1. Who we are
Jelto is operated by Taha Bozdemir. For privacy questions or requests, email [email protected].
We control the information used for Jelto’s accounts, billing and security. We process customer analytics on the customer’s instructions under our DPA. For data collected by a website or app using Jelto, contact that operator first. This notice explains processing; it does not request consent.
2. Account information
We collect your email, authentication and session records, settings, team memberships, subscription records and support messages electronically. These come from you, inviting administrators, your service usage and enabled sign-in, payment or integration providers. Google sign-in supplies verified identity information. Email and authentication details are required for account access; integrations are optional.
Under applicable data protection law, our purposes and legal grounds are:
- Accounts, subscriptions and requested support: performing a contract or taking requested steps before one, when you are personally a party.
- Business contacts, team access and security: our and our customers’ legitimate interests in managing and protecting the service, balanced against your rights.
- Required financial records and authority requests: legal obligations applicable to us.
- Optional processing requiring consent: separately requested consent, which you can withdraw.
Customers determine the legal grounds for their own analytics. Lemon Squeezy handles checkout; Jelto’s invoice records contain neither card details nor billing addresses.
3. Analytics data
Collection depends on the customer’s settings:
- Websites: page and referrer hosts and paths, campaign labels, events and permitted properties, timestamps, browser and device details, user agent, language, approximate location and engagement such as scroll depth, downloads and outbound hostnames.
- Desktop apps: a persistent random install ID, app and operating-system details, language, approximate location, activity and configured properties.
- Revenue: amounts, currencies, payment times, transaction digests and aggregate attribution labels; app revenue may include an install ID.
- Server crawlers: request time, hostname, redacted path, GET/HEAD method, optional status and crawler classification. The crawler user agent is used transiently.
Jelto uses IP addresses in memory for approximate location and daily website hashes, but does not write them to application stores or logs. Network providers receive connection addresses and may retain their own network or security logs. We do not link website visitors to app installations.
Hashes, cookies and install IDs can be personal data. Query strings are removed except for supported campaign labels; advertising click-identifier values are discarded. Customers must avoid unnecessary personal information in paths, labels, properties and imports.
4. Cookies and local storage
- Default website tracker: no cookies or browser storage. Daily hashes are scoped to each product; salts expire within 48 hours.
- Optional cookie tracker: a first-party visitor cookie recognizes returning visitors on the same host for 395 days from creation. Later visits do not extend it.
- Optional attribution memory: a first-touch channel label and date in local storage for 30 days, without a visitor identifier.
- Optional checkout memory: an entry-group label and timestamp in session storage for 30 minutes.
- Jelto accounts: essential sign-in cookies. A website origin supplied during signup may be saved locally for up to 24 hours to continue setup.
Customers must provide notices and obtain consent where required. Browser or app controls can stop future collection; clearing local storage does not erase server history.
5. Connected services and sharing
Enabled GitHub connections supply repository and commit metadata, including titles and contributor logins, without code or diffs. Search Console supplies query and page aggregates. Revenue connections supply credentials and payment records needed for the feature. Imported content may contain personal information.
Email reports send recipients and selected aggregate content through our email provider. Public dashboards and widgets expose aggregates customers choose to share. Customers control these features and any copies they download or distribute.
7. Retention and deletion
- Analytics: 30 days to your plan maximum—three years on Starter, five on Growth. The default is three years. Live cleanup can lag the reporting period by approximately two days.
- Product deletion: a seven-day cancellation window, followed by live-store deletion processing within 24 hours. Recovery backups age out within 30 days and the ingest archive within 90 days. Recovery must apply deletion records before restoring data to service.
- Trials: collection stops after 14 days without payment, with deletion scheduled seven days later. Cancelling a previously paid subscription does not itself erase history.
- Stored exports: files are available for seven days from job creation. Expiry blocks new downloads immediately; scheduled maintenance removes the files and retries failures. Installation erasure revokes and removes its specific files and product-wide exports. Customers can generate new exports from remaining data after erasure completes. Product/account deletion removes all their stored exports. Cleanup metadata remains until file removal succeeds. Jelto does not delete copies already downloaded to customers’ devices.
- Other records: accounts and settings remain while needed for service and outstanding requests. Current storage schedules are seven years for financial records, 365 days for security audit records and 30 days for rendered weekly reports. Legal financial-retention requirements may be longer.
- Deletion records: scope, account/product or install identifiers and completion evidence document erasure and prevent restoration. These currently have no scheduled expiry.
These schedules and the deletion-record limitation do not waive erasure rights. The 30- and 90-day recovery periods do not cover every stored copy. Contact us about data that remains; customers are responsible for copies they download or share.
8. Security
Jelto’s security design includes access controls, encrypted connections and backups, hashed account tokens and API keys, encrypted integration credentials, and time-limited, audited support access. Recovery copies are restricted to recovery. These describe the service design, without claiming an independent certification.
9. Your rights
Depending on applicable law, you may learn whether and why we process your data and who receives it; access, correct, erase or obtain it; restrict or object to processing; and withdraw consent. You may also request that recipients receive corrections or erasure notices, object to adverse decisions based solely on automated processing, and seek compensation for unlawful processing. Withdrawal does not affect earlier lawful processing.
For Jelto account data, email [email protected]. For customer analytics, contact the website or app operator. Account controls support exports and deletion, subject to Section 7. App users can provide their install ID. Cookieless website records may no longer be identifiable after their short-lived context expires; we assess information you provide without collecting new identifiers solely to identify you.
Ordinary requests are free, with only necessary identity checks. We respond without undue delay and within applicable legal deadlines. GDPR responses normally take one month; permitted extensions of up to two further months are explained within the first month. Any legally permitted fee or refusal will be explained.
You may complain to the competent data protection authority or seek a remedy in court. Our contractual liability and venue clauses do not restrict these rights or regulators’ powers.
10. Governing law and updates
This Privacy Policy is governed by the laws of the Republic of Türkiye, without limiting your rights under applicable data protection laws.
We date revisions and communicate material changes through the service or account email where appropriate. This version is for review; the business address, transfer details and final review will be completed before it takes effect.