Privacy policy
What Zaps collects, why it is collected, how long it is kept, and what you can ask for.
Last updated:
Pre-launch draft. This document describes how Zaps is built and operated today and is pending legal review before general availability. It is not yet a binding agreement.
What this covers
This describes what Zaps collects when you use the workspace application, and what is collected when a visitor opens a Brandfront or follows a Link you published.
Account information
When you create an account we store your display name and email address, and the workspaces, Handles, Brandfronts, and Links you create.
Passwords are held by our identity provider, never by the Zaps product API. Your browser holds an opaque session cookie that identifies the session and nothing else — no provider tokens are placed in browser storage.
Visitor measurement
When someone opens one of your Links or Brandfronts, we record the event so you can measure it. Measurement is aggregate by design.
- We record the time, the referring source, coarse device type, and country.
- We do not store a visitor’s IP address alongside the event, and we do not build cross-site profiles of visitors.
- Where a visitor has to be recognised for a limited purpose — rate limiting abuse reports, for example — a one-way hash is used rather than the address itself.
How long data is kept
Analytics retention depends on your plan; the window for each tier is published on the pricing page. Events older than the window are removed.
Account and workspace records are kept while the account is open. Abuse reports and their outcomes are kept longer, because a trust and safety record that expires is not a record.
Who else sees it
Zaps first-party measurement does not sell personal information. A creator may separately enable Google, Meta, or TikTok tracking on their published Brandfront; those providers receive visitor data when their scripts load.
We use infrastructure and payment providers to run the service — hosting, email delivery, and payment processing. They process data on our instructions and only for that purpose.
We disclose information to a legal authority only where we are required to, and only to the extent required.
Your choices
You can edit your profile and export the data your plan makes available. Account deletion requests currently use the contact address below.
To ask what we hold about you, to correct it, or to have it deleted, write to the address below. We answer within 30 days.
Cookies
Zaps sets cookies to keep you signed in and complete sign-in safely. Creators can enable Google Analytics, Meta Pixel, or TikTok Pixel on a published Brandfront; these services may use advertising and cross-site tracking cookies.
Optional tracking asks for your choice by default. Creators can declare that they manage consent separately. Analytics preferences on the Brandfront let you decline these services; an explicit decline overrides that setting. Choices expire after 180 days and are requested again when the configured tracking identifiers change.
Changes to this policy
If this policy changes in a way that affects what we collect or how long we keep it, we will update the date at the top of this page and tell account holders before the change takes effect.
Contact
Questions about this document go to legal@zaps.one.