This Privacy Policy explains how Zenith AI ("Zenith AI," "we," "us," or "our") collects, uses, discloses, and protects personal information in connection with our platform, websites, applications, APIs, and related services (collectively, the "Services"). Information about the legal entities behind Zenith AI is set out in Section 15.
This Policy is designed to meet the requirements of major privacy laws, including the EU and UK General Data Protection Regulation (GDPR/UK GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.
Depending on the context, we act in different roles under data protection law:
We collect the following categories of personal information:
When you connect a Third-Party Service (such as TikTok Shop, Shopify, or others) to the Services, we receive data from those platforms as authorized by you — for example, store, catalog, order, performance, and account data. The data we receive depends on the integration and the permissions you grant. This may include personal information relating to your customers or contacts; where it does, you act as the controller and we process it on your behalf.
You and your Authorized Users may submit content and data into the Services. To the extent Customer Data contains personal information, we process it as a processor on your behalf.
We use personal information to:
The Services use artificial intelligence and machine learning. We may use Customer Data and usage data to operate the AI Features and to train, fine-tune, evaluate, and improve our models and Services.
When we use data for model-improvement purposes:
Where you are our direct customer, you may request to opt your Customer Data out of model-improvement use by contacting us at hello@joinzenith.ai. Opting out may limit the availability or quality of certain features.
AI-generated Output may be inaccurate and should be reviewed before use. See our Terms of Service for details.
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
Where we act as a processor, the controller (our customer) is responsible for establishing a lawful basis for processing.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share personal information only as described below:
We operate across the United States and Canada and may process personal information in these and other countries. Where we transfer personal information across borders — including from the European Economic Area, the UK, or Switzerland to countries that may not provide an equivalent level of protection — we implement appropriate safeguards, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement/Addendum, and additional measures as required. You may request more information about these safeguards using the contact details in Section 15.
We retain personal information for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. When personal information is no longer needed, we will delete or de-identify it. Where we act as a processor, we retain and delete Customer Data in accordance with our agreement with the relevant customer. Specific retention periods depend on the type of data and the purpose for which it is held.
We do not retain personal data from Shopify. Order data is aggregated on receipt into daily totals — date, order count, gross and net sales, and currency. No customer names, email addresses, postal addresses, phone numbers, or order identifiers are stored at any point.
Aggregated data and encrypted access credentials are retained only while the integration is active. When a merchant uninstalls the app or disconnects their store, both are deleted on receipt of Shopify’s deletion request.
Your rights depend on where you are located. We honor the rights granted to you under applicable law.
You may have the right to: access your personal information; correct inaccurate data; request erasure; restrict or object to processing; data portability; and withdraw consent. You also have the right to lodge a complaint with your local supervisory authority.
California residents have the right to: know the categories and specific pieces of personal information collected; know whether information is sold or shared; access and delete personal information; correct inaccurate information; and limit the use of sensitive personal information. As noted in Section 6, we do not sell or share personal information. We will not discriminate against you for exercising these rights.
Individuals in Canada have the right to access and correct their personal information and to withdraw consent, subject to legal and contractual restrictions.
To exercise any right, contact us at hello@joinzenith.ai. We will verify your request and respond within the timeframes required by applicable law. You may use an authorized agent where permitted. If your request concerns data we process on behalf of a business customer (as a processor), we will refer your request to that customer or act on their instructions.
We implement administrative, technical, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, or alteration. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials confidential and for securing access to your Account.
We use only essential (strictly necessary) cookies and similar technologies required to operate the Services, authenticate users, maintain sessions, and keep the Services secure. We do not use advertising cookies, and we do not use cookies for cross-context behavioral advertising. Because these cookies are necessary for the Services to function, they cannot be disabled through a consent banner, though you can manage cookies through your browser settings (which may affect functionality). If we introduce analytics or other non-essential cookies in the future, we will update this Policy and provide any required controls.
The Services are intended for businesses and are not directed to children. We do not knowingly collect personal information from individuals under the age of 18. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
The Services may contain links to, or integrate with, third-party websites and services that we do not control. This Policy does not apply to those third parties. We encourage you to review their privacy policies.
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the Services or by other appropriate means and update the "Last updated" date above. Your continued use of the Services after the changes take effect constitutes acceptance.
If you are in the EEA or UK and have unresolved concerns, you have the right to complain to your local data protection authority.
zenith