Your information, clearly explained

Privacy Policy

This policy explains how JAMMY GROUP INC. collects, uses, shares, protects, retains, and deletes personal information across our apps, websites, events, programs, and connected services.

Last updated August 21, 2026

1. Scope and accountability

This policy applies to consumer, attendee, and participant services operated by JAMMY GROUP INC., including, where available, JAMMY, JAMMY Accounts, JAMMY CON, JAMMY DANCE, JAMMY MARKET, JAMMY PHOTO, Kawaii Alley, public websites, mobile and web apps, ticket and badge experiences, event operations, community features, support, and related services that link to this policy. In this policy, “JAMMY,” “we,” “us,” and “our” mean JAMMY GROUP INC.

A ticket checkout, event, class, contest, waiver, form, photo experience, or other feature may provide an additional notice when information is collected. A more specific notice supplements this policy and controls for that activity if there is a direct conflict. Separate notices or agreements may apply to employees, contractors, volunteers, performers, vendors, sponsors, media, and other business or workforce relationships.

JAMMY is responsible for personal information under its control, including information processed on its behalf by service providers. Our Alberta operations are subject to Alberta’s Personal Information Protection Act where applicable. Canada’s Personal Information Protection and Electronic Documents Act may apply to commercial information that crosses provincial or national borders, and other laws may apply to a particular activity.

2. How we collect information

We collect personal information directly from you when you create an account, choose profile settings, link a ticket, purchase or register, submit content, use a photo service, communicate with another user, contact Support, or otherwise use a Service.

We may also collect information:

  • from a parent or guardian who creates or manages an eligible participant profile;
  • automatically from a browser, device, app session, JAMMY-operated booth, or interaction with a Service;
  • from another user who communicates with you, reports content, invites you, or submits information involving you;
  • from ticketing, payment, authentication, notification, hosting, venue, event, or other service providers;
  • from authorized support, security, moderation, administrative, event, or program personnel; and
  • from public sources or business partners where collection is lawful and reasonably appropriate for the identified purpose.

We also create operational records such as account status, consent history, ticket-link status, security sessions, moderation decisions, delivery status, support history, and audit records.

3. Information we handle

Account and identity

Account information may include email address, password credential records, identifiers and limited profile information from Apple or Google sign-in, passkey records, optional name or display name, username, birth month and year, a derived age band, profile image, biography, interests, city, social links, account status, roles, permissions, recovery information, linked sign-in methods, consent choices, security history, and notification preferences. Birth month and year are required during ordinary account setup so we can apply age-appropriate protections without collecting a full birth date. Product features receive the derived age band they need rather than the underlying birth month or year.

Tickets, purchases, and events

We may handle ticket and QR identifiers, event and ticket type, access status, purchaser or attendee information made available for the ticket, linking and transfer status, refund or cancellation status, check-in records, badge or wristband references, schedules, favourites, maps, accessibility or support requests, offline ticket data, order and transaction identifiers, items purchased, amount, currency, taxes, fees, and limited processor-provided payment information such as card brand or last four digits.

Payment providers process full payment-card details. JAMMY does not intentionally store full card numbers in its own application databases.

JAMMY DANCE and guardian-managed participation

Dance and physical-program information may include participant and guardian names and contact details, birth date where needed to calculate program eligibility, age band, guardian relationship and approval, registrations, classes, attendance, payment status, waiver and media-consent choices, emergency contact, and information voluntarily provided for safety, support, or accommodation.

Community, chat, and JAMMY MARKET

Community information may include profiles, activity, direct and group messages, voice notes, reactions, invitations, attachments, delivery or read status, edit or deletion status, blocks, reports, restrictions, moderation records, appeals, and abuse or safety signals. For MARKET safety, records may include relevant message or edited text, supported media or a derived transcript where available, moderation categories and status, automated review results, evidence summaries, restriction history, appeal submissions, and actions taken.

MARKET information may include an account holder’s username, city or exchange area, adult or youth-safe participation mode, seller-verification status, listing text, price, trade preferences, item condition and origin labels, listing photos, offers, chats, transaction status, reports, suspected fraud, dispute evidence, and moderation decisions. MARKET receives the participation mode needed to apply safety rules rather than another collector’s birth month, birth year, or precise age. MARKET uses a manually selected area rather than requiring precise GPS location for local exchanges.

JAMMY PHOTO

JAMMY PHOTO may process captured photos and videos, edited or formatted media, previews, thumbnails, print files, session tokens, media keys, storage references, booth or device records, timestamps, expected and completed file counts, account-library associations, and upload, processing, print, delivery, download, sharing, expiry, support, security, and deletion records.

