JTM Secure

Privacy notice

Draft for pre-launch review. Not effective and not an approved consent notice.

Legal operator
TBD
Privacy contact
TBD
Effective date
TBD — not yet effective
Draft revision
2026-09-03-draft-1

What this notice covers

This draft describes information handled by the JTM Secure website and iOS app for Patrons, Members, and people acting for an organization. It covers Circle invitations, requests, relationship records, commitments, and account activity.

Separate notices and agreements may apply to a bank account, card, credit report, or service provided by another company. This draft does not replace those documents or an applicable financial privacy notice.

Information used by the service

Information you or an authorized representative provide can include identity and contact details, organization and representative details, your relationship to another participant, request amounts and purposes, financial information, documents, acknowledgments, and support messages.

Depending on the feature you use, records can include income and debt information, business financial information, identity-verification results, credit and risk information, account and transaction records, agreement terms, payment history, and servicing events. An invitation can include information supplied by the person inviting you before you create an account.

The service also handles sign-in and security events, device and application information, notification preferences, and device-registration tokens. The final notice will identify any additional information collected by deployed infrastructure and service providers.

How information supports your account

Information supports account access and verification, Circle connections, request review, agreement records, payments and servicing, notifications, customer support, and fraud and security controls. Financial and relationship information can inform request eligibility, risk summaries, and proposed terms.

Information also supports recordkeeping, dispute handling, and applicable compliance processes. Acknowledging this notice is not, by itself, authorization for a credit inquiry, a debit, or a payment; those actions have their own requirements.

What your Patron and other participants can see

Your Patron can see information needed to review and manage your relationship and requests. Depending on the record, this includes your identity, relationship details, purpose and requested terms, supporting documents, financial-profile information, risk summaries, decisions, commitments, and payment history.

Financial-profile information shown during review can include income, debt payments, bankruptcy history, credit-score range, and relevant business financial information. Do not assume your Patron sees only a score or a short summary.

Members can see their own requests, terms, decisions, agreements, and payment records. Authorized representatives, delegates, and operational staff may access records according to their role. The final notice must confirm the precise sharing practices and any choices available to you.

Other companies involved

The service uses providers for hosting and data storage, authentication, communications, and enabled banking, identity-verification, screening, document, and payment functions. Information involved depends on the feature and provider.

Before publication, JTM Secure must confirm its provider arrangements, affiliate relationships, marketing practices, any sale or sharing for advertising, and the disclosures permitted or required by law. This draft does not assert that these arrangements have been finalized.

Your phone, browser, and notifications

When you use Face ID, Touch ID, or your device passcode, iOS performs the authentication. JTM Secure receives the authentication result, not your face scan, fingerprint, or device passcode.

The native app keeps loaded financial records in memory. Authentication credentials and session material are handled separately using protected device storage. Temporary document files are cleaned up when the viewing session ends or the app clears protected state. This does not delete the underlying server records or copies you export.

Push notifications use a generic message and an opaque record reference rather than a balance, amount, or person’s name on the lock screen. Email notifications are different and may contain record details. You can manage notification permissions in device settings and supported preferences in the app.

The website uses browser storage for sign-in and session behavior. The final notice must describe the deployed cookie and analytics inventory; native in-memory handling should not be read as a promise that the website stores no data.

Keeping and protecting records

Access controls, session protection, and activity records help protect account information. No service can guarantee that every security risk is eliminated.

The final notice must specify retention periods or criteria for account, request, agreement, transaction, identity, support, and security records. Signing out or deleting the app does not itself delete server records. Record retention and deletion may be affected by outstanding agreements, disputes, and applicable requirements.

Questions, choices, and changes

The legal operator and a monitored privacy contact must be finalized before this notice is approved. The final notice must explain the access, correction, deletion, and information-sharing choices that apply, including any state-specific rights, verification steps, and exceptions. This draft does not promise a right or response time that has not been established.

A final notice will include an effective date and describe how material changes are communicated. Existing agreements and required disclosures remain separate records.