Zexora Technologies Inc. logo ZEXORATECHNOLOGIES INC.
Platform Products Pricing Security Terms Privacy
Sign in Enter Zexora →
Legal · Privacy

Privacy Policy

Effective August 15, 2026 Last updated August 15, 2026 Zexora Technologies, Inc.
In short: we collect the information needed to run the Zexora platform for your business — account details, billing information handled by Stripe, usage logs, and the business data you put into your workspace. We do not sell personal information, and we do not use your data to train foundation AI models. Data you place in your workspace is processed on your instructions, is isolated to your company, and is shared only with the service providers listed in Section 7.

On this page

1. Scope and our role 2. Information we collect 3. Data inside your workspace 4. How we use information 5. AI processing and model training 6. Cookies and tracking 7. How we share information 8. Calls, recordings and transcripts 9. Mailbox and document import 10. How long we keep information 11. Security and data isolation 12. Your privacy rights 13. If you are an End Customer 14. International transfers 15. Children's privacy 16. Third-party sites 17. Changes to this policy 18. How to contact us

1. Scope and our role

This Privacy Policy explains how Zexora Technologies, Inc. ("Zexora," "we," "us") handles personal information in connection with the Zexora platform, our websites, and related services (the "Services"). It applies to our public website and to the authenticated platform.

1.1 Two different roles

Our responsibilities depend on whose data is involved:

  • We are the controller (a "business" under California law) for information about our own customers and website visitors — the accounts you register, the people who administer them, billing records, support conversations, and website analytics. This policy governs that information.
  • We are a processor (a "service provider") for the business data you load into your workspace, including personal information about your own customers, leads, callers, employees, and contacts. We handle that data on your instructions to provide the Services. The customer whose workspace holds the data is the controller of it, and their own privacy notice — not this one — governs how they collect and use it.

If you are an individual whose information is held in a Zexora customer's workspace, see Section 13.

2. Information we collect

2.1 Information you give us

  • Account and profile information — name, business email address, phone number, company name, industry, job role, and the credentials used to sign in.
  • Authentication data — hashed passwords (we never store passwords in readable form) and passkey public-key credentials. Passkeys are stored as public keys and identifiers only; the private key never leaves your device.
  • Billing information — plan selection, billing contact, subscription and invoice history, and the last four digits and card brand of a payment method. Complete payment card numbers are collected and stored by Stripe, our payment processor, not by Zexora.
  • Communications — messages you send to support or sales, including attachments, and your responses to surveys or forms.
  • Connected-account credentials — access tokens and identifiers for third-party accounts you choose to connect, such as social, advertising, telephony, or email accounts. These are stored scoped to your workspace.

2.2 Information we collect automatically

  • Usage data — pages and features accessed, actions taken, timestamps, session identifiers, and metered usage such as AI receptionist minutes or message volume.
  • Device and connection data — IP address, browser type and version, operating system, language, and referring page.
  • Log and diagnostic data — application logs, error traces, performance metrics, and security events such as failed sign-in attempts and rate-limit triggers.
  • Cookie data — see Section 6.

2.3 Information from other sources

  • Payment processor — subscription status, payment success or failure, and chargeback notices from Stripe.
  • Connected platforms — account identifiers, page or channel names, publishing results, and performance metrics returned by services you connect.
  • Security providers — bot and abuse signals from providers such as Cloudflare Turnstile.
  • Public and licensed business sources — where a feature identifies business opportunities or verifies business details, it may draw on publicly available or licensed business information. This concerns businesses rather than consumer profiles.

3. Data inside your workspace

Depending on which modules you use, your workspace may hold: customer and lead records; quotes, jobs, schedules, invoices, and payment status; documents, notes, and knowledge-base content; imported email and attachments; call recordings and transcripts; marketing and social content; advertising configuration and performance; vehicle, inventory, or procurement records; and analytics derived from the above.

We process this data to operate the Services for you and for the other purposes described in Section 4. We do not use it for our own marketing, and we do not sell it. As the controller of this data, you decide what is collected, how long it is kept within the tools available, and who in your organization can see it.

4. How we use information

PurposeWhat this involvesLegal basis (UK/EU)
Provide the Services Creating and running your workspace, authenticating users, executing the features and automations you enable, and generating AI output you request. Performance of a contract
Billing and administration Processing subscriptions and metered charges, sending invoices and receipts, managing trials, renewals, and cancellations. Performance of a contract; legal obligation
Support Responding to your requests, investigating issues, and — with your permission or where necessary to resolve a reported fault — accessing your workspace configuration. Performance of a contract; legitimate interests
Security and abuse prevention Detecting fraud, spam, credential abuse, and unauthorized access; enforcing rate limits; maintaining audit and security logs. Legitimate interests; legal obligation
Reliability and improvement Monitoring performance, diagnosing errors, and analyzing aggregated or de-identified usage to improve the Services. Legitimate interests
Service communications Sending administrative messages about outages, security, billing, and material changes to terms. You cannot opt out of these while you hold an account. Performance of a contract
Marketing to our own prospects Sending product news and offers to business contacts who requested them or who are existing customers. Every message includes an unsubscribe link. Consent; legitimate interests
Legal compliance Meeting tax, accounting, and regulatory obligations, and responding to lawful requests. Legal obligation

We do not engage in automated decision-making that produces legal or similarly significant effects about individuals without human involvement. Where our AI features score, rank, or classify records inside a customer's workspace, the customer controls whether and how those results are acted on.

