Privacy Policy

Last updated: May 3, 2026

Jewelia LLC ("Jewelia," "we," "us," or "our") is committed to protecting the privacy and security of your information. This Privacy Policy describes how we collect, use, disclose, retain, and safeguard your information when you access or use our business-to-business platform, website, APIs, and related services (collectively, the "Services"). By using our Services, you acknowledge that you have read and understood this Privacy Policy.

1. Definitions

For the purposes of this Privacy Policy:

  • "Personal Information" means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to an identifiable individual or household.
  • "Business Data" means information uploaded, entered, or generated within the Services by or on behalf of a user's organization, including but not limited to customer records, inventory data, sales orders, invoices, production records, and business communications.
  • "Organization" means a business entity that has registered an account on the Services.
  • "Authorized User" means an individual who has been granted access to an Organization's account on the Services.
  • "Sub-Processor" means a third-party service provider that processes data on our behalf.

2. Information We Collect

2.1 Information You Provide Directly

We collect information that you voluntarily provide when you:

  • Register and create an account: Name, email address, phone number, job title, business name, business address, and login credentials.
  • Set up your Organization: Company name, industry classification, tax identification numbers, business licenses, and organizational structure.
  • Use the Services: Customer records, inventory items, sales orders, invoices, production jobs, trade-in records, consignment memos, certifications, and other Business Data you enter or upload.
  • Use networking features: Business profile information, connection requests, messages sent through our B2B messaging system, posts, and recommendations.
  • Subscribe to paid plans: Billing information, payment card details (processed by our payment processor, Stripe), and billing address.
  • Contact us: Information provided through support requests, feedback, surveys, or other communications.

2.2 Information Collected Automatically

When you access or use our Services, we automatically collect:

  • Device and browser information: Device type, operating system, browser type and version, screen resolution, and device identifiers.
  • Log and usage data: IP address, access times, pages viewed, features used, clickstream data, referring URLs, and search queries within the platform.
  • Location data: Approximate geographic location derived from your IP address.
  • Performance data: Page load times, errors encountered, and other diagnostic information.
  • Cookies and similar technologies: Session cookies (essential for authentication), preference cookies, and analytics cookies. See Section 9 for details.

Technical and Location Information

When you join our waitlist or use our Services, we automatically collect technical information including your IP address, and we use that IP address to determine your approximate geographic location (city, region, and country). We use this information to:

  • Understand where interest in our platform is coming from
  • Allocate sales and onboarding resources by region
  • Detect and prevent abuse or fraudulent signups
  • Comply with applicable export and sanctions regulations

We retain IP address and approximate location information for no longer than 24 months from collection, after which it is deleted or anonymized. You may request deletion of this information at any time by emailing privacy@jewelia.io.

2.3 Information from Third Parties

We may receive information about you from third-party sources, including authentication providers (such as Google) when you use single sign-on, payment processors (Stripe) for billing verification, and publicly available business information to enhance your networking profile.

3. How We Use Your Information

We use the information we collect for the following purposes:

3.1 Service Delivery

  • Providing, operating, and maintaining the Services, including CRM, inventory management, production tracking, sales, finance, and networking features.
  • Processing transactions and sending related information, including purchase confirmations, invoices, and subscription receipts.
  • Authenticating users and managing account access, including role-based permissions within Organizations.
  • Facilitating B2B connections and communications between Organizations on our platform.

3.2 Service Improvement

  • Analyzing usage patterns to improve features, performance, and user experience.
  • Conducting research and development to build new features and products.
  • Monitoring and measuring the effectiveness of our Services.

3.3 AI-Powered Features

Our Services include AI-powered features (such as search, insights, and analytics) that process your Business Data to provide personalized recommendations and actionable insights. AI processing occurs in real time when you initiate a request and is performed by our third-party AI provider (Anthropic). Your Business Data is sent to Anthropic solely to generate a response to your specific request. Anthropic does not use your Business Data to train its AI models. AI-generated outputs are not stored by our AI provider beyond the duration of the request. You may choose not to use AI features, and your core access to the Services will not be affected.

3.4 Communications

  • Sending administrative notices, including security alerts, system updates, and changes to our terms or policies.
  • Responding to your inquiries, comments, and support requests.
  • Sending product announcements, feature updates, and educational content related to the Services (you may opt out at any time).

3.5 Security and Compliance

  • Detecting, investigating, and preventing fraudulent, unauthorized, or illegal activity.
  • Enforcing our Terms of Service and other policies.
  • Complying with applicable legal obligations, including responding to lawful requests from law enforcement or governmental authorities.
  • Maintaining audit logs of security-relevant actions for compliance and incident response purposes.