Support, communications, and technical information

We may collect support messages, attachments, contact details, relevant account, ticket, photo-session, event, or transaction context, notification and marketing preferences, delivery records, and steps taken to resolve a request.

Technical information may include IP address or an abbreviated or contextual IP value, approximate city or region for security, browser and platform information, app and device version, language, device label, session identifiers and timestamps, notification tokens, login and recovery events, rate-limit and fraud signals, administrative actions, errors, and server, queue, storage, security, and observability logs.

4. Why we use personal information

We use personal information to:

  • create accounts, authenticate users, manage sessions, recover access, and protect sign-in methods;
  • link and validate tickets, create passes, support check-in, and provide schedules, maps, favourites, and event notices;
  • manage purchases, registrations, guardians, waivers, classes, attendance, refunds, transfers, disputes, accounting, and fulfilment;
  • operate profiles, chats, groups, reactions, listings, trades, photo tools, and other requested features;
  • capture, process, print, deliver, import, share, and delete JAMMY PHOTO media;
  • answer support, privacy, accessibility, account, and safety requests;
  • detect spam, fraud, abuse, prohibited content, compromised accounts, invalid tickets, and threats to people or Services;
  • moderate content, investigate reports, enforce rules, review eligible decisions, and preserve appropriate evidence;
  • send necessary account, purchase, program, event, security, privacy, and safety communications;
  • send marketing where we have an appropriate basis and respect opt-out choices;
  • diagnose errors, measure limited product performance, secure, maintain, and improve Services; and
  • meet legal, regulatory, insurance, tax, accounting, accessibility, and recordkeeping obligations.

We do not use analytics to intentionally collect message bodies, ticket QR secrets, payment credentials, or the contents of your photo library.

6. Device permissions and local storage

Camera, photos, and microphone

Camera access may be used to scan ticket QR codes, capture profile or listing images, or use photo features. Photo-library access may be used to select an upload or save requested media. Microphone access may be used when you choose to record a voice note or video with audio. We do not access these sources when permission is unavailable, and operating-system controls can limit or revoke access.

Notifications, biometrics, and calendar

Notification permission allows delivery of account, event, ticket, class, chat, marketplace, photo, safety, and optional marketing notifications. Device biometrics may unlock a passkey or protected local feature; the device platform performs the biometric comparison and JAMMY does not receive the biometric template.

Calendar permission may be used when you ask JAMMY to add or update a registered dance class or event. Calendar access depends on the device platform and permission level. We use it for the requested calendar function, not to build an advertising profile from unrelated calendar entries.

Cookies and local technologies

Websites and apps may use cookies, secure local storage, caches, and similar technologies for authentication, security, consent, preferences, offline tickets, schedules, rate limiting, and service delivery. Where non-essential analytics or marketing technologies require consent, we will provide an appropriate choice.

7. Profiles, visibility, and communications

Email addresses and eligible profile fields are private by default unless you deliberately share them or a feature clearly requires limited visibility. A MARKET username, listing, seller indicator, general exchange area, and selected activity may be visible to the audiences identified in the feature. Do not put a home address, payment credential, government identifier, private ticket code, or another person’s confidential information in a public field.

Chats are not described as end-to-end encrypted. Messages and media are delivered to their participants and may be accessed by authorized personnel where reasonably needed for a report, safety issue, support request, technical problem, abuse prevention, appeal, or legal obligation. Automated tools may also process content as described below. In MARKET, a message or attachment may be held from the recipient or removed while review continues.

Text messages may be editable for 15 minutes, and a sender may be able to unsend content. Unsend removes the ordinary in-service view but does not guarantee removal from notifications, recipient devices, reports, moderation history, backups, legal holds, or information another person already saved.

8. When we disclose information

Other users and the public

We disclose profile, content, listing, message, group, photo, and activity information to the audience you select or the feature identifies. When you share a tokenized JAMMY PHOTO link, anyone with the link may be able to access its media during the availability window.

Events and activity partners

We may provide information reasonably needed for admission, accessibility, safety, performance, registration, fulfilment, or incident response to an applicable venue, ticketing partner, artist or agency, instructor, security provider, insurer, photographer, medical responder, or activity partner. Sponsors, vendors, exhibitors, and third-party booths may operate their own forms, contests, payment systems, websites, or mailing lists under their own privacy practices.

Legal, safety, and organizational disclosures

We may disclose information where reasonably necessary to comply with law or legal process; protect a person, event, property, or Service; investigate fraud, abuse, or a security incident; establish or defend legal rights; collect a debt; or respond to an emergency. We may also disclose information in connection with a proposed or completed financing, reorganization, merger, sale, or transfer, subject to confidentiality and legal requirements.

