Privacy Policy
This Privacy Policy explains how JPAgency LLC ("Chispa", "we", "us") collects, uses and shares personal data. Where we process personal data on behalf of an agency that uses the Service, including the data of its Managed Creators and Fans, the agency is the controller and we act as processor under the Data Processing Agreement; this Policy describes our own practices. Capitalized terms not defined here have the meaning in the Terms of Service.
1. Who we are
JPAgency LLC operates Chispa from the United States. For privacy questions or to exercise your rights, contact [email protected]. If a data-protection representative or officer is required by law, we will designate one and update this Policy with their details. Data subjects in the EU/UK may contact us directly and retain the right to complain to their supervisory authority.
2. Personal data we process
(a) Account data you provide: agency name, user names, email, password (stored hashed), team roles. (b) Connected-platform data: public handles; message content and metadata; Fan names, notes, tags and spending patterns; and connection/session credentials (encrypted). (c) Usage and security data: feature usage, AI generation counts, logs, device information, IP address and the country derived from it (via our edge/CDN provider), used for security and abuse prevention, for example, to flag a sign-in from a new country and to show you your active sessions. (d) Billing data: prepaid balance, commission and seat records, and payment references from our payment processor (we do not store full payment credentials).
3. Sources
We obtain personal data directly from you, from your team members, from the connected Fan Platform accounts you authorize (including Fan interactions routed through the Service), and automatically from your use of the Service (usage and security data).
4. Purposes and legal bases
We process personal data to: provide, operate and secure the Service; generate the AI drafts you request; compute Attributed Sales and collect fees; prevent fraud, abuse and security incidents; comply with law; and communicate with you. Where the GDPR applies, our legal bases are performance of a contract, our legitimate interests in operating and securing the Service (balanced against your rights), your consent where required, and compliance with legal obligations.
5. AI processing
To generate drafts and content descriptions, relevant conversation context and content is sent to AI inference providers acting as our sub-processors under confidentiality and data-protection terms. We aim to minimize the data sent. Depending on the mode the agency chooses, AI output is either suggested to a human operator who reviews and sends it, or sent automatically on the agency's behalf under the agency's configuration and safety controls (see Section 13). We do not sell your data, and we do not use it to train models except on an aggregated and de-identified basis (see Section 16).
6. Recipients and sub-processors
We share personal data with sub-processors that help us run the Service, cloud and hosting infrastructure; edge/CDN and network security; AI inference providers; a cryptocurrency payment processor; and a transactional email provider, each under appropriate data-protection terms (see the DPA, Exhibit C). We also disclose data to authorities where legally required, and in a merger or acquisition subject to this Policy. We do not share personal data with third parties for their own marketing.
7. We do not sell your data
We do not sell personal data and do not share it for cross-context behavioral advertising. Under the California Consumer Privacy Act (CCPA/CPRA) and comparable laws, we do not "sell" or "share" personal information as those terms are defined. California residents have the rights described in Section 10 and will not be discriminated against for exercising them.
8. International transfers
We are a U.S. company and process personal data primarily in the United States, with certain sub-processors in other jurisdictions. Where personal data subject to EU or UK law is transferred to a country without an adequacy decision, we use appropriate safeguards, including the Standard Contractual Clauses and, for UK data, the UK IDTA.
9. Retention
We retain personal data only as long as necessary for the purposes in this Policy, or as required by law. On account termination we delete or anonymize personal data within a reasonable period, except records we must keep. Default periods (subject to change):
| Category | Retention |
|---|---|
| Account and profile data | While your account is active; deleted or anonymized within a reasonable period after termination. |
| Operational data (recent messages, activity, AI logs) | Pruned on rolling windows (typically up to twelve (12) months). |
| Compliance and financial records (immutable archive of messages sent, audit logs, billing) | Retained longer as needed for legal, tax and dispute-resolution purposes. |
| Security data (IP address, login country) | Retained for a limited period for abuse prevention and to show your active sessions. |
10. Your rights
Depending on your location, you may have the right to access, correct, delete, restrict, port or object to the processing of your personal data, to withdraw consent, and (for California residents) to know, delete and opt out. For data we process on an agency's behalf (including Fan data), please direct requests to that agency, which is the controller; we will assist it as processor. To exercise rights regarding our own processing, contact [email protected]. We will verify your request and respond within the time required by law. You may also lodge a complaint with your supervisory authority.
11. Security
We apply technical and organizational measures appropriate to the risk, including encryption of sensitive credentials, TLS in transit, request signing, role-based access, tenant isolation, rate limiting, audit logging and backups (see the DPA, Exhibit B). No method is perfectly secure; you are responsible for safeguarding your credentials and may enable two-factor authentication and review your active sessions in the Service. If a security breach affects your personal data, we will notify you and, where required, the competent authorities, in accordance with applicable law.
12. Children and prohibited content
The Service is for businesses and adults only. It is not directed to anyone under 18, and we do not knowingly collect personal data from anyone under 18. You must ensure that every Managed Creator is a legal adult and that Fans are adults on the Fan Platform. If we become aware that we hold data of a person under 18, we will delete it promptly. Where content that may depict a minor is suspected, we will preserve evidence and report to the appropriate authorities, including the National Center for Missing & Exploited Children (NCMEC), INHOPE or equivalent, as required by law.
13. Automated decision-making and profiling
We do not make decisions that produce legal or similarly significant effects on a data subject based solely on automated processing. The AI Copilot supports the agency's communication with its own audience: depending on the mode the agency chooses, it either suggests replies that a human sends, or sends routine messages automatically on the agency's behalf under the agency's configuration and safety controls, with human override available at any time and sensitive moments handed off to a human. Analytics and fan "scoring" shown in the Service are decision-support for the operator, not automated decisions about the data subject.
14. Cookies
We use only strictly necessary cookies and equivalent local storage to operate the Service, as described in the Cookie Policy. We do not use advertising or third-party tracking cookies.
15. Do-Not-Track
Because we do not track users across third-party sites or serve advertising, we do not alter our practices in response to "Do-Not-Track" browser signals.
16. Aggregated and de-identified data
We may create and retain aggregated and de-identified data that no longer identifies any individual, and use it to operate, secure, evaluate and improve the Service and its models (see Section 10.3 of the Terms and Section 5 of the DPA). Such data is not personal data; we do not attempt to re-identify it.
17. Changes to this Policy
We may update this Policy at any time, at our discretion. Changes become effective when posted to our legal pages with an updated version identifier. It is your responsibility to review the current Policy. Your continued use of the Service after a change is posted constitutes your acceptance of it.
18. Contact
JPAgency LLC, [[REGISTERED ADDRESS]]. Privacy contact: [email protected].