JPINZ legal

Cookie & Storage Notice

Version 1.1 · Effective 27 August 2026

This notice lists what JPINZ actually stores in your browser. It is built from the current implementation, not from a template. JPINZ has no advertising cookies, no behavioural advertising trackers, and no third-party analytics service — so this notice does not invent those categories to look conventional.

JPINZ is operated by the team building it. The legal operating entity has not yet been incorporated, so this document does not yet state a registered company name, company registration number, registered office or VAT number. Those details will be added here before JPINZ opens to the public, and this notice will be removed at that point.

Cookies

JPINZ itself sets one cookie, and only inside the Business dashboard, when you collapse or expand the dashboard sidebar. One further cookie is set by Cloudflare, the service that delivers and protects the site.

NameSet byPurposeLifetimeEssential?
sidebar_stateJPINZRemembers whether you collapsed the dashboard sidebar.7 daysFunctional preference. Set only by your own action, holds no identifier.
__cf_bmCloudflareBot management and abuse protection: helps tell real visitors apart from automated traffic so the site stays available. It is not used for advertising, and not used to profile you or track you across other websites.About 30 minutes, renewed while you browseStrictly necessary (security / availability).

Your JPINZ sign-in session is not held in a cookie. It is held in your browser's local storage by the authentication library, as described below.

Authentication and session storage

Stored itemPurposeEssential?
Authentication token (local storage, key beginning sb-)Keeps you signed in between page loads and refreshes your session. Set by our authentication provider's library.Strictly necessary — without it you are signed out on every page load.
jpinz.auth.pendingVerifyRemembers that you have just signed up and are waiting to confirm your email address, so the right screen is shown.Strictly necessary for the sign-up flow.
jpinz.auth.verifyResendAtStops the “resend confirmation email” button being used repeatedly.Strictly necessary (abuse protection).
jpinz.auth.ageConfirmedCarries your 18+ confirmation and your acceptance of the Terms and Privacy Policy through sign-up, including a redirect to Google and back, so they are recorded against the new account.Strictly necessary for account creation.
jpinz.preview.sessionPre-launch only: remembers that you arrived with a valid preview invite. See Privacy Policy.Strictly necessary while JPINZ is invite-only.

Your settings and app state

These are kept in your browser so the app behaves the way you left it. They stay on your device, and none of them is used to identify or track you.

Stored itemPurposeEssential?
jpinz.map-stateYour last map position, zoom, radius and filters.Functional preference.
jpinz.intent.sessionYour Quick Check-In answers for the current browsing session.Functional preference (session only).
jpinz.scopeWhether you are browsing nearby or nationwide.Functional preference.
jpinz.viewedContentWhich offers you have already opened, so “new” badges and story rings are accurate.Functional preference.
jpinz.seenActivityWhich business stories you have already viewed.Functional preference.
jpinz.dashboard.visitedWhether you have seen the onboarding tour, so it is not shown again.Functional preference.
jpinz.admin.stateAdministrator screen filters. Only present for administrator accounts.Functional preference.
jpinz.brandkit.v1A local copy of your Brand Kit while you are editing it, so work is not lost.Functional (Business accounts).
jpinz.profile.localEditedAtTracks unsaved business-profile edits.Functional (Business accounts).
jpinz.creation-ref.*Groups the AI generations belonging to one piece of content you are creating, so quotas are applied fairly.Functional (Business accounts).
jpinz.redeem-lockPrevents a redemption being submitted twice by a double tap.Strictly necessary during redemption.
jpinz.analytics.sessionA random reference for the current browsing session, so a single visit is not counted many times in a business's view count.See “Analytics” below.
jpinz.storage.migrated.v1Records that older keys from the previous product name have been cleaned up, so it happens once.Housekeeping.

Analytics

JPINZ counts views of businesses and offers so businesses can see how their own content performs. The session reference stored in your browser is random, is regenerated for each browsing session, is not linked to your account, and is used only to avoid counting the same visit repeatedly. No third-party analytics service, advertising pixel or cross-site identifier is used.

Pending legal review: JPINZ treats this as strictly necessary first-party measurement rather than analytics requiring prior consent, because the reference is per-session, not persistent across sessions, not shared with anyone, and not used for profiling or advertising. This classification should be confirmed by a privacy adviser before launch, since it determines whether a consent banner is needed at all.

Service worker and push notifications

If you turn on push notifications, JPINZ registers a service worker (/sw.js) so your browser can receive and show them. Your browser creates a push subscription, which JPINZ stores on your account rather than in your browser storage.

  • The service worker is registered only when you enable push notifications, never before.
  • It is used for notification delivery, not for tracking or advertising.
  • You can remove a device in your notification settings, and revoke notification permission in your browser at any time.

Google Maps

JPINZ draws its maps with the Google Maps JavaScript API. This is what we have established from the actual implementation:

CategoryWhat JPINZ has established
When it loadsOnly on screens that show a map, and only when that screen is opened. The current pre-launch homepage loads no Google code and makes no request to Google.
Technical data transmittedYour IP address, the requested map area and zoom, and standard technical request information (browser, referring page) go to Google so the map tiles and code can be returned.
Strictly necessary functionalityThe map is the core of JPINZ discovery. Loading map code and imagery on a map screen is required for the feature you asked for.
What JPINZ does not sendYour name, email address, account identifier or saved notification area are not sent to Google for maps. Your device location is used in your browser to centre the map; JPINZ does not transmit it to Google as a separate identifier.
Storage placed by MapsGoogle's map library may place its own technical storage in your browser for map functionality. JPINZ does not create it, cannot read it and does not use it.
Potentially requiring consentAny Google storage that persists beyond the map screen and could function as an identifier. JPINZ has not confirmed the current behaviour of Google's library in enough detail to state this definitively.

Pending legal review: Whether Google Maps places any non-essential identifier that requires prior consent under the ePrivacy rules is a legal determination JPINZ cannot make from its own code, because the storage belongs to Google's library. This is recorded as a decision required before launch. JPINZ has deliberately not installed a consent banner merely because a third party is involved, and has deliberately not claimed the position is settled.

Is there a cookie banner?

No. On the current inventory, everything JPINZ itself stores is either strictly necessary or a preference you set by using the app, so an Accept/Reject banner would ask you to consent to nothing. The one open question is Google Maps technology, above. If that determination shows prior consent is required, JPINZ will gate the map behind consent — rather than adding a banner that changes nothing.

Managing this yourself

  • You can clear cookies and site data for JPINZ in your browser settings at any time. You will be signed out and your preferences reset.
  • You can revoke location permission and notification permission for JPINZ in your browser settings.
  • You can remove your saved notification area, and your push devices, in your JPINZ notification settings.

Questions about this notice: privacy@jpinz.com.

Contact

For privacy questions and data-rights requests, email privacy@jpinz.com. For anything else, email support@jpinz.com. Neither address is a Data Protection Officer: JPINZ has not appointed one.