Skip to content
Jam Portal
PrivacyTermsRefundsData Rights

Legal

Jam Portal Data Retention and User Rights Policy

Effective date: 12 August 2026

Privacy contact: zyroth@jamportal.app

This document explains Jam Portal's pilot retention rules and the practical process for access, correction and deletion requests.

It should be read together with the Jam Portal Privacy Policy.

1. Retention principles

Jam Portal aims to keep personal data only for a defined operational, security, contractual, accounting or legal purpose; delete or de-identify data when that purpose ends and no lawful reason requires continued retention; avoid keeping Guest or Staff data indefinitely merely because storage is available; preserve records where reasonably necessary for fraud prevention, security, legal claims, tax, accounting or regulatory obligations; and allow backups to expire according to configured retention where selective deletion is not technically supported.

2. Pilot retention schedule

Data categoryPilot retention rule
Active queue dataSession and queue lifecycle based
ChatExisting automatic cleanup; may also be trimmed when collection limits are reached
Presence recordsNormally cleaned when stale/offline and older than approximately 7 days
Guest anonymous-auth/device recordsTarget: delete or de-identify after 90 days of inactivity
Guest device identifiers/device logsTarget: 90 days after inactivity unless needed for active abuse/security enforcement
Queue history and dedicationsTarget: 90 days
Feedback and ratingsUp to 12 months
Removed/inactive Staff membership recordsUp to 12 months, unless longer retention is needed for security, audit or dispute resolution
Support requests/contentUp to 12 months
General operational audit recordsNormally up to 90 days where practical
Security, warning, ban and moderation recordsNormally up to 90 days; longer where reasonably necessary to prevent abuse, investigate an incident or resolve a dispute
Payment, subscription and accounting recordsUp to 7 years where reasonably needed for tax, accounting, fraud prevention, audit, dispute or legal obligations
Email-delivery ledgerUp to 12 months
Closed venue account dataTarget: delete or de-identify within 90 days after termination, except payment, tax, accounting, security, fraud, dispute or legal records that must remain
Daily Firestore backupsIntended expiry after 7 days
Weekly Firestore backupsIntended expiry after 28 days
Search browser cacheApproximately 10 minutes, bounded
Media catalogue unavailable entriesTarget pruning after approximately 1 day
Inactive media catalogue entriesTarget pruning after approximately 30 days
Infrastructure/provider logsAccording to configured provider retention; where Jam Portal controls the setting, only as long as reasonably needed for security, reliability and troubleshooting

3. Guest session end

Ending a Guest session does not necessarily delete all Guest-related information immediately.

Presence may be removed or marked offline, while queue history, chat, feedback, audit or moderation records may remain for their applicable retention period.

Anonymous authentication and device records may also remain until they reach the applicable inactivity/deletion threshold.

4. Staff removal

Removing Staff access revokes or disables access but may leave an inactive membership and historical actions for the retention period needed for security, accountability and dispute resolution.

5. Venue closure

Where a venue account is terminated, Jam Portal aims to remove or de-identify ordinary venue-account personal data within 90 days, subject to payment/accounting retention, tax obligations, audit/security records, fraud prevention, disputes or legal claims, backup expiry and provider-log retention.

A disabled, restricted, locked or expired subscription is not the same thing as an immediate deletion request.

6. Backups and deletion

Primary data may be deleted before copies in scheduled backups expire.

Jam Portal's intended backup retention is 7 days for daily backups and 28 days for weekly backups.

If selective deletion from a backup is not supported, the backup will normally expire according to its schedule.

If Jam Portal restores a backup containing information that had already been validly deleted or corrected, Jam Portal should re-apply the deletion or correction where reasonably necessary.

7. Your rights

Subject to applicable Ugandan law, you may request confirmation, access, correction, deletion or destruction where Jam Portal no longer has authority to retain data, stopping certain harmful processing, stopping direct marketing, and information about recipients or categories of recipients where applicable.

8. How to make a privacy request

Email zyroth@jamportal.app with the subject Privacy Request.

State whether you are requesting Access, Correction, Deletion, Stop Processing, Stop Direct Marketing or another privacy matter.

Provide only enough information for Jam Portal to identify you and locate the relevant records.

Do not send passwords, PINs, complete payment credentials or authentication tokens.

9. Identity verification

Jam Portal may request reasonable proof that the requester is the data subject or is authorised to act for them before disclosing, changing or deleting account-linked data.

Verification should be proportionate and should not collect excessive information.

10. Handling a request

Jam Portal should record the request, verify identity where needed, locate relevant data, determine whether the request can be fulfilled, perform the appropriate action, notify the requester of the outcome, and explain any lawful retention exception.

Jam Portal will respond within the period required by applicable law and aims to respond promptly.

11. Reasons some data may remain

Data may remain where retention is reasonably necessary for tax or accounting obligations, fraud or abuse prevention, security investigations, legal claims, regulatory compliance, protection of another person's rights, a valid contractual/legal requirement or scheduled backup expiry.

12. Direct marketing

A user may ask Jam Portal to stop using personal data for direct marketing.

Operational or security messages necessary to provide or protect an account are not treated as marketing merely because the user has opted out of marketing.

13. Complaints

If you believe Jam Portal has not handled your privacy request appropriately, contact zyroth@jamportal.app.

You may also have the right to complain to Uganda's Personal Data Protection Office (PDPO).

14. Internal responsibility

Jam Portal should maintain a simple privacy-request log containing the request date, verified identity status, request category, systems checked, action taken, completion date and lawful retention exception if any.

The request log itself must not contain unnecessary personal data.

15. Review

This retention schedule should be reviewed whenever Jam Portal adds a new personal-data field/provider/payment integration/analytics system, changes backup retention, introduces new account/deletion workflows, or materially changes venue or Guest functionality.

HomePrivacyTermsRefundsData Rights

© 2026 Jam Portal. Kampala, Uganda.