Privacy Policy
Last Updated: October 9, 2025
1. Introduction and Commitment to Privacy
Welcome to Zaplane Insights ("Zaplane," "we," "us," or "our"). We are deeply committed to protecting your privacy and maintaining the trust you place in us when you use our marketing intelligence platform and services (the "Services").
This Privacy Policy explains:
- What information we collect and why we collect it
- How we use, process, and protect your information
- Your rights and choices regarding your information
- How we comply with applicable privacy laws and regulations
This Privacy Policy applies to:
- All users of our platform, website, and services
- Data collected through our website, applications, and integrations
- Information accessed from third-party platforms you connect to our Services
By using our Services, you agree to the collection, use, and disclosure of your information as described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our Services.
We reserve the right to update this Privacy Policy at any time. Material changes will be communicated through email notification and by updating the "Last Updated" date above. Your continued use of our Services after changes constitutes acceptance of the updated Privacy Policy.
2. Information We Collect
We collect information in several ways to provide, improve, and protect our Services. The information we collect falls into the following categories:
2.1 Information You Provide Directly
Account Registration Information:
- Full name and email address
- Company or business name
- Job title and role
- Phone number (optional)
- Password (encrypted and never stored in plain text)
- Profile photo (optional)
- Time zone and language preferences
Billing and Payment Information:
- Billing name and address
- Payment method details (processed securely by third-party payment processors)
- Tax identification numbers (if required)
- Purchase and transaction history
- Invoices and receipts
Communications and Support:
- Messages, emails, and correspondence with our support team
- Feedback, survey responses, and product reviews
- Feature requests and bug reports
- Customer service interactions and chat logs
User-Generated Content:
- Custom dashboard configurations and settings
- Saved reports and analytics views
- Notes, annotations, and comments
- Workspace settings and preferences
- API configurations and integrations
2.2 Information from Connected Third-Party Platforms
When you authorize Zaplane to connect to your advertising, e-commerce, and analytics platforms, we collect and process data from those platforms to provide our Services. This data access is authorized by you through OAuth consent flows or API key authentication.
Platform-Agnostic Data Collection:
We integrate with multiple advertising, e-commerce, and analytics platforms. Regardless of which platforms you connect, we collect similar types of data to provide our marketing intelligence services:
Advertising Platform Data:
Supported platforms include: Meta Ads (Facebook/Instagram), Google Ads, TikTok Ads, LinkedIn Campaign Manager, Pinterest Ads, Snapchat Ads, Twitter/X Ads, Microsoft Advertising, Amazon Advertising, and others
- Account information and account structure
- Campaign, ad group, and ad-level data
- Performance metrics (impressions, clicks, conversions, spend, revenue, ROAS, CTR, CPC, CPM, etc.)
- Targeting settings (audiences, demographics, interests, locations, devices)
- Bidding strategies and budget information
- Ad creative assets (images, videos, copy, headlines)
- Keyword data and search terms
- Conversion tracking and attribution data
- Historical performance data and trends
E-Commerce Platform Data:
Supported platforms include: Shopify, WooCommerce, BigCommerce, Magento, Wix eCommerce, Squarespace Commerce, and others
- Store information and settings
- Product catalog and inventory data
- Order and transaction data (order values, quantities, timestamps)
- Customer purchase behavior (aggregated and anonymized)
- Revenue and sales metrics
- Abandoned cart data
- Product performance analytics
Analytics Platform Data:
Supported platforms include: Google Analytics, Adobe Analytics, Mixpanel, Amplitude, and others
- Website traffic and visitor data
- User behavior and engagement metrics
- Conversion funnel data
- Traffic sources and attribution
- Session duration and page views
- Event tracking data
Email Marketing Platform Data:
Supported platforms include: Klaviyo, Mailchimp, Constant Contact, and others (if connected)
- Campaign performance metrics
- Email engagement data (opens, clicks)
- Subscriber list information (aggregated)
- Automation workflow data
Other Business Tools:
May include: CRM systems (HubSpot, Salesforce), data warehouses, business intelligence tools, and other marketing technology platforms
2.3 Third-Party Platform API Data Usage and Commitments
When you connect any third-party platform to Zaplane, we access data through that platform's API in accordance with their respective policies and our commitments below.