5. AI processing and model training

We do not use your data to train foundation or publicly available AI models, and we do not permit our AI providers to do so.

To generate AI output — drafting content, summarizing documents, answering calls, analyzing records, producing diagrams or media — the relevant portion of your data is transmitted to a third-party AI provider, processed to produce a result, and the result is returned to your workspace. We use providers under commercial API terms that prohibit training on submitted data.

We may use aggregated or de-identified statistics about AI usage — such as request volumes, error rates, and latency — to operate and improve the Services. This information does not identify you, your users, or your customers.

AI output can be inaccurate or incomplete. It should be reviewed by a person before it is relied on or sent to anyone, as described in our Terms of Service.

6. Cookies and tracking

We use a small number of cookie categories:

  • Strictly necessary — session cookies that keep you signed in, maintain your workspace context, and protect against cross-site request forgery. The Services cannot function without these.
  • Security — cookies and tokens set by bot-protection services such as Cloudflare Turnstile to distinguish humans from automated traffic.
  • Preferences — cookies that remember display choices you make.
  • Analytics — where enabled on our public website, cookies and tags that help us understand how visitors find and use the site. These are used in aggregate.

You can block or delete cookies through your browser, but blocking strictly necessary cookies will prevent you from signing in. We do not use cookies to build cross-site advertising profiles of individuals, and we do not honor a "Do Not Track" browser signal because there is no common standard for it; we do honor Global Privacy Control signals where required by law.

7. How we share information

We do not sell personal information, and we do not share it for cross-context behavioral advertising as those terms are defined under California and other U.S. state privacy laws. We have not done so in the preceding twelve months.

7.1 Service providers

We share information with vendors who process it on our behalf, under contracts that limit them to our instructions and require appropriate safeguards. The principal categories, and representative providers, are:

CategoryRepresentative providersWhat they process
Hosting and infrastructureRender, Amazon Web ServicesApplication hosting, databases, file and media storage
PaymentsStripePayment card data, subscription and invoice records
AI and machine learningOpenAI and other model providersContent submitted for AI processing, for inference only
Voice and receptionistVapi, telephony and speech providersCall audio, transcripts, caller phone numbers
Telephony and messagingTwilioPhone numbers, message content, delivery status
Email deliveryResend and similar providersRecipient addresses, message content, delivery events
Social publishingMeta (Facebook, Instagram), TikTok, YouTubeContent you publish and its performance metrics
Advertising platformsGoogle Ads and similar networksCampaign configuration and performance data you authorize
Security and bot protectionCloudflareIP address, request metadata, challenge results

Which providers apply to you depends on the features and integrations you use. Data sent to a platform you connect is thereafter also governed by that platform's own privacy policy.

7.2 At your direction

We share information when you instruct us to — for example when you publish content, send a message or invoice, connect an integration, invite a user, or export records.

7.3 Legal and safety

We may disclose information where we believe in good faith that it is necessary to comply with a law, regulation, subpoena, court order, or other lawful request; to enforce our agreements; to detect or prevent fraud or security issues; or to protect the rights, property, or safety of Zexora, our customers, or the public. Where we are legally permitted, we will notify the affected customer before disclosing data held in their workspace.

7.4 Business transfers

If Zexora is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction. We will provide notice before personal information becomes subject to a materially different privacy policy.

7.5 Affiliates

We may share information with entities under common control with Zexora, for the purposes described in this policy and subject to the same protections.

8. Calls, recordings and transcripts

Where a customer enables voice or AI receptionist features, calls placed to or from their workspace may be recorded, transcribed, and analyzed to produce summaries, lead records, and follow-up actions. Recordings, transcripts, caller phone numbers, and derived records are stored in that customer's workspace.

The Zexora customer operating the phone line is responsible for providing any legally required recording notice and for obtaining consent. Florida and several other states require the consent of all parties to a recorded call. If you are a caller and want to know how a business handles your recording, or want it deleted, contact that business directly; we will assist them in responding.

9. Mailbox and document import

The Services include features that let a customer import documents and mailbox archives — for example .pst, .ost, .eml, and .msg files — into their workspace, where the content may be indexed and made searchable by AI features.

These imports happen only when a customer explicitly uploads the files. A mailbox archive can contain a large volume of personal information about third parties, including people who never interacted with the customer's business. The importing customer is responsible for confirming they have a lawful basis to import and process that content, for excluding personal or unrelated mailboxes, and for deleting imported content that should not be retained.

10. How long we keep information

  • Workspace data — retained while your subscription is active. After termination, you have thirty (30) days to request an export, after which we may delete it from active systems.
  • Account and profile records — retained for the life of the account and for a reasonable period afterward to handle disputes and reactivation requests.
  • Billing and tax records — retained as long as required by tax and accounting law, typically at least seven years.
  • Security and audit logs — typically retained up to twenty-four months.
  • Support communications — retained for as long as needed to service the relationship and resolve disputes.
  • Backups — deleted data may persist in encrypted backups for a limited period until those backups expire on their normal cycle.

We may retain information longer where required by law, or where necessary to establish, exercise, or defend legal claims.

11. Security and data isolation

We use administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit, hashed password storage, support for passkey authentication, role-based access controls, rate limiting, bot protection, and audit logging.

Each customer workspace is provisioned with its own company identifier, and the Services are designed so that workspace data and connected-account credentials are scoped to the workspace that owns them. A credential belonging to one company is not used to act on behalf of another.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach affecting personal information occurs, we will notify affected customers and regulators as required by applicable law and without undue delay.

12. Your privacy rights

Depending on where you live, you may have some or all of the following rights over personal information we hold about you as a controller: to access it and receive a copy; to correct inaccuracies; to delete it; to obtain it in a portable format; to object to or restrict certain processing; to opt out of sale, sharing, or targeted advertising (note that we do none of these); and to withdraw consent where processing is based on it.

12.1 How to exercise them

Email info@zexoratech.com with your request and the email address associated with your account. We will verify your identity before acting, usually by confirming control of that address, and will respond within the period required by applicable law — generally 45 days under U.S. state laws and one month under UK/EU law, each extendable where permitted. Exercising a right will not result in discriminatory treatment.

12.2 Requests about data in a customer's workspace

If your information is held in a Zexora customer's workspace, that customer controls it. Send your request to them. If you send it to us, we will refer you to the relevant customer where we can identify them, and we will assist them in responding as their processor.

12.3 European Economic Area and United Kingdom

Where the GDPR or UK GDPR applies, our legal bases are set out in the table in Section 4. You have the right to lodge a complaint with your local supervisory authority, or with the UK Information Commissioner's Office. Where we rely on legitimate interests, you may object, and we will stop unless we have compelling grounds to continue.

12.4 California

Under the CCPA as amended by the CPRA, we have collected the following categories of personal information in the preceding twelve months: identifiers; commercial information; internet or other electronic network activity information; audio or electronic information (where voice features are used); professional or employment-related information; and inferences drawn from the above. The sources, purposes, and disclosure recipients are described in Sections 2, 4, and 7. We do not sell or share personal information, and we do not knowingly collect or sell the personal information of consumers under 16. You may exercise your rights of access, deletion, correction, and portability, and to limit the use of sensitive personal information, as described in Section 12.1. An authorized agent may submit a request with proof of authorization.

12.5 Other U.S. states

Residents of Florida, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have comparable rights, including the right to appeal a refusal of a request. To appeal, reply to our decision with the word "appeal" and your reasons; if we deny the appeal, you may contact your state Attorney General.

13. If you are an End Customer

If you are a customer, lead, caller, or contact of a business that uses Zexora, that business — not Zexora — decides what information about you is collected and how it is used. We process it on their behalf under contract.

Direct questions, access requests, deletion requests, and marketing opt-outs to the business you dealt with. If you do not know who they are or cannot reach them, contact info@zexoratech.com and we will make reasonable efforts to route your request to the right customer.

14. International transfers

Zexora is based in the United States and our infrastructure and service providers are located primarily in the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States, which may have data protection laws different from those in your country.

Where we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary measures where needed. You may request a copy of the relevant safeguards by contacting us.

15. Children's privacy

The Services are for business use and are not directed to children. We do not knowingly collect personal information from anyone under 18 as an account holder, or from children under 13 in any capacity. If we learn we have collected such information, we will delete it. If you believe a child has provided us information, contact info@zexoratech.com.

16. Third-party sites

The Services link to and integrate with websites and platforms we do not control. This policy does not apply to them. Review their privacy policies before providing information to them.

17. Changes to this policy

We may update this Privacy Policy. When we do, we will revise the "Last updated" date at the top of this page. For material changes, we will provide notice by email to your account address or by in-product notice before the change takes effect. Your continued use of the Services after that date means you accept the updated policy.

18. How to contact us

For privacy questions, requests, or complaints:

Zexora Technologies, Inc.
Email: info@zexoratech.com
Web: www.zexoratech.com

We will acknowledge privacy requests and respond within the timeframes required by applicable law.

See also our Terms of Service, which governs your use of the Zexora platform.
ZEXORATECHNOLOGIES INC.

The unified intelligence and operations platform for businesses ready to work differently.

Platform

CRMOperationsKnowledgeDiagram AI

Company

PricingIndustriesStatusContact

Legal

Terms of ServicePrivacy Policy

Resources

DocumentationDevelopersAPISign in
© 2026 Zexora Technologies Inc. All rights reserved. Terms of Service · Privacy Policy
🌐