The details, in plain language
JTC Invest LLC
Privacy policy
Information about JTCSignal and its automated website analysis service.
Who is responsible for this service
This notice, dated 2026-09-06, describes personal information handled through this website-analysis service. The operator identified below is responsible for deciding how customer, billing, support and operational information is used for its own service purposes. A brand name does not by itself identify a separate legal company. For questions, use the listed service contact and identify the brand or order concerned. Processing a customer website can involve different responsibilities; the data-processing page explains when an organization should discuss additional requirements before submitting material.
JTC Invest LLC operates JTCSignal at jtcsignal.com. You can reach the service about personal information at or through the contact form. Identify the storefront and any relevant reference because the platform supports separate storefronts with their own displayed seller identities. The business details at the end of the page identify the operator; a translated page or a local currency does not imply that a separate company has been established in your country.
This notice addresses visitors, people requesting scans, purchasers, support correspondents and individuals whose information appears in submitted public pages. The relationship can differ for each group. For example, a person mentioned on a scanned staff page may never have ordered a report. A person paying on behalf of a company may provide their own work contact details alongside company billing details.
Where a customer needs us to process information under a specific organizational agreement, that requirement must be discussed before submission. The separate data-processing explanation is not proof that such an agreement has been signed. Likewise, a payment provider can have its own responsibilities for fraud checks and regulated records. We describe the application’s actual processing here rather than treating every activity of every independent provider as exclusively controlled by this website.
Information you provide
We receive the website address submitted for a scan and the contact and billing details supplied at checkout. These can include your name, email, company, postal address, country and tax identifier. Contact forms, order conversations, speculative career enquiries and privacy-request emails contain the information you choose to write. Privacy records can also include the requested scope and any appropriate verification record. Do not send passwords, full card numbers, identity documents or sensitive personal information through these channels. Contact us first if a request requires a more appropriate exchange method.
Different forms collect different information. A free scan starts with the public website address; checkout adds information needed to identify the purchaser and issue billing documents. An optional company field does not make a personal email address non-personal. A support message can contain additional information you choose to include, and quoted correspondence or screenshots can reveal information about other people.
Provide only what is needed for the particular task. If a billing question can be resolved with an invoice reference, do not include a full bank statement. If a report concern relates to one paragraph, identify that paragraph rather than sending a private customer export. We do not offer these forms as a secure repository for medical records, identity documents, employee files or account passwords.
Some information is needed to perform the requested action. An inaccessible or missing URL can prevent a scan; an invalid email can prevent receipt of a verification or private access message; incomplete required billing fields can prevent checkout. Optional information should remain optional unless a relevant form or subsequent explanation identifies why it is necessary. If you have provided inaccurate information, contact us with the correction and relevant reference. Correcting a record is different from altering the historical evidence of a completed payment.
The dedicated withdrawal form records your name, contract or order reference, email address, withdrawal statement and submission date and time. Those records support acknowledgement and review of the request. It does not require a customer account or a reason for withdrawal. Supply your own contact details or identify any authority to act for another person; submitting a reference is not permission to disclose that person's private order information.
Website content and generated information
The scanner retrieves accessible public pages and related crawl resources. Stored results can include page text, headings, metadata, structured data, source URLs, technical observations and retrieval errors. Public content may identify business owners, employees or other individuals even when it is openly accessible. Paid reports add generated recommendations and their supporting evidence. We also retain processing status, timestamps and diagnostic information needed to explain or retry an operation. Public availability does not make personal information unrestricted, and you should submit only pages appropriate for this workflow.
A scan can discover additional public URLs on the submitted website within its purchased scope. Related resources may include robots instructions, sitemap references and other publicly available technical files. The evidence records what the application could retrieve, not everything that a human might see after logging in or interacting with a browser. Page excerpts, source locations and error information can remain connected to the scan and its report.
A business page may contain personal names, direct email addresses, photographs described in page markup, testimonials or biographical details. We do not infer that the website owner has permission to disclose every person’s information simply because the page responds publicly. The person submitting the website should assess whether this analysis is appropriate for the content.
If you are an individual mentioned in that material, you can contact us without buying a report. Give the source URL and identify the relevant information, while avoiding unnecessary copies of sensitive material. An analysis request does not enable us to edit the original website or remove it from search engines. A correction or removal within our records does not automatically change the source publisher’s page. Generated suggestions based on that page may need to be considered separately when reviewing the request.