Our Universal Data Handling Commitments:
Regardless of which platform you connect, we adhere to the following principles:
Limited Use Principle:
- We only use data accessed from third-party platforms to provide our marketing intelligence and optimization services
- Data is used solely for the specific purposes you have authorized when connecting each platform
- We do not use platform data for unrelated purposes or activities outside our core Services
- Each platform's data is used only within the scope of our stated functionality
Automated Processing:
- Platform data is primarily processed by automated systems and algorithms
- Human access to platform data occurs only when necessary for:
- Security purposes and fraud prevention
- Technical debugging and troubleshooting
- Compliance with legal obligations
- With your explicit consent for support requests
- All human access is logged and monitored
No Sale or Unauthorized Transfer:
- We do not sell, rent, or trade data accessed from any third-party platform
- We do not transfer platform data to other third parties except:
- As necessary to display information to you within our Services
- To trusted service providers under strict contractual obligations
- As required by law or legal process
- Platform data remains under your control
Secure Storage and Transmission:
- All platform data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
- We implement appropriate security measures to protect data from unauthorized access
- Access controls limit who can view platform data
- Regular security audits and monitoring
User Control and Revocation:
- You can revoke our access to any connected platform at any time
- Disconnecting a platform stops future data synchronization
- You can request deletion of previously collected platform data (see Section 7)
- Each platform connection is independently controllable
Platform-Specific Compliance:
We comply with each connected platform's specific API terms of service and data use policies, including:
- Google APIs: Google API Services User Data Policy, including Limited Use requirements
- Meta Business APIs: Meta Platform Terms and Developer Policies
- TikTok for Business: TikTok Developer Terms and Privacy Policy
- LinkedIn Marketing APIs: LinkedIn API Terms of Use
- Shopify: Shopify API Terms and App Store Requirements
- All Other Platforms: Respective API terms, data policies, and platform requirements
For detailed information about how each platform handles your data, please review their respective privacy policies:
- Google Privacy Policy: https://policies.google.com/privacy
- Meta Privacy Policy: https://www.facebook.com/privacy/policy
- TikTok Privacy Policy: https://www.tiktok.com/legal/privacy-policy
- LinkedIn Privacy Policy: https://www.linkedin.com/legal/privacy-policy
2.4 Automatically Collected Information
Usage and Activity Data:
- Pages visited and features used within our platform
- Actions taken (campaigns analyzed, reports generated, settings changed)
- Time spent on different sections of the platform
- Frequency and patterns of use
- Feature engagement and adoption metrics
- Click paths and navigation flows
- Search queries within the platform
Device and Technical Information:
- Device type, model, and operating system
- Browser type, version, and language settings
- Screen resolution and display settings
- IP address and approximate geographic location
- Internet service provider (ISP)
- Referring and exit pages
- Date and time stamps of access
Cookies and Tracking Technologies:
- Session cookies for authentication and security
- Preference cookies for settings and customization
- Analytics cookies for usage tracking and improvement
- Advertising cookies (only with your consent)
For detailed information about our use of cookies, please see Section 10 below.
Log Data:
- API requests and responses
- System errors and debugging information
- Performance and uptime metrics
- Security and authentication logs
3. How We Use Your Information
We use the information we collect for the following legitimate business purposes:
3.1 Provide and Maintain Our Services
- Platform Functionality: Operate and maintain our marketing intelligence platform
- AI-Powered Analysis: Generate insights, recommendations, and predictions using machine learning algorithms
- Data Synchronization: Retrieve and sync data from your connected advertising and e-commerce platforms
- Campaign Optimization: Provide automated campaign management and optimization features
- Custom Dashboards: Create and maintain personalized dashboards, reports, and analytics views
- Performance Monitoring: Track and display campaign performance metrics in real-time
- Cross-Platform Analysis: Aggregate and analyze data across multiple advertising platforms
3.2 Account and Subscription Management
- Account Creation: Set up and manage your user account
- Authentication: Verify your identity and maintain account security
- Billing and Payments: Process subscription payments, manage billing cycles, and issue invoices
- Subscription Management: Handle plan upgrades, downgrades, and cancellations
- Usage Monitoring: Track usage against plan limits and quotas
3.3 Customer Support and Communication
- Support Services: Respond to your questions, troubleshoot issues, and provide technical assistance
- Product Updates: Inform you about new features, improvements, and platform changes
- Service Notifications: Send important account alerts, security notifications, and system updates
- Educational Content: Provide tips, best practices, and guidance on using our Services effectively
- Marketing Communications: Send promotional emails about our Services (you can opt-out at any time)
3.4 Service Improvement and Development
- Product Development: Develop new features and improve existing functionality