JAMMY does not sell JAMMY Account personal information. We do not provide attendee contact lists to independent parties for their own marketing without appropriate permission or another lawful basis.

9. Service providers

We use providers that process information for defined operational purposes. Access should be limited to what the provider needs for its role and governed by applicable contracts, settings, and law. Core providers may include:

  • Cloudflare for websites, hosting, application services, databases, object storage, queues, security, email-related services, logs, and configured AI processing;
  • Expo for mobile application delivery, updates, notifications, and related app services;
  • Apple for Sign in with Apple, passkeys and device platform services, Wallet, and push notifications;
  • Google for Google Sign-In, passkeys and device platform services, Wallet, and push notifications;
  • TicketSpice/Webconnex for ticketing, checkout, attendee, order, and payment-related services; and
  • Stripe for payment processing where configured, including JAMMY DANCE, JAMMY PHOTO, and supported in-person services.

A provider may collect additional information directly under its own terms and privacy policy. The particular providers used can change as Services evolve; we will update this policy or provide another notice when a change is material.

10. Event media and JAMMY PHOTO

Incidental event photography

Events may take place in public or shared spaces where JAMMY, venues, artists, accredited media, sponsors, vendors, performers, and attendees photograph, record, or livestream. Official event media may be used to operate, document, report on, and promote JAMMY events and services, subject to notices, releases, partner arrangements, and applicable law.

Contact Support before an event or designated staff onsite about a privacy, safety, accessibility, cultural, or minor-related concern. We will consider reasonable options, but cannot guarantee exclusion from every background image, livestream, attendee recording, or independently controlled venue camera. Staged, featured, testimonial, or private promotional uses may involve separate permission.

Private booth media

JAMMY PHOTO booth media is handled separately from incidental crowd photography. At initial upload, the workflow is designed to use a session token and operational metadata rather than sending a customer’s name, email, account identifier, age, or ticket information with the media. A later account import creates an association with that account.

Temporary booth media and tokenized share access are designed around a 24-hour period measured from session creation or upload initialization. Do not share the link publicly. We do not use private booth media for advertising, public social promotion, or generative-AI training without separate express permission.

11. Retention, deletion, and anonymization

We keep personal information only as long as reasonably needed for the identified purpose and applicable legal, safety, security, accounting, tax, dispute, insurance, and recordkeeping needs. Retention depends on the Service, sensitivity, user choices, legal requirements, unresolved issues, and whether information can be safely deleted or anonymized. We do not promise one period for every category.

MARKET messages, media, automated review results, restrictions, reports, appeals, evidence summaries, and audit records may be retained for different periods based on delivery, moderation, safety, abuse prevention, support, disputes, legal obligations, and approved retention schedules. Blocking, unsending, or deleting an account does not necessarily erase information preserved for an unresolved report, appeal, safety investigation, legal hold, or another person’s legitimate record.

Account deletion

You can schedule account deletion in the JAMMY App or use the verified process at jammygroup.ca/delete-account. The account is disabled during a 30-day recovery period. If you do not restore it, deletion processes remove or de-identify account information that is no longer needed. Public-facing content may be removed earlier.

Deletion does not necessarily remove another user’s legitimate transaction or communication record, de-identified information, or limited records required for safety, fraud prevention, legal claims, consent proof, financial compliance, or enforcement. Guardian relationships or active participant obligations may need to be resolved with Support first.

JAMMY PHOTO and backups

Temporary booth media and share access are designed to expire after 24 hours, with limited operational time for cleanup. Account-imported copies may remain until you delete them or delete the account. Limited session identifiers, timestamps, object references, delivery state, device records, deletion proof, and audit records may remain longer for operations, security, support, fraud prevention, or law.

Residual copies may remain in protected backups until normal rotation. We restrict backup use and do not restore deleted information to ordinary production use except where needed for disaster recovery, security, or legal purposes.

12. Security and processing locations

We use administrative, technical, and physical safeguards appropriate to the information and context. Measures may include access controls, role-limited administrative tools, authentication and step-up verification, passkeys, encryption in transit, secure credential handling, audit records, rate limits, monitoring, backups, vendor controls, and incident response. No system can guarantee absolute security.

Protect your account, device, email, ticket QR codes, recovery methods, and private share links. Contact Support promptly about suspected unauthorized account access. Good-faith technical vulnerability reports can be sent to webdev@jammygroup.ca under our Good-Faith Security Reporting Policy.

