Joomjoo

Privacy Policy

Effective 20 August 2026. Last updated 3 September 2026.

The short version, and every line of it is expanded below.

Joomjoo is a business service, so most of what we hold is business information. The personal information we do hold is there for three reasons: to let you sign in, to satisfy the identity checks the banks and networks require of us, and to run the purchases you ask us to make.

We do not sell personal information, we do not share it for advertising, and we do not use your data to train anyone's model.

Two things are worth knowing before you read on. When an agent buys something for you, it drives a real browser and takes screenshots of the pages it sees, which is how it works and how a purchase can be reviewed afterwards. And your data is stored in the United States.

Contents

1. Who is responsible
2. What we collect
3. Where it comes from
4. Why we use it
5. Card data, and what we never hold
6. Agent runs, screenshots and browsing
7. Voice
8. Your own model keys

9. Who we share it with
10. International transfers
11. How long we keep it
12. Security
13. Your rights
14. Cookies and similar technology
15. Children
16. Changes, and how to reach us

1. Who is responsible

Joomjoo, LLC, a Delaware limited liability company, of 131 Continental Dr, Suite 305, Newark, Delaware 19713-4324, United States, is the controller of the personal information described here.

Where you use Joomjoo to serve your own customers, and you decide what happens to their information, you are the controller of that information and we process it for you under our agreement with you.

2. What we collect

Account and business information

Business name, legal form, registration number, tax identifier, addresses, website, and the name, role, email address and telephone number of the people who sign up and administer the account.

Verification information

To satisfy the identity checks required of the card programme: the identity of beneficial owners and control persons, including name, date of birth, nationality, residential address and government identification documents, and images taken during an identity check, including a photograph of a document and of the person's face. Also the results of sanctions, politically exposed person and adverse media screening.

Financial and transaction information

Balances, funding events and their source, cards and their limits and status, transactions, merchants, amounts, timestamps, authorisation and settlement outcomes, disputes, and the reference codes used to match a bank transfer.

Product usage

Actions taken in the product, agents created and their configuration, purchase runs and their status, API requests including method, path, status, latency and a request identifier, activity and audit records, notification preferences, and support correspondence.

Content you give us

Messages you send to the assistant, files you attach, and instructions you give an agent.

Technical information

IP address, browser and device information, language, timestamps, and error diagnostics. Where a card is shared by link, we record a keyed hash of the claimant's IP address and browser identifier rather than the values themselves, so a claim can be investigated without holding an address that anyone could match back to a person.

3. Where it comes from

Most of it comes from you, or from your systems calling our API. Some comes from others: our identity verification provider and the business registries and screening databases it consults; our card programme partners, who tell us about authorisations, settlements and disputes; our payment processor, which tells us a funding payment succeeded; and our bank, which tells us a transfer arrived.

4. Why we use it, and on what basis

PurposeLegal basis, where the GDPR or a similar law applies
Providing the service you asked for: accounts, cards, balances, agents, purchasesPerformance of a contract
Verifying your business and its owners, screening for sanctions, preventing and detecting money laundering and fraudLegal obligation, and legitimate interests in preventing crime
Keeping records of transactions and activityLegal obligation, and legitimate interests in being able to answer a question about what happened
Security, abuse prevention, rate limiting, and investigating incidentsLegitimate interests in protecting the service and its customers
Support, service messages and notifications you switched onPerformance of a contract
Improving the product, in aggregate and de-identified formLegitimate interests
Marketing email to a business contactLegitimate interests, or consent where it is required. Every one carries an unsubscribe link
Complying with a lawful request, and establishing or defending a legal claimLegal obligation, and legitimate interests

We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are used in United States state privacy laws. We do not use your content to train a machine learning model, and our providers are engaged on terms that do not permit them to train on it either.

5. Card data, and what we never hold

Cards are issued by our banking partner, not by us, and the full card number, expiry and security code live with the issuer.

6. Agent runs, screenshots and browsing

When you ask an agent to buy something, it operates a real web browser on a hosted browser service and works through the merchant's site. To do that it captures screenshots of the pages it is looking at and sends them, with your instruction, to the model that decides what to do next.

Two consequences follow, and we would rather say them plainly.

Do not point an agent at a page holding information you are not willing to have processed this way.

7. Voice

If you dictate rather than type, the audio is sent to our speech to text provider, converted to text, and the text is placed in the message box for you to read before you send it. We do not store the audio, and the recording is made only while you hold the control open.

8. Your own model keys

Where you connect your own model provider key to an agent, that key is encrypted and held in a managed secret store, is never written to a log, and is never returned by the API or shown in the product after you save it. It is used only to run the agent you attached it to. Anything you spend with your own provider is between you and that provider.

9. Who we share it with

We share personal information only with the parties below, only for the purposes described, and under contracts that require them to protect it.

