Privacy Policy
Effective date: 2026-09-28. Last updated: 2026-09-28
This Privacy Policy explains how Jewgo LLC ("Jewgo," "we," "us," or "our") collects, uses, shares, and retains personal information when you use the Jewgo mobile app, website, and related services (the "Service"). Capitalized terms not defined here have the meaning given in our Terms of Service.
1. Information We Collect
Account Information
- Name and display name
- Email address
- Phone number (if provided for OTP login or contact)
- Profile photo and bio
- Authentication identifiers from Google or Apple Sign In (if used)
- Sign-in credentials and one-time authentication codes are handled by Jewgo Account — see the Jewgo Account Privacy Policy for information about those data. If your account still uses Jewgo Nav's own legacy sign-in (kept only for app versions installed before Jewgo Account launched), we store a salted password hash for that credential — never your password in plaintext — until you sign in through Jewgo Account instead
Sign-in for Jewgo Nav is provided by Jewgo Account, the shared identity platform used across Jewgo Nav, Jewgo Biz and Jewgo Card. Where Jewgo Account is enabled for your session, it — not Jewgo Nav — verifies your credentials and manages your email, password, and linked-provider identity fields; Jewgo Nav then links your Jewgo Account identity to your Nav profile. See Jewgo Account's own Privacy Policy for how that identity data is collected, used, and retained. Deleting your Jewgo Nav account (below) does not delete your Jewgo Account identity, which may still be used to sign in to Jewgo Biz or Jewgo Card.
Platform Activity
- Listings created (eateries, stores, shuls, mikvahs, events, jobs, minyanim, deals)
- Reviews, favorites, follows, claims, and reports
- Minyan commits and event RSVPs
- Dashboard activity and admin actions (if applicable)
Location Data
- Device GPS or IP-derived location, used with your permission to show nearby listings
- If you set a default location in your profile, we store it on your account so we can personalize search results until you change or remove it
- The most recent map-browse location may be stored on your account to resume sessions
- You can clear stored locations at any time from Settings or by deleting your account
Device, Network & Usage Data
- Device type, operating system, app version, and locale
- App interactions, screen views, and performance metrics
- Server log data, including request paths, timestamps, and error traces
- IP address, and a coarse country/region derived from it, captured at signup and during sensitive actions for fraud prevention and security auditing
- Push notification tokens (if you opt in)
Promotions, Sweepstakes & Challenges
If you enter a Jewgo sweepstakes or challenge, we collect your entry details (an alternative, email-only method of entry is always available and never requires an Instagram handle or screenshot — see the program's Official Rules), a hashed form of your IP address (for anti-fraud, Instagram entries only), any marketing opt-ins you select, and, for winners, contact details required to deliver the prize. Entry data is retained for up to two years after the promotion ends. If you win, your name and the prize awarded are kept for up to four years after the promotion ends for our own recordkeeping; every other field on your entry is cleared at the same two-year mark. Screenshots are deleted no later than seven days after the promotion ends. Marketing opt-ins are retained until you unsubscribe. Each program's Official Rules, linked from the challenge entry page, apply to that promotion and govern where they add detail beyond this Policy.
Payment Information
Jewgo no longer offers paid subscriptions or in-app purchases, and the app collects no payment information. If you hold a subscription purchased before this change, it is managed entirely by the Apple App Store or Google Play Store under their terms, and cancellation or refunds are handled there. Jewgo has never directly collected or stored payment card details.
2. How We Use Information
- Operate, maintain, and secure the Service
- Display listings and personalize search and discovery
- Send transactional notifications (account, security, listings you follow)
- Send marketing communications you have opted into, which you can stop at any time via the unsubscribe link or notification settings
- Provide dashboard analytics to listing owners about their own listings
- Detect, investigate, and prevent fraud, abuse, and policy violations
- Comply with legal obligations and enforce our Terms
- Improve product performance, including aggregated analytics
3. Sharing Information
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under California law.
