Effective date: 10/13/2021
Last Updated: 8/3/2026
This Privacy Policy describes how Zenpire Holdings (https://zenpire.tech) collects, uses, discloses, and protects personal information in connection with:
This Privacy Policy should be read together with our Terms of Service. By using the Services, you acknowledge the practices described in this Privacy Policy.
Because our Apps are installed by Shopify merchants (“Merchants“) whose stores are visited by shoppers (“Customers“), we handle personal information in two distinct capacities:
We act as a data controller for personal information relating to Merchants, their staff, Site visitors, and prospective customers — for example, account details, billing records, support conversations, marketing preferences, and Site analytics. This Privacy Policy governs that processing.
We act as a data processor (or “service provider” under U.S. state privacy laws) when we process personal information about a Merchant’s Customers on the Merchant’s behalf and instructions — for example, order data, customer tags, chat transcripts handled by Flash AI Chatbot, pre-order notification email addresses handled by PreOrder Now, and ticket-holder details handled by Evey. In this capacity, the Merchant is the controller of its Customers’ data, and our processing is governed by our Data Processing Agreement (“DPA”), available on request at [email protected].
If you are a Customer of a store that uses one of our Apps, please direct privacy requests to the Merchant operating that store. We will assist the Merchant in fulfilling your request as described in Section 9.
When you visit the Site or use the Apps, we and our service providers automatically collect usage data such as IP address, browser type and version, device identifiers, pages viewed, referring URLs, timestamps, and diagnostic and error data. We use cookies and similar technologies (session, preference, security, analytics, and advertising cookies) as described in our Cookie Policy.
Flash AI Chatbot processes shopper chat messages and relevant store content (such as product and policy information) to generate automated responses. Chat content may be processed by third-party AI model providers acting as our sub-processors, listed in Section 8. We do not use Merchants’ or their Customers’ data to train generalized AI models.
Acting as a controller, we use personal information to:
Acting as a processor, we use Customer personal information solely to provide the Apps to the relevant Merchant in accordance with our DPA and the Merchant’s instructions, and for no other purpose.
Where the EU or UK General Data Protection Regulation applies and we act as controller, our legal bases are: performance of a contract (providing the Services you request); legitimate interests (improving the Services, security, fraud prevention, and B2B marketing, balanced against your rights); consent (where required, e.g., certain cookies and marketing); and legal obligation (tax, accounting, and compliance requirements).
We retain Personal Data only as long as necessary for the purposes outlined in this Privacy Policy, to comply with legal obligations, resolve disputes, and enforce agreements.
Usage Data is retained for internal analysis and security purposes.
We do not sell personal information for money. We disclose personal information only:
Our use of behavioral advertising and remarketing services (Google, Microsoft, Meta, Pinterest, X/Twitter) may constitute “sharing” for cross-context behavioral advertising or “targeted advertising” under certain U.S. state laws. Section 11 describes your right to opt out.
We are based in the United States and process data on servers located in the United States. Where we transfer personal data from the EEA, the UK, or Switzerland, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum).
We use the following categories of third-party providers. A current, complete sub-processor list is incorporated into our DPA:
Our Apps subscribe to and honor Shopify’s mandatory privacy webhooks:
We process Shopify protected customer data in accordance with Shopify’s Protected Customer Data requirements, including data minimization, purpose limitation, encryption in transit and at rest, and access controls.
If you are located in the EEA, the UK, or Switzerland, you have the right to: access your personal data; rectify inaccurate data; erase data; restrict or object to processing (including direct marketing); data portability; and to withdraw consent at any time without affecting prior processing. You also have the right to lodge a complaint with your local supervisory authority.
To exercise these rights, contact us at [email protected]. We will respond within one month. If you are a Customer of a Merchant’s store, we will refer your request to the relevant Merchant and assist them in responding.
Residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have rights that may include:
We do not sell personal information for money. Our use of advertising cookies and remarketing may constitute “sharing” or “targeted advertising”; you can opt out by emailing [email protected]. We recognize and honor Global Privacy Control (GPC) browser signals as a valid opt-out of sale/sharing. We also honor Do Not Track signals.
You may submit requests at [email protected] or via https://zenpire.tech/contact/. We will verify your identity before responding and will respond within the timeframes required by applicable law (generally 45 days). You may designate an authorized agent to submit requests on your behalf. If we deny your request, you may appeal by replying to our decision; we will respond to appeals as required by law.
Categories collected (last 12 months): identifiers; commercial information; internet or other network activity; geolocation (approximate, from IP); professional information; and inferences — each collected from the sources and for the purposes described in Sections 3 and 4, and disclosed to the categories of recipients in Sections 6 and 8.
We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit (TLS) and at rest, role-based access controls, logging and monitoring, and secure development practices. No method of transmission or storage is completely secure; we cannot guarantee absolute security. We will notify affected Merchants and regulators of personal data breaches as required by applicable law and our DPA.
The Services are business tools intended for users who are at least 18 years old. We do not knowingly collect personal information from anyone under 18, and no part of the Services is directed to children under 13. If you believe a child has provided us personal information, contact us at [email protected] and we will delete it.
The Services may link to third-party websites and services we do not control. Their privacy practices are governed by their own policies, which we encourage you to review.
We may update this Privacy Policy from time to time. We will post the updated version on this page with a revised “Last Updated” date and, for material changes, will provide notice by email or prominent notice within the Services before the changes take effect.
Privacy questions and requests: [email protected].