Privacy Policy
Last Updated: September 1, 2026 • Valid for payment gateway underwriting (Razorpay & PayPal), GDPR, CCPA, and PCI-DSS standards.
1. Company Overview & Scope of Services
This Privacy Policy governs the collection, processing, and protection of personal information by JChat Inc. ("JChat", "we", "our", or "us") through our official digital storefront (jchatcloud.com and associated store services).
We specialize exclusively in digital software products, providing self-hosted real-time communication software licenses, source code repositories, and sandboxed add-on plugins.
2. Self-Hosted Infrastructure & Zero Chat Telemetry
We never intercept, store, or monitor your chat communications.
- Self-Hosted Chat Data: All messages, user rosters, channels, media uploads, and server databases remain strictly on your self-hosted servers or cloud infrastructure.
- License Server Communication: When activated, the software client connects to the JChat License Server solely to validate the purchase code, domain binding, and entitlement status, with cached cryptographic offline fallback.
3. Information We Collect on Store Checkout
To process commercial orders, fulfill software delivery, and comply with tax and accounting laws, we collect:
Full name, email address, password hash (salted using Argon2/bcrypt), and optional company name for commercial invoicing and Customer Portal access.
Order IDs, item SKUs, purchase timestamp, payment provider reference IDs, currency, and the target domain URL bound to the software license.
IP address, user agent, and browser session headers used strictly for fraud prevention, chargeback verification, and CSRF token protection.
We never store raw credit card numbers, debit card PANs, or CVV/CVC security codes on our servers.
4. Payment Processors & Gateway Compliance (Razorpay & PayPal)
All checkout payments are processed through certified, PCI-DSS Level 1 compliant payment gateways:
- Razorpay (Razorpay Software Pvt. Ltd.): When choosing Razorpay, payment information (UPI, cards, net banking, wallets) is securely encrypted and tokenized directly via Razorpay's checkout SDK without touching our servers.
- PayPal (PayPal Pte. Ltd. / PayPal Holdings): When selecting PayPal, transactions are authenticated directly within PayPal's encrypted interface. We receive only standard transaction tokens and order confirmation payloads.
All transmissions during checkout use Transport Layer Security (TLS 1.3) with 256-bit encryption.
5. Purpose of Data Use & Strict No-Sale Policy
We do not sell, rent, monetize, or trade your personal information with any third-party advertisers.
Your data is utilized solely for the following explicit purposes:
- • Delivering purchase codes, download tokens, and cryptographic license files.
- • Generating valid tax invoices, transaction receipts, and accounting records.
- • Providing customer technical support and license domain re-binding assistance.
- • Preventing payment fraud, identity theft, and unauthorized chargeback claims.
- • Complying with applicable statutory legal and financial audit obligations.
6. Cookies & Session Storage
The JChat Store uses only strictly essential functional cookies:
- •
jchat_store_session: Secure, HttpOnly, SameSite cookie used to maintain authenticated customer sessions. - •
store_theme: Stores your light/dark display preference.
We do not utilize third-party ad retargeting trackers, social media pixel beacons, or invasive analytics scripts.
7. Customer Rights (GDPR, CCPA & Global Laws)
Regardless of your jurisdiction, you possess the following comprehensive data rights:
- • Right of Access: Request a complete export of your customer account profile and purchase history.
- • Right to Rectification: Update or correct your billing email and contact details at any time.
- • Right to Erasure: Request the deletion of your account and personal identifiers (subject to statutory financial recordkeeping requirements).
- • Right to Non-Discrimination: We provide equal pricing and service regardless of the exercise of your privacy rights.
8. Contact Information & Grievance Officer
In compliance with global electronic commerce and payment gateway regulations, you may contact our dedicated Data Protection and Grievance Officer regarding any privacy inquiries, data requests, or compliance questions: