Nojo — Privacy Policy
Effective date: July 16, 2026 · Last updated: August 30, 2026
This Privacy Policy explains how JC Labs LLC ("Nojo," "we," "us") collects, uses, and shares information when you use the Nojo mobile app and the getnojo.app website (together, the "Service"). Nojo is a platform that replaces physical wristbands at university Greek-life events with digital passes.
1. Information we collect and why
We collect only what the Service needs to work.
| What we collect | Why we collect it |
|---|---|
| Mobile phone number | This is how you log in. Nojo uses phone-based one-time passcodes (OTP) as the sole login method — your number is your credential, not just a contact detail. It also receives account and event text messages you consent to. |
| Phone number change history | The date and time you change the phone number on your account. We do not keep the previous number itself. |
| Name (first and last) | Shown on your digital pass, in your chapter roster, on the attendee ("Who's Going") list, and in event check-in records. |
| School year | Determines which events and passes you're eligible for. |
| Profile photo (optional) | Displayed on your pass and roster so event staff can visually verify you at the door. |
| Chapter affiliation | Associates you with your fraternity, sorority, or (for guests) your self-declared affiliation for event security. |
| Event attendance and check-in records | Records which events a pass was issued for, whether you checked in, and when. Used for event operations, safety, and post-event summaries. |
| Sober-assignment and wristband-invalidation history | Supports risk-management and safety functions that are core to the product. |
| Guest information (for people invited as guests) | A guest provides their own name, phone number, SMS consent, and affiliation when they self-register through an invite link, so we can issue their pass. |
| Payment information (chapter officers only) | Chapter subscriptions are paid through Stripe. Nojo does not see or store full card numbers — Stripe handles that. |
| Crash and error diagnostics | Technical diagnostic data sent when the app crashes or hits an error — device and app version, and the technical details of the failure — so we can fix problems and keep the app working. |
| Product usage data | A record of key actions — opening the app, starting signup, claiming a pass, a pass being scanned at a door — and which pages of our website you visit, so we can see which parts of the product work and which ones confuse people. These are tied to your account identifier once you have an account. Before you sign up, activity on our website is tied only to an identifier stored in your browser; when you create your account, that earlier activity is linked to it. It does not include your name, your phone number, or anything you type. |
| Device and connection details | Sent automatically alongside the usage data above: your device model, operating system and version, app version, language, time zone and screen size, and the internet address your device connects from, from which an approximate city is estimated. We do not use this to locate you. |
We do not sell your personal information, and we do not use it for third-party advertising.
2. Text messages and SMS consent
When you provide your mobile number, you'll see a separate, optional checkbox directly beneath the field. It is unchecked by default, and you can leave it unchecked and still finish creating your account, registering your chapter, or changing your number — agreeing to texts is never required to use Nojo. If you check it, you agree to receive account and event text messages from Nojo at that number: event pass delivery, event cancellations, and account notices. These are transactional messages only — pass delivery, event cancellations, guest-list actions, chapter account approval notices, and chapter subscription reminders. We do not send marketing texts.
Login codes are separate and are not covered by that checkbox. The one-time verification code we text when you sign in is part of signing in, is sent whether or not you check the box, and is required to use a phone-number-based account.
We record your answer — whether you agreed or declined, when, and the exact wording shown to you at that moment — so we can show what you consented to.
- Message frequency varies based on your account and event activity. Message and data rates may apply.
- Reply STOP to any message to opt out of texts. Reply START to opt back in.
- Reply HELP, or contact help@getnojo.app, for help.
- We do not share your mobile phone number, SMS consent, or opt-in data with third parties or affiliates for marketing or promotional purposes. Text messaging opt-in data is used only to deliver the transactional messages described above, through our SMS provider acting on our behalf.
- We only text numbers whose owners consented directly. If a member invites a guest who isn't on Nojo, the invitation is shared person-to-person from the member's own phone — Nojo doesn't text that guest until they self-register and consent with their own number.
Text messages are delivered through Twilio, our SMS provider.
3. Information visible to other users
Nojo is a shared platform for chapters and events, so some of your information is visible to other users by design:
- Your chapter: Your name, photo, and school year appear in your chapter's member roster, visible to your chapter's members, admins, and president.
- Event attendees: If you hold a pass for an event, your name and photo may appear in the event's "Who's Going" attendee list, visible to other pass holders. You can turn this off in Profile → Privacy → "Appear in Who's Going."
- Event staff — always: Even if you opt out of "Who's Going," event admins and designated Sober monitors (from the hosting chapter and your own) can always see your name, photo, and check-in status. This operational visibility is required so staff can verify attendees at the door and account for members during an event — it cannot be disabled.
- Guests: If you're added as a guest, your name and status are visible to the member who invited you and to the hosting chapter's admins. Your self-declared affiliation is used for event security and is not shown to other guests.
