Privacy Policy

Effective: July 13, 2026Last updated: July 13, 2026

1. Purpose

This Privacy Policy explains how 2moni Ltd., operating as Jorrify, collects, uses, discloses, stores and protects personal information.

Jorrify is designed around birthdays, relationships and celebrations. These features require privacy controls that are understandable and proportionate.

Canadian private-sector privacy requirements may apply to personal information collected, used or disclosed during commercial activities.

2. Information we collect

Account information

  • name;
  • username;
  • email;
  • telephone number;
  • profile photograph;
  • login information;
  • authentication-provider information;
  • account preferences.

Birthday information

  • birth month;
  • birth day;
  • birth year;
  • calculated age;
  • birthday visibility preferences.

Relationship information

  • connections;
  • manually added people;
  • relationship categories;
  • invitations;
  • blocked users;
  • connection history.

Contact-discovery information

With permission, Jorrify may process:

  • contact names;
  • telephone numbers;
  • email addresses;
  • normalized contact identifiers;
  • hashed matching values.

Contact information should be used only for clearly disclosed purposes.

Celebration information

  • celebration details;
  • celebration photographs;
  • organizer information;
  • privacy settings;
  • participant activity;
  • wishes;
  • memories;
  • comments;
  • reactions;
  • invitation activity.

Gift and payment information

  • gift amount;
  • currency;
  • fee information;
  • payment status;
  • payment-provider references;
  • transaction reference;
  • refund information;
  • dispute information;
  • payout eligibility;
  • connected-account status.

Payment-card information may be collected directly by the payment provider rather than Jorrify.

Guest information

Guests may provide:

  • display name;
  • email;
  • birthday wish;
  • gift message;
  • contribution information;
  • guest-session information.

Device and technical information

  • device type;
  • operating system;
  • browser;
  • Internet Protocol address;
  • application version;
  • language;
  • timezone;
  • device identifiers;
  • crash information;
  • security logs.

Usage information

  • pages viewed;
  • features used;
  • celebrations opened;
  • sharing methods;
  • actions completed;
  • notification interactions;
  • conversion and retention events.

Analytics should not contain private messages, raw contact lists or full payment details.

3. How we use information

Jorrify may use information to:

  • create and manage accounts;
  • provide birthday reminders;
  • calculate upcoming birthdays;
  • create celebration pages;
  • support gifting;
  • process payments;
  • support group gifts;
  • connect users;
  • match contacts;
  • deliver wishes and memories;
  • send notifications;
  • provide customer support;
  • prevent fraud;
  • moderate content;
  • investigate abuse;
  • improve performance;
  • understand product use;
  • comply with law;
  • enforce policies.

4. Consent

Jorrify should obtain meaningful consent appropriate to the sensitivity and purpose of the information.

Consent should be:

  • understandable;
  • specific;
  • accessible;
  • connected to a clear purpose.

The privacy commissioner\u2019s guidance emphasizes that people should understand the nature, purpose and consequences of collection, use and disclosure.

Separate consent should be used where appropriate for:

  • contact access;
  • push notifications;
  • marketing;
  • public birthday visibility;
  • public celebration visibility;
  • optional analytics cookies;
  • optional profile discovery.

5. Contact matching

If a user grants contact access, Jorrify may compare contact identifiers with existing Jorrify accounts.

The developer should:

  • normalize identifiers locally where possible;
  • hash identifiers before matching where appropriate;
  • minimize raw uploads;
  • avoid storing unnecessary contact records;
  • provide manual alternatives;
  • allow permission withdrawal.

Contact import must not automatically create public profiles.

6. Information about non-users

A Jorrify user may add birthday information concerning a person who does not yet use Jorrify.

Such information should:

  • remain private by default;
  • be used only to support the user’s birthday organization;
  • not become publicly searchable automatically;
  • be removable;
  • be claimable only after verification.

Non-users should have a method to request access, correction or removal where applicable.

7. How information is shared

With other users

According to:

  • privacy settings;
  • celebration visibility;
  • connection status;
  • user choices.

With payment providers

To:

  • process gifts;
  • complete verification;
  • facilitate payouts;
  • prevent fraud;
  • process refunds;
  • manage disputes.

With service providers

For:

  • hosting;
  • authentication;
  • email;
  • notifications;
  • analytics;
  • fraud prevention;
  • moderation;
  • customer support.

For legal and safety reasons

Where reasonably necessary to:

  • comply with law;
  • respond to valid legal process;
  • protect users;
  • investigate fraud;
  • prevent harm;
  • enforce policies.

During a business transaction

Information may be transferred during:

  • merger;
  • acquisition;
  • financing;
  • restructuring;
  • sale of assets.

Appropriate confidentiality and legal protections should apply.

8. What we do not do

Jorrify should state:

  • We do not sell personal contact lists.
  • We do not sell imported address-book information.
  • We do not publicly display full dates of birth by default.
  • We do not use private birthday wishes as advertising content without permission.
  • We do not store complete payment-card details when payment information is collected directly by our payment provider.

Only publish these promises if the architecture actually enforces them.

9. Public information

Information may become public when a user intentionally:

  • creates a public celebration;
  • submits a public wish;
  • posts a public memory;
  • displays a public profile;
  • shares a public celebration link.

Users should understand that public content may be:

  • viewed;
  • copied;
  • reshared;
  • captured;
  • indexed where permitted.

10. Data retention

Jorrify should retain information only as long as reasonably necessary for:

  • service delivery;
  • legal obligations;
  • financial records;
  • fraud prevention;
  • dispute resolution;
  • security;
  • legitimate operational requirements.

Create a retention schedule for:

  • Account data
  • Guest data
  • Imported contacts
  • Payment records
  • Support records
  • Security logs
  • Deleted content
  • Backups
  • Analytics
  • Minor data

Do not use "we retain data forever" as the default.

11. Security

Jorrify should use reasonable administrative, technical and organizational safeguards, including:

  • encryption in transit;
  • encryption at rest where appropriate;
  • access controls;
  • multi-factor authentication for administrators;
  • audit logs;
  • secure password handling;
  • token expiration;
  • rate limiting;
  • secure backups;
  • vulnerability management;
  • incident monitoring.

No system is completely secure.

12. Privacy incidents

Jorrify should maintain:

  • incident-response procedures;
  • breach-assessment procedures;
  • breach records;
  • notification procedures.

Canadian privacy requirements may require reporting and notification where a breach creates a real risk of significant harm, and organizations may be required to retain breach records.

13. International processing

Information may be processed outside the user\u2019s province or country.

Where this occurs:

  • appropriate contractual safeguards should be used;
  • service providers should be reviewed;
  • applicable disclosures should be made;
  • users should be informed that foreign authorities may have lawful access under local laws.

14. User privacy rights

Depending on location, users may have rights to:

  • access personal information;
  • correct information;
  • withdraw consent;
  • delete information;
  • object to certain processing;
  • obtain information about disclosures;
  • complain about privacy practices.

Requests may be sent to compliance@jorrify.com

Identity verification may be required.

15. Children and minors

Information concerning minors receives additional protections.

See the Minor and Guardian Policy.

16. Marketing

Marketing preferences must remain separate from essential account and transaction communications.

Users may unsubscribe from marketing without losing:

  • payment receipts;
  • security notices;
  • essential account messages.

17. Privacy officer

Jorrify should designate a Privacy Officer.

Privacy Officer

2moni Ltd. / Jorrify

Email: compliance@jorrify.com

⚠️ Pending Legal Review

The registered business mailing address is pending confirmation. It will be published here before the final policy goes live.

18. Contact

Privacy enquiries: compliance@jorrify.com