Orders, security and delivery records
The application records order references, payment-provider identifiers, amounts, currency, payment state, invoice details and purchase-consent wording. It records email status and provider events so an accepted message is not confused with confirmed delivery. Session and operational records may include technical request information, security events and abuse-prevention identifiers, including hashed identifiers used in applicable workflows. Administrative activity is recorded for accountability. We do not store full payment-card numbers or card security codes; the payment interface sends those details to Stripe.
Payment records connect the order to identifiers returned by Stripe, including the saved checkout session and the confirmed payment state. The application uses these references to reconcile an uncertain checkout, issue an invoice, recognize a refund and avoid treating a browser return alone as proof of payment. It does not need your full card number or security code for those checks. Stripe handles card entry through its payment interface.
Service-email records include the recipient, message purpose, private delivery link and processing status. A provider may report acceptance, delivery, a bounce or a complaint. A delivery event is not evidence that a person read the message. Information required to investigate a failed email is different from the content of the website report.
For security and accountability, records can include timestamps, administrator actions and technical request information. Some workflows use hashes of normalized addresses or network identifiers to match records without storing that value in the matching field itself. Hashing is not a promise of irreversible anonymity: the application may still associate the hash with other records. Infrastructure access logs can also contain request information. Do not assume that removing a visible form field eliminates all operational records related to the action.
Purposes and applicable grounds
We use information to supply requested scans and reports, take payment, issue documents, deliver access links, answer enquiries and manage support. Where GDPR applies, contractual processing includes steps requested before an order and performance of the purchased service. Applicable accounting requirements can justify retention as a legal obligation. Security, fraud prevention and reliable operations can involve legitimate interests, subject to the safeguards and rights applicable to that basis. Optional marketing requires an appropriate permission or other lawful basis for the particular communication; submitting an order is not unrestricted marketing consent.
The purpose depends on the record. We use a submitted URL and retrieved evidence to perform analysis; contact information to deliver the requested link and answer you; billing data to document the sale; payment references to verify and reconcile the transaction; and security records to protect access and investigate misuse. We do not need to treat all of these activities as consent-based merely because you accepted website terms.
Where a contract is with you personally, information necessary to carry out that contract or requested pre-contract steps can be processed on that basis. Where you act as a company representative rather than the contracting individual, handling your work contact information may instead involve a relevant legitimate interest. A legal-obligation basis applies only when an actual obligation requires the processing, not as a general reason to keep every record forever.
Where consent is the applicable basis, withdrawing it affects future consent-based processing and does not retrospectively invalidate earlier lawful use. Other necessary processing can continue on its separate applicable basis. You may ask which purpose and basis apply to a particular record and object where the relevant law allows. Accepting immediate digital delivery is a purchase-consent record; it is not an unrestricted agreement to promotional profiling.
Providers involved in delivery
Stripe receives information needed for payment processing, authentication and fraud prevention. OpenAI receives the website evidence and instructions used to prepare paid recommendations. Mailgun is used for transactional email delivery and its delivery-status events. Hosting and database services store and process application information, and configured infrastructure services may handle network security and delivery. Each provider receives information relevant to its function rather than general access being implied by this notice. Payment and other providers may also process information under their own responsibilities and published privacy terms.
The provider receiving information depends on the task. Stripe processes checkout and related payment verification. OpenAI receives selected website evidence and instructions for paid report generation. Mailgun handles service-email delivery; a configured marketing workflow may use Mailgun or Brevo if an eligible campaign is explicitly operated. Hosting and database infrastructure hold the application and its records.
The scanner also resolves the submitted hostname through configured public DNS services, including Cloudflare with Google as a fallback. That lookup concerns the domain name needed to reach the website. It is distinct from sending the full report, billing information or a support message to the DNS service. The target website itself receives the crawler’s requests and can record them under its own practices.
We may need to disclose relevant information to professional advisers, competent authorities or parties involved in a legal claim where there is an appropriate lawful basis. This notice does not give every recipient unrestricted access to the database. An independent provider’s contractual terms, legal responsibilities and retention can differ from ours. Ask for information about the recipients involved in your specific order if you need a supplier assessment; do not infer a hosting region or a transfer arrangement solely from a provider’s name.
AI processing and human-authored content
Paid generation uses public website evidence, which may contain names or other personal information from the source pages. The report workflow does not require your site login or private customer database. Do not treat this service as a channel for confidential records. An AI-generated recommendation is advisory content, not a decision establishing your legal rights, creditworthiness or eligibility for an essential service. Your own support messages and generated business recommendations are not silently rewritten when you change the interface language; technical interface labels may be localized separately.
