Privacy Policy
Last updated: August 2026 — Version: 1.0
1. Who We Are (Data Controller)
The data controller for Jokaya is Canopia, a company organized under French law, with its registered office at 191 avenue de l'étang 40000 Mont de marsan, France. You can reach our privacy team at contact@canopia.cloud.
Because we are established in the European Union, the EU General Data Protection Regulation (GDPR) applies to all our processing of personal data, wherever you live. In addition, if you are a California resident, the California Consumer Privacy Act as amended by the CPRA ("CCPA") gives you specific rights described in Section 10.
2. What Data We Collect
2.1 Account data
- Email address, username, hashed password.
- Country and, where required for rewards or tax compliance, name and address.
- Support messages you send us and our replies.
2.2 Technical data
- IP address and approximate location derived from it.
- Browser user agent, operating system, screen characteristics.
- Device fingerprint: a signal computed from technical attributes of your device and browser, used to detect duplicate accounts and fraud.
- Log data: timestamps of logins and key actions.
2.3 Behavioral data
- Offer clicks: which offers you view and start, and when.
- Conversions: which offers advertiser networks report as completed, reversed, or rejected for your account.
2.4 Financial data
- Credit and withdrawal history: amounts, dates, chosen gift card brands, redemption status.
- Where legally required (US users at or above the annual reporting threshold): tax identification information collected via Form W-9.
We do not collect bank account numbers or card numbers; redemptions are fulfilled as gift cards through our payout partner.
3. Why We Process Your Data (Purposes and GDPR Legal Bases)
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Operating your account, crediting offers, processing redemptions | Account, behavioral, financial | Performance of the contract (Art. 6(1)(b)) |
| Fraud prevention: duplicate-account detection, anomaly scoring, protecting advertisers and honest users | Technical (incl. IP and device fingerprint), behavioral | Legitimate interest (Art. 6(1)(f)) — keeping the platform viable and payouts safe |
| Tax reporting and responding to lawful requests | Account, financial, tax information | Legal obligation (Art. 6(1)(c)) |
| Support and dispute handling | Account, behavioral, financial | Performance of the contract; legitimate interest |
| Product analytics (aggregate usage measurement) | Technical, behavioral | Consent (Art. 6(1)(a)) for non-essential cookies; legitimate interest for strictly aggregated, cookie-less measurement |
| Service emails (security, balance changes, policy updates) | Account | Performance of the contract |
Where we rely on legitimate interest, we have balanced our interest against your rights; you may object as described in Section 9.
4. Who Receives Your Data (Recipients by Category)
- Affiliate/advertiser networks (our offer partners): receive a pseudonymous user identifier, click identifiers, and technical signals (such as IP address and device data) needed to attribute and validate conversions and to fight fraud. They do not receive your email or name from us.
- Tremendous (our gift card issuance partner): receives the data needed to deliver your reward, such as your email address and the reward amount and brand selected.
- Hosting provider: DigitalOcean, which stores our infrastructure and therefore processes all categories above on our behalf as a processor.
- Analytics tool: our analytics provider processes technical and behavioral usage data, subject to your cookie consent for any non-essential measurement.
- Professional advisers and authorities: accountants, lawyers, tax authorities, and law enforcement where we are legally required to disclose.
We do not sell your personal data for money. See Section 10 for how California law treats data shared with advertising partners and how to opt out.
5. International Transfers
Our company is in France and our users are mostly in the United States, so data necessarily moves between the EU and the US. Where personal data is transferred outside the European Economic Area to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (SCCs), supplemented where needed by additional safeguards, or on the recipient's certification under an adequacy framework recognized by the European Commission. You may request a copy of the relevant safeguards at contact@canopia.cloud.
6. How Long We Keep Your Data (Retention)
| Category | Retention period | Reason |
|---|---|---|
| Account data | Life of the account + 3 years after closure | Contract records, defense of legal claims |
| Technical logs (IP, user agent) | 12 months | Security and fraud investigation |
| Device fingerprint signals | Life of the account + 24 months | Preventing banned users from returning with new accounts |
| Behavioral data (clicks, conversions) | Life of the account + 3 years | Reversal handling, dispute resolution |
| Financial / redemption records | 10 years | French accounting and tax law obligations |
| Tax forms (e.g. W-9 data) | Duration required by applicable tax law (typically at least 4 years after filing) | Legal obligation |
| Support tickets | 3 years after closure of the ticket | Service quality, dispute resolution |
At the end of a retention period, data is deleted or irreversibly anonymized.
7. Security
We apply technical and organizational measures appropriate to the risk: encryption in transit, password hashing, access controls and logging, least-privilege access for staff, and separation of production data. No system is perfectly secure; if a breach affects your data in a way that creates a high risk for you, we will notify you and the competent authorities as required by law.
