Last Updated: February 16, 2026
This Privacy Policy describes how JellyMachine ("we," "us," "our," or the "Company") collects, uses, discloses, and protects your personal information when you use our website builder platform and related services (collectively, the "Service").
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the Service.
When you create an account, we collect:
When you subscribe to paid plans, we collect through Stripe:
We do not directly store your full credit card numbers. All payment information is processed and securely stored by Stripe in accordance with PCI DSS standards.
When you create websites on our platform, we collect:
If you use our e-commerce features, we collect:
We automatically collect data about how you found our service:
We automatically collect information about your use of the Service:
We collect data from your communications:
If you connect third-party accounts, we collect:
When you connect your Facebook Page and/or Instagram Business or Creator account, we may access the following data through Meta's APIs:
You can disconnect your Facebook or Instagram account at any time from the Social Poster settings in your website dashboard. Disconnecting will revoke our access to your account data and stop any scheduled posts. You may also revoke access directly from your Facebook Settings or Instagram Settings.
If you use our Kanban boards, we collect:
If you add team members, we collect:
JellyMachine provides SMS/text messaging capabilities that allow businesses using our platform to communicate with their customers. If you provide your phone number and consent to receive SMS messages through a form on a website built with JellyMachine:
For questions about SMS messaging, contact us at support@jellymachine.com.
We share information with third-party service providers who perform services on our behalf:
If you connect social media accounts (Facebook, Instagram, X/Twitter), we share:
We also receive data from these platforms (profile information, insights, comments, messages, and media) as described in Section 1.8 to provide our social media management features. This data is used solely to power the Service and is not shared with other third parties.
If you use e-commerce features:
We may disclose information when required:
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
We may share information with third parties when you explicitly consent to such sharing.
We may share aggregated or anonymized data that cannot reasonably be used to identify you for research, analytics, or other purposes.
We use essential cookies for authentication:
| Cookie Name | Type | Purpose | Duration |
|---|---|---|---|
| accessToken | Essential | Authentication | 3 hours |
| refreshToken | Essential | Authentication | 24 hours |
These cookies are HTTP-only, secure, and use same-site strict policy. They are necessary for the Service to function and cannot be disabled.
If you enable analytics on your websites, the following data is collected from your website visitors:
If you enable analytics or tracking on your websites, you are responsible for:
We currently do not respond to "Do Not Track" browser signals. However, you can manage cookies through your browser settings.
We retain your account information for as long as your account is active. Upon account deletion, we will delete or anonymize your personal data within 30 days, except where retention is required by law.
Your website content is retained while your subscription is active. After account termination, content is retained for a reasonable period (typically 30 days) before deletion.
Payment records are retained for 7 years to comply with tax and accounting regulations.
If you use our analytics feature:
Backup copies may be retained for disaster recovery purposes and are deleted in accordance with our backup retention policies.
We may retain information longer if required by law, to resolve disputes, or to enforce our agreements.
We implement industry-standard security measures to protect your information:
We use AWS Rekognition to automatically scan uploaded images for inappropriate content as an additional security and content safety measure.
In the event of a data breach affecting your personal information, we will:
You are responsible for:
Our Service uses AWS infrastructure, which may process and store data in various locations globally, including the United States.
For transfers of personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to countries that have not been deemed to provide adequate data protection, we rely on:
While the EU-US Privacy Shield was invalidated, we ensure adequate protections through alternative transfer mechanisms.
You have the right to:
You have the right to request correction of inaccurate or incomplete personal information.
You have the right to request deletion of your personal information, subject to certain exceptions (e.g., legal obligations, ongoing disputes).
You have the right to:
Where processing is based on consent, you have the right to withdraw consent at any time.
To exercise your privacy rights, please:
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).
We collect the following categories of personal information:
We will verify your identity before processing requests by matching information you provide with information in our records.
You may designate an authorized agent to make requests on your behalf with proper verification.
We do not sell your personal information as defined under the CCPA.
We may offer financial incentives for participation in programs. Terms will be disclosed at enrollment.
JellyMachine is the data controller for personal information collected through the Service.
We process personal information under the following legal bases:
As an EEA, UK, or Swiss resident, you have additional rights:
For GDPR-related inquiries, please contact us at the address in the "Contact Us" section.
You have the right to lodge a complaint with your local data protection supervisory authority.
We maintain Data Processing Agreements with our sub-processors (AWS, Stripe, etc.) as required by GDPR.
The Service is not directed to children under 13 (or under 16 in certain jurisdictions). We do not knowingly collect personal information from children.
If you believe we have collected information from a child, please contact us immediately. We will take steps to delete such information.
Users of our platform who create websites are responsible for their own compliance with children's privacy laws (COPPA, etc.) if their websites target or collect information from children.
The Service integrates with third-party services. Your use of these services is governed by their respective privacy policies:
Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these sites.
Websites you create and publish through our Service may collect information from your visitors. You are responsible for:
We may update this Privacy Policy from time to time. We will notify you of material changes by:
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
Your continued use of the Service after changes to this Privacy Policy constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us:
JellyMachine Privacy Team
privacy@jellymachine.com
www.jellymachine.com
We will respond to your inquiries within 30 days, or as required by applicable law.
If you have a complaint about our privacy practices, please contact us first. If you are not satisfied with our response, you may have the right to lodge a complaint with a data protection authority.
We use the following categories of sub-processors to process personal data:
| Category | Provider | Purpose |
|---|---|---|
| Cloud Infrastructure | Amazon Web Services (AWS) | Hosting, storage, compute, security |
| Payment Processing | Stripe | Subscriptions, e-commerce, billing |
| AI Services | OpenAI, Google (Gemini) | Content generation, AI image generation |
| Mapping | Mapbox | Map components on websites |
| Social Media | Meta, X Corp | Social media integration |
| Feature | Data Collected |
|---|---|
| Account Registration | Email, username, password (hashed) |
| Subscriptions | Payment info (via Stripe), billing history |
| Website Builder | Content, layouts, settings, media files |
| E-commerce | Inventory, orders, customer data |
| Analytics | Visitor data, pageviews, sessions |
| Kanban Boards | Cards, workflows, assignments |
| Email Services | Recipient addresses, email content |
| AI Features | Prompts, generated content |
| Social Integration | OAuth tokens, scheduled posts, profile data, insights, comments, messages, media |
| SMS/Text Messaging | Phone numbers, SMS consent status and timestamps, opt-out records |