Legal

Privacy Policy

Last updated: September 2026

1. Who this covers

This policy covers everyone who touches JFOO: customers who order from a store, merchants who run stores, drivers who deliver, and the platform's own administrators. We wrote it to match how the system actually behaves — where data lives, when it is deleted, and who can see it.

2. What we collect and why

Customers (guest checkout — no account): the name, email, phone, delivery address, and order instructions you type at checkout; the items you order; and the map pin you drop. We use this to run your order, email you the confirmation, delivery code, and status updates, and show you the tracking page. We also keep the one review you may leave after delivery.

Merchants: your account email and password (stored only as a bcrypt hash), your store's business details, menu, delivery settings, the payment-provider account you connect (we store connection identifiers — never your provider password), your ledger and invoices, and the content you generate with the AI studio.

Drivers: the email the merchant invites you with, your delivery activity, and the GPS positions you share while a delivery is active.

Everyone: security and audit records (logins, consequential actions like payment confirmations or refunds, with IP and timestamp) and anonymous aggregate analytics such as store views and cart events used to compute conversion for the merchant.

3. Conversations and deletion

Every order has a chat connecting the customer, the merchant, and the driver. When an order completes, the conversation content is cleared automatically — only the fact that messages existed may remain in history. If you message again after delivery, a fresh conversation begins.

Delivery verification codes are stored hashed, expire after the configured lifetime, and can never be read in plain text after they are emailed.

4. Payments

Card and PayPal payments are processed by the payment provider connected to the store (Stripe or PayPal). Card numbers never touch JFOO's servers — you enter them on the provider's hosted pages. We store only the provider's transaction references and the amount, to mark orders paid and issue refunds.

Platform-fee invoices are settled with XPay; we store invoice records and verified payment references.

5. Emails

Transactional email (order confirmations, codes, status changes, review requests, billing notices) is sent through our email provider, Mailrelay. Delivery of each message is logged in the platform with its status and queued retries so nothing is silently lost.

6. Sharing

We share data only as needed to run the platform: your order details with the merchant and assigned driver of that store; payment details with the store's payment provider; your email address with our email provider for the transactional messages above. Maps and address validation use OpenStreetMap services — they receive the address or coordinates needed to geocode, not your identity.

We do not sell personal data, and we do not run third-party advertising trackers.

7. Access, roles, and security

Access is role-based: a merchant sees their own store's data; a driver sees only their active deliveries; administrators can act on stores and orders for support and safety, and every consequential admin action is recorded in an immutable audit log. Passwords are hashed; sessions are server-side and revocable; order totals are always computed server-side.

8. Retention and your choices

Order and financial records are retained as long as required for accounting and dispute resolution. Chat content is cleared at delivery (section 3). You may request a copy of your personal data, corrections, or deletion of your account (financial records excepted) by contacting support from the email you use with JFOO.

Reviews are public by design but carry privacy-protected author names. If you want a review removed, contact support — merchants cannot delete reviews themselves, only platform administrators can hide them for cause.

9. Children

JFOO is intended for adults. Do not use the platform if you are under 18, and merchants must not fulfill orders knowingly placed by minors.

10. Changes and contact

If we change this policy materially, we will announce it in the platform before it takes effect. Questions or requests: reach us through the support link on any order tracking page, or at the platform support address.

Related: Terms of Service. This page is a plain-language summary provided as a starting template — have your counsel review it before launch.