JOGA

Privacy Policy

Last updated: August 14, 2026

Contents

  1. Who we are
  2. Information we collect
  3. How we use information
  4. SMS and WhatsApp messaging
  5. How we share information
  6. Cookies
  7. Data retention
  8. Security
  9. Your rights
  10. Children's privacy
  11. Changes to this policy
  12. Contact us

1. Who we are

JOGA ("JOGA", "we", "us", or "our") operates JOGA POS, a sales and inventory management platform provided to businesses ("tenants") and their staff ("users") at jogapp.fr and its tenant subdomains. This Privacy Policy explains what information we collect, how we use it, and the choices you have.

This policy applies to visitors of our public website, and to users of the JOGA POS application, including tenant administrators and staff accounts created within a tenant workspace.

2. Information we collect

We collect the following categories of information:

  • Account information: name, email address, phone number, role, and password (stored as a salted hash, never in plain text).
  • Business data: store, inventory, product, customer, and transaction data that a tenant enters into the platform to operate their business.
  • Authentication data: multi-factor authentication (MFA) preferences and the phone number you provide for that purpose (see Section 4).
  • Usage and log data: IP address, browser type, device information, pages visited, and timestamps, collected automatically for security and reliability purposes.
  • Payment and billing data: subscription plan, billing status, and payment references. Card details are processed by our payment providers and are not stored on our servers.

3. How we use information

We use the information we collect to:

  • Provide, operate, and maintain the JOGA POS platform
  • Authenticate users and secure accounts, including sending one-time verification codes
  • Send service-related communications, such as account, billing, and security notices
  • Respond to support requests
  • Monitor, troubleshoot, and improve the reliability and security of the platform
  • Comply with legal obligations

4. SMS and WhatsApp messaging

Mobile phone numbers collected for multi-factor authentication are used solely to send you one-time verification codes. We do not sell, rent, or share your mobile phone number with third parties for marketing or promotional purposes. Your consent to receive these messages is never shared with any third party.

If you enable SMS or WhatsApp as your multi-factor authentication channel, you will receive a text message containing a one-time verification code each time this is required to log in or confirm a security-sensitive action on your account. These are transactional, not marketing, messages.

This is the exact notice shown at the moment you opt in, on your account's MFA settings page, directly beneath the phone number field and the "Save phone number" button:

"By providing your phone number and clicking "Save phone number", you consent to receive SMS text messages from JOGA POS for two-factor authentication purposes. Message and data rates may apply. Reply STOP to opt out, HELP for help. See our Privacy Policy and Terms of Service."

Message frequency varies by user and depends entirely on how often you log in or perform actions that require identity verification. A typical active user might receive a small number of messages per week; frequency is not fixed and is driven solely by your own account activity, not by any marketing schedule.

Message and data rates may apply. Standard carrier text messaging and data rates from your mobile carrier apply to any SMS or WhatsApp message we send you. Contact your carrier for details about your plan.

You can change your MFA channel or update the phone number on file at any time from your account's MFA settings page. To stop receiving SMS messages, reply STOP to any message we send, or disable SMS/WhatsApp MFA in your account settings (note: if MFA is required by your organization's administrator, you may need to switch to an alternate available channel rather than disabling MFA entirely).

5. How we share information

We do not sell your personal information. We share information only in the following limited circumstances:

  • Service providers: vetted vendors who process data on our behalf under contract, strictly to provide the service — for example, our cloud hosting provider, our email delivery provider, and our SMS/WhatsApp messaging provider (used solely to transmit the verification code to your device, not for their own marketing purposes).
  • Within your tenant workspace: business data you enter is visible to other authorized users within the same tenant, according to their assigned role and permissions.
  • Legal requirements: when required to comply with applicable law, regulation, legal process, or a valid governmental request.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this policy continuing to apply to your information.

6. Cookies

We use strictly necessary cookies (such as session and CSRF-protection cookies) to keep you securely signed in and to protect the platform from cross-site request forgery. These cookies are essential to the service and cannot be disabled without affecting core functionality. We do not use third-party advertising or tracking cookies.

7. Data retention

We retain account and business data for as long as your tenant's subscription is active, and for a reasonable period afterward as required to comply with legal, accounting, or reporting obligations, or to resolve disputes. You may request earlier deletion as described in Section 9.

8. Security

We use industry-standard safeguards to protect your information, including encryption of data in transit (HTTPS/TLS), encrypted storage of sensitive credentials, password hashing, and schema-level data isolation between tenants. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

9. Your rights

Depending on your location, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise any of these rights, contact us using the details in Section 12. We will respond within a reasonable timeframe and in accordance with applicable law.

10. Children's privacy

JOGA POS is a business tool and is not directed at, or knowingly used by, children. We do not knowingly collect personal information from anyone under the age of 16.

11. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above and, where appropriate, notify tenant administrators by email.

12. Contact us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at support@jogapp.fr.

© 2026 JOGA. All rights reserved.

Privacy Policy Terms of Service