Privacy

What we collect,
and what we do with it.

Jumpframe is intentionally small — one operator, one pipeline, one monthly retainer — which means the data we touch is equally small. This page lists every category, where it lives, who sees it, how long it stays, and what to do if you want it changed.

01 — Information we collect
Three categories, nothing more.

The simplest way to describe the data Jumpframe collects: anything you send us through a form on this site, anything we generate from those submissions to deliver the paid work, and the minimum billing metadata Stripe Connect returns to us. We do not run trackers, advertising pixels, third-party analytics, or session replay tooling — there is no audience graph that follows a visitor across the web.

  • Audit submissionsWhen you submit the free 60-second audit we capture the homepage URL you provide, the probe results (title tag, meta description, sitemap link, JSON-LD blocks, response time), and the email address you give so we can deliver the report. Probe output is generated live and stored, the raw audit is not republished.
  • Founding leadsWhen you express interest in the founding retainer we capture your name, email, the URL of the site you want Jumpframe to work on, and the channel or vertical you operate in. Used to scope a kickoff and to send the founding terms. No marketing list, no resale.
  • Billing detailsWhen you sign a paid retainer we capture an email address for invoices and receipts. Card details are never stored on Jumpframe infrastructure — Stripe Connect handles the card form and stores the payment method under its own privacy terms.
02 — Storage and processing
One Postgres, one payment processor.

Audit submissions, founding leads, and the metadata that ties a paid engagement to a Stripe Connect charge live in a hosted Postgres instance. The database is operated on a private network and accessed by the Jumpframe application layer and by the audit probe itself. Backups are kept encrypted at rest and retained on the same schedule as the source rows.

Card data, card expiry, and the billing address attached to a card never reach Jumpframe infrastructure. Stripe Connect owns the card form, the storage of the payment method, and the dispute surface — we see charge id, amount, currency, and status. Invoices and receipts are sent through the Polsia email proxy from the operator address so a customer reply reaches the founder directly.

03 — Third parties we share with
Three processors, all named.

Jumpframe does not run a marketing automation platform, an ad network, or a retargeting pixel. The only processors that ever see personal data from Jumpframe are the three operating the live service:

  • Stripe ConnectProcesses every paid retention through Stripe Connect from your checkout to the reconciled invoice. Card data, billing address attached to the card, and dispute events live under Stripe’s privacy policy; Jumpframe sees the charge metadata (amount, timing, status) but never the card.
  • Polsia email proxyOutbound transactional mail (audit reports, kickoff briefs, invoices) is sent through the Polsia email proxy so mail is deliverable from a stable sender and replies route back to the operator inbox. The proxy logs envelope metadata, not message bodies, for abuse handling.
  • Polsia object storageGenerated assets (audience briefs, draft calendars, copy libraries) and founder-generated images you upload reference live in Polsia-managed object storage behind signed URLs. The storage tier logs access (who, when) for the same retention window as the underlying record.
04 — Retention
How long each row stays.

Every category of personal data has an explicit hold time. The numbers were chosen so a follow-up months later still has the context to land, but no row parks indefinitely without a reason written down.

  • Audit submissionsKept for 12 months from submission. Used to improve the audit heuristic and to follow up once. You can request earlier deletion any time.
  • Founding leadsKept while the conversation is open and for 24 months after the last reply, so a follow-up months later still reaches you. Delete earlier by request.
  • Billing recordsKept for the length of the engagement plus 7 years to satisfy accounting and audit obligations. Card data is never on our infrastructure and follows Stripe’s retention.
  • Generated assetsKept for the active engagement. On cancellation we hand you every draft, asset, and metric, then delete Jumpframe copies within 30 days (so a re-onboarding keeps nothing hanging around).
05 — Your rights
Access, correction, deletion.

Send a single email and we will route the request — no portal, no support ticket, no waiting on a queue. Replies come from the operator inbox, async.

  • AccessEmail the founder and we will return the categories of personal data we hold about you (audit submissions, founding conversations, billing records tied to your email). Response within 30 days.
  • CorrectionTell us what changed and we update the record on the next working day. Active engagements get the tighter correction window as part of working together.
  • DeletionWe honour deletion requests subject to the retention rules above — billing records stay for the accounting window, generated assets and lead records delete on request. You can also tell us to delete just one category.
Questions about your data?

Reach the founder
by email.

One address reads every privacy request that comes in. Tell us the category of data and the action you want — access, correction, deletion — and we'll route it the same day.

Email jumpframe@polsia.app