Terms and Policies
Jin Martial Arts Privacy Policy
Privacy practices for JinMa member, family, app, CRM, and related service data.
Effective April 29, 2026
Overview
Effective Date: April 29, 2026 Last Updated: April 29, 2026
This Privacy Policy describes how Jin Martial Arts Academy, LLC, doing business as Jin Martial Arts Academy, Jin Martial Arts, and JinMa ("Jin Martial Arts," "JinMa," "we," "us," or "our"), collects, uses, discloses, retains, and protects personal information when you use our Services.
This Privacy Policy covers our public website at https://jinmartialarts.com, the JinMa Members mobile application, any member portal or student portal we operate, hosted member APIs, staff CRM and staff-facing operational tools where relevant, legal/support/account pages, and related digital services that link to or reference this Privacy Policy (collectively, the "Services").
1. Important context about how the Services work
Our Services are family- and academy-authorized services, not open public registration platforms. Access is generally tied to existing academy records, approved contact methods, role assignments, family relationships, and access settings.
Much of the information in our systems about children is provided by parents, legal guardians, family organizers, authorized adults, staff, or existing academy records. In some cases, we may also enable a teen or child to use a permitted feature directly. If we know we are collecting personal information online directly from a child under 13, our Children's Privacy and Parent Notice also applies, and we may require direct notice and verifiable parental consent before full use of the relevant feature.
2. Categories of personal information we may collect
Depending on the Service, account type, feature, and relationship involved, we may collect the following categories of personal information.
2.1 Identity and account identifiers
Examples include first and last name, nickname, display name, certificate name, academy member ID, account ID, family ID, roster ID, Supabase or authentication IDs, device or installation ID, and role or permission data.
2.2 Contact information
Examples include email address, mobile phone number, home phone number, mailing address, city, state, ZIP code, and emergency contact information.
2.3 Family, relationship, and role information
Examples include parent or guardian relationships, family organizer status, adult/child/helper role data, linked families, authorized family users, app-access settings, and family-level permissions.
2.4 Member, student, and profile information
Examples include date of birth, age category, child/minor status, gender, belt size, program or rank status, progress data, participation history, absences, and related academy profile details.
2.5 Attendance, enrollment, and academy-operation information
Examples include class check-ins, attendance history, event sign-ups, schedule data, program enrollment, participation records, and related operational information.
2.6 Coaching, support, and note information
Examples include goals, support tickets, parent concerns, coaching notes, progress observations, behavior notes, home-context notes, benchmark readings, and similar support information.
2.7 Health and safety information
Examples may include allergy, injury, disability, accommodation, medical, or safety-related information you or your family provide so we can support participation and respond appropriately.
2.8 Payment and billing information
If payment features are used, we may collect billing-related information such as payment status, invoice history, transaction records, subscription or tuition status, who is responsible for payment, and payment processor reference data. We use Stripe or other approved processors and do not intend to store full payment card numbers in our own systems.
2.9 Messages, uploads, and user-generated content
Examples include messages, support requests, attachments, uploaded documents, profile photos, videos, audio, goals, feedback, benchmark submissions, and similar content.
2.10 Device, app, browser, and technical information
Examples include push token, installation ID, platform, app version, build number, notification permission state, selected family or member context, session state, IP address or derived request metadata where logged, cookies, browser storage, device storage, app cache data, and security or troubleshooting logs.
2.11 Public media, marketing, and analytics information
Examples include photographs or videos taken at classes or events, website analytics data, campaign measurement data, advertising or referral data, and related marketing information.
2.12 Staff, volunteer, and internal operational information
Examples include staff names, work contact details, internal roles, permissions, groups, access history, and account status.
3. Sources of personal information
We may collect personal information from:
- you directly;
- a parent, legal guardian, family organizer, or other authorized adult;
- academy staff, instructors, admins, or support personnel;
- existing academy membership, waiver, attendance, billing, or operational records;
- your device, browser, or app instance;
- service providers and technical vendors; and
- app stores, payment processors, communications providers, analytics providers, or similar third parties that support the Services.
4. How we use personal information
We may use personal information to:
- provide, operate, maintain, and improve the Services;
- authenticate users and prevent unauthorized access;
- manage family, member, staff, and role relationships;
- allow family organizers or authorized adults to manage family records and access settings;
- process account-change requests, office approvals, contact-method verification, and related workflow logs;
- communicate through announcements, messages, tickets, push notifications, email, or similar channels;
- operate classes, schedules, events, attendance, progress tools, and academy administration;
- process billing, recurring tuition, merchandise, event fees, or payment updates where available;
- store, display, moderate, or remove photos, messages, and other content;
- maintain legal acceptance, consent, and audit records;
- troubleshoot issues, monitor performance, and secure our systems;
- investigate misuse, support safety, respond to incidents, and enforce policies; and
- comply with legal obligations, contracts, insurance needs, and recordkeeping requirements.