- Performance Optimization: Monitor and improve system performance, speed, and reliability
- Bug Fixes: Identify and resolve technical issues and errors
- User Experience: Analyze usage patterns to enhance user interface and experience
- AI Model Training: Improve our machine learning algorithms and recommendation systems using aggregated and anonymized data
- Research and Analytics: Conduct research to better understand user needs and market trends
3.5 Security and Fraud Prevention
- Account Security: Protect your account from unauthorized access
- Fraud Detection: Identify and prevent fraudulent activities, payment fraud, and abuse
- Security Monitoring: Monitor for security threats, vulnerabilities, and suspicious activities
- Compliance: Maintain security standards and compliance certifications
3.6 Legal Compliance and Protection
- Legal Obligations: Comply with applicable laws, regulations, and legal processes
- Terms Enforcement: Enforce our Terms of Service and policies
- Rights Protection: Protect our intellectual property, rights, and interests
- Dispute Resolution: Respond to legal claims and participate in dispute resolution proceedings
- Regulatory Reporting: Fulfill regulatory reporting and audit requirements
3.7 Business Operations
- Analytics and Metrics: Understand platform usage, user behavior, and business performance
- Financial Planning: Forecast revenue, analyze subscription trends, and manage business operations
- Business Transfers: Facilitate mergers, acquisitions, or sales of our business
4. How We Share Your Information
We respect your privacy and do not sell, rent, or trade your personal information to third parties for their marketing purposes. We only share your information in the limited circumstances described below:
4.1 Service Providers and Business Partners
We share information with trusted third-party service providers who assist us in operating our platform and providing our Services. These service providers are contractually obligated to:
- Use your information only for the specific purposes we authorize
- Implement appropriate security measures to protect your data
- Comply with applicable privacy laws and regulations
- Delete or return data when no longer needed for the specified purposes
Categories of service providers:
- Cloud Hosting: Amazon Web Services (AWS), Google Cloud Platform, Microsoft Azure, or similar providers for infrastructure and data storage
- Payment Processing: Stripe, PayPal, or other payment processors for billing and transactions
- Analytics: Platform analytics tools for usage analysis and service improvement
- Customer Support: Support platforms for ticket management and customer service
- Email Services: Email service providers for transactional and marketing emails
- Security: Authentication, monitoring, and security services
- API and Integration Partners: Services that facilitate connections to advertising and e-commerce platforms
4.2 Third-Party Platform Integrations
When you connect third-party platforms (Meta Ads, Google Ads, Shopify, etc.) to our Services:
- We share authentication tokens and API credentials with those platforms to access your data
- Data flows between our platform and third-party platforms according to their respective APIs and policies
- You should review the privacy policies of those third-party platforms to understand how they handle your data
We do not control and are not responsible for the privacy practices of third-party platforms.
4.3 Legal Requirements and Law Enforcement
We may disclose your information when required by law or when we believe disclosure is necessary to:
- Comply with legal processes, court orders, subpoenas, or government requests
- Enforce our Terms of Service, Privacy Policy, or other agreements
- Protect the rights, property, or safety of Zaplane, our users, or the public
- Investigate and prevent fraud, security issues, or illegal activities
- Respond to claims of rights violations or harmful content
- Comply with regulatory obligations and audits
We will notify you of legal requests for your information unless:
- We are legally prohibited from doing so
- Notification would compromise an investigation or endanger safety
- The request involves emergency circumstances
4.4 Business Transfers and Corporate Transactions
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or substantially all of our assets:
- Your information may be transferred to the acquiring or successor entity
- The acquiring entity will be bound by the terms of this Privacy Policy unless you consent to a new privacy policy
- We will provide notice before your information is transferred and becomes subject to a different privacy policy
- You will have the right to delete your information before the transfer
4.5 With Your Consent
We may share your information with third parties when you explicitly consent to or request such sharing, including:
- Integrating with additional third-party tools or services you choose to connect
- Sharing data with business partners as part of collaborative features
- Participating in case studies or testimonials (only with explicit permission)
4.6 Aggregated and Anonymized Data
We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you:
- Industry benchmarks and performance metrics
- Market trends and insights
- Research and analytics
- Product improvement and development
This anonymized data is not subject to the restrictions in this Privacy Policy as it does not identify you personally.
5. Data Security and Protection
We take the security of your information seriously and implement comprehensive technical, administrative, and physical security measures to protect your data from unauthorized access, use, disclosure, alteration, or destruction.
