Privacy Policy
This Privacy Policy explains how ClaimJumper LLC ("ClaimJumper," "we," "us," or "our") collects, uses, discloses, and protects information when you visit claimjumper.ai or use our cross-platform advertising management, analytics, and automation services (collectively, the "Service").
ClaimJumper is designed for businesses and their authorized personnel. It is not intended for personal, family, or household use.
1. Our role
We may process information in different roles:
- As a controller or business, we decide how to process information about website visitors, prospective customers, account administrators, billing contacts, and users of the Service.
- As a processor or service provider, we process advertising, campaign, conversion, and related data on behalf of our business customers and according to their instructions. In that context, the customer controls the data, and its privacy notice and our data processing agreement govern the processing.
If you are an individual whose information was submitted to the Service by one of our customers, please direct your privacy request to that customer. We will assist the customer as required by applicable law and our agreement with it.
2. Information we collect
2.1 Information you provide
We may collect:
- Business contact information, such as name, business email address, telephone number, employer, job title, and billing address.
- Account information, such as login credentials, user roles, authentication records, and communication preferences.
- Contract, billing, and transaction information. Payment card details may be collected directly by our payment processor rather than by us.
- Communications, including support requests, feedback, survey responses, sales communications, and meeting records.
- Business objectives and configuration information, such as budgets, performance targets, risk tolerances, campaign rules, and approval settings.
2.2 Information from connected advertising and business platforms
When an authorized user connects an account, we may receive information permitted by that user and the relevant platform, including:
- Advertising account, business, campaign, ad set, ad group, and advertisement identifiers.
- Campaign configuration, budget, bid strategy, targeting configuration, status, and delivery settings.
- Aggregated performance information, such as spend, impressions, clicks, attributed conversions, revenue, cost-per-action, and return on advertising spend.
- Account permissions and limited profile information needed to authenticate and administer the connection.
- OAuth access and refresh tokens or equivalent credentials. We use these credentials to access connected accounts as authorized and do not disclose them except to service providers that help us securely operate the Service.
- Conversion or customer relationship management information when a customer elects to connect those sources.
Information obtained from Google, Meta, or another third-party platform is also subject to that platform's terms and policies. We do not use platform data in a manner prohibited by those terms.
2.3 Information collected automatically
We may collect:
- Device and network information, including IP address, browser type, device type, operating system, and approximate location derived from IP address.
- Service activity, including pages viewed, features used, actions taken, timestamps, referring pages, session records, errors, and diagnostic logs.
- Cookie and similar-technology information. See Section 10.
- Security information, such as authentication events, access attempts, suspected abuse, and audit logs.
2.4 Inferences and model state
The Service may generate forecasts, recommendations, anomaly indicators, response-curve estimates, confidence scores, and other derived information. Customer-specific model parameters or state that can reasonably be linked to a customer or advertising account are treated as Customer Data, not anonymous data.
3. How we use information
We may use information to:
- Provide, operate, maintain, and secure the Service.
- Authenticate users and administer connected accounts.
- Analyze campaign performance and generate recommendations, forecasts, alerts, and authorized automated actions.
- Process transactions and administer our commercial relationship with customers.
- Provide support and communicate about the Service.
- Detect fraud, abuse, security incidents, technical failures, and violations of our agreements.
- Monitor reliability, debug problems, and improve usability and performance.
- Comply with law, enforce our agreements, and establish, exercise, or defend legal claims.
- Create and use Aggregated and De-identified Data as described in Section 4.
- Send product updates and business marketing communications where permitted by law. You may opt out of marketing emails at any time.
Where the GDPR or UK GDPR applies, our legal bases may include performance of a contract, our legitimate interests in operating and securing the Service and conducting business-to-business communications, compliance with legal obligations, and consent where required. When we process Customer Data for a customer, the customer determines the applicable legal basis.
4. Aggregated and de-identified data
We may transform Customer Data and Usage Data into aggregated or de-identified information for purposes such as:
- Measuring and improving Service performance and reliability.
- Improving forecasting, optimization, anomaly-detection, and decision-support models.
- Developing new features and evaluating algorithms.
- Producing statistical research, benchmarks, and industry insights.
- Detecting abuse and protecting the Service.
We call this information "Aggregated and De-identified Data" only when we apply measures reasonably designed to prevent it from being associated with an identifiable individual or customer, taking into account the data itself and other information reasonably available to us.
We will:
- Not attempt to re-identify Aggregated and De-identified Data.
- Maintain technical and organizational safeguards intended to prevent re-identification and unauthorized disclosure.
- Require recipients to observe restrictions against re-identification where appropriate.
- Avoid publicly disclosing statistics about cohorts so small that a customer or individual could reasonably be identified.
- Continue treating information as Personal Data or Customer Data if it does not meet the applicable legal standard for de-identification or anonymization.