4. Legal Bases for Processing (Where Applicable)

Where required by applicable law (including the GDPR), we rely on the following legal bases:

  • Performance of a contract: Processing necessary to provide the Services you have subscribed to.
  • Legitimate interests: Processing necessary for our legitimate business interests, such as improving the Services, preventing fraud, and ensuring security, where those interests are not overridden by your rights.
  • Consent: Processing based on your explicit consent, such as receiving marketing communications or using optional AI features.
  • Legal obligation: Processing necessary to comply with applicable laws and regulations.

5. Information Sharing and Disclosure

We do not sell, rent, or trade your Personal Information. We may share your information in the following limited circumstances:

5.1 With Your Organization

If you are an Authorized User, your Organization's administrators may access your account activity, usage data, and Business Data within the Organization's account. Organizations control their own data and are responsible for their own privacy practices with respect to their employees and customers.

5.2 With Other Platform Users

When you use our networking features, certain business profile information (such as your name, job title, company name, and business description) is visible to other users on the platform. You control what information is included in your public business profile. Messages and connection requests are only visible to their intended recipients.

5.3 With Service Providers (Sub-Processors)

We engage trusted third-party service providers who process data on our behalf to support the operation of our Services. These providers are contractually obligated to use your information only as directed by us and to maintain appropriate security measures. Our current Sub-Processors include:

  • Supabase (Database & Authentication): Stores and manages application data and user authentication. Data is hosted in the United States.
  • Vercel (Hosting & CDN): Hosts our application and delivers content globally through their edge network.
  • Stripe (Payment Processing): Processes subscription payments. Stripe receives only the billing and payment information necessary to complete transactions. We do not store full payment card numbers on our servers.
  • Anthropic (AI Processing): Provides AI capabilities for search, insights, and analytics features. Business Data is sent to Anthropic only when you initiate an AI-powered request and is not retained by Anthropic after processing.
  • Sentry (Error Monitoring): Collects error and performance data to help us identify and resolve technical issues. Sentry may receive limited technical metadata but does not receive your Business Data.
  • Upstash (Rate Limiting): Provides rate-limiting infrastructure to protect our Services from abuse. Processes only IP addresses and request metadata.

5.4 For Legal Reasons

We may disclose your information if required to do so by law or in the good faith belief that such action is necessary to comply with a legal obligation or lawful request (such as a subpoena, court order, or government investigation); protect and defend the rights, property, or safety of Jewelia, our users, or the public; detect, prevent, or address fraud, security issues, or technical problems; or enforce our Terms of Service or other agreements.

5.5 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on our website of any change in ownership or uses of your Personal Information, as well as any choices you may have regarding your information.

6. Data Security

We implement industry-standard technical and organizational security measures to protect your information, including but not limited to:

  • Encryption: All data in transit is encrypted using TLS 1.2 or higher. Sensitive data at rest is encrypted using AES-256 encryption.
  • Access controls: Role-based access control (RBAC) limits access to data based on user roles within an Organization. Row Level Security (RLS) is enforced at the database level on all tables to ensure strict multi-tenant data isolation.
  • Authentication: Secure authentication with support for single sign-on (SSO). Session re-authentication is required for sensitive operations such as data deletion and bulk imports.
  • Audit logging: Security-relevant actions are recorded in tamper-evident audit logs, including who performed the action, what was changed, and when.
  • Web Application Firewall (WAF): Our application is protected by a WAF with custom rules for rate limiting, bot detection, and attack mitigation.
  • DDoS protection: Automatic distributed denial-of-service mitigation is in place at the infrastructure level.
  • Input validation: All user inputs are validated and sanitized to prevent injection attacks and data corruption.
  • Security headers: HTTP security headers including Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, and X-Content-Type-Options are enforced on all responses.
  • Dependency management: Automated scanning for known vulnerabilities in third-party software dependencies.

While we strive to protect your information using commercially reasonable measures, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security, but we are committed to promptly addressing any security incidents. In the event of a data breach that affects your Personal Information, we will notify affected users and relevant authorities as required by applicable law.

7. Data Retention

We retain your information for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, including:

  • Active accounts: We retain your Personal Information and Business Data for as long as your account is active and you continue to use the Services.
  • After account closure: Upon account deletion or Organization termination, we will delete or anonymize your Personal Information within 90 days, except as required to comply with legal obligations, resolve disputes, or enforce our agreements.
  • Audit logs: Security audit logs are retained for 90 days and then automatically purged.
  • Backup data: Copies of data in backup systems may persist for up to 30 days after deletion from production systems.
  • Legal requirements: We may retain certain information for longer periods where required by applicable law (such as tax, accounting, or regulatory requirements).