5.1 Technical Security Measures
Encryption:
- In Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher (256-bit SSL encryption)
- At Rest: Sensitive data stored in our databases is encrypted using AES-256 encryption
- Database Encryption: Database-level encryption for all production databases
- Backup Encryption: All backups are encrypted and stored securely
Access Controls:
- Multi-factor authentication (MFA) for employee access to production systems
- Role-based access control (RBAC) limiting access to data based on job responsibilities
- Principle of least privilege ensuring minimal necessary access
- Automated access reviews and periodic access audits
- Immediate access revocation for terminated employees
Infrastructure Security:
- Secure cloud infrastructure with leading providers (AWS, GCP, Azure)
- Network segmentation and firewall protection
- Intrusion detection and prevention systems (IDS/IPS)
- DDoS protection and mitigation
- Virtual Private Cloud (VPC) isolation
- Regular security patches and updates
Application Security:
- Secure coding practices and code reviews
- Regular vulnerability scanning and penetration testing
- Web Application Firewall (WAF) protection
- SQL injection and XSS attack prevention
- CSRF token protection
- Rate limiting and abuse prevention
- Input validation and sanitization
Monitoring and Logging:
- 24/7 security monitoring and alerting
- Centralized logging and log analysis
- Anomaly detection and automated threat response
- Security Information and Event Management (SIEM) systems
- Audit trails for all access to sensitive data
5.2 Administrative Security Measures
Employee Training and Policies:
- Mandatory security awareness training for all employees
- Privacy and data protection training
- Confidentiality agreements and NDAs
- Clear security policies and procedures
- Incident response protocols
- Background checks for employees with data access
Vendor Management:
- Security assessments of third-party service providers
- Data processing agreements (DPAs) with all vendors
- Regular vendor security reviews and audits
- Contractual security requirements
Compliance and Certifications:
- SOC 2 Type II compliance (in progress/certified)
- GDPR compliance for European users
- CCPA compliance for California residents
- Regular compliance audits and assessments
- Privacy impact assessments (PIAs) for new features
5.3 Physical Security Measures
Data Center Security:
- Tier III or higher data centers with physical access controls
- 24/7 security personnel and surveillance
- Biometric access controls
- Environmental controls (fire suppression, climate control)
- Redundant power and network connectivity
5.4 Incident Response
In the event of a data breach or security incident:
- Detection and Response: We have incident response procedures to quickly detect, contain, and remediate security incidents
- Notification: We will notify affected users and relevant authorities as required by applicable laws (typically within 72 hours of discovery)
- Investigation: We conduct thorough investigations to determine cause, scope, and impact
- Remediation: We implement corrective measures to prevent future incidents
- Transparency: We communicate openly about incidents and our response
5.5 Important Security Disclaimers
No system is 100% secure. While we implement industry-leading security measures, we cannot guarantee absolute security. You acknowledge that:
- Internet transmission is inherently not completely secure
- Unauthorized access or security breaches may occur despite our efforts
- You are responsible for maintaining the security of your account credentials
- You should use strong, unique passwords and enable multi-factor authentication
- You should not share your account credentials with anyone
You are responsible for:
- Keeping your password secure and confidential
- Logging out after each session on shared devices
- Notifying us immediately of any unauthorized account access
- Using updated and secure devices and browsers
6. Your Privacy Rights and Choices
We respect your rights to control your personal information. Depending on your location and applicable privacy laws (including GDPR, CCPA, and other regulations), you may have the following rights:
6.1 Access and Data Portability
Right to Access:
- Request confirmation of whether we process your personal information
- Obtain a copy of your personal information in our possession
- Receive information about how we use and share your data
Right to Data Portability:
- Receive your personal information in a structured, commonly used, machine-readable format (JSON, CSV)
- Transfer your data to another service provider
How to Exercise: Contact us at privacy@zaplane.io or use the data export feature in your account settings.
6.2 Rectification and Correction
Right to Correction:
- Request correction of inaccurate or incomplete personal information
- Update your account information and preferences
How to Exercise: You can update most information directly in your account settings or contact privacy@zaplane.io for assistance.
6.3 Erasure and Deletion
Right to Deletion ("Right to be Forgotten"):
- Request deletion of your personal information under certain circumstances
- Request removal of data that is no longer necessary for the purposes collected
- Withdraw consent for data processing based on consent
Limitations: We may retain certain information when required by law, necessary to resolve disputes, enforce agreements, or for legitimate business purposes (such as fraud prevention).
How to Exercise: See Section 10 below for our comprehensive data deletion process.
6.4 Restriction and Objection
Right to Restrict Processing:
- Request limitation of how we process your personal information in specific situations
- Object to processing based on legitimate interests
Right to Object:
- Object to processing of your personal information for direct marketing purposes
- Object to automated decision-making or profiling
How to Exercise: Contact privacy@zaplane.io with specific details about your objection or restriction request.
6.5 Withdraw Consent
If we process your information based on your consent:
- You have the right to withdraw consent at any time
- Withdrawal does not affect the lawfulness of processing before withdrawal
- We will inform you of consequences of withdrawal, if any
How to Exercise: Contact privacy@zaplane.io or adjust consent settings in your account preferences.
6.6 Marketing Communications Opt-Out
Email Marketing:
- Unsubscribe from promotional emails using the "unsubscribe" link in any marketing email
- Opt-out through your account notification settings
- Contact privacy@zaplane.io to opt-out
Important: You cannot opt-out of transactional emails necessary for the Services (e.g., password resets, billing notifications, critical account alerts).
6.7 Cookie Preferences
You can control cookies through:
- Your browser settings (block, delete, or manage cookies)
- Our cookie preference center (if available)
- Third-party opt-out mechanisms
See Section 12 for detailed cookie information.
6.8 Connected Platform Access
Revoke Platform Connections:
- Disconnect any third-party platform at any time through your account settings
- Revoke OAuth permissions directly in your platform account settings (Google, Meta, LinkedIn, etc.)