- Exclude data obtained from a third-party platform from these uses when the platform's terms do not permit the relevant use.
Unless a customer expressly opts in through a separate written agreement or product control, we do not use the customer's ad creative, audience lists, user-level conversion records, directly identifying information, or identifiable customer-specific data to train a model made generally available to other customers.
5. How we disclose information
We may disclose information:
- To service providers that provide hosting, infrastructure, security, communications, customer support, analytics, payment processing, and professional services under contractual restrictions.
- To connected platforms when necessary to carry out a customer's instructions or an authorized action.
- Within a customer's organization according to configured roles and permissions.
- For legal and safety purposes when we reasonably believe disclosure is necessary to comply with law, protect rights or safety, investigate fraud or abuse, or enforce our agreements.
- In a corporate transaction, such as a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections.
- With consent or at a customer's direction.
We do not sell Personal Data for money. We do not share Personal Data for cross-context behavioral advertising.
A current list of our subprocessors is available on request at mikhail@claimjumper.ai.
6. Data retention
We retain information for as long as reasonably necessary for the purposes described in this Policy, including providing the Service, maintaining business and audit records, complying with law, resolving disputes, and enforcing agreements.
Our default retention periods are:
- Account and contract records: 7 years after termination or as required by law.
- Connected-platform raw or account-level data: 24 months, unless a customer configures a shorter period.
- Security and audit logs: 12 months.
- Support records: 24 months.
- OAuth tokens: until the connection is revoked, the account is closed, or the token is no longer required.
- Customer-specific model state: 90 days after account termination, unless earlier deletion is required.
Aggregated and De-identified Data may be retained longer where it no longer constitutes Personal Data or Customer Data and our contractual commitments permit that retention. Backup copies may persist for a limited period before being overwritten.
7. Security
We use administrative, technical, and physical safeguards designed to protect information, including access controls, encryption in transit and at rest where appropriate, tenant separation, logging, vulnerability management, and incident-response procedures. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Customers are responsible for maintaining appropriate access controls, protecting their credentials, configuring user permissions, and promptly revoking access that is no longer required.
8. International data transfers
We and our service providers may process information in countries other than the country where it was collected. Where required, we use recognized transfer mechanisms, such as adequacy decisions or approved standard contractual clauses, and implement supplementary safeguards where appropriate.
9. Privacy rights
Depending on your location and subject to applicable exceptions, you may have rights to:
- Access or obtain a copy of Personal Data.
- Correct inaccurate Personal Data.
- Delete Personal Data.
- Restrict or object to processing.
- Receive certain Personal Data in a portable format.
- Withdraw consent without affecting prior lawful processing.
- Opt out of certain sales, sharing, targeted advertising, or profiling activities.
- Appeal a denied privacy request.
- Lodge a complaint with a privacy or data-protection authority.
To submit a request, contact mikhail@claimjumper.ai. We may need to verify your identity and authority. Authorized agents may submit requests where permitted by law.
We will not discriminate against you for exercising an applicable privacy right.
California notice
The categories described in Section 2 may include identifiers, commercial information, internet or electronic-network activity, professional or employment-related information, and inferences. We collect and disclose these categories for the business purposes described in Sections 3 and 5. We retain them as described in Section 6.
We do not knowingly sell or share, as those terms are defined under California law, Personal Information of consumers under 16 years of age.
10. Cookies and similar technologies
We may use cookies and similar technologies that are strictly necessary for authentication, security, preferences, and Service operation. We may also use analytics technologies to understand Service usage.
Where required, non-essential technologies will be used only after obtaining consent. You can manage or delete cookies through your browser settings; blocking strictly necessary cookies may prevent parts of the Service, such as sign-in, from working.
11. Third-party services
The Service may contain links to or integrate with third-party services, including advertising platforms. Those third parties independently control their services and may process information under their own privacy policies and terms. ClaimJumper is not responsible for their independent practices.
Users can revoke a connected platform's access through the Service, where available, or through the platform's account settings. Revocation may not delete information already lawfully retained by ClaimJumper; deletion requests can be submitted as described in Section 9.
12. Google user data and Limited Use
ClaimJumper requests the Google Ads (adwords) scope so it can read campaign structure and performance from the Google Ads accounts you connect, and adjust campaign budgets on your behalf. That is the only purpose for which the scope is requested.
ClaimJumper's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Information obtained through Google APIs is used only to provide and improve the budget-management features described in this Policy. It is never sold, never used to serve, target, or personalize advertising, and never transferred to others except as set out in Section 5.
13. Children
The Service is intended for businesses and is not directed to children. We do not knowingly collect Personal Data from anyone under 18. If you believe a child has provided Personal Data to us, contact mikhail@claimjumper.ai.
14. Changes to this Policy
We may update this Policy periodically. We will post the updated version and revise the effective date. If changes materially affect how we use Personal Data, we will provide additional notice when required by law.