Draft for review by qualified legal counsel. Not legal advice.

Verification privacy and data notice

What JML uses

Order and payment-result summaries, order email, relevant processor risk and authentication results, versioned acknowledgments, verification status, support/refund records, and factual delivery/access events. For an elevated device check, JML stores the WebAuthn public-key credential, whether local user verification succeeded, credential backup/device type, transports, verified origin, coarse browser family, timestamps, and a keyed hash used for network-abuse controls.

What JML does not collect here

JML does not collect complete card numbers, card security codes, Face ID or fingerprint data, face geometry, biometric templates, selfies, government ID documents, Social Security numbers, or exact location. Face ID, Touch ID, Windows Hello, and device-passcode comparisons remain on the device; the site receives only the signed WebAuthn result.

What the device proof means

The passkey check confirms control of the credential on the device or device account used for the order. It does not establish a government identity and is not the sole basis for an adverse decision. Manual review, support, cancellation, and refund paths remain available.

Retention and rights

Retention is configured separately by data category and remains subject to qualified legal review. Eligible deletion or anonymization requests are supported, while active disputes, lawful accounting duties, and documented legal holds may delay or limit deletion. Every sensitive export is logged.

Contact

Use JML's secure support flow for access, correction, deletion, appeal, or privacy questions. Do not email identity documents or card details.