- Revoking access will stop data synchronization but will not automatically delete previously collected data (request deletion separately if desired)
6.9 Exercising Your Rights
How to Submit Requests:
- Email: privacy@zaplane.io
- Account Settings: Many rights can be exercised directly through your account dashboard
- Support Portal: Submit a privacy request through our support system
Response Timeline:
- We will respond to verified requests within 30 days (may extend to 60 days for complex requests with notification)
- We will verify your identity before processing requests to protect your information
- No fee for requests unless excessive or repetitive (we may charge reasonable administrative costs)
Verification Process:
To protect your privacy, we may require:
- Confirmation of email address associated with your account
- Additional identifying information to verify your identity
- Verification that you are authorized to make requests on behalf of another user (if applicable)
6.10 Right to Lodge a Complaint
If you believe we have violated your privacy rights, you have the right to:
- Contact us directly at privacy@zaplane.io to resolve concerns
- Lodge a complaint with your local data protection authority or supervisory authority
EU Data Protection Authorities: https://edpb.europa.eu/about-edpb/board/members_en
California Privacy Rights: California Attorney General at https://oag.ca.gov/
7. Data Retention
We retain your information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
7.1 Account Data
Active Accounts:
- Account information is retained while your account is active
- Connected platform data is retained for as long as platforms are connected
- Usage and activity logs are retained to provide ongoing services
Inactive Accounts:
- Accounts inactive for 24 months may be flagged for deletion
- We will notify you before deleting inactive accounts
- You can reactivate your account before deletion occurs
7.2 Retention Periods by Data Type
Personal and Account Information:
- Retained while account is active and for 30 days after account closure
- May be retained longer if required for legal, tax, or regulatory purposes
Campaign and Performance Data:
- Historical data retained while account is active to provide analytics and insights
- Deleted within 30 days of account closure or disconnection of platform
- Aggregated and anonymized data may be retained indefinitely
Financial and Billing Records:
- Retained for 7 years from the date of transaction for tax, accounting, and legal compliance purposes
- Required by law in many jurisdictions
Communications and Support Data:
- Support tickets and communications retained for 3 years for quality assurance and dispute resolution
- May be retained longer if related to ongoing legal matters
Log and Security Data:
- System logs retained for 90 days for security monitoring and troubleshooting
- Security incident logs retained for 7 years for compliance and legal purposes
Backup Data:
- Backups retained for 90 days and then permanently deleted
- Backup data may contain deleted information until backups are fully cycled
Cookies and Tracking Data:
- Session cookies deleted when you close your browser
- Analytics cookies retained according to cookie settings (typically up to 2 years)
7.3 Legal and Regulatory Requirements
We may retain information beyond standard retention periods when:
- Required by applicable law, regulation, or legal obligation
- Necessary for litigation, investigations, or dispute resolution
- Required to comply with tax, accounting, or regulatory requirements
- Necessary to enforce our Terms of Service or protect our rights
7.4 Deletion After Retention Period
When retention periods expire:
- Data is permanently deleted from our active systems
- Backups containing expired data are deleted during normal backup cycles (within 90 days)
- Aggregated and anonymized data may be retained indefinitely for analytics
8. International Data Transfers
Zaplane is based in the United States, and our servers and service providers are primarily located in the United States. If you access our Services from outside the United States, your information will be transferred to, stored, and processed in the United States.
8.1 Legal Basis for International Transfers
For Users in the European Economic Area (EEA), UK, and Switzerland:
We transfer your personal data to the United States based on the following legal mechanisms:
Standard Contractual Clauses (SCCs):
- We use European Commission-approved Standard Contractual Clauses for transfers of personal data to the United States
- SCCs provide appropriate safeguards for your data under GDPR
- Copies of our SCCs are available upon request at privacy@zaplane.io
Adequacy Decisions:
- We comply with any adequacy decisions issued by the European Commission regarding data transfers
- We monitor developments in international data transfer regulations and adapt our practices accordingly
Your Consent:
- By using our Services, you consent to the transfer of your information to the United States and other countries where we operate
- You have the right to withdraw this consent at any time by ceasing use of our Services and requesting data deletion
8.2 Data Protection Standards
Regardless of where your data is processed:
- We apply the same high standards of data protection globally
- We comply with applicable data protection laws in the jurisdictions where we operate
- We implement technical and organizational measures to protect your data
- We conduct regular assessments of our data transfer mechanisms
8.3 Third-Party Service Providers
Our third-party service providers may be located in various countries. We ensure that:
- Service providers implement appropriate data protection measures
- Data Processing Agreements (DPAs) are in place with all processors
- Transfers comply with applicable data transfer mechanisms (SCCs, Privacy Shield alternatives, etc.)
8.3 Data Deletion Process and Timeline
Request Submission
Submit your deletion request via self-service portal, email, or account settings. You will receive an immediate acknowledgment of your request.
Identity Verification (If Necessary)
We may require verification of your identity to protect your account. Verification typically completed within 1-2 business days.
Optional Confirmation Email
You will receive a confirmation email with a secure verification link. Click the link to confirm your deletion request. This step helps prevent unauthorized deletion requests.
