Privacy Policy
Last updated 28 July 2026
Who we are
Zoppl is an AI marketing operator sold to performance-marketing agencies. Agencies connect their clients' advertising, analytics and catalog accounts to Zoppl; Zoppl reads performance data from those accounts, diagnoses what is underperforming, and — only after a human approves — applies changes back to the connected account.
This policy explains what data we handle, why, where it lives, and how to get it deleted. For privacy questions or requests, contact inbound@zoppl.com.
The data we handle
Zoppl does not own or originate marketing data. Everything we show is read from a source an authorised user explicitly connected, and every figure in the product is labelled with the source it came from and when it was last synced.
| Category | What it is | Why we need it |
|---|---|---|
| Account data | Your name, work email, organisation, workspace roles | To create your account, authenticate you, and enforce who may see which client |
| Connection credentials | OAuth access and refresh tokens for the platforms you connect | To read performance data and apply approved changes on your behalf |
| Advertising performance data | Campaign, ad-set and ad names, impressions, clicks, spend, conversions | To diagnose performance and produce insights and reports |
| Analytics and conversion data | Conversion counts and values, event names, and hashed identifiers where you send them | To attribute outcomes to marketing activity |
| Catalog data | Product, menu, listing or inventory records from a connected catalog | To support catalog-backed campaigns |
| Usage and billing data | Feature usage counts, seats, managed spend, invoices | To meter your subscription and bill you |
Conversion identifiers are hashed, never raw
Where you send us conversion data that identifies an end customer — an email address or phone number — Zoppl accepts and stores it only as a cryptographic hash. We do not store raw end-customer email addresses or phone numbers, and we cannot recover them from the hash. Hashes exist solely to match a conversion to a marketing touchpoint.
Artificial intelligence — no third-party model providers
Zoppl uses large language models to explain and prioritise findings. Those models run on inference infrastructure we operate ourselves, inside our own private network.
Your data is never sent to a third-party AI provider — not OpenAI, not Anthropic, not Google — for model inference. It is not used to train any model, ours or anyone else's.
Every diagnosis in Zoppl is produced by deterministic, auditable arithmetic first. The language model only writes the explanation and orders the results; it cannot invent a finding or change a finding's severity.
How we protect connection credentials
- OAuth tokens are encrypted at rest with AES-256-GCM, under a key held in a separate secret store, and are keyed per connection.
- Tokens are never returned by any public API, never rendered in the interface, and never written to logs. The product surfaces a connection's health and provenance — never its credential.
- Tokens are released only to the internal service that needs them, over the private service mesh, authenticated per call.
- We request the narrowest scope each integration needs. Where a platform offers a read-only scope sufficient for a job, we use it.
Who we share data with
We do not sell personal data and we do not share it for advertising. We use a small number of sub-processors to run the service:
| Sub-processor | Purpose | Data reached |
|---|---|---|
| OVHcloud | Hosting and infrastructure (Singapore) | All service data at rest |
| Resend | Transactional email (confirmation, password reset, invitations) | Name, email address |
| Razorpay | Subscription payments | Billing contact, payment token, invoice amounts |
| Cloudflare | DNS, TLS termination and DDoS protection | Request metadata in transit |
We also transmit data to the marketing platforms you connect — to read your data and, where you approve it, to apply changes. That exchange is governed by your agreement with that platform.
We disclose data to authorities only where legally compelled, and will notify you unless prohibited from doing so.
Where data lives and how long we keep it
Service data is hosted in Singapore. Retention:
| Data | Retention |
|---|---|
| Connection credentials | Deleted within 30 days of disconnecting the connection or closing the account |
| Performance, analytics and catalog data | Retained while the account is active; deleted within 30 days of account closure |
| Audit and approval records | Retained 24 months — these are the record of who approved which change |
| Invoices and billing records | Retained as required by tax and accounting law |
| Backups | Purged on a rolling 35-day cycle |
Your rights
You may request access to, correction of, export of, or deletion of your personal data, and you may object to or restrict certain processing. Email inbound@zoppl.com and we will respond within 30 days.
To delete data obtained from a connected platform, see our data deletion page, which also documents the automated callbacks connected platforms use to request deletion on a user's behalf.
If an agency connected data about you and you are not a Zoppl account holder, contact that agency — they are the controller of that data and we process it on their instruction. We will assist them in responding to you.
Children
Zoppl is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.
Changes to this policy
We will post any change here and update the date above. For changes that materially affect how we handle your data, we will notify account administrators by email before the change takes effect.
Contact
inbound@zoppl.com for privacy requests, or inbound@zoppl.com to report a vulnerability.