The paid-report workflow assembles source pages, technical findings, the requested coverage and output-language instructions for generation. It does not require a connection to your analytics account, customer database or website administration panel. If a source page itself contains personal information, selected excerpts can be included in that evidence. The fact that a page is public does not mean you should submit a page containing sensitive information.
The application instructs the report generator to treat retrieved website text as evidence rather than instructions, and it checks that recommendations refer to inspected material. These are controls for the intended workflow, not a guarantee that generated text is always accurate or that it contains no personal information. Review suggestions before sharing or publishing them, especially where they repeat names, contact information or factual claims.
We do not describe an advisory website report as a solely automated decision with legal or similarly significant effects on the person reading it. If a generated passage misidentifies someone or contains a problematic inference, identify the passage and source so it can be reviewed. This notice does not promise zero retention or a particular training exemption across every AI-provider arrangement; organizational requirements about provider use and retention should be settled against the actual applicable contract.
Optional marketing and suppression
Marketing is separate from requested service messages. Campaign delivery requires the relevant marketing permissions and operational enablement; the public interface does not load advertising pixels or behavioral analytics scripts. Where marketing is sent, use its unsubscribe link to stop further marketing. The service retains a suppression record to prevent the address being reintroduced across its brands. This record can remain even when other contact information is removed. Receipts, purchased-report notices, verification messages and responses to support you initiate are handled for their separate service purposes.
A purchase confirmation, a report-ready notice, a privacy-verification email and a reply to your support request have purposes separate from advertising. Unsubscribing from marketing does not cancel the report you purchased or prevent necessary correspondence about a request you initiated. Conversely, supplying an address for an invoice or a question does not by itself authorize every future campaign.
The marketing workflow requires a recorded permission, its source and timing, and checks against the suppression list. An authorized operator must explicitly enable and launch a campaign; the existence of a contact record is not equivalent to an instruction to send. A suppression applies across the storefronts using this application so that moving the address to another storefront does not bypass the objection.
The suppression record uses a normalized-address hash and relevant source information. It is retained to recognize and honor the objection, not to keep sending marketing to a person who asked to stop. A message already handed to an independent email provider may still arrive while a new objection is being processed. If marketing continues, contact with the sending address and message date. Do not send complete private links or mailbox credentials. We can investigate the permission and suppression records without requiring you to place an order.
Storage and retention
Retention depends on the record and the reason it is needed. Scan evidence and reports support delivery and related enquiries; order and invoice records support accounting and payment disputes; security records support investigations; suppression records preserve an objection to marketing. We do not claim that every category has the same fixed deletion date or that an automatic erasure schedule is currently available. Ask about a specific record if you need more detail. A deletion decision must also consider applicable legal retention, disputes and the rights of other people.
There is no single retention clock for every item. A completed report and its source evidence can remain necessary for delivery, explaining a recommendation, investigating a quality issue or restoring access. A pending or failed operation may retain diagnostic information so that its cause can be understood. The retention of those records must be assessed against their continuing purpose rather than assumed to be permanent because storage is available.
Order, invoice and payment records can need longer retention for applicable accounting obligations, fraud investigations or a legal dispute. A privacy or complaint case also records what was requested and how it was handled. Marketing suppression information has a different purpose: removing it indiscriminately can cause an opted-out address to be selected again.
The application does not currently advertise automatic deletion of all scans after a fixed number of days. The 24-hour verification-link period applicable to previously issued, unconfirmed privacy cases is an access-control expiry, not a statement that every related record is erased then. Copies held by service providers or in infrastructure backups can follow different applicable retention arrangements. Ask about the category and purpose relevant to you. Where continued retention is justified, restriction, minimization or removal of unnecessary details may be appropriate instead of deleting a legally required transaction record.
Your rights and ways to contact us
Depending on the applicable law and processing basis, you may have rights to access, correct, erase, restrict, object to or obtain a portable copy of personal information, and to withdraw consent for future consent-based processing. Send your request by email to ; the data-deletion page provides instructions rather than a submission form. Where GDPR applies, responses are generally due within one month, with a permitted extension for complex or numerous requests explained within that month. You may complain to a competent supervisory authority without first surrendering that right through our support process.
Rights are not identical for every category or legal basis. Access concerns personal information about you, not automatic access to another customer’s confidential report. Rectification can address incorrect personal details, while an invoice correction may need to preserve an accounting audit trail. Portability applies in the circumstances specified by law, rather than to every internal note or security record in every format.
You can object to relevant processing and request that use be restricted while a matter is assessed. Where an erasure exception applies, we should explain the reason instead of treating silence as a resolution. Where a request also affects other people, proportionate checks or redaction may be needed to protect their information. A representative can contact us, but may need to show appropriate authority.