30-Day Grace Period
After confirmation, your data is scheduled for deletion 30 days later. During this period your account is suspended, billing is canceled, and you can cancel the deletion request anytime to restore your account.
Permanent Deletion
After 30 days, all your data is permanently and irreversibly deleted from active databases, backup systems, log files, and all connected platform authorizations are revoked.
Deletion Confirmation
You will receive final confirmation once deletion is complete, including verification that all data has been removed.
8.4 Data Export Before Deletion
We strongly recommend exporting your data before requesting deletion. Once deletion is complete, data cannot be recovered.
To Request Data Export:
- Navigate to Settings → Privacy & Data → Export My Data
- Or email privacy@zaplane.io with subject line "Data Export Request"
Your export will include:
- Account profile and settings (JSON format)
- Connected platform information (excluding sensitive OAuth tokens)
- Campaign performance metrics and analytics (CSV format)
- Historical reports and dashboard configurations (JSON format)
- Custom settings and preferences
- Activity logs and usage data
Export Processing Time:
- Small accounts: 1-3 business days
- Large accounts: 5-7 business days
- You will receive a secure download link via email when ready
- Export files are available for 14 days after generation
8.5 Important Deletion Considerations
⚠️ Critical Information:
Permanence:
- • Data deletion is permanent and cannot be undone or reversed
- • Once deleted, your data cannot be recovered by Zaplane or anyone else
- • You will lose access to all historical data, reports, and insights
Billing and Subscriptions:
- • Active subscriptions will be canceled immediately upon deletion request
- • No refunds are provided for remaining subscription time (except as outlined in Terms of Service)
- • Outstanding balances must be paid before deletion can be completed
Workspace and Team Implications:
- • If you are a workspace owner, the entire workspace may be deleted
- • Shared data that other team members depend on may be preserved
- • Team members will be notified before workspace deletion
- • Consider transferring workspace ownership before requesting deletion
Legal and Regulatory Retention:
- • Some data may be retained for legal or regulatory compliance requirements
- • Financial and billing records (retained for 7 years for tax purposes)
- • Data required for ongoing legal proceedings or disputes
- • Fraud prevention and security logs (no personally identifiable information)
- • Aggregated and anonymized analytics data (cannot identify you)
Additional Considerations:
- • Deletion logs maintained for compliance (contain no personal data)
- • Connected platform data must be managed separately on those platforms
- • OAuth permissions are revoked but don't delete data on third-party platforms
- • Backup data may persist in encrypted backups for up to 90 days
8.6 Canceling a Deletion Request
During the 30-day grace period, you can cancel your deletion request:
How to Cancel:
- Click the "Cancel Deletion" link in your confirmation email
- Email privacy@zaplane.io with subject line "Cancel Data Deletion"
- Log into your suspended account (if accessible) and click "Restore Account"
What Happens After Cancellation:
- Your account is immediately reactivated
- All data is restored to its previous state
- You must reactivate any canceled subscriptions separately
- Platform connections may need to be re-authorized
Important: After the 30-day period expires, cancellation is not possible and deletion proceeds automatically.
8.7 Alternative to Full Deletion
If you're unsure about permanent deletion, consider these alternatives:
Account Deactivation:
- Temporarily suspend your account without deleting data
- Pause subscriptions without losing historical data
- Reactivate anytime in the future
Disconnect Platforms:
- Remove specific platform connections without deleting account
- Stop data synchronization while maintaining account access
Downgrade Subscription:
- Switch to a free or lower-tier plan instead of deleting
- Retain access to historical data with limited features
Contact Us: Email privacy@zaplane.io to discuss alternatives to deletion.
10. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to provide, improve, protect, and promote our Services. This section explains what these technologies are, why we use them, and your choices.
10.1 What Are Cookies
Cookies are small text files stored on your device (computer, tablet, phone) when you visit websites. Cookies allow websites to remember your actions and preferences over time.
