Privacy Policy
Effective July 3, 2026
This Privacy Policy explains what information ZT Ziro ("we," "us," or "our") collects through the Service, how we use it, and the choices you have. It applies to everyone who creates an account or otherwise uses the Service.
1. Information We Collect
Account information. When you sign up, our authentication provider (Clerk) collects your name, email address, and authentication credentials.
Connected data-source information. When you authorize an integration, we retrieve business data from that source on your behalf, for example:
- Shopify: orders, revenue, inventory, and store metadata;
- Meta: advertising spend and campaign performance;
- Google Calendar: event data you choose to sync.
Content you create. Goals, accountability tasks, briefings, team notes, and questions you ask Jarvis.
Usage and device data. Standard technical data such as IP address, browser type, and access timestamps, collected for security, rate-limiting, and audit-logging purposes.
2. How We Use Information
- To operate the Service: display your dashboards, calculate metrics, and run the features you use;
- To power Jarvis: relevant workspace data is sent to our AI provider to generate the specific answer you requested;
- To secure the Service: rate limiting, audit logging, and fraud/abuse prevention;
- To communicate with you: service notices, security alerts, and (only if you opt in) product updates;
- To comply with legal obligations.
3. AI Processing
When you use Jarvis, the relevant portion of your workspace data and your question are sent to our AI model provider, Anthropic, solely to generate the response you requested. We do not permit that data to be used to train Anthropic's models. Anthropic's handling of data it processes on our behalf is described at anthropic.com/legal/privacy. Jarvis is designed to retrieve real data before answering and to say so when data is missing, rather than fabricate a metric.
4. Who We Share Information With
We do not sell your personal information. We share information only with:
- Service providers who process data on our behalf under contract: Clerk (authentication), Neon (database hosting), Vercel (application hosting), Upstash (background job queue), Resend (transactional email), and Anthropic (AI processing);
- The data sources you connect (Shopify, Meta, Google), when your actions in the Service require an API call back to them;
- Other members of your workspace, according to the role-based permissions in effect for that workspace;
- Law enforcement or regulators, only when required by valid legal process.
5. Data Security
Every database query is scoped to your workspace so that other tenants can never see your data. Integration credentials (API keys/tokens for connected data sources) are encrypted at rest using AES-256-GCM. Access to mutating actions is gated by role-based permissions, and security-relevant actions are recorded in an audit log. No method of transmission or storage is 100% secure, but we design and review the Service with this as the baseline standard.
6. Data Retention
We retain workspace data for as long as your workspace remains active. If you delete your workspace or request account deletion, we delete or anonymize your data within a reasonable period, except where we are required to retain it for legal, security, or legitimate audit-logging purposes.
7. Cookies
The Service uses essential cookies set by our authentication provider (Clerk) to keep you signed in and to protect against cross-site request forgery. We do not currently use third-party advertising or cross-site tracking cookies. If that changes, this section will be updated and, where required, we will ask for your consent.
8. Your Rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, or to object to or restrict certain processing (for example, under the GDPR if you are in the EU/UK, or the CCPA/CPRA if you are a California resident). To exercise any of these rights, contact us using the details below. We will respond within the timeframe required by applicable law.
9. International Transfers
Our service providers may process data in countries other than your own, including the United States. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for these transfers.
10. Children's Privacy
The Service is intended for business use by adults and is not directed to children under 16. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated effective date above, and where appropriate we will provide additional notice.
12. Contact
Questions about this Privacy Policy, or requests to access, correct, or delete your data, can be sent to andrewlife45@gmail.com.