days before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision. Where consent is required, we will request it separately; continued use does not replace that choice.

13Section 13

Contact & Data Controller

For any privacy-related questions, requests, or concerns, please contact us:

  • Email: [email protected]
  • Website: jdmarket.cc
  • Data controller: JDMarket, operated by Amine Hamane, 5905 boulevard du Quartier, Suite 1003, Brossard, Quebec J4Z 0R7, Canada — [email protected].
  • EU / UK users: you may also contact your national data-protection authority or the UK ICO. Any appointed EU/UK Article 27 representative will be listed here.
  • Canada: Office of the Privacy Commissioner — www.priv.gc.ca