JUNGLENODE / LEGAL CENTRE
Privacy policy
Keeping you signed in
We use a first-party authentication cookie named __Host-jn_php_session on the HTTPS website. Ordinary login sessions last up to four hours. If you select the optional, unchecked “Remember me for 30 days” checkbox when signing in, the cookie and server session last up to 30 days from that login. This choice is separate from newsletter and display preferences.
The cookie contains a random login token, not your password. It is restricted to HTTPS, inaccessible to browser JavaScript, and uses SameSite=Lax. A hashed token and expiry are stored on our server, and the remembered-login choice is recorded in account security activity. It is not used for advertising.
Sign out to end the current session, or revoke other sessions from your account security page. Changing or resetting your password revokes existing sessions. Clearing the cookie removes access from that browser. Do not enable remembered login on shared or public devices.
Who is responsible
JungleNode’s legal operator is the controller for website accounts, enquiries and reseller applications. Its verified legal name, postal address and direct privacy contact must be inserted before production use. The footer’s pending fields are not verified business registrations.
Use the existing private support portal for a privacy enquiry in the meantime. Hosting customers may be controllers for data they place on a server; JungleNode’s processor responsibilities must be set out in a separate data-processing agreement where applicable.
Information used by this website
- Account name, email address, salted password hash, verification/reset records and an essential session identifier when the new backend is enabled. Plain-text passwords are not stored.
- Reseller application name, brand, email, phone, country, interests, estimated scale and the additional information you choose to provide.
- Authenticated service and billing summary information received through a configured billing integration. The new website does not collect card numbers.
- Security and request information, including the connection IP used for rate limiting and records of significant account/admin actions. A production host may also maintain server logs; its practices must be added before launch.
- Your local consent choice and optional motion preference. With optional consent, automatic region selection uses the available catalogue. With only UK servers configured, it selects the UK without reading your time zone. GPS is not requested.
The local hosting guide keeps its conversation in the current tab; it does not send chat messages to a human agent or external AI provider. File/image selections and link drafts are held only in the page; attachments are not uploaded or analysed, and links are not fetched. Reloading or leaving the page clears that draft. Downloading a hosting brief saves it to your device and does not send it to JungleNode.
Purposes and lawful bases
Account and requested service administration generally relies on performing a contract or taking steps you request before a contract. Security, abuse prevention and proportionate service administration may rely on legitimate interests, balanced against your rights. Records required by law rely on legal obligations. Optional device preferences rely on consent; refusing them does not block ordinary browsing.
A reseller enquiry is used to assess and respond to your requested partnership discussion. It is not permission for unrelated marketing. Promotional email requires a separate lawful basis and, where required, PECR consent. No analytics or advertising scripts are installed in this build.
Recipients and transfers
Only authorised staff and necessary service providers should receive the data needed for their role. The optional account-email integration uses Resend when configured. Existing billing, payment, panel and Discord services have their own arrangements; the final operator must identify actual providers, roles and hosting locations.
Before making a restricted international transfer, the operator must confirm the applicable safeguard or exception and explain how to obtain relevant details. This draft does not claim all data stays in the UK.
Retention and security
The consent choice is checked for expiry after 180 days. Website sessions last up to four hours; email verification tokens expire after one hour and password reset tokens after 30 minutes. Optional motion preferences remain locally until removed, replaced or consent is withdrawn.
Business retention periods for customer records, tickets, reseller applications, security audits and backups are not yet configured. They must be defined before production use based on the purpose, legal requirements and claims that reasonably need records. This draft does not claim automated deletion that has not been implemented.
The supplied backend uses password hashing, protected session cookies, access checks, CSRF protection and request limits. These measures reduce risk; they are not a guarantee of absolute security. Access to the hosting environment, backups and email provider also requires operational controls.
Your choices and rights
Subject to the relevant conditions, you can request access, correction, erasure, restriction or portability of personal data, and object to certain processing. You can withdraw consent for optional preferences through Cookie settings; withdrawal does not make earlier lawful processing unlawful. You can complain to the Information Commissioner’s Office.
Provide enough information to identify your request safely. Do not post identity documents or account secrets in public Discord channels. The operator must respond within the applicable legal time limit and explain any lawful extension or refusal.
Other important information
The supplied website does not make solely automated decisions with legal or similarly significant effects. A time-zone suggestion is only a convenience and does not determine eligibility or pricing. If a required account or application field is missing, the relevant request may not be completed. Material changes to actual processing must be reflected in this notice and communicated where required.
Review basis: ICO guidance on the right to be informed. Actual provider, retention and controller details remain required.