Use for access, correction, portability, objections and other privacy requests. The contact page is also available if you need clarification or help reaching the operator. You do not need to cite a legal article or buy a product to ask, and these instructions do not exclude other legally recognized ways to exercise a right. Applicable response deadlines and complaint rights remain relevant if proportionate identity checks are needed. A competent data-protection authority, including the ICO where relevant in the UK, can provide guidance on rights under its jurisdiction.
Verification and existing privacy cases
The public data-deletion page explains how to email the operator; it does not collect a new request through a form. Identify the information concerned and the outcome you seek. The team reviews the request and may ask for proportionate information to verify your identity or authority before disclosing, correcting or deleting personal information. A new email does not automatically create a private case, send a verification link or erase information. Do not send identity documents or confidential credentials as part of an initial request unless an appropriate method has been agreed.
If you previously received a private verification link for an existing case, its original access rules still apply. An unconfirmed link expires after 24 hours. Opening the page alone does not authorize action; the confirmation step records verification. The link contains a private token and is tied to its original brand. Keep it confidential and contact if it has expired or the original mailbox is inaccessible.
For those existing cases, confirmation makes the case available for administrative review. A previously requested marketing or all-information scope also applies marketing suppression after confirmation. Other deletion decisions remain manual. Existing private status pages can show processing and the recorded resolution, with a notification email when a final outcome is recorded. Changing the public information page does not silently cancel those cases or mechanically remove their records.
Whether the request arrives by email or relates to an older private case, the review must consider applicable rights, relevant retention obligations and other people’s information. A case label is not itself proof that every requested record has been deleted. The response should explain the scope of action and why information has been retained where relevant. Knowing an email address or order reference does not entitle a person to another customer’s records.
Access safeguards and international processing
Private scans, orders and support conversations use access-bearing links and brand-scoped checks. Keep those links confidential and report accidental exposure. These controls reduce risk but cannot promise that every system is immune to an incident. Infrastructure and providers may process information outside your country. Applicable transfer requirements depend on the parties, locations and arrangement; contact the operator for the documentation relevant to your organization. This notice does not claim that a particular hosting region, signed transfer mechanism or security certification has been independently verified for every request.
Customer resources are checked against their owning brand and private token. Administrative access is separately restricted to active authorized staff, and significant administrative actions can be recorded. Certain fields, including private access tokens and privacy-request contents, are encrypted by the application. These measures do not establish that every database field, every backup or every third-party record is encrypted in every environment.
Your own sharing choices remain important. An authorized recipient can copy a report or forward its access link. Downloaded PDFs and screenshots are then handled on the receiving device. Do not send tokens or passwords in a public bug report. If a link or document appears exposed, report the affected page and circumstances through the contact route without publishing the secret again.
Cross-border processing can arise because the operator, infrastructure and independent providers are not necessarily in the same country as the visitor. Where data-protection law requires a transfer mechanism or safeguards, those requirements must be addressed for the relevant arrangement. This notice does not invent a certification, representative, adequacy decision or signed contractual clause. Contact the operator for applicable recipient and safeguard information before submitting material that requires a restricted processing location. A translated interface does not create a data-residency guarantee.
Updates and relevant contacts
The notice can be updated when the service, providers or applicable requirements change. The date identifies the published version rather than an automatic daily review. A new notice does not itself supply permission for an unrelated new purpose. Use the service contact below for privacy questions, mistakes in submitted information, concerns about public content included in a report or difficulty exercising a right. State the relevant brand, email address and reference where available. Provide only the information needed to help locate and understand the issue.
The latest date shows when this published explanation was revised. Future changes can concern provider arrangements, new features, purposes or legal requirements. A change in wording alone does not supply a missing lawful basis, retrospectively authorize a new use or remove an existing right. Where additional notice or permission is required for a new purpose, that requirement must be dealt with separately.
This service is intended for website analysis and related business or personal purchasing, not as a service for children to upload personal records. We do not ask users to supply a date of birth for an ordinary scan. If you believe a child’s information was submitted inappropriately, or appears in a source page used for a report, contact the operator with the relevant location and concern. Do not send more identifying information than is necessary to explain the issue.
When contacting , identify whether your concern is about information you supplied, information on a scanned website, an order, marketing or a privacy case. These records can involve different actions and recipients. An acknowledgement means the message was received or queued in the workflow, not that every requested action is already complete. Keep relevant correspondence and ask for clarification if a response does not explain the handling of your request.