8. Automated Decision-Making (Anti-Fraud Scoring)
We use automated systems that score account activity for fraud risk (for example: many accounts sharing one device fingerprint, VPN patterns inconsistent with declared location, or abnormal conversion velocity). A high score can automatically freeze redemptions pending review.
No account is permanently banned or has its balance forfeited by a machine alone. Any consequential decision is reviewed by a human being, and you have the right to obtain human intervention, to express your point of view, and to contest the decision by writing to contact@canopia.cloud (see the appeal procedure in our Prohibited Conduct policy).
9. Your Rights (GDPR)
Wherever you live, we extend the following GDPR rights to you:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion, subject to legal retention obligations (e.g. accounting records).
- Restriction — limit processing while a dispute or verification is pending.
- Portability — receive data you provided in a structured, machine-readable format.
- Objection — object to processing based on legitimate interest, including fraud scoring, on grounds relating to your particular situation.
- Withdraw consent — at any time for consent-based processing (e.g. non-essential cookies), without affecting prior processing.
How to exercise your rights: email contact@canopia.cloud from the address linked to your account, or write to Canopia, 191 avenue de l'étang 40000 Mont de marsan, France. We may ask for information to verify your identity. We respond within one month, extendable by two further months for complex requests (we will tell you if so). Exercising your rights is free of charge.
Complaints: you can lodge a complaint with the French supervisory authority, the CNIL (Commission Nationale de l'Informatique et des Libertés, www.cnil.fr), or with your local data protection authority. We would appreciate the chance to address your concern first at contact@canopia.cloud.
10. California Residents (CCPA/CPRA)
This section applies to you if you are a California resident. Terms like "personal information", "sell", and "share" have the meanings given in the CCPA/CPRA.
10.1 Your California rights
- Right to know — what categories and specific pieces of personal information we collect, the sources, the purposes, and the categories of third parties we disclose it to.
- Right to delete — subject to statutory exceptions (e.g. records we must keep for legal compliance and fraud prevention).
- Right to correct — inaccurate personal information.
- Right to opt out of sale or sharing — see below.
- Right to limit use of sensitive personal information — we do not use sensitive personal information for purposes requiring a limitation right.
- Right to non-discrimination — we will not deny service, charge different rates, or reduce quality because you exercised a privacy right.
10.2 "Sale" and "sharing" — an honest explanation
We do not sell personal information for money. However, when you click an offer, we transmit identifiers and technical data (such as a click ID, your IP address, and device signals) to the advertiser network operating that offer so the conversion can be attributed and validated. Under the CCPA's broad definitions, this transmission may qualify as "sharing" (and potentially a "sale") of personal information. We treat it as such rather than argue the point.
How to opt out: email contact@canopia.cloud with the subject "California opt-out" from your account email, or use the "Do Not Sell or Share My Personal Information" link in the site footer. We will honor your request within 15 business days. Please note the practical consequence: offer attribution requires transmitting these identifiers to networks, so after an opt-out you will not be able to start new offers, though you can still redeem your existing balance and use your account. We also honor the Global Privacy Control (GPC) signal as an opt-out for the browser it is set on.
10.3 Categories collected (CCPA mapping)
In the last 12 months we have collected: identifiers (email, username, IP address, device identifiers); commercial information (offers started, rewards redeemed); internet activity (clicks, interactions with the service); geolocation at the approximate (IP-derived) level; and professional/tax information only where legally required for reporting. Sources: you, your device, and advertiser networks. Purposes and recipients are as described in Sections 3 and 4.
10.4 Authorized agents
You may designate an authorized agent to submit requests on your behalf; we will require proof of the authorization and may verify your identity directly.
11. Other US State Privacy Laws
Residents of other states with comprehensive privacy laws (such as Virginia, Colorado, Connecticut, Texas, and Oregon) have similar rights of access, correction, deletion, and opt-out of targeted advertising or sale. We honor requests from those residents under the same procedure as Section 9 and 10, and you may appeal a refusal by replying to our decision email; we will respond to appeals within the period your state's law requires.
12. Children
Jokaya is strictly for adults aged 18 or over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has an account, contact contact@canopia.cloud and we will close it and delete the data, subject to fraud-prevention retention.
13. Cookies
Our use of cookies and similar technologies, including the consent banner for any non-essential cookies, is described in our Cookie Policy.
14. Changes to This Policy
We may update this policy. The version and date at the top will change, and material changes will be announced by email or in-product notice before they take effect. Prior versions are available on request.
15. Contact
Privacy questions and rights requests: contact@canopia.cloud — Canopia, 191 avenue de l'étang 40000 Mont de marsan, France.