Legal

Privacy Policy

We take privacy seriously. This policy explains exactly what data we collect, why we collect it, how we protect it, and what rights you have over it.

Last updated: 2026-06-30Effective: [EFFECTIVE DATE — UPON LLC FORMATION]GDPR · CCPA/CPRA · UK GDPR

Data controller

Zerqano LLC

Standards

GDPR · CCPA · UK GDPR

Version

2.0.0

Review cycle

Annual minimum

1. Introduction & scope

Zerqano LLC (“Zerqano,” “we,” “us,” or “our”) operates the platform available at zerqano.com and associated subdomains, APIs, mobile applications, and services (collectively, the Service”).

This Privacy Policy applies to all visitors, registered users, account administrators, and the organisations (“Customers”) that purchase or trial the Service. It describes our practices regarding the collection, use, storage, disclosure, and protection of personal data, and explains the rights available to data subjects under applicable law.

By accessing or using the Service you acknowledge that you have read and understood this Policy. If you are using the Service on behalf of an organisation, you represent that you have the authority to bind that organisation to this Policy.

Where Zerqano acts as a data processor on behalf of a Customer (e.g., processing files and documents uploaded by the Customer), the Customer's own privacy policy and our Data Processing Agreement govern that processing, and this Policy applies only to the extent Zerqano independently determines the purposes and means of processing.

2. Information we collect

We collect information in the following categories, limited to what is necessary for the purposes described in Section 4.

2.1 Account & identity data

  • Full name, work email address, and profile information you provide during registration or account settings updates.
  • Organisation name, role / job title, team size, and billing address.
  • Authentication credentials stored as one-way cryptographic hashes. OAuth tokens from Google, Microsoft, or other SSO providers.
  • Phone number and two-factor authentication (2FA) device metadata if you opt into MFA.

2.2 Customer-uploaded content ("Customer Data")

  • Files, documents, receipts, invoices, purchase orders, and spreadsheets you upload or connect to the platform.
  • Product catalogs, inventory records, sales orders, and supplier data ingested via CSV, API, or direct integration.
  • Scanned receipts, photos, and OCR-extracted text processed through our document intelligence pipeline.
  • Any personal data of third parties (e.g., customer names, supplier contacts) contained within Customer Data. The Customer is the data controller for such data.

2.3 Usage & telemetry data

  • Pages and features accessed, click-paths, time-on-page, and session duration.
  • Feature usage frequency (e.g., which AI modules are run, how often forecasts are generated).
  • API request logs (endpoint, timestamp, HTTP status — not request body content).
  • Error reports, crash logs, and performance metrics collected via Sentry and our internal logging infrastructure.

2.4 Device & browser data

  • IP address (truncated to /24 after 90 days for analytics).
  • Browser type and version, operating system, device type and screen resolution.
  • Referring URL and UTM campaign parameters (anonymised after 30 days).
  • Cookie and local-storage identifiers (see Section 10).

2.5 Communications data

  • Emails, support tickets, and chat messages you send to us, including attachments.
  • Survey responses, feedback form submissions, and NPS responses.
  • Demo request form submissions and scheduling information.

4. How we use your data

We use personal data to:

  • Create and manage your account, authenticate your identity, and deliver the features you have subscribed to.
  • Process Customer Data through our AI pipeline (ingestion, forecasting, inventory, pricing, procurement, cross-sell) and return results to you.
  • Generate reports, insights, and recommendations within the platform.
  • Send transactional emails: account confirmations, password resets, pipeline-complete notifications, and invoice receipts.
  • Provide customer support and respond to enquiries.
  • Detect and prevent fraud, abuse, security breaches, and unauthorised access.
  • Monitor and improve performance and reliability (debugging, load-testing, capacity planning).
  • Conduct aggregate, anonymised product analytics to understand feature usage and prioritise roadmap decisions.
  • Send marketing communications and product updates if you have opted in (or as an existing customer under soft opt-in).
  • Comply with legal obligations, including tax record-keeping and responding to lawful regulatory requests.

We do not sell, rent, or broker personal data to third parties for their own marketing purposes.

5. Sharing & subprocessors

5.1 Subprocessors

We engage the following subprocessors to operate the Service. All are bound by data processing agreements imposing obligations no less protective than this Policy.

SubprocessorPurposeLocation
Supabase / PostgreSQLPrimary database, authentication, row-level securityUSA (AWS)
QdrantVector embeddings for AI search and cross-sellEU / self-hosted
OpenAILarge language models for document intelligence and AI chatUSA
GroqFast LLM inference (optional fallback)USA
VercelFrontend hosting and edge functionsGlobal CDN
Hostinger VPSBackend API hostingEU
SentryError monitoring and crash reportingUSA
ResendTransactional email deliveryUSA
StripePayment processing (no card data stored by us)USA
MLflowML experiment tracking (self-hosted)EU VPS

We will update this table when adding new subprocessors and will provide at least 30 days' notice to Customers via email.

5.2 Business transfers

In the event of a merger, acquisition, or asset sale, personal data may transfer to the acquiring entity. We will notify affected users before their data becomes subject to a materially different privacy policy.

5.3 Legal disclosure

We may disclose personal data if required by law or court order, or to protect the rights, property, or safety of Zerqano, our users, or the public. We will notify you unless legally prohibited from doing so.

5.4 Aggregated & de-identified data

We may publish aggregated, anonymised insights (industry benchmark reports, product usage statistics) that cannot reasonably identify any individual or organisation.

6. International data transfers

Some of our subprocessors are located in the United States. Transfers from the EEA, UK, or Switzerland are governed by one or more of the following:

  • EU Standard Contractual Clauses (SCCs) — 2021 Module 2 (controller-to-processor) incorporated into DPAs with all relevant subprocessors.
  • UK International Data Transfer Agreement (IDTA) — for transfers from the UK to non-adequate third countries.
  • Adequacy decisions — where applicable between EEA/UK countries.

You may request a copy of the safeguards we have put in place by contacting us at the address in Section 15.

7. Data retention

Data categoryRetention periodBasis
Account profile data90 days after account deletionContract / support window
Customer Data (uploaded files, extracted data)90 days after subscription endContract performance
AI pipeline outputs (forecasts, recommendations)24 months from generationLegitimate interest
Billing & invoice records7 yearsLegal obligation (tax law)
Security / access logs12 months rollingLegitimate interest (security)
Error / crash logs (Sentry)90 daysLegitimate interest (debugging)
Marketing analytics24 monthsConsent / legitimate interest
Support ticket conversations3 yearsLegitimate interest (quality)

When retention periods expire, data is securely deleted or anonymised per our deletion procedures. You may request earlier deletion under Section 8.

8. Your rights

8.1 Rights under GDPR (EEA & UK)

Right of access (Art. 15)

Receive a copy of the personal data we hold about you.

Right to rectification (Art. 16)

Correct inaccurate or incomplete data.

Right to erasure (Art. 17)

Request deletion of your data, subject to legal obligations.

Right to restriction (Art. 18)

Restrict processing in certain circumstances.

Right to portability (Art. 20)

Receive your data in a machine-readable format.

Right to object (Art. 21)

Object to processing based on legitimate interests, including profiling.

Right to withdraw consent

Withdraw consent for marketing or optional cookies at any time.

Right to lodge a complaint

File a complaint with your national supervisory authority (e.g., ICO in the UK).

8.2 Rights under CCPA / CPRA (California)

  • Right to know — what categories of personal information we collect, the purposes, and with whom we share it.
  • Right to delete — request deletion of personal information, subject to exceptions.
  • Right to opt-out of sale/sharing — we do not sell or share personal information for cross-context behavioural advertising.
  • Right to correct — correct inaccurate personal information.
  • Right to limit use of sensitive personal information — collected only for the limited purposes described above.
  • Right of non-discrimination — exercising your rights will not result in differential service or pricing.

To exercise California rights, submit a verifiable consumer request to the address in Section 15. We will respond within 45 days (extendable by a further 45 days with notice).

How to exercise your rights

Email privacy@zerqano.com with subject “Data Subject Request.” We verify your identity before processing and respond within 30 days (or as required by applicable law).

9. Children's privacy

The Service is directed to businesses and professionals. It is not intended for children under the age of 16 (or 13 in the United States under COPPA). We do not knowingly collect personal data from children under 16.

If you believe a child has provided personal data to us, please contact privacy@zerqano.com and we will promptly delete that information.

10. Cookies & tracking

We use cookies and similar technologies (local storage, session storage) to operate the Service and understand how it is used.

Cookie / keyTypePurposeDuration
sb-auth-tokenEssentialSupabase session authenticationSession
sb-refresh-tokenEssentialSupabase refresh token for persistent login7 days
zerqano_themeFunctionalSaves your theme preference (light/dark/newspaper)1 year (localStorage)
zerqano_fontFunctionalSaves your font mode preference (techno/editorial)1 year (localStorage)
zerqano_cookie_consentFunctionalRecords your cookie consent choice1 year
_ga, _gidAnalyticsGoogle Analytics — page views and session stats (anonymised IP)2 years / 24 h
sentry-sessionTechnicalSentry error tracking session identifierSession

Managing cookies

You can manage or disable non-essential cookies via our cookie preferences panel. Disabling essential cookies will prevent you from signing in. You can also configure your browser to refuse cookies — consult your browser's help pages for instructions.

11. AI & automated decision-making

  • Customer Data processing. When you upload files or data, our pipeline processes that data to generate recommendations. We act as a data processor for Customer Data.
  • LLM providers. Some features send portions of Customer Data to OpenAI or Groq for language model inference. Data is processed under our API agreements and is not used to train their models (per current service agreements).
  • No fully automated decisions with legal effects. Our AI outputs (forecasts, price recommendations, reorder suggestions) are advisory. No decisions with legal or similarly significant effects on individuals are made solely by automated means.
  • Model training. We may use anonymised, aggregated Customer Data to improve our internal ML models. We will never use identifiable personal data for model training without explicit consent.

12. Security

We implement technical and organisational security measures proportionate to the risks of processing:

  • TLS 1.2+ encryption in transit for all data exchanged with the Service.
  • AES-256 encryption at rest for database volumes and file storage.
  • Row-Level Security (RLS) policies on all database tables ensuring strict multi-tenant isolation.
  • Bcrypt / Argon2 one-way password hashing — we cannot recover your password.
  • Continuous security monitoring via Sentry and server-level intrusion detection.
  • Automated dependency vulnerability scanning in our CI/CD pipeline.
  • Strict Content-Security-Policy headers and OWASP-guided secure coding practices.
  • Regular access reviews ensuring principle of least privilege.

For full technical details, see our Security & Data Protection page.

In the event of a personal data breach posing risk to your rights, we will notify affected users and relevant supervisory authorities within 72 hours (as required by GDPR).

14. Policy changes

We may update this Privacy Policy from time to time. For material changes, we will:

  • Update the “Last updated” date at the top of this page.
  • Send a notification email to all registered users at least 14 days before changes take effect.
  • Display a prominent notice in the platform dashboard.

Continued use of the Service after the effective date constitutes acceptance. If you disagree, you may close your account before changes take effect.

15. Contact & DPO

Email: privacy@zerqano.com

Subject line: “Data Subject Request” or “Privacy Enquiry”

Company: Zerqano LLC

Registered address: 2152 North Tripp Avenue, Chicago, IL 60639

Response time: Within 5 business days, completed within 30 days (or as required by law).

If located in the EEA or UK and not satisfied with our response, you have the right to lodge a complaint with your local data protection authority:

  • UK: Information Commissioner's Office (ICO) — ico.org.uk
  • EU: Your national supervisory authority — edpb.europa.eu
  • California: California Privacy Protection Agency — cppa.ca.gov

Document information

Document: Zerqano Privacy Policy

Version: 2.0.0

Effective: [EFFECTIVE DATE — UPON LLC FORMATION]

Data controller: Zerqano LLC

Registered address: 2152 North Tripp Avenue, Chicago, IL 60639

Language: English (governing)

Privacy contacts

Privacy & DPO: privacy@zerqano.com

General legal: legal@zerqano.com

Security reports: security@zerqano.com

This document was last reviewed on 2026-06-30. Zerqano reviews its Privacy Policy at least annually and upon any material change to data processing activities, applicable law, or the Service. If you are located in the EEA or UK and have an unresolved complaint, you may contact your local supervisory authority. Historic versions are available on request from privacy@zerqano.com. Where a conflict exists between this English-language version and any translation, this English version prevails.