We may disclose information:
- To service providers and sub-processors (see § 11) acting on our behalf under contractual confidentiality and security obligations
- To listing owners when you interact with their listing (e.g., follow, review, claim, contact)
- To other users, in the form of public profile content, listings, reviews, and similar content you choose to publish
- To comply with law, valid legal process, or to protect rights, safety, and property
- In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections
4. Data Retention
We retain personal information only as long as needed for the purposes described in this policy, including for legal, security, and operational reasons. Indicative retention periods:
- Account profile while your account is active; deleted within 30 days of account deletion (some records may be retained longer for legal compliance or fraud prevention)
- Listings, reviews, and public content retained while published; soft-deleted content may be retained for up to 15 days for recovery
- Device / session location (GPS) used to show nearby results while location access is active; not kept as a separate long-term history beyond your saved default location and last map-browse location described above
- Saved default and last-browse map location retained on your account until you clear them in Settings or delete your account
- Server and security logs up to 90 days, longer where required for incident response
- Signup IP and country retained with the account record for fraud and abuse defense
- Sweepstakes/challenge entries up to two years after the program ends; if you win, your name and the prize awarded are kept up to four years for our recordkeeping and every other field is cleared at the two-year mark; screenshots are purged no later than 7 days after the program ends
- Disabled push notification tokens purged 90 days after the token was disabled
- In-app analytics event logs (e.g., screen views, feed engagement, search activity) retained for 13 months
- Admin audit logs kept indefinitely — these record administrative actions (not ordinary user activity) and we retain them to investigate abuse, security incidents, and misuse of administrative access
- Backups backup copies may retain deleted or previously-changed data until they are rotated out under our backup schedule
5. Your Rights
Subject to applicable law, you may:
- Access your data — request a copy of personal information we hold about you
- Correct inaccurate information — edit your profile or ask us to update records
- Delete your account — request permanent erasure of your account and associated personal data, subject to limited exceptions (legal, fraud, financial records)
- Export your data — receive a copy of your account data in a machine-readable JSON format via the in-app data export feature; we will respond to written requests within 30 days
- Object to or restrict processing of your personal information
- Withdraw consent for optional processing (e.g., marketing, push notifications)
If you entered a Jewgo Challenge (sweepstakes), that entry is not part of your account record and deleting your account does not delete it — a challenge entry is not even tied to an account, since anyone can enter without signing in. To request deletion of a challenge entry, email [email protected] with the email address you entered with; we locate an entry by that address. See the Challenge Privacy Notice shown on the challenge entry page for what is collected and how long it is kept.
For EU/EEA/UK users, these rights are provided under GDPR Articles 15–22 and the UK GDPR. You may also lodge a complaint with your local supervisory authority.
Where the GDPR or UK GDPR applies, we rely on the following legal bases depending on the activity:
- Creating and managing your account performance of a contract
- Providing core platform features (listings, search, discovery) performance of a contract
- Transactional and security notices performance of a contract and, where applicable, legitimate interests
- Personalizing your experience legitimate interests
- Analytics and product improvement legitimate interests
- Fraud detection, abuse prevention, and security legitimate interests
- Marketing communications consent
- Complying with legal obligations legal obligation
- Precise device location (if you enable it) consent
- Tax, accounting, and regulatory records legal obligation
- Religion-adjacent inferences (e.g., from use of Jewish community features) where GDPR Article 9 applies: Article 9(2)(e) — data manifestly made public by the data subject through voluntary use of the Jewish community features of the Service; and/or Article 9(2)(a) — explicit consent where required by law. Exercise GDPR rights (including withdrawal of explicit consent where that is the basis) by contacting [email protected]. See also § 6.
The "legitimate interests" entries in the table above apply only to processing that is not special-category personal data under GDPR Article 9. Religion-adjacent processing that qualifies as special-category data is not grounded in Article 6(1)(f) legitimate interests as its Article 9 basis.
Where we rely on legitimate interests for non-special-category processing, you may object by contacting [email protected]. Where we rely on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, contact [email protected]. We will not discriminate against you for exercising your rights.
If we deny all or part of your privacy request, you may appeal by replying to our decision or emailing [email protected] with the subject "Privacy Request Appeal." We will review the appeal and respond within 30 days. If we deny your appeal, we will explain how to contact the appropriate state regulator.
6. California & US State Privacy Rights
If you are a resident of California, Virginia, Colorado, Connecticut, Utah, or another U.S. state with a comprehensive privacy law, you have the right to:
- Know the categories and specific pieces of personal information we collect, use, and disclose
- Delete personal information we have collected about you, subject to legal exceptions
- Correct inaccurate personal information
- Opt out of the "sale" or "sharing" of personal information — Jewgo does not sell or share personal information for cross-context behavioral advertising, but you may still submit a request
- Limit the use of sensitive personal information — we use sensitive information (such as precise location) only for the purposes described in this policy and not for advertising
- Be free from retaliation for exercising your rights
Categories of personal information collected in the prior 12 months: identifiers (name, email, phone, account IDs), internet/network activity, geolocation data, user-generated content, and inferences drawn from the foregoing. Disclosed for business purposes to the service providers listed in § 11. Sources: directly from you, automatically from your device, and from authentication providers.
Submit a verifiable request to [email protected]. You may use an authorized agent; authorized agents must provide a signed written authorization from the consumer, and Jewgo may also require the consumer to verify their identity directly with us. Where California law applies, we may require documentation consistent with the CCPA and the California Probate Code for agency. California residents may also request information under California Civil Code § 1798.83 (Shine the Light) at the same address.
Religion-adjacent information: By its nature, Jewgo is a Jewish community discovery platform. Your use of the Service (for example, following kosher eateries, shuls, mikvahs, or Jewish events) may reveal preferences or affiliations related to religion. We use such information only to operate the Service, personalize discovery, improve the product, and keep the community safe — not for cross-context behavioral advertising. We do not sell personal information or share it for cross-context behavioral advertising as defined under California law. We do not use religion-adjacent information to infer characteristics for advertising. Except as described in this Policy, we do not share religion-adjacent information with third parties beyond our service providers processing data on our behalf.
7. Security
We use a layered set of safeguards, including:
- TLS 1.2+ for data in transit and disk-level encryption at rest with our hosting providers
- Salted password hashing using industry-standard algorithms (bcrypt)
- Short-lived access tokens, secure session cookies (HttpOnly, Secure, SameSite), and CSRF protections for the admin dashboard
- Role-based access controls and audit logs for administrative actions
- Rate limiting, abuse detection, and ongoing dependency vulnerability monitoring
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and, where required, regulators without undue delay and within the timelines required by applicable law (including, where applicable, the 72-hour timeline under GDPR Article 33).
8. Children's Privacy
Jewgo is not directed to children under 13 and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact [email protected] and we will delete the information and the associated account. Jewgo complies with applicable U.S. state children's privacy laws and international equivalents where applicable. Where required by local law (for example, the EU and UK's higher digital age of consent), additional age limits may apply.
9. International Users & Data Transfers
Jewgo is operated from the United States. If you access the Service from outside the U.S., your information will be transferred to, stored, and processed in the U.S. and other countries where our service providers operate. For transfers from the EU/EEA, UK, and Switzerland, we rely on Standard Contractual Clauses or other lawful transfer mechanisms with our sub-processors.
10. Cookies, Analytics & Tracking
On the Jewgo Nav website, we use a small number of cookies and similar technologies for the following purposes:
- Strictly necessary authentication, session management, CSRF protection. These cannot be disabled.
- Functional remembering your preferences (e.g., theme, language).
- Analytics aggregate, privacy-respecting usage measurement to improve the product. On the website, this is PostHog (page views, performance/Core Web Vitals) and Google Analytics (page views), described further in Section 11.
The Jewgo Nav website shows a consent banner before any analytics or third-party embed (such as an Instagram post) loads: PostHog and Google Analytics, specifically, load only after you accept. If your browser sends a Global Privacy Control (GPC) signal, we treat it as a request to opt out and analytics do not load, whether or not you have interacted with the banner. You can also manage cookies through your browser settings.
