We're committed to protecting your data with enterprise-grade security and transparent practices.
Welcome to Zatisfied ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how Zatisfied Inc., a Delaware corporation with principal offices in Greenwood Village, Colorado, collects, uses, discloses, and safeguards your information when you use our AI-powered restaurant reputation management platform (the "Service").
This Privacy Policy applies to all information collected through our website located at zatisfied.io (the "Website"), our web-based application, any mobile applications we may offer, APIs, widgets embedded on third-party websites, and any other products, services, or features we provide (collectively, the "Services"). This policy also applies to information collected when you interact with us through social media or other platforms, attend our events, or communicate with our customer support team.
By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the practices described in this policy, please do not use our Services. Your continued use of the Services following the posting of changes to this policy will be deemed your acceptance of those changes.
Regulatory Compliance: We are committed to complying with applicable data protection laws and regulations, including but not limited to the General Data Protection Regulation (GDPR) for users in the European Economic Area (EEA), the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) for California residents, and other applicable state, federal, and international privacy laws.
We encourage you to read this Privacy Policy carefully and contact us if you have any questions. For purposes of the GDPR, Zatisfied Inc. is the "data controller" of your personal information. Our Data Protection Officer can be reached at dpo@zatisfied.io.
We collect information that you provide directly to us, information we obtain automatically when you use our Services, and information from third-party sources. The types of personal information we collect depend on how you interact with us, the Services you use, and the choices you make.
We collect information you provide when you create an account, subscribe to our Services, fill out forms, make purchases, communicate with us, or otherwise interact with our platform. This includes:
When you access or use our Services, we automatically collect certain information about your device, your use of our Services, and your interactions with our platform:
Our Services integrate with various third-party platforms to provide comprehensive reputation management. When you connect these integrations, we may receive information from those platforms:
A core function of our Service is processing customer reviews from various platforms. This review data may include the reviewer's publicly displayed name or username, the content of their review, star ratings, the date and time of the review, any photos or media attached to the review, and your organization's responses. We process this data solely to provide our reputation management services and in accordance with the terms of service and privacy policies of the respective review platforms. We do not use customer review data for purposes unrelated to providing and improving our Services.
We use the information we collect for various purposes, all aimed at providing, maintaining, and improving our Services, communicating with you, and ensuring the security of our platform. We process personal data only when we have a valid legal basis to do so.
More specifically, we use your information in the following ways:
We use your information to operate, maintain, and provide the features and functionality of our Services. This includes creating and managing your account, authenticating your identity, processing your subscription and payments, aggregating reviews from connected platforms, generating AI-powered response suggestions based on your brand voice settings, sending notifications about new reviews and platform activity, and providing customer support when you need assistance.
We analyze usage patterns, feedback, and performance metrics to understand how our Services are used and to identify areas for improvement. This includes developing new features and functionality, optimizing user experience and interface design, training and improving our AI models using aggregated and anonymized data sets, conducting research and analysis to enhance our algorithms, and testing new features and updates before wider release.
We use your contact information to communicate with you about your account and our Services. This includes sending transactional emails such as account confirmations, password resets, subscription receipts, and payment notifications; providing customer support and responding to your inquiries; sending service announcements and updates about changes to our Services or policies; and with your consent, sending marketing communications about new features, promotions, or related services.
We use your information to maintain the security and integrity of our Services. This includes detecting, investigating, and preventing fraudulent transactions, abuse, and other harmful activities; monitoring for and addressing security vulnerabilities; enforcing our Terms of Service and other agreements; and protecting the rights, property, and safety of Zatisfied, our users, and the public.
We may process your information to comply with applicable laws, regulations, legal processes, or enforceable governmental requests. This includes responding to subpoenas, court orders, or other legal process; cooperating with law enforcement and regulatory agencies; and meeting tax, accounting, and reporting requirements.
For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process your personal data only when we have a valid legal basis to do so under the General Data Protection Regulation (GDPR). The legal bases we rely on include:
Processing necessary to perform our contract with you and provide the Services you requested.
Processing for our legitimate business interests, balanced against your rights and freedoms.
Where you have given explicit, informed consent for specific processing activities.
Processing necessary to comply with applicable laws and regulations.
Contractual Necessity (Article 6(1)(b)): We process certain personal data because it is necessary to perform our contract with you. This includes processing your account information to create and maintain your account, processing payment information to fulfill your subscription, and processing usage data to provide the core features of our Services.
Legitimate Interests (Article 6(1)(f)): We process certain personal data based on our legitimate interests, where those interests are not overridden by your data protection rights. Our legitimate interests include improving and developing our Services, understanding how users interact with our platform, detecting and preventing fraud and abuse, marketing our Services to existing customers, and ensuring the security of our platform. We conduct a balancing test to ensure our interests do not override your fundamental rights and freedoms.
Consent (Article 6(1)(a)): For certain processing activities, we rely on your explicit consent. This includes sending you marketing communications, using analytics cookies and similar technologies, and processing data for purposes beyond what is necessary to provide our Services. You may withdraw your consent at any time by contacting us or using the preference controls in your account settings.
Legal Obligation (Article 6(1)(c)): We process certain personal data because it is necessary to comply with applicable laws and regulations, such as tax laws, anti-money laundering regulations, and legal process requirements.
We do NOT sell your personal information to third parties.
We take your privacy seriously and are committed to limiting the sharing of your personal information. We do not sell, rent, or trade your personal data. However, we may share your information in the following limited circumstances:
AWS, Google Cloud Platform
Stripe (PCI-DSS compliant)
SendGrid
Telnyx
OpenAI
Mixpanel (anonymized)
Service Providers: We share information with third-party service providers who perform services on our behalf. These providers are contractually bound by data processing agreements that require them to protect your information and prohibit them from using your data for any purpose other than providing services to us. Our service providers include cloud hosting and infrastructure providers, payment processors, email delivery services, SMS notification services, AI and machine learning platforms, analytics providers, and customer support tools.
Legal Requirements: We may disclose your information if required to do so by law or in response to valid legal process, such as a subpoena, court order, or government request. We may also disclose information when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
Business Transfers: If Zatisfied is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of company assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our Services of any change in ownership or uses of your personal information, as well as any choices you may have regarding your personal information.
With Your Consent: We may share your information with third parties when you have given us your explicit consent to do so.
Aggregated and Anonymized Data: We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you. This data may be used for industry analysis, benchmarking, and other business purposes.
We implement comprehensive technical and organizational security measures designed to protect your personal information against unauthorized access, alteration, disclosure, or destruction. Security is a top priority at Zatisfied, and we continuously invest in improving our security posture.
TLS 1.3 in transit, AES-256 at rest
Role-based access with MFA required
Independently audited compliance
Annual penetration testing
Mandatory security awareness
72-hour breach notification
Our security measures include:
While we implement robust security measures, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to promptly addressing any security incidents and continuously improving our security practices.
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. The retention period depends on the type of data and the purpose for which it was collected.
Retained while active + 30 days after deletion for recovery
Retained for tax and legal compliance requirements
Deleted or anonymized after account termination
Retained for security and analytics purposes
When determining the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process the data, whether we can achieve those purposes through other means, and applicable legal requirements.
Upon account deletion or at your request, we will delete or anonymize your personal data within the timeframes specified above, unless we are required to retain it for legal, regulatory, or legitimate business purposes. Some information may be retained in our backup systems