Privacy Policy
Effective June 13, 2026
What we collect
JewelForce stores the operational data you and your staff enter: inventory, customers, sales, memos, appraisals, outreach contacts, and related records. We also log standard request metadata (IP address, user agent, timestamps) for security and abuse-prevention purposes.
Who owns it
You do. JewelForce is the custodian of your data; we never sell it, rent it, or use it for advertising. You can export every table at any time. If you cancel, your data stays available for 90 days before permanent destruction.
Subprocessors
We use a small set of vetted infrastructure providers to deliver the service:
- Supabase — Postgres database, auth, and file storage.
- Vercel — application hosting and edge network.
- Stripe — subscription billing (your card data never touches our servers — Stripe handles it).
- Resend — transactional email delivery.
- Anthropic — optional AI assistance for appraisal enrichment and OCR. Customer-identifying data is redacted before send.
Retention
Operational records: kept for the life of your subscription, plus 90 days post-cancellation. Audit logs: 18 months. Request metadata: 30 days.
Security
Database connections are TLS-encrypted in transit. At-rest encryption is provided by Supabase. Two-factor authentication is available on every account. Row-level security isolates each shop's data from every other shop on the platform.
Contact
Privacy inquiries: privacy@jewelforce.net.