JUMP legal document — Privacy Policy Version: 2027-01-01 Effective: January 1, 2027 Review status: draft Source: https://jumpco.co/legal/privacy/ Archived: 2026-09-10T00:45:28.202Z SHA-256 (body below, excluding this header): ec6a7bb18b0818f211b9336e22ce2ccaa8947b74714c4d8b92f5e9790afc849b **Effective January 1, 2027** · Version `2027-01-01` · All versions (/legal/versions/) **Draft — pending legal review.** This document is a working draft provided for transparency and is not yet final. Version `2026-08-13` applies until January 1, 2027. If you accepted before that date, that is the version recorded on your account. Every published version is listed on all versions (/legal/versions/). This Privacy Policy explains how JumpCo LLC (“JUMP,” “we,” “us”) collects, uses, and shares personal information when you use our website, mobile apps, and services (the “Services”). JUMP operates in the United States. In this policy a **worker** is someone using JUMP to find shifts, and an **employer** is a business posting them. ## What we collect ### From workers - Name, email address, phone number, and date of birth. We ask for date of birth because JUMP is for adults only and some shifts have a legal minimum age. - Your home address — street, city, state, postal code, and country — and the maximum distance you are willing to travel. See Location (#location) below for what we do with them, and what we do not. - The résumé or CV file you upload, and the profile we build from it — work history, skills, years of experience, and work authorisation. You review and confirm that profile before it is used. - The job categories you choose, your profile photo, the ratings and any written comments an employer leaves about you, and the ratings and comments you leave about an employer. - A push notification token for your device, so we can tell you about a shift while the app is closed. ### From employers - Company name, business address, contact name, email address, and phone number — and a tax or VAT identification number, where one is given to us when the account is set up. - The exact location of the business address, taken from the address you pick from Google’s suggestions when you sign up. - A customer record with our payment processor. **Card details are entered directly into Stripe and never reach our servers**, so we do not hold your card number. ### From everyone - Shifts posted, applications made, and who was accepted for what. - Clock-in and clock-out times for shifts that are worked. - Messages sent between a worker and an employer about a shift. - Choices you make about who you work with — for a worker, any employer you have chosen to hide, so we stop sending you their shifts. - Device type, operating system, and app version, and a crash report if the app stops unexpectedly. ### From visitors to this website - Whatever you type into the request-access form: company, name, email, industry, hiring volume, and your message. - A one-way hash of your IP address, used to stop one sender flooding that form and kept with the enquiry it came from. We do not store the address itself. - Web server access logs, which do record IP addresses. They are deleted after 90 days. - **No cookies, no analytics, and no advertising trackers.** This website sets nothing on your device. ## Résumés and automated processing When you upload a résumé, we send it to an AI model run by Amazon Web Services to read it into a structured profile — jobs, dates, skills, work authorisation. **You see that profile and confirm it before anything else uses it.** We then turn the confirmed profile into a numeric representation used to rank you against shifts. That ranking decides _who gets notified_ about a shift. It does not decide who gets the job: an employer sees the workers who accepted and chooses one. No employment decision is made automatically by JUMP. ## Location **We do not collect your device location.** The JUMP app never asks for location permission and has no ability to read where your phone is. A worker’s location is worked out from the **postal code you type in**: we look it up in a table of postal-code area centres and use that centre point as your approximate home. The point we place you at is the middle of your ZIP area, not your street address. We use it with the travel distance you set to decide which shifts to tell you about. If you change your postal code, that centre point changes with it. **We do hold the street address you enter** when you set up your account. It is not used to place you on a map, it is not part of matching, and it is not shown to employers — the only address an employer sees is the one on their own shift. An **employer’s business location is exact**, because a worker has to be able to get to the right place. It comes from the address the employer picks at sign-up, and it is shown to workers on the shift. ## Notifications JUMP sends push notifications about shifts, applications, confirmations, and messages. Delivery goes through Expo and then through Apple or Google, depending on your phone — see our sub-processor list (/legal/sub-processors). **A message notification shows up to the first 80 characters of the message on your lock screen**, so it can be read by anyone holding your phone. You can turn notifications off in your device settings, but doing so means you will not hear about shifts in time to accept them. ## How we share information **Between the two sides of a shift.** An employer sees a worker’s name, photo, ratings, categories, skills, and years of experience — but only for a worker who applied to one of that employer’s own shifts. There is no worker directory to browse, and your résumé file is never sent to an employer. A worker sees the employer’s business details on the shift. **With the companies that run parts of the Services for us.** They act on our instructions and may not use your information for their own purposes. There are nine, and our sub-processor list (/legal/sub-processors) sets out for each one what it does, what it receives, and where it is: - **Amazon Web Services** — hosting, storage, and the AI that reads résumés and ranks matches. - **Stripe** — employer payments and refunds. - **Expo** — delivering push notifications. - **Apple** — delivering notifications to iPhones. - **Firebase Cloud Messaging** — delivering notifications to Android phones. - **Google Maps Platform** — the address lookup at employer sign-up and the in-app map. - **Sentry** — crash reports from the mobile app. - **Cloudflare** — our domain, and routing email sent to us. - **Gmail** — the mailbox that email arrives in. **When the law requires it**, or to investigate fraud, abuse, or a threat to someone’s safety. **We do not sell personal information. We do not run advertising, we do not use analytics, and this website sets no cookies.** ## How long we keep information - **Your account** — for as long as it exists. You can delete it in the app, under your profile. - **Notifications** — 365 days, then deleted automatically. - **Requests to join an employer** — 90 days, then deleted automatically. - **This website’s access logs** — 90 days. - **What you send us through the request-access form** — kept until we no longer need it. There is no automatic expiry on an enquiry; email us and we will delete yours. - **The record of our own team reading a worker’s data** — 400 days. That record is itself about you, which is why it has a limit rather than being kept forever. - **Backups** — a daily backup kept 35 days and a monthly backup kept 365 days, so we can recover from a failure or a mistake. **A backup is never used to bring back an account that asked to be erased.** If we restore from a backup after your deletion, the deletion is re-applied; we do not repopulate an erased account from an older copy. Some records survive account deletion because we are required to keep them or because they are not only about you: payment records we must keep for tax and accounting, and a shift another party also took part in. Deletion removes your profile, your résumé, your photo, and your contact details. ## Your choices and rights - View and change your account information in the app at any time. - **Delete your account from inside the app** — both workers and employers can. - Turn notifications off in your device settings. - Depending on where you live, you may have further rights over your personal information, such as asking for a copy of it. Email support@jumpco.co (mailto:support@jumpco.co) and we will help. Workers are never charged to use JUMP, and we never ask a worker for payment details. ## Security How we protect this information — encryption, two-factor sign-in for our own team, and the record kept of internal access — is described on our security page (/security). ## Children The Services are for adults (18 and over) and are not directed to children. We do not knowingly collect information from anyone under 18; if you believe we have, email us and we will delete it. ## Changes to this policy Every published version of this policy carries a version label and an effective date, shown at the top of this page. **Any change to the wording is published as a new version, including a correction to a typo.** That is what makes “you accepted version 2027-01-01” a statement about one specific text. Previous versions, and the exact text of each, are listed on all versions (/legal/versions/). ## Contact Questions about privacy? Email support@jumpco.co (mailto:support@jumpco.co) or write to JumpCo LLC, 160 Alewife Brook Pkwy #1486, Cambridge, MA 02138.