Privacy policy
What we store. Account records (email, hashed password, role), business profile, published websites, contacts, conversations, bookings, quotes, invoices, AI interaction logs, audit events, subscription and billing metadata.
Payments. Card payments on your storefront are processed by Stripe through a connected account you authorize with Stripe (Stripe Connect). Zanelvo never stores your Stripe secret key; we store only your connected-account identifier and the capability flags Stripe reports. Until your Stripe account is connected and enabled, checkout runs in a clearly labelled test mode and no card data is collected.
Other providers. Email delivery, voice/SMS and advertising run only through accounts you connect under Integrations. Until you connect one, the feature is shown as "Not connected" and no data is sent to that provider.
AI subprocessors. When you use AI features, the request content (visitor questions, generation prompts, page text) is sent to our LLM provider (Anthropic Claude models via our AI gateway). Prompts are used only to produce your output; we do not sell your data or use it to train models.
Retention. Data stays for the life of your subscription; a soft-delete workflow gives you a 30-day grace window to recover, then the record is purged.
Access & export. Owners can export the full org's data as a JSON ZIP any time from Setup → Data.
Authentication & cookies. Signing in sets a short-lived, Secure, HttpOnly session cookie plus a readable CSRF token. No password or session token is stored in browser storage. Published sites record first-party analytics events (page views, CTA clicks, form submissions, attribution source) to power your dashboard; we do not run third-party ad trackers unless you add your own analytics IDs.
Security logging. Sign-in attempts, staff actions and impersonation sessions are recorded in an audit log with IP address and timestamp for abuse prevention.