8. Your Rights and Choices

Depending on your jurisdiction, you may have certain rights regarding your Personal Information. We honor these rights regardless of where you are located, to the extent feasible:

8.1 Access and Portability

You may request a copy of the Personal Information we hold about you in a structured, commonly used, and machine-readable format. You may also request that we transmit this data directly to another service provider, where technically feasible.

8.2 Correction

You may request correction of any inaccurate or incomplete Personal Information we hold about you. You can also update most of your account information directly through the Services.

8.3 Deletion

You may request deletion of your Personal Information, subject to certain exceptions (such as information we are required to retain for legal compliance). Organization administrators can delete their Organization's data through the platform's data management tools or by contacting us.

8.4 Restriction and Objection

You may request that we restrict the processing of your Personal Information or object to processing based on legitimate interests. We will honor such requests unless we have compelling legitimate grounds for the processing.

8.5 Marketing Opt-Out

You may opt out of receiving promotional communications from us by clicking the "unsubscribe" link in any marketing email or by contacting us. Please note that you may still receive transactional and administrative communications related to your account.

8.6 Exercising Your Rights

To exercise any of these rights, please contact us at privacy@jewelia.io. We will respond to verified requests within 30 days (or sooner if required by applicable law). We will not discriminate against you for exercising your privacy rights.

9. Cookies and Tracking Technologies

We use the following types of cookies and similar technologies:

  • Essential cookies: Required for authentication, session management, and core platform functionality. These cannot be disabled without impairing the Services.
  • Preference cookies: Remember your settings and preferences (such as theme selection and dashboard layout).
  • Analytics cookies: Help us understand how the Services are used, which features are most popular, and where users encounter issues. We use this data in aggregate form to improve the Services.

We do not use advertising cookies or third-party tracking pixels. We do not participate in cross-site advertising networks. You can control cookie preferences through your browser settings. Please note that disabling essential cookies will prevent you from using the Services.

10. Multi-Tenant Data Isolation

Jewelia is a multi-tenant platform, meaning multiple Organizations share the same underlying infrastructure. We implement strict data isolation measures to ensure that each Organization's data is accessible only to its Authorized Users. These measures include database-level Row Level Security (RLS) policies on every data table, server-side verification of Organization membership on every API request, and separate logical data partitions for each Organization. No Organization can access, view, or modify another Organization's data through the Services.

11. International Data Transfers

Jewelia is based in the United States, and our primary data infrastructure is located in the United States. If you access the Services from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers maintain facilities. These countries may have data protection laws that differ from those in your jurisdiction. By using the Services, you consent to the transfer of your information to the United States and other countries as described in this Privacy Policy. Where required by applicable law, we implement appropriate safeguards (such as Standard Contractual Clauses) to protect your information during international transfers.

12. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to Know: You may request disclosure of the categories and specific pieces of Personal Information we have collected about you, the categories of sources from which it was collected, the business purpose for collection, and the categories of third parties with whom it was shared.
  • Right to Delete: You may request deletion of your Personal Information, subject to certain exceptions.
  • Right to Correct: You may request correction of inaccurate Personal Information.
  • Right to Opt Out of Sale/Sharing: We do not sell your Personal Information and do not share it for cross-context behavioral advertising. Therefore, there is no need to opt out.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.

To exercise your California privacy rights, please contact us at privacy@jewelia.io. We will verify your identity before processing your request.

13. European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) and equivalent local laws. These include the rights described in Section 8, as well as the right to lodge a complaint with your local data protection authority if you believe we have not complied with applicable data protection laws. Our legal bases for processing are described in Section 4.

14. Children's Privacy

Our Services are designed for business use and are not directed to individuals under 18 years of age. We do not knowingly collect Personal Information from children under 18. If we become aware that we have collected Personal Information from a child under 18, we will take prompt steps to delete such information. If you believe that a child under 18 has provided us with Personal Information, please contact us at privacy@jewelia.io.

15. Third-Party Links and Integrations

Our Services may contain links to third-party websites, services, or integrations that are not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access through our platform. This Privacy Policy applies solely to information collected through our Services.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. If we make material changes, we will notify you by email (sent to the email address associated with your account) or by posting a prominent notice on our website at least 30 days before the changes take effect. The "Last updated" date at the top of this page indicates when this Privacy Policy was last revised. Your continued use of the Services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.

17. Data Protection Officer

If you have questions or concerns about our data practices, or if you wish to exercise your privacy rights, you may contact us at:

Jewelia LLC
Attn: Privacy Team
Email: privacy@jewelia.io

We will respond to all privacy-related inquiries within 30 days.