Google Play
Use this page as the privacy policy URL for the Jellin store listing. Anyone can request deletion of an app account and the data tied to it, without installing the app, at the account and data deletion page.
1. Who we are
Jellin is a loyalty and promotions service. The public site is https://jellinapp.com/. The app name on Google Play is Jellin.
For privacy requests, including access, correction, and deletion, email nick.glezakos@gmail.com or use the deletion page. We will respond to a valid request within one month, or tell you if we need more time under the GDPR.
Jellin does not offer a stored-value wallet and does not provide point-of-sale card acceptance. Those activities are outside this policy.
2. Two kinds of personal data
Data we decide about
We are the controller for personal data of people who create a Jellin account or contact us directly: business operators, referral partners, and people who write to us through the website. We decide why that data is used, as described below.
Customer records a business enters
When a business records a customer’s phone number or email address, a visit, stamps, a coupon, or participation in a promotional draw, that business decides why the record exists. Jellin processes those records on the business’s instructions in order to run the program, deliver the reward, and show the business its own summaries. For that data the business is the controller and Jellin is the processor. The business must give its customers their own notice. A customer can still contact us, and we will help erase or export the record as described in section 9.
3. Data we process
Business accounts
| Data | Where it comes from |
|---|---|
| Business or workspace name, country code, phone number, email address, password, and optional VAT number | You, when you register |
| Email confirmation status, phone confirmation status, and whether the operator owns a separate workspace | Generated when the account is used |
| Password-reset codes and email activation keys | Generated by Jellin and sent to your email |
| Operator name and email, role, and permissions inside a workspace | The business that invites the operator |
| Login session: access token and refresh token, stored in the browser’s local storage on the web app | Created when you sign in |
| Push token for the device (Firebase Cloud Messaging), sent with token refresh | The mobile app, if you allow notifications |
| Subscription status, selected plan, Stripe customer and subscription identifiers | You, when you subscribe, and Stripe |
We do not ask you to store a card number in Jellin. Card payments for subscriptions are entered on Stripe Checkout.
Referral accounts
If you create a referral account we process your referral code, first name, last name, phone number, email address, and password, plus confirmation and password-reset data, your session tokens, and the list of business workspaces associated with you.
Loyalty customers
For a person taking part in a business’s program we process the phone number and/or email address the business enters, visit date and time, the group and program, stamps awarded, coupons and redemptions, and eligibility information used for a promotional draw (such as last visit, program, and group). We do not require a customer’s full name, address, or national identifier to record a visit.
Content inside the product
Businesses store program names, group names, coupon rules, message templates, broadcast content, and inbox messages. That content can include personal data if the business puts it there.
Website and support
If you request a demo from the website we receive the email address you type, the page address, the browser user agent, and the time of the request. The form is delivered through Formspree. We also receive whatever you send if you email us.
What we do not collect for this service
The loyalty service described here does not collect precise location, contacts, photos, advertising identifiers for ad networks, or a government identity number from loyalty customers. Business registration may include a VAT number because the account is a business account.
4. Why we use it, and the legal basis
| Purpose | Legal basis |
|---|---|
| Create and secure your account, confirm email, reset passwords, and keep you signed in | Contract, and legitimate interests in keeping accounts secure |
| Provide loyalty programs, visits, coupons, groups, messages, inbox notices, and summaries to the business that configured them | Contract with that business. For customer records, the business’s instructions and its own legal basis |
| Send operational email or SMS about an account, a reward, or a security code | Contract, or legitimate interests in delivering the reward the customer was enrolled for |
| Send marketing email about Jellin itself | Consent, or soft opt-in where the law allows it for our own similar services. You can opt out at any time |
| Take subscription payments, prevent failed payments and fraud, and keep invoices | Contract, legal obligation, and legitimate interests |
| Send a push notification you have allowed on the device | Consent for the device permission, and contract for service messages |
| Diagnose faults, protect the service, and establish or defend a legal claim | Legitimate interests and, where it applies, legal obligation |
We do not sell personal data. We do not use loyalty visit history to build advertising profiles for unrelated third parties.
5. Who we share it with
We share personal data with service providers who process it for us, only as needed to run Jellin:
- Stripe — subscription checkout, plan changes, cancellation, and refunds. Stripe receives billing details and the workspace the subscription belongs to.
- Email delivery — transactional mail such as account confirmation, password reset, and coupon messages, and, separately, marketing mail about Jellin if you are subscribed to it.