Types of Cookies We Use:
Session Cookies:
- Temporary cookies that expire when you close your browser
- Essential for navigation and using platform features
- Cannot be disabled without affecting functionality
Persistent Cookies:
- Remain on your device for a set period or until manually deleted
- Remember your preferences and settings across sessions
- Improve user experience by maintaining login status and preferences
First-Party Cookies:
- Set directly by Zaplane
- Used for essential functions and analytics
Third-Party Cookies:
- Set by our service providers and partners
- Used for analytics, advertising, and social media features
- Subject to third-party privacy policies
10.2 Why We Use Cookies
Strictly Necessary Cookies (Cannot be Disabled):
- Authentication: Keep you logged in securely
- Security: Prevent fraud and protect against attacks
- Session Management: Maintain your session state across pages
- Load Balancing: Distribute traffic across servers for performance
Functional Cookies:
- Preferences: Remember your settings, language, time zone
- Customization: Maintain dashboard layouts and custom views
- Feature Enablement: Support platform features and functionality
Analytics and Performance Cookies:
- Usage Analytics: Understand how users interact with our platform
- Performance Monitoring: Identify errors, slow pages, and areas for improvement
- A/B Testing: Test new features and improvements
- Heatmaps: Understand user behavior and navigation patterns
Advertising and Marketing Cookies (Requires Consent):
- Remarketing: Show relevant ads on other websites
- Campaign Measurement: Track effectiveness of marketing campaigns
- Social Media: Enable social sharing and integration
- Conversion Tracking: Measure ROI of advertising efforts
10.3 Specific Cookies We Use
Essential Cookies:
session_id- Maintains your login session (expires on browser close)csrf_token- Protects against cross-site request forgery attacksauth_token- Secure authentication token (persistent)
Analytics Cookies:
- Analytics tracking cookies for traffic and usage analysis (expires: 2 years)
- User behavior tracking cookies (expires: 1 year)
Preference Cookies:
user_preferences- Stores your settings and preferences (expires: 1 year)timezone- Remembers your timezone setting (expires: 1 year)dashboard_layout- Saves your dashboard configuration (expires: 1 year)
Marketing Cookies (if enabled):
- Conversion tracking cookies
- Advertising platform pixels
- Social media tracking pixels
10.4 Other Tracking Technologies
Local Storage:
- HTML5 local storage for application state and preferences
- Survives browser sessions but can be cleared
- Used for offline functionality and performance optimization
Pixels and Web Beacons:
- Small transparent images used to track email opens and website visits
- Used in marketing emails and for analytics
- Can be blocked by disabling images in emails
Log Files:
- Automatically collected server logs including IP address, browser type, pages visited
- Used for security, troubleshooting, and analytics
10.5 Managing Cookies and Your Choices
Browser Controls:
Most browsers allow you to:
- Block all cookies
- Block third-party cookies only
- Delete cookies after each session
- Manage cookies on a site-by-site basis
How to Manage Cookies:
- Google Chrome: Settings → Privacy and Security → Cookies and other site data
- Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Preferences → Privacy → Cookies and website data
- Microsoft Edge: Settings → Privacy, search, and services → Cookies and site data
Cookie Preference Center (if available):
- Access our cookie preference center from our website footer
- Customize your cookie preferences by category
- Changes take effect immediately
Third-Party Opt-Outs:
Analytics Opt-Out:
Many analytics providers offer browser add-ons to opt-out of tracking
Network Advertising Initiative:
Opt-out of interest-based advertising at https://optout.networkadvertising.org/
Digital Advertising Alliance:
Manage ad preferences at https://optout.aboutads.info/
10.6 Impact of Disabling Cookies
If you disable cookies:
- Some features may not work properly
- You may need to re-enter login credentials on each visit
- Your preferences and settings may not be saved
- You may see less relevant content and advertisements
Essential cookies cannot be disabled without preventing access to our Services.
10.7 Do Not Track Signals
Some browsers transmit "Do Not Track" (DNT) signals. There is currently no industry standard for responding to DNT signals. Our platform does not respond to DNT signals at this time. We will update this policy if we adopt a DNT protocol in the future.
11. Children's Privacy
Our Services are not intended for, and we do not knowingly collect personal information from, children under the age of 18.
Our Policy:
- We do not knowingly solicit data from or market to children under 18
- Our Services are designed for business use by adults
- Users must be at least 18 years old to create an account
- We do not knowingly process personal information of minors
If We Learn of Children's Data:
- If we become aware that we have collected personal information from a child under 18 without parental consent, we will take steps to delete that information as quickly as possible
- If you believe a child has provided us with personal information, please contact us immediately at privacy@zaplane.io
Parental Rights:
Parents or guardians who believe their child has provided information to us may contact us to request access to and deletion of that information.
12. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).
12.1 Your California Privacy Rights
Right to Know:
- What personal information we collect about you
- Categories of sources from which we collect information
- Business purposes for collecting information
- Categories of third parties with whom we share information
- Specific pieces of personal information we have collected about you
Right to Delete:
- Request deletion of personal information we have collected from you
- Subject to certain exceptions (legal requirements, fraud prevention, etc.)