5. When we disclose personal information
We may disclose personal information to the following categories of recipients.
5.1 Authorized staff, instructors, admins, helpers, and contractors
We disclose information to academy personnel and approved internal users who need it for support, operations, moderation, safety, technical administration, or compliance.
5.2 Authorized family or account users
Depending on the family structure and permissions, we may disclose information within a family or linked-account context to family organizers, authorized adults, helpers, and other approved users.
5.3 Service providers and processors
We may disclose information to service providers that help us host, secure, store, deliver, analyze, and support the Services. Depending on the Service and build, these providers may include services such as Supabase, Vercel, Expo, Apple, Google/Firebase, SendGrid, Brevo, Twilio, Stripe, Google Calendar, Google Analytics, Meta tools, and AI-assisted support or operations providers that we actually use from time to time.
5.4 Legal, safety, insurance, and compliance recipients
We may disclose information where reasonably necessary to comply with law, respond to lawful requests, protect rights or safety, investigate misuse, respond to incidents, work with insurers, or enforce agreements.
5.5 Business transfers
If we are involved in a merger, financing, acquisition, reorganization, or sale of all or part of our business, information may be disclosed as part of that process, subject to applicable law.
5.6 Public media use
We may disclose photos, videos, or similar media publicly only where a separate release, other permission, or another lawful basis allows it.
6. Account management, correction requests, and access controls
6.1 Request-and-approval changes
Some core family or member profile changes may be handled as submitted requests instead of immediate edits. Depending on the field and risk involved, we may require office approval, manual review, or supporting verification before the requested change becomes effective.
Examples may include family name, address, phone number, member name, certificate name, gender, and date of birth.
6.2 Verification of email and phone changes
If we allow you to request a new email address or phone number, we may require confirmation codes, confirmation links, or similar verification before the new value becomes active for communications or account access.
6.3 Pending requests and withdrawals
Where functionality allows, a pending correction or update request may be withdrawn before it is approved or denied. Even after a request is withdrawn, we may keep the request history and related audit information for support, security, or compliance purposes.
6.4 Family organizers and direct login controls
Family organizers or other authorized adults may be able to turn direct app access on or off for family members, subject to academy controls. Direct under-13 access may require a separate parent or legal guardian consent process before login or child-interactive features become available.
7. Children's privacy, youth access, and parent rights
7.1 Child information in adult-managed systems
A large amount of child-related information in our systems is provided by parents, guardians, family organizers, authorized adults, or staff rather than directly by the child.
7.2 Direct minor use
We may allow teens or children to use permitted parts of the Services where family permissions and academy controls allow it. Current functionality may vary by role and feature. If a child under 13 is enabled to log in directly or otherwise provide personal information directly, we may require a separate children's privacy workflow before full use of that feature.
7.3 COPPA and parent notice
If we have actual knowledge that we collect personal information online directly from a child under 13, our Children's Privacy and Parent Notice applies, and where required by law we will provide direct notice and obtain verifiable parental consent before collecting, using, or disclosing that information, unless a legal exception applies.
7.4 Parent rights
A parent or legal guardian may ask us to review, correct, delete, or stop future collection or use of a child's personal information, subject to reasonable identity and authority verification and records we are legally permitted or required to retain.
7.5 Data minimization for children
We do not intend to require a child to provide more personal information than is reasonably necessary for the specific activity or feature involved.
8. Messaging, moderation, and content handling
If you use messaging, ticketing, or related communication features:
- messages and attachments may be stored on our systems and cached on your device;
- messages are not represented as end-to-end encrypted;
- authorized staff may review, monitor, archive, export, or delete messages for support, safety, moderation, investigations, training, recordkeeping, or compliance; and
- deleted or archived items may persist for a limited time in backups, logs, or internal records.
9. Photos, media, and uploads
Our Services may allow profile photo uploads and may display photos or media in family, member, CRM, or announcement contexts.
We may store, resize, moderate, version, and delete uploaded media as reasonably necessary to operate the Services. Public marketing or social-media use of class or event media is governed by a separate photo or media release or another lawful basis.
If you request removal of a specific online image or video we control, we will review the request. We may be able to remove online copies we control and stop future use, but we may not be able to retrieve printed materials or third-party reposts.
10. Cookies, browser storage, and on-device storage
10.1 Website and CRM technologies
Our website and CRM may use cookies, session tokens, browser storage, and similar technologies for authentication, security, remembering settings, analytics, and related operations.