- SMS delivery — one-time codes and reward messages sent to a mobile number.
- Google Firebase Cloud Messaging — delivery of push notifications to a device token the app has registered.
- Cloudflare — hosting and DNS for the public website.
- Formspree — the public contact and account-deletion forms.
- Google Play — if you install the Android app, Google processes installation and store data under Google’s own policies. If you pay through Google Play, Google also processes that payment.
Inside a workspace, operators see the customer and visit data their role allows. A partner operator invited into a group sees what that group’s permissions allow, which is typically the ability to assign an offer, not the whole business.
We also share data if the law requires it, or if we sell or reorganise the business, in which case the recipient must honour this policy for existing data.
Referral profiles are visible to Jellin administrators so we can operate the referral program. A business associated with a referrer can see that the association exists.
6. International transfers
We operate with users in Greece and other countries. Some providers (including Stripe, Google, and messaging providers) process data in the European Economic Area and in the United States or other countries. Where personal data leaves the EEA, we use a transfer tool recognised by EU law, such as the European Commission’s standard contractual clauses or an adequacy decision that covers the recipient.
7. How long we keep it
- Account data is kept while the account is open.
- Customer loyalty records are kept while the business keeps them in its workspace. They are deleted or irreversibly dissociated when the business deletes them, when the workspace is deleted, or when a valid erasure request is completed, unless a shorter or longer period is required below.
- Subscription and invoice records are kept for as long as Greek tax and accounting law requires. That period is commonly five years and can be longer for a specific record.
- Security and troubleshooting logs are kept for a limited period and then deleted or aggregated.
- Demo requests are kept long enough to answer you and for a short period afterwards, unless you ask us to delete them sooner and we have no duty to keep them.
Closing an account is not the same as deactivating it. Deletion is described on the deletion page.
8. Security
Accounts are protected by a password, email confirmation, and short-lived access tokens. Operators only see the workspace and permissions they are given. Traffic to the website is served over HTTPS. No method of storage or transmission is perfectly secure. Please use a unique password and sign out on shared devices. Signing out removes the session tokens from that browser’s local storage.
9. Your rights
If the GDPR or a similar law applies to you, you can ask us to:
- confirm whether we process your data, and for a copy of it;
- correct inaccurate data;
- erase data, or restrict its use;
- receive data you provided in a portable form, where the basis is contract or consent;
- object to processing based on legitimate interests, and object at any time to direct marketing;
- withdraw consent, where processing is based on consent, without affecting earlier lawful use; and
- lodge a complaint with a supervisory authority. In Greece that is the Hellenic Data Protection Authority, Kifissias 1-3, 115 23 Athens, www.dpa.gr.
If your data was entered by a business (for example a café recorded your phone number), we may need to refer the request to that business or act on its instruction, because they decide the program. We will not ignore the request. Write to us if the business does not help you.
We may need to confirm that the request comes from you, usually by writing back to the registered email address, before we disclose or delete an account.
10. Account and data deletion
Business and referral accounts can be deleted from Profile while you are signed in to the web app. You can also request deletion without the app. The request path, what is deleted, what may be kept, and how subscriptions are handled are on a separate page so the link can be given to Google Play:
https://jellinapp.com/legal/delete-account.html
Deleting a user who was only invited into someone else’s business removes that person’s login. It does not erase the business’s programs or customer records. Deleting a workspace that you own removes the workspace and the loyalty records stored in it, apart from records we must keep for tax, security, or legal claims.
11. Children
Jellin business and referral accounts are for adults who can enter a contract. The service is not directed at children under 16, and we do not knowingly create an account for a child. Loyalty programs are operated by businesses; a business must not use Jellin to profile children. If you believe we hold a child’s account, contact us and we will delete it.
12. Cookies, local storage, and the website
The marketing site does not run an advertising cookie. It loads typefaces from Google Fonts and a styling library from a content-delivery network. Those providers may process your IP address to serve the file.
The web app stores the access token, refresh token, and basic account details in the browser’s local storage so you can stay signed in. That storage is cleared when you log out or delete the site data in your browser. It is required to provide the account you asked for.
The Android app may store a push token and session so the app can sign you in and deliver notifications you have allowed. You can turn notifications off in Android settings.
13. Changes
We will update this page when our practices change and will change the date at the top. If you have an account and a change is material, we will also notify you by email or in the product.
14. Contact
Privacy and data protection: nick.glezakos@gmail.com
Account deletion: Delete your Jellin account
Terms: Terms of Use