Legal
Jam Portal Privacy Policy
1. What this policy covers
This Privacy Policy explains how Jam Portal collects, uses, stores, shares, protects and deletes personal data when people use Jam Portal as venue administrators, staff members, guests, platform administrators, support contacts or website visitors.
Jam Portal is designed to help venues operate a guest music-request portal, including song requests, voting, chat, dedications, feedback, staff moderation, venue administration and related support functions.
2. Data we collect
Depending on how you use Jam Portal, we may collect or generate the following categories of data:
Account and identity data
For administrators, staff and platform administrators, this may include a user ID, email address, display name, profile image, role, venue association, authentication status and account-security information.
Guests normally use anonymous authentication. Jam Portal may still generate or store a technical user ID, guest display name, device identifier and session identifiers.
Venue and account data
This may include venue name, portal settings, branding, staff memberships, subscription status, subscription dates, payment references, payment method labels and administrative actions.
If a venue enables location-based access features, Jam Portal stores the venue's configured latitude, longitude and radius.
Activity and content data
This may include song requests, votes, dedications, chat messages, feedback, ratings, support messages, notices, warnings, bans, moderation reasons, queue history, timestamps and related audit information.
Please do not submit sensitive personal information through free-text fields unless it is genuinely necessary.
Device, security and technical data
Jam Portal may process device identifiers, browser type, language, screen characteristics, timestamps, session identifiers, presence information, security or abuse-prevention signals, error information, request metadata and similar technical data.
Search and media data
When you search for media, the search text and related media metadata may be processed to return results and maintain Jam Portal's media catalogue.
Payment and subscription data
For manual payment administration, Jam Portal may store a payment or transaction reference, amount, currency, plan, payment method label, status, subscription dates, approval information and audit history. Where supplied for reconciliation, this may also include a customer name, phone number or note.
Jam Portal does not intentionally store card numbers, CVVs, Mobile Money PINs, bank-account credentials or similar payment credentials.
3. Information that is required and information that is optional
Certain information is required to provide the service safely. For example, authenticated administrators and staff must provide enough identity information for Jam Portal to verify their authority.
Guest participation may require a display name or system-generated identifiers. Optional actions such as posting chat messages, sending feedback, adding dedications or requesting location verification require the information needed for that feature.
If required information is not provided, Jam Portal may be unable to provide the relevant account, feature or access.
4. Why we use personal data
Jam Portal uses personal data only for purposes connected to operating and protecting the service, including to:
- authenticate users and verify Staff, Venue Admin and Platform Admin authority;
- create and operate venue portals;
- display guest names, requests, votes, chat, dedications and feedback where the feature requires it;
- manage queues, sessions, presence and venue settings;
- prevent abuse, enforce bans or restrictions and investigate security incidents;
- provide customer support and respond to problems;
- manage subscription and manual payment records;
- send invitations, welcome messages, security notices and operational email;
- perform media search and playback-related functions;
- keep audit records and diagnose errors;
- protect Jam Portal, venues and users from misuse;
- comply with legal, accounting, tax, security and regulatory obligations.
Jam Portal does not sell personal data to advertisers.
5. Browser storage and device identifiers
Jam Portal uses browser storage where needed for authentication, session continuity, guest display names, device or session identifiers, notice state, moderation state, venue verification state and related product functions.
Some identifiers may persist after a browser is closed. Clearing browser data may remove locally stored Jam Portal identifiers and may require the user to sign in or identify themselves again.
Jam Portal currently does not intentionally use application-controlled advertising cookies.
6. Location information
When a venue enables geofencing, the guest's browser may ask for device location permission.
Guest latitude and longitude are used by the browser to compare the guest's position with the venue's configured location and radius. The audited Jam Portal application does not intentionally write the guest's precise coordinates to Jam Portal's database or send them to a Jam Portal server function.
A local/session verification marker may be stored after a successful location check.
The venue's own latitude, longitude and radius may be stored as part of its portal settings.
Location-based gating is a convenience and proximity feature, not a guarantee that a user is physically present at a venue.
7. Service providers and recipients
Jam Portal uses selected service providers to operate the service. Depending on the feature used, personal data or ordinary network/request information may be processed by categories of providers such as:
- cloud hosting, database, storage and authentication providers;
- security, anti-abuse and application-attestation providers;
- media search and playback platforms;
- email-delivery providers;
- map and location-search providers;
- avatar, font or content-delivery providers;
- payment-service providers when a user chooses an external payment method;
- infrastructure, monitoring and support providers.