Right to Opt-Out of Sale or Sharing:
- We do not sell your personal information
- We do not share personal information for cross-context behavioral advertising
- No opt-out action is required
Right to Correct:
- Request correction of inaccurate personal information
Right to Limit Use of Sensitive Personal Information:
- We do not use or disclose sensitive personal information for purposes other than providing our Services
Right to Non-Discrimination:
- We will not discriminate against you for exercising your privacy rights
- Same quality of service regardless of privacy choices
12.2 Categories of Personal Information We Collect
Under CCPA, we collect the following categories:
| Category | Examples | Collected? |
|---|---|---|
| Identifiers | Name, email, IP address | Yes |
| Personal Information (Cal. Civ. Code § 1798.80) | Name, address, payment information | Yes |
| Protected Classifications | Age, gender (if provided) | Limited |
| Commercial Information | Purchase history, subscription details | Yes |
| Internet/Network Activity | Browsing history, interactions with our Services | Yes |
| Geolocation Data | Approximate location based on IP address | Yes |
| Sensory Information | None | No |
| Professional/Employment Information | Job title, company (if provided) | Yes |
| Education Information | None | No |
| Inferences | Preferences, behaviors, predictions | Yes |
12.3 How to Exercise California Rights
Submit Requests:
Email: privacy@zaplane.io with subject line "California Privacy Rights Request"
Verification:
- We will verify your identity before processing requests
- May require you to confirm your email address and provide account details
- May require additional information for sensitive requests
Authorized Agents:
- You may designate an authorized agent to make requests on your behalf
- We require written authorization from you to the agent
- We may require the agent to verify their identity
Response Timeline:
- We respond to verified requests within 45 days
- May extend by an additional 45 days if necessary (with notification)
12.4 Shine the Light Law
California Civil Code Section 1798.83 permits California residents to request information about disclosure of personal information to third parties for direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.
13. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) and equivalent laws.
13.1 Legal Basis for Processing
We process your personal data based on the following legal grounds:
Contractual Necessity:
- Processing necessary to perform our contract with you (providing Services)
- Account creation, billing, and service delivery
Legitimate Interests:
- Improving and developing our Services
- Security and fraud prevention
- Marketing and business development
- Analytics and research
Consent:
- Marketing communications (you can withdraw consent anytime)
- Non-essential cookies and tracking
- Specific data processing you explicitly consent to
Legal Obligations:
- Compliance with laws and regulations
- Response to legal processes
- Tax and accounting requirements
13.2 Your GDPR Rights
All rights outlined in Section 6 apply, including:
- Right of access
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object
- Rights related to automated decision-making and profiling
13.3 Data Protection Officer
For GDPR-related inquiries, you may contact our Data Protection Officer:
Email: dpo@zaplane.io
Mailing Address:
Data Protection Officer
Zaplane Insights
5337 Melbourne Lane
Flowery Branch, Georgia 30542
United States
13.4 Supervisory Authority
You have the right to lodge a complaint with your local data protection supervisory authority. A list of EU data protection authorities is available at: https://edpb.europa.eu/about-edpb/board/members_en
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
14.1 Notification of Changes
Material Changes:
- We will notify you via email to your registered email address
- We will provide prominent notice on our website or within the Services
- We will update the "Last Updated" date at the top of this policy
- We will provide at least 30 days' notice before material changes take effect
Non-Material Changes:
- Minor updates may be made without notification
- "Last Updated" date will always reflect the most recent update
- We encourage you to review this policy periodically
14.2 Your Choices After Changes
If you do not agree with updated Privacy Policy:
- You may terminate your account before changes take effect
- Continued use of Services after effective date constitutes acceptance
- We will treat your information according to the policy in effect at the time of collection unless you consent otherwise
15. Contact Us
We are committed to resolving any privacy concerns or questions you may have. Please don't hesitate to reach out.
15.1 Privacy Inquiries
Privacy Rights Requests:
Email: privacy@zaplane.io (subject line: "Privacy Rights Request")
Response Time: Within 30 days (may extend to 60 days for complex requests)
15.2 Mailing Address
Zaplane Insights
Attn: Privacy Department
5337 Melbourne Lane
Flowery Branch, Georgia 30542
United States
15.3 Support
General Support:
Email: support@zaplane.io
In-App Chat:
Available 24/7 for technical support
16. Acknowledgment and Consent
By using our Services, you acknowledge that:
- You have read and understood this Privacy Policy in its entirety
- You understand how we collect, use, and share your information
- You consent to the collection, use, and disclosure of your information as described
- You understand your privacy rights and how to exercise them
- You consent to the transfer of your information to the United States and other countries where we operate
- You understand our use of cookies and tracking technologies
- You have reviewed our data security measures and retention policies
Important Notice:
If you do not agree with this Privacy Policy, you must not use our Services.
Last Updated: October 9, 2025
Privacy Policy Version: 2.0
Quick Reference Guide
Key Contacts:
- • General Privacy: privacy@zaplane.io
- • Data Protection Officer: dpo@zaplane.io
- • Security: security@zaplane.io
- • Support: support@zaplane.io
Your Rights:
- • Access your data: Account Settings → Export Data
- • Delete your data: Account Settings → Request Deletion
- • Update preferences: Account Settings → Privacy
- • Manage cookies: Browser settings or preference center
- • Opt-out of marketing: Unsubscribe link in emails
Data Deletion
30-day grace period, permanent after 30 days
Response Time
30 days for privacy requests (may extend to 60 days)
Retention
Active accounts retained indefinitely; 30 days after account closure