Privacy policy
Applies to myjp.ca and pay.myjp.ca. Last updated 15 September 2026.
The short version: we collect as little as a sign-in and a payment need, we sell nothing, we run no advertising and no analytics service, and you can have it all deleted by asking. The long version follows, and it is the one that counts.
Who we are
myjp.ca is operated by its owner in Ontario, Canada, on computers we run ourselves. Questions about this policy, or about your data, go to support at myjp dot ca.
What we collect
Without an account. The games and the front pages work signed out. Our web server keeps an ordinary access log (the address you connect from, the page requested, the time, the browser’s user-agent string) for troubleshooting. A tip left signed out is recorded as anonymous — see Payments below.
When you create an account. You sign in with a passkey: your device keeps the private key and we keep the public half, a credential id, and the sign-in counter the device reports. We never see a password because there is none. We give you a random handle (like user-4f2k) and a display name you can change. Your account page also lets you add a recovery email; if you do, we store the address and whether it has been confirmed. Nothing else is asked for — no real name, no date of birth, no phone number, no address.
While you are signed in. Each sign-in makes a session record with its start time, when it was last seen, and the address and browser user-agent it came from, so that your account page can show you which devices are signed in and let you remove one. Security-relevant actions (a passkey added or removed, an email added, a payment that landed on your account, a sign-in) are written to an audit log with the time and the address they came from.
When you play. Each game keeps what a game needs: the tables you open or join, who sat where, every move made, and the result. Server-dealt games are replayed on the server to score them, so the moves are kept with the score. Your display name is shown to the other people at your table and, if you make the leaderboard, on it — to anyone who looks. There is no chat between players. Games may store settings (sound, a preferred colour) in your browser’s local storage; that never leaves your device.
When you use a tool. The video tool takes the file you upload, converts it on our machines, and lets you download the result. We keep the file’s name, size and the conversion settings with the job. Uploaded source files are deleted after 7 days and the converted output after 30 days, or sooner when you delete the job. Anonymous statistics about each run (duration, resolution, codec, how long each stage took — never the file name, the job id, or who ran it) are kept to plan capacity.
When you pay. Card payments happen on Stripe’s hosted checkout page. Your card number, expiry and security code are entered on Stripe’s page and go to Stripe; they never reach us. What Stripe sends back to us, and what we keep, is: the checkout session id, the amount and currency, the payment status, the email address you gave Stripe for the receipt, the fee Stripe charged, and — when you paid with Apple Pay or Google Pay — the first name on the wallet, which we use as the name on your account unless you change it. A payment made while signed in is linked to your account so we can say thanks and unlock what you paid for; a payment made signed out is kept without a name. A monthly supporter subscription additionally keeps Stripe’s subscription and customer ids so that you can manage or cancel it through Stripe’s portal. Lightning payments record the invoice and the amount, which identify no one. If you send money through Wise, that happens on Wise’s site under Wise’s policy; we see only what arrived.
What we do not collect. No advertising identifiers, no cross-site tracking, no third-party analytics, no fingerprinting. The only cookie is the session cookie, described below.
What we use it for
- To sign you in, keep you signed in for 30 days, and let you see and end your sessions.
- To run the games and tools: deal, replay, score, rank, convert, deliver.
- To record what you paid, show it on your account, unlock what it bought, and answer a question or a refund request about it.
- To get you back into your account if you lose your passkeys (the recovery email).
- To notice and stop abuse: rate limits by address, the bot check on account creation, the audit log.
- To keep the site running: error logs and anonymous run statistics.
We do not use your data for advertising, we do not profile you, and we do not sell, rent, or trade it to anyone.
Who else sees it, and how
We share data with the following services, each only what its job needs, and each by a direct encrypted (HTTPS) connection from our server or your browser to theirs:
| Service | What they receive | Why |
|---|---|---|
| Stripe · policy | Your payment details, entered on their page; from us, the amount, your handle, and the purpose of the payment. | Processing cards, wallets, bank debits and subscriptions. |
| Cloudflare Turnstile · policy | A bot-check token from your browser on account creation and account recovery only; Cloudflare sees your address and browser as any visited site does. | Keeping automated sign-ups out. |
| Resend · policy | Your recovery email address and the code we are sending it. | Delivering verification and recovery codes. |
| Wise · policy | Whatever you enter on Wise’s page, if you choose that route. | An alternative way to send support. |
Beyond these, we disclose personal data only if the law requires it — a valid order from a Canadian court or authority — and then only what the order covers. Our own machines and the payment records on them are in Canada; Stripe, Cloudflare, Resend and Wise process data in their own regions, including the United States, under their own policies.
Cookies
One cookie, myjp_session, set when you sign in, on .myjp.ca so the same sign-in works across the site. It holds a random token (we store only a hash of it), lasts 30 days from your last visit, and is marked Secure, HttpOnly and SameSite. Signing out deletes it. There are no other cookies, ours or anyone else’s.
How long we keep it
- Account, passkeys, emails, game history: while your account exists.
- Sessions: a session expires 30 days after its last use; you can end one sooner from your account page.
- Uploaded files: sources 7 days, outputs 30 days, or sooner when deleted.
- Payment records: as long as we are required to keep them for tax and accounting purposes — in Canada, seven years — even after an account is deleted. A deleted account’s payments stay in the books with no account attached.
- Audit log: while your account exists.
- Server access logs: rotated by the web server; not kept longer than a year.
How we keep it safe
- Everything travels over HTTPS; there is no plain-HTTP version of the site.
- Sign-in is by passkey (WebAuthn): public-key cryptography, phishing-resistant, no password for anyone to leak or guess. Session tokens are stored hashed, so the database cannot be used to impersonate you.
- Card details never touch our systems; they are handled by Stripe, who are PCI DSS Level 1 certified.
- The database, logs and secrets live outside the web root, on a private server that only the operator can reach. Every request that reads or changes your data is checked against the signed-in session and the page’s origin.
- Account creation and recovery are rate-limited and behind a bot check; sign-in codes expire in ten minutes and allow five guesses.
No system is perfect. If we ever discover a breach that affects your data, we will tell you by the recovery email on your account, or by a notice on this site if there is none, without undue delay.
Your rights and choices
You can see and change your display name, passkeys, recovery email and sessions on your account page, and see every payment tied to the account. You can ask us at any time to send you a copy of everything we hold about you, to correct it, or to delete it; write to support at myjp dot ca from the recovery email on the account, and we will act within seven days. Deletion removes your account, passkeys, emails, sessions, game history and tool jobs; payment records are kept as described above, unlinked from any account. You may also complain to the Office of the Privacy Commissioner of Canada.
Children
The site is not directed at children under 13, and we do not knowingly hold an account or a payment from one. If you believe a child has made an account, tell us and we will remove it.
Changes
If this policy changes in a way that matters, the date at the top moves and, if you have a recovery email on your account, we tell you there first. Continued use after that is acceptance of the new version.