1. Who we are
JewIQ (“JewIQ”, “we”, “us”) runs jewiq.com, a free directory that helps buyers find jewellery manufacturers, wholesalers, diamond and gemstone dealers and other jewellery businesses. We are the controller of the personal data described here. You can reach us, including for any privacy or grievance matter, through our contact form.
2. The short version
- Business listings are built from information the businesses themselves have made public: trade-show directories, their own websites and public business listings.
- Full phone numbers and email addresses are shown only to signed-in members, with a daily limit, to discourage spam and bulk copying.
- We use essential cookies only. No advertising or tracking cookies, and we don’t sell personal data.
- Any business or person can ask us to correct or remove their information, and members can delete their account at any time.
3. Information about listed businesses
What we collect
Business name, category and description; website; business phone number and email address; postal address or city; trade-show participation (for example “JCK Las Vegas exhibitor”); and the public page each detail was read from. Listings are about businesses. Where a business is run by an individual, or a contact detail names a person, that information is personal data and this policy applies to it.
Where it comes from
- Public exhibitor and member directories of jewellery trade shows and associations, such as JCK Las Vegas, JIS, VicenzaOro and HKJMA.
- The business’s own public website, mainly its contact and about pages and the structured data it publishes for search engines. We respect each site’s robots.txt.
- Public business listings and map services (such as Google Maps), where available.
- The business itself, when it claims or corrects its listing.
We use automated tools to read addresses from public web pages; this can include an AI language model that is given only the public page text. No decision with legal or similarly significant effect is made about anyone by automated means.
Why, and on what legal basis
To help buyers find and contact jewellery businesses, which is the purpose those businesses published the details for. Where the GDPR or a similar law applies, our legal basis is legitimate interests (Art. 6(1)(f) GDPR). We have balanced it against the interests of the people concerned: we only use business contact details already made public by the business, we don’t look for home addresses or private numbers, we hide full contact details from anonymous visitors, and anyone can object at any time.
Your choices
If your business or your personal details are listed, you can claim the listing to correct it, or ask us to correct or remove it through the removal form. We complete removals within 30 days and keep a minimal record (name and website) solely so the listing is not added again.
4. Information about visitors and members
Browsing
You can browse JewIQ without an account. We don’t use analytics or advertising cookies. Our hosting infrastructure keeps standard technical logs (IP address, browser type, requested page, time) for security and troubleshooting, for a short period.
Member account
If you sign in we store your email address, a display name and, if you use Google, your Google account identifier and profile picture. Email sign-in uses a one-time code that we store only in hashed form and that expires after 10 minutes. Your sign-in session is kept as a hashed token for up to 90 days.
Contact details you view
When you reveal a business’s full phone and email, we record which business and when. We use this to enforce the daily limit, to show you your history in your account, and we may give businesses aggregated counts (for example “12 buyers viewed your contact details this month”). We do not give businesses your name or email unless you contact them yourself or agree to it.
Messages and claims
When you use our contact or claim forms we keep your name, email, message and IP address (for spam protection) to handle your request.
Legal bases
Providing your account and the service you asked for (contract); keeping JewIQ secure and preventing abuse (legitimate interests); and your consent where the law requires it.
5. Who we share it with
We use a small number of service providers who process data for us under contract:
- Hosting provider: runs our servers and database.
- Google: only if you choose “Continue with Google”, to confirm your identity.
- Resend: delivers sign-in code emails.
- OpenRouter and the AI model it routes to: reads the text of public business web pages to find addresses. It receives no visitor or member data.
We may disclose information if required by law or to protect our rights and users. We do not sell personal information and we do not “share” it for cross-context behavioural advertising, as those terms are defined in the California Consumer Privacy Act.
6. International transfers
Our providers may process data outside your country, including in the United States and the European Union. Where the law requires it, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
7. How long we keep it
- Listings: while the business is active and the information is accurate, or until removal is requested.
- Member accounts and contact-view history: until you delete your account.
- Sign-in codes: 10 minutes. Sign-in sessions: up to 90 days.
- Contact and claim messages: up to 2 years after the request is closed.
- Technical logs: a short period, normally no more than 30 days.
8. Your rights
Depending on where you live, you can ask to access, correct, delete or receive a copy of your personal data, object to or restrict how we use it, and withdraw consent. Members can delete their account themselves from Your account. For anything else use the privacy request form; we may ask you to confirm your identity and will reply within 30 days.
- EU, EEA and UK: rights under the GDPR and UK GDPR, including the right to object to processing based on legitimate interests and to complain to your data protection authority.
- California: the rights to know, delete and correct, and to not be discriminated against for using them. We don’t sell or share personal information.
- India: rights under the Digital Personal Data Protection Act, 2023, including grievance redressal through our contact form and escalation to the Data Protection Board of India.
- Elsewhere (including Canada, Australia, Singapore, Hong Kong, Switzerland and the UAE): the rights your local privacy law gives you. We apply the same process.
9. Security
We use HTTPS throughout, store passwords, sign-in codes and session tokens only as hashes, encrypt service keys at rest, limit staff access by role and keep an audit log of administrative changes. No system is perfectly secure, but we work to protect your data and will notify you and the authorities of a breach where the law requires.
10. Children
JewIQ is a business directory and is not intended for anyone under 18. We do not knowingly collect personal data from children.
11. Changes to this policy
We will update this page when our practices change and revise the date above. Significant changes will be highlighted on the site.
Questions about this page? Contact us.