In our mobile apps, we use Firebase Analytics and PostHog for optional product analytics, and Firebase Crashlytics and PostHog for crash and diagnostic reporting. Share Usage Analytics is off until you turn it on under Settings → Privacy; when it is off, we disable Firebase Analytics and PostHog product-analytics collection on your device, and PostHog does not associate events with your identity. Crash and diagnostic reporting (Firebase Crashlytics and PostHog) may still run regardless of that setting, the same way it would for any crash-reporting tool, so we can detect and fix failures. Before a crash or diagnostic report leaves your device, we automatically strip email addresses, phone-number-like digit sequences, auth tokens, and the query-string portion of URLs from the error message and the stack trace; this data is intended to describe the software, not you, and we do not deliberately include your name or content, but an error message or stack trace could still incidentally contain other unexpected details our filter does not catch. If you turn Share Usage Analytics on, PostHog also links analytics events to your account using an internal Jewgo user ID — never your email or name — until you turn it off again, sign out, or delete your account, at which point new events stop being linked to you. To have previously collected PostHog analytics events tied to your account deleted rather than merely unlinked, email [email protected] and we will request their deletion from PostHog.
11. Service Providers & Sub-processors
We use the following categories of service providers to operate Jewgo:
- Cloudflare CDN, image storage (R2), and DDoS protection. Privacy policy · DPA.
- Firebase (Google) push notifications, analytics, crash reporting, remote configuration. Firebase privacy · Google Cloud DPA.
- Google Sign-In & Google Maps authentication, mapping, geocoding. Google privacy policy.
- Apple Sign In authentication for iOS users. Apple privacy policy.
- Resend transactional and marketing email delivery. Resend privacy policy.
- Sentry application error monitoring and performance tracing. Sentry privacy policy.
- PostHog on the website, page-view and performance analytics after you accept the consent banner; in our mobile app, product analytics and crash/diagnostic reporting (see Section 10). PostHog privacy policy.
- Google Analytics page-view analytics on the website, loaded only after you accept the consent banner. Google's privacy policy.
- OpenTelemetry-based observability backend telemetry and tracing, exported to a self-hosted collector. OpenTelemetry project.
- Cloud hosting providers for our database, application servers, and backups. Specific providers and DPAs available on request to [email protected].
Each provider processes personal information on our behalf under contractual confidentiality and security obligations and only for the purposes we instruct. Business customers requiring a Data Processing Addendum (DPA) may contact [email protected].
12. AI Features (Coming Soon)
We are developing optional AI-assisted features (for example, a community-focused chat assistant and AI-powered discovery aids). These features are not yet generally available to users. We are publishing this section in advance so it is clear how data will be handled when the feature launches. Before any AI feature is generally available, we will update this Privacy Policy (including the Service Providers list in § 11, retention specifics, and any new legal bases or choices) and advance the effective date, with any additional notice required by law.
- AI features will be powered by one or more third-party large-language-model providers, which will be added to the Service Providers list above when the feature ships.
- If you choose to use an AI feature, the messages and prompts you send may be transmitted to the LLM provider strictly to generate a response.
- We may store chat sessions and any preferences or memories you opt into, for a limited retention period to operate and improve the feature. Specific retention windows will be disclosed here at launch.
- AI features are entirely optional — you are not required to use them, and you can disable them in Settings when they ship.
- Personal information collected through AI features is handled under the same protections described in this policy, including your rights of access, correction, and deletion.
13. Updates to this Policy
We may update this Privacy Policy from time to time. We will provide notice of material changes before they take effect, using the "Last updated" date above and, where required, additional notice appropriate to the change (for example, in-app or by email). This policy describes our data practices; it does not replace any consent choice required by law.
14. Contact & Data Controller
The data controller for personal information processed under this policy is:
- Company Jewgo LLC
- Address 20401 Northwest 7th Court, Miami Gardens, FL 33169, USA
- Privacy [email protected]
- Support [email protected]
- General [email protected]
Version 2026-09-28