- Post-event records: Chapter admins and presidents can view attendance summaries for their events, which include attendee names and check-in data.
4. Third-party service providers
We share information with the vendors that run parts of the Service. Each only receives what it needs to do its job, and each has its own privacy terms.
| Provider | What it does | What it handles |
|---|---|---|
| Supabase | Authentication, database, and file storage | Your account data, your profile photo, and phone-OTP login |
| Twilio | SMS delivery | Your phone number and message content |
| OneSignal | Push notifications | A device push token and notification content |
| Sentry | Crash and error monitoring | Technical crash/diagnostic data |
| PostHog | Product analytics | Usage events, an account or browser identifier, the device and connection details listed in Section 1, and the internet address your device connects from |
| Vercel | Website hosting and page-visit counts | Requests to our website, and aggregate visit and performance figures |
| Stripe | Payments (chapter subscriptions) | Chapter officer payment details |
| Resend | Email delivery for the chapter access request form | The name, campus, chapter, role and contact details you enter on that form |
Legal and institutional requests. Requests for a chapter's records from a chapter's university, national/international organization, or any other third party should be directed to the chapter — the chapter controls its own data and can export it directly through the app. We do not provide chapter or member records directly to a university, law enforcement, or any other third party without either the chapter's written authorization or valid legal process (such as a subpoena or court order). We may also disclose information where required by law, to protect someone's safety, or in connection with a business transfer (e.g., a merger or acquisition).
5. Cookies, analytics, and "Do Not Track"
Our website and web pages (including guest self-registration and checkout) and our app use a small number of technologies to function and to help us understand how the product is used:
- Essential technologies keep you logged in and make pages work.
- Product analytics (PostHog) records which features are used, using an identifier stored in your browser or, in the app, on your device, so we can see where the app is confusing. Vercel separately counts page visits to our website.
- Crash reporting (Sentry) records technical diagnostics when something breaks.
We do not use advertising cookies, and we do not permit third parties to collect information on our Service for their own advertising purposes. Because we don't track you across other websites or services, our Service does not respond differently to browser "Do Not Track" signals — there is no cross-site tracking to disable.
6. How long we keep information
We keep your account information for as long as your account is active.
Important — safety and event records are retained after deletion. Even after you delete your account, certain records tied to past events are kept permanently: your first and last name, chapter affiliation, event attendance and check-in timestamps, Sober-assignment history, and wristband-invalidation records. We retain these for legitimate safety, legal, and risk-management purposes. This is disclosed to you before you delete your account. When these historical records are viewed by chapter admins, your account is marked as deleted.
We also keep a record of the dates on which an account's phone number was changed. This record contains no phone number and is kept for account-security purposes.
Product usage data is held by our analytics provider under the identifiers described in Section 4, and is not deleted automatically when you delete your account. You can ask us to remove it — see Section 7.
7. Deleting your account and data
You can delete your account at any time from Profile → Account Settings → Delete Account in the app. When you do:
- Your profile photo, phone number, and login credentials are permanently removed from your account.
- Any active passes are cancelled and their slots return to your chapter.
- You are logged out and can no longer log in.
- The event safety records described in Section 6 are retained as disclosed.
If you are a chapter president, you must transfer the president role before deleting your account.
To request deletion of data you can't remove yourself, or to ask what we hold about you, email help@getnojo.app.
8. Your U.S. state privacy rights
Depending on where you live, you may have rights over your personal information — including the right to access it, correct it, delete it, and obtain a copy, and the right not to be discriminated against for exercising these rights. Nojo does not sell your personal information or share it for cross-context behavioral advertising.
To exercise any of these rights, email help@getnojo.app. We may need to verify your identity before responding, and we'll respond within the timeframe your state's law requires. If we decline a request, you may appeal by replying to our decision, and we'll review the appeal and respond with our reasons; depending on your state, you may also contact your state attorney general.
California residents
If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) may give you additional rights, including the right to know what personal information we collect and why, the right to access and delete it, the right to correct inaccurate information, and the right to limit use of sensitive personal information. Nojo does not sell or "share" (as defined under California law) your personal information, and does not use it for targeted advertising. California residents may exercise these rights by emailing help@getnojo.app, and may designate an authorized agent to make a request on their behalf. We will not discriminate against you for exercising your rights.
9. Children's privacy
Nojo is intended for university students and adults. It is not directed to children under 13, and we do not knowingly collect information from them.
10. Security
We use reasonable technical and organizational measures to protect your information, including encrypted transport and access controls through our providers. No system is perfectly secure, so we can't guarantee absolute security.
11. Changes to this policy
We may update this policy. If we make material changes, we'll update the "Last updated" date and, where appropriate, notify you in the app.
12. Contact us
Questions about privacy? Email help@getnojo.app or write to us at JC Labs LLC, 6545 Market Ave N Ste 100, Canton, OH 44721.