WhoWhat they receive, and why
Card programme partners, including our issuing bank and the programme operatorBusiness and beneficial owner details, card and transaction data. Required to issue cards and to settle and dispute transactions
Identity verification providerBusiness details, beneficial owner identity and documents. Required to verify you and to screen for sanctions and financial crime
Business registry data providerBusiness name and registration details, to confirm a company exists and who controls it
Payment processorFunding payments, subscriptions and billing. It receives your payment details directly; we do not
Our bankBank transfers you send us, so that they can be matched and settled
Cloud infrastructure and database providerHosting, authentication, storage and compute for the whole service
Model providerYour messages and attachments, and the screenshots described in section 6, so the assistant can answer and an agent can act
Hosted browser providerThe browsing session an agent drives, including pages it visits on your instruction
Speech to text providerAudio you dictate, converted to text and not retained by us
Email providerYour email address and the content of service messages we send you

We also disclose information where the law requires it, to a regulator, court or law enforcement body acting under proper authority; where it is necessary to establish, exercise or defend a legal claim; and to a buyer or successor if the business is sold, merged or reorganised, in which case this policy continues to apply until it is replaced with notice to you.

10. International transfers

Joomjoo is operated from the United States and the United Arab Emirates, and your data is stored and processed in the United States, in Google Cloud's central United States region. Some of our providers process data elsewhere.

Where information is transferred out of the United Kingdom, the European Economic Area or Switzerland, we rely on the European Commission's Standard Contractual Clauses, and the United Kingdom addendum where it applies, together with any additional measures the transfer requires. Ask us and we will describe the safeguards for a specific transfer.

11. How long we keep it

WhatHow long
Verification records, including identity documents and screening resultsAt least five years after the account closes, because financial crime rules require it
Transaction, balance and funding recordsAt least seven years, for accounting, tax and dispute purposes
Activity and audit records, API request logsUp to two years
Assistant conversations, attachments and agent runsWhile the account is open, then up to twelve months, unless you delete them sooner
Dictated audioNot retained
Support correspondenceUp to three years after the case closes

Where we no longer need information but cannot delete it immediately, for example because it sits in a backup, we isolate it and delete it on the ordinary backup cycle.

12. Security

We protect information with measures appropriate to its sensitivity. Data is encrypted in transit and at rest by our infrastructure provider. Secrets and customer model keys are held in a managed secret store rather than in code or in the database. Access to production systems is limited to people who need it. Money movements are written as single atomic operations so that a failure cannot leave a balance in an inconsistent state, and the ledger behind them is append only.

No service is perfectly secure. If a breach affects your personal information and the law requires it, we will notify you and the relevant authority within the time the law allows, and we will tell you what happened and what to do about it.

Your part matters as much as ours: keep your credentials and API keys secret, and tell us at once at support@joomjoo.com if one may have been exposed.

13. Your rights

Depending on where you live, you may have the right to access the personal information we hold about you, to have it corrected, to have it deleted, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent where we relied on it. Under United States state privacy laws you may also have the right to know what we collect and disclose, to correct and delete it, and to be free from discrimination for exercising a right.

Write to support@joomjoo.com. We will verify who you are before we act, and we will answer within the time the applicable law allows, ordinarily within thirty days. You may use an authorised agent where the law permits.

Two honest limits. We cannot delete information we are required to keep, in particular verification and transaction records, and a request to delete those will be refused for that reason. And deleting information necessary to run the service means we can no longer provide it, so such a request will be treated as a request to close the account, with the balance returned under section 7 of the Terms.

If you are in the United Kingdom, the European Economic Area or Switzerland, you may complain to your local supervisory authority. We would rather you came to us first.

14. Cookies and similar technology

The product uses cookies and browser storage that are strictly necessary to run it: keeping you signed in, keeping your session secure, and remembering preferences such as your theme and your approval setting. These cannot be switched off without breaking the product.

Our public website uses a small amount of analytics to count visits and understand which pages are read. We do not run advertising cookies and we do not permit third party ad tracking. Where the law requires consent for analytics, we ask for it before setting those cookies, and we honour a Global Privacy Control signal as an opt out where the law requires that.

15. Children

Joomjoo is a business service and is not directed at children. We do not knowingly collect personal information from anyone under 18. Every person we hold identity information about is an owner or officer of a business and must be an adult. If you believe a child's information has reached us, write to support@joomjoo.com and we will delete it.

16. Changes, and how to reach us

We may update this policy. The effective date at the top always tells you which version applies. If a change materially affects how we use your personal information, we will tell you by email or in the product before it takes effect.

Joomjoo, LLC
131 Continental Dr, Suite 305
Newark, Delaware 19713-4324
United States

Privacy questions and rights requests: support@joomjoo.com