Draft for review by qualified legal counsel. Not legal advice.
Verification privacy and data notice
What JML uses
Order and payment-result summaries, order email, relevant processor risk and authentication results, versioned acknowledgments, verification status, support/refund records, and factual delivery/access events. For an elevated device check, JML stores the WebAuthn public-key credential, whether local user verification succeeded, credential backup/device type, transports, verified origin, coarse browser family, timestamps, and a keyed hash used for network-abuse controls.
What JML does not collect here
JML does not collect complete card numbers, card security codes, Face ID or fingerprint data, face geometry, biometric templates, selfies, government ID documents, Social Security numbers, or exact location. Face ID, Touch ID, Windows Hello, and device-passcode comparisons remain on the device; the site receives only the signed WebAuthn result.
What the device proof means
The passkey check confirms control of the credential on the device or device account used for the order. It does not establish a government identity and is not the sole basis for an adverse decision. Manual review, support, cancellation, and refund paths remain available.
Retention and rights
Retention is configured separately by data category and remains subject to qualified legal review. Eligible deletion or anonymization requests are supported, while active disputes, lawful accounting duties, and documented legal holds may delay or limit deletion. Every sensitive export is logged.
Contact
Use JML's secure support flow for access, correction, deletion, appeal, or privacy questions. Do not email identity documents or card details.