JAMMY is based in Alberta, but providers and personnel may process information elsewhere in Canada, the United States, or other places where they operate. Information processed outside your province or country may be subject to the laws and lawful access rules of that place. We remain responsible for information under our control and use contractual, technical, organizational, and provider-selection measures appropriate to the circumstances.

13. Your choices and privacy rights

Depending on the context and applicable law, you may ask to:

  • access personal information under JAMMY’s control and learn how it has been used or disclosed;
  • correct inaccurate or incomplete personal information;
  • receive an available account data export;
  • withdraw consent for an optional future use;
  • change profile visibility, notification, permission, or marketing choices;
  • delete eligible content or schedule account deletion; and
  • raise a concern or request review of a privacy decision.

Some rights have legal limits. We may need to verify identity or authority, search relevant systems, sever another person’s information, charge only a fee permitted by law after notice, or refuse a request with reasons where the law permits. We will respond within the period required by applicable law.

Send requests to info@jammygroup.ca with “Privacy request” in the subject or use JAMMY Support. If a concern is not resolved, you may contact the Office of the Information and Privacy Commissioner of Alberta or another regulator with jurisdiction.

14. Marketing and service communications

Necessary account, ticket, purchase, class, event, security, privacy, support, and safety messages are service communications, not marketing. We may send them where reasonably needed to provide or protect a Service.

Email and push marketing use separate choices where offered. Available controls may also let you choose brands, topics, or event interests. Commercial electronic messages identify the sender and include an unsubscribe method as required. You can withdraw consent without charge through the message or available settings; processing may take the period permitted by law. We keep appropriate consent and unsubscribe records.

We do not knowingly direct interest-based marketing to children under 13. Marketing to teens is handled with attention to age, sensitivity, the feature, and applicable consent requirements.

15. Children and teens

A child under 13 cannot create a standalone JAMMY Account. A parent or legal guardian may create and manage an eligible child participant profile for JAMMY DANCE or another supported activity. Standalone accounts use 13–17 and adult age bands, and particular events, community tools, public profiles, purchases, or other features may impose higher age or guardian requirements.

JAMMY MARKET is available to standalone JAMMY Account holders age 13 or older. Under-13 participant profiles are not ordinary public accounts and do not receive independent access to MARKET or general community chat. MARKET uses an adult or youth-safe participation mode to apply age-appropriate protections without disclosing one collector’s age to another. An exchange involving youth-safe mode must use an approved Kawaii Alley location or a currently published JAMMY CON safe zone. Teen access may require age confirmation, acceptance of safety rules, and guardian involvement where the feature or activity requires it.

Guardians should provide only information reasonably needed for the child’s activity and supervise the child’s participation. Contact Support if information was submitted by a child contrary to these rules or if a guardian relationship, consent, access request, correction, or deletion needs attention.

16. Automated processing and artificial intelligence

JAMMY may use rules, risk signals, and configured artificial-intelligence tools to classify, allow, hold, or remove text and other content for moderation, identify spam or prohibited activity, detect account or ticket abuse, prioritize safety or support work, and assist with answers or summaries in a support feature. MARKET message text, edited message text, and supported message media may be checked before delivery.

Automated tools may consider submitted content, limited content metadata, conversation and account safety context, prior moderation outcomes, reports, and feature-specific signals relevant to the task. They can make mistakes. Outcomes can include a held or removed item, limits on MARKET messaging or media, or a MARKET-scoped suspension. A serious MARKET suspension may remain active until an approved appeal or another authorized review restores access. For an apparent critical and immediate safety risk, a temporary whole-account safety lock may be applied pending priority human review.

Users can contact Support about an eligible automated outcome or restriction. An authorized person reviews the available evidence and may uphold, reverse, narrow, extend, or otherwise adjust the result. Appeals are not decided only by the same automated result being challenged. Operational thresholds, model prompts, confidential anti-abuse controls, and another person’s protected evidence are not made public.

We do not use private JAMMY PHOTO booth media for generative-AI training without separate express permission. We also do not describe automated tools as making legal, employment, credit, or similarly consequential decisions unless a specific feature notice explains that use and applicable safeguards.

17. Changes, questions, and complaints

We may update this policy as Services, practices, providers, and legal requirements change. We will post the updated date and provide additional notice or seek consent where required for a material change. A more specific notice may be updated on its own when it applies only to that activity.

Questions, access or correction requests, consent withdrawals, deletion questions, and privacy complaints can be sent to info@jammygroup.ca or through JAMMY Support. Please write “Privacy request” in the subject and do not email passwords, passkeys, ticket QR codes, full payment-card details, government identification, or unnecessary sensitive information.

Good-faith security reports can be sent to webdev@jammygroup.ca. Read the security reporting rules before testing or submitting evidence.