Privacy Policy
JMI Backstage is the members’ app for Jones Musical Instruments. This page says exactly what the app collects, why it is collected, and how to have it removed.
Last updated 10 September 2026
| What | Why | Where it lives |
|---|---|---|
| Username, display name, password | Signs you in and names you on the community wall. | On the JMI server. The password is kept only as a scrypt hash, so nobody at JMI can read it. |
| Email address, if you give one | Lets staff reach you about your account, an ownership claim, or a build you asked for. It is optional at sign-up. | On the JMI server, and on your record in JMI’s customer records, the same set the company builds its email campaigns from. |
| Profile details | A short bio and a profile photo, if you choose to add them. | On the JMI server, shown to other signed-in members. |
| Sign-in token | Keeps you signed in so you do not retype a password on every visit. | On your phone and on the JMI server. A token left unused for 180 days stops working. |
| Posts, comments, replies and likes | They are the community wall. Other signed-in members read them. | On the JMI server, with the time you posted. |
| Photos you attach | Shown with the post or the ownership claim you attached them to. They come from your camera or your photo library, only when you pick one. | As image files on the JMI server. |
| Questions, upvotes and event RSVPs | Puts your question in front of Darryl and the staff, and tells JMI who plans to come to an event. | On the JMI server. |
| Feedback about the app | Suggestions and bug reports you send from inside the app, stored with your username so staff can reply. | On the JMI server. |
| Reports you make | Tells staff which post, comment or member to look at, and why. It records your account, what you reported and the reason you picked. | On the JMI server, in the moderation queue staff work from. The member you reported is not told who reported them. |
| Members you block | Keeps the two of you off each other’s screens. It records which account blocked which. | On the JMI server, until you unblock them. |
| Ownership claims | The serial number you enter, an optional note and an optional photo, so staff can check it against the company’s serial register and mark you as the owner. | On the JMI server, with the decision and the date it was made. |
| Custom build requests | Only if you use the build tool: your name, email address, an optional phone number, your notes, and the specification you chose. | On the JMI server, in the build queue the workshop works from. |
| A deposit you pay | Only if you reserve a build: the amount, the date, and the name, phone number and billing postcode Stripe collected on its own payment page. Your card number is not part of it. | On the JMI server, on the order the deposit belongs to. |
What the app does not do
- It carries no advertising and no advertising networks.
- It carries no third party analytics, no crash reporting service and no tracking software. Nothing in the app follows you to other apps or websites.
- It never asks for your location, and it does not read your contacts, your microphone or your photo library on its own. When you attach a photo, iOS hands the app that one photo and nothing else.
- JMI does not sell, rent or trade your information, and does not share it with advertisers or data brokers.
Who your information reaches
Your account details and everything you post are held by Jones Musical Instruments, Inc. Other members see what you choose to publish: your display name, your profile, your posts, comments, likes, and the model and serial number of any instrument you have been verified as owning. Your email address and your password are never shown to other members. JMI staff can see member accounts, claims, feedback and reports in order to run the app and to moderate the wall.
A small number of companies handle parts of the service for JMI, and each one gets only what it needs:
- Hosting. The server and its database run on Fly.io, on machines in the United States.
- Email delivery. When JMI emails you, the message goes out through SendGrid, which receives your email address and the contents of that message.
- Payments. If you reserve a build with a deposit, the payment opens in your browser and is handled by Stripe. Card numbers go to Stripe, never to JMI. What comes back to JMI is the record that a deposit was paid, along with the name, phone number and billing postcode Stripe collected on that page.
- Lesson video. Lessons play on the video host they are published on, usually YouTube. Opening one loads a page from that host, which sees the request under its own privacy policy. Video thumbnails in the lesson list load from YouTube for the same reason.
Email you receive
Creating an account also creates a record for you in JMI’s customer records. That is the same set of records the company builds its email campaigns from, so it is worth being exact about what does and does not follow from it.
Being in those records does not put you on the mailing list. A campaign only goes to an address that has marketing consent recorded against it, and that is checked twice: every campaign audience is filtered on it, and each message is checked again at the moment it is sent. Registering in the app records no such consent, so registering alone will not bring you company news.
Consent is recorded when you ask for it: by ticking the newsletter box on the JMI website, or by telling staff to add you, in which case the request is logged against your record with the date. JMI may email you without it about your own account, an ownership claim, a build request or an order, because those are answers to something you did.
To stop marketing email, use the unsubscribe link at the foot of any marketing message. It works on its own, takes effect at once, and does not need a reply from anyone. You can also write to info@jonesmusicalinstruments.com and ask to be taken off. Neither one stops email about your own account.
How long it is kept
Your account, your posts, your messages and your photos stay until you delete them, either one at a time or by deleting the whole account from Profile. Deleting the account closes it at once and hides everything on it from other members; the account and its content are deleted for good 30 days later. Sign in within those 30 days to restore it. A sign-in token left unused for 180 days stops working. Records tied to a purchase, such as a receipt or a deposit, are kept as long as tax and accounting law requires, even after an account is closed.
Your choices
- Delete a post or a comment. You can delete anything you posted, from inside the app, at any time.
- Change your password. From your profile in the app.
- Correct your details. Your display name, bio, profile photo and email address are yours to change in the app, from your profile. For an ownership record, email JMI and staff will fix it.
- Ask for a copy. Email JMI and you will be sent everything the app holds about you.
- Delete your account. From inside the app: open Profile, then Delete account. The account closes at once, and your posts, comments, messages, photos and claims stop being visible to anyone else. Thirty days later all of it is deleted for good. Sign in with the same username and password inside those 30 days to restore it. If you cannot get into the app, email JMI instead and staff will close it, restore it or delete it for you.
To delete your account or your data
In the app, open Profile and choose Delete account. The app tells you what is about to go and asks you to confirm it. No reason is needed and nobody has to approve it. The account closes immediately and everything on it is hidden; it is deleted for good 30 days later, and signing in before then restores it.
If you cannot get into the app, or you want a copy of your data first, write to info@jonesmusicalinstruments.com with your username. Staff can close an account, restore one that is still inside its 30 days, or delete it for good, working from the email address on the account. They do it by hand within 30 days and confirm by email.
Security
Passwords are stored as scrypt hashes with a salt for each account, never as readable text. Everything the app sends travels over HTTPS. Sign-in attempts are rate limited so a password cannot be guessed by brute force. The database is backed up continuously. Access to member records is limited to JMI staff who need it.
A photo you attach is served from a long random web address. That address is not listed or guessable, but anyone you send it to can open it, so treat a photo you post as shared.
Children
JMI Backstage is rated for ages 13 and over and is not intended for children under 13. JMI does not knowingly collect information from a child under 13. If you believe a child has created an account, write to the address below and it will be deleted.
Changes to this policy
If what the app collects changes, this page changes with it and the date at the top is updated. Material changes will also be announced on the community wall.
Contact
Questions about this policy, about what is held on your account, or about anything else in the app:
info@jonesmusicalinstruments.com
The support page covers how to get help with the app itself, and the terms of use cover the rules of the community wall. This policy covers the JMI Backstage app. The company website and its shop are covered separately by the Jones Musical Instruments privacy policy.