10.2 Analytics and advertising or measurement tools
We may use analytics, campaign measurement, or similar tools on websites or related pages, including technologies provided by companies such as Google Analytics or Meta where used. These tools may collect browser, device, usage, or referral information to help us understand traffic, measure campaigns, and improve our Services.
We do not say that we sell personal information for money. We also do not knowingly sell or make child personal information publicly available for cross-context behavioral advertising. Depending on the law and configuration of a tool, some disclosures of technical or usage data to analytics, measurement, or advertising-related providers may be treated differently under some privacy laws.
10.3 Mobile app and portal device storage
The Members App and related portals may use on-device storage for cached announcements, messages, settings, push preferences, and similar data. Removing the app or clearing device data may remove local copies but does not automatically remove server-side records.
11. Communications and notifications
We may send:
- one-time sign-in codes and security messages;
- account, family, billing, schedule, attendance, or event notices;
- support, ticket, and operational messages;
- service announcements and reminders;
- push notifications you enable; and
- marketing or promotional emails as allowed by law.
Our Communications and Notifications Notice provides additional detail about operational notifications, push-related device data, controls, and child-notification handling.
If SMS or automated texting is enabled for a particular workflow, separate disclosures, consent, and opt-out instructions may apply.
12. Retention and deletion practices
We keep personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law, contract, insurance, litigation, safety, or recordkeeping needs.
Our current retention framework is as follows:
- Member, family, and account records: while the relationship remains active and generally up to 7 years after the relationship ends, with longer retention where reasonably necessary for waivers, disputes, safety, insurance, or legal claims.
- Attendance, enrollment, program, and progress records: generally up to 7 years after the relevant relationship ends, and sometimes longer where tied to legal or safety matters.
- Messages, tickets, and support content: while reasonably needed for the relationship and generally up to 24 months after closure or last activity, with longer retention where needed for safety, abuse investigations, legal disputes, or compliance.
- Billing, accounting, and tax records: generally up to 7 years.
- Legal acceptance, waiver-reference, and consent records: for the life of the relevant relationship and generally up to 7 years afterward; child-related consent records may be kept longer where reasonably necessary to document permissions and revocations.
- Push tokens, app identifiers, and similar technical records: while active and generally up to 24 months after last use unless longer retention is reasonably necessary for security, troubleshooting, or compliance.
- Server, application, and security logs: generally up to 12 months, unless longer retention is reasonably necessary for investigation, abuse prevention, or legal compliance.
- Consent-initiation-only child contact information: if child consent is required and not completed, we generally delete that limited information within 30 days unless a legal exception applies.
- Backups and disaster-recovery copies: may retain information for a limited additional period consistent with backup cycles and restoration needs.
We do not promise indefinite retention of all data, and we may delete or de-identify information when it is no longer reasonably necessary.
13. Security
We use administrative, technical, and physical safeguards that are reasonably designed for our size and operations to protect personal information from unauthorized access, acquisition, use, modification, disclosure, or destruction.
These measures may include role-based access controls, service-provider controls, account security checks, logging, device or browser protections, and encryption in transit where supported. No system is perfectly secure, and we do not guarantee absolute security.
14. Your choices and request rights
Subject to applicable law and reasonable verification, you may request to:
- access or correct certain personal information;
- request deletion of certain personal information;
- review, correct, or request deletion of a child's information if you are the parent or legal guardian;
- opt out of marketing emails;
- control push notifications through device or in-app settings where available; and
- request removal of certain photos or content we control.
To make a request, contact support@jinmartialarts.com. We may ask for information reasonably necessary to verify identity, account authority, or parental authority. Our target response time is generally 30 days.
If you are an active member, deleting a digital account may result in removal of digital access only, while some membership, waiver, attendance, billing, safety, consent, or legal records remain retained. Digital-account deletion does not by itself cancel a separate membership contract or recurring billing arrangement.
15. App account deletion page
We maintain a public account and data deletion request page or equivalent support process for app-related deletion requests. Until any self-service in-app or web workflow is made available, deletion requests may be handled manually through support.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Updated versions become effective when posted or when otherwise communicated, unless a later effective date is stated. We may require renewed acceptance where appropriate.
17. Contact information
Jin Martial Arts Academy, LLC 728 Butterfield Rd North Aurora, Illinois 60542 Phone: (630) 345-6395 Email: support@jinmartialarts.com Website: https://jinmartialarts.com
Document Version
Version: v1.0.0
SHA-256: e9d7cf2af01f16e37e5c4c946296a7e9503f4e48afca5f5d27a2914e623edec9