We disclose only information reasonably needed for the relevant service. We may also disclose information where required by law, to protect legal rights, investigate fraud or abuse, or respond to a lawful authority.
We do not publish Jam Portal's private infrastructure design, security secrets or internal system configuration in this policy.
8. Processing outside Uganda
Some service providers may process or store information outside Uganda. Where personal data is processed or stored outside Uganda, Jam Portal will seek to use appropriate safeguards and comply with applicable requirements for cross-border processing.
9. Data retention
Jam Portal keeps personal data only for as long as reasonably necessary for the purpose for which it was collected, or where a longer period is needed for legal, tax, accounting, security, dispute-resolution or contractual reasons.
The current pilot retention approach includes:
- active queue data: for the active session and applicable queue lifecycle;
- chat: subject to existing automatic cleanup;
- presence records: normally cleaned after approximately 7 days when offline/stale;
- inactive guest authentication/device records: target of 90 days after inactivity;
- queue history and dedications: target of 90 days;
- feedback: up to 12 months;
- removed Staff membership records: up to 12 months unless longer retention is needed for security or disputes;
- support records: up to 12 months;
- general operational audit data: normally up to 90 days where practical;
- security, moderation and ban records: normally up to 90 days, or longer where needed to prevent abuse or resolve a dispute;
- payment, subscription and accounting records: up to 7 years where needed for tax, accounting, fraud-prevention, audit or legal purposes;
- email-delivery records: up to 12 months;
- closed venue account data: normally deleted or de-identified within 90 days after termination, except records that must be retained for payment, tax, accounting, security, fraud-prevention, dispute or legal purposes;
- scheduled backups: daily backups are intended to expire after 7 days and weekly backups after 28 days.
Some infrastructure or provider logs follow the service provider's configured retention. Where Jam Portal controls the setting, we aim to keep operational logs only as long as reasonably needed for security, reliability and troubleshooting.
See the separate Data Retention and User Rights Policy for more detail.
10. Backups
Deleted information may remain temporarily in protected backup systems until the relevant backup expires. Jam Portal does not promise immediate selective deletion from an existing backup where the backup system does not support that operation.
If data is restored from a backup, Jam Portal should re-apply valid deletion or correction requests where reasonably necessary.
11. Your rights
Subject to applicable law and appropriate identity verification, you may ask Jam Portal to:
- confirm whether we hold personal data about you;
- provide access to personal data we hold about you;
- correct inaccurate, incomplete, misleading or out-of-date data;
- delete or destroy data that we no longer have authority or a lawful reason to retain;
- stop certain processing that causes or is likely to cause unwarranted substantial damage or distress;
- stop using your personal data for direct marketing;
- explain the categories of third parties that have had access to your data where applicable.
To make a request, email zyroth@jamportal.app with the subject Privacy Request. We may ask for information reasonably necessary to verify your identity and locate the relevant records.
Some records may be retained despite a deletion request where retention is required or permitted for tax, accounting, fraud prevention, security, legal claims, regulatory obligations or other lawful purposes. We will explain this where applicable.
12. Children
Privileged Jam Portal accounts are intended for adults who are authorised to act for a venue.
Jam Portal does not intentionally invite children to provide personal data without the consent or authority required by applicable law. A venue that makes a guest portal available to minors is responsible for ensuring that its use of Jam Portal complies with applicable requirements, including obtaining parent or guardian consent where required.
If you believe a child has submitted personal data without appropriate authority, contact us so the matter can be reviewed.
13. Security
Jam Portal uses technical and organisational measures intended to protect information, including authenticated role checks, least-privilege access controls, server-authoritative sensitive operations, application attestation, rate limiting, secure transport, monitoring and backups.
No online system can guarantee absolute security.
14. Changes to this policy
We may update this policy as Jam Portal changes, as service providers change, or where legal requirements change. Material changes will be reflected by an updated effective date and, where appropriate, an in-product or account notice.
We will not describe a future payment or service-provider integration as active before it is actually used.
15. Contact and complaints
For privacy questions or requests:
Jam Portal
Email: zyroth@jamportal.app
Address: Kampala, Uganda
You may also have the right to complain to Uganda's Personal Data Protection Office (PDPO).
This policy should be read together with the Jam Portal Terms of Service, Refund and Cancellation Policy, and Data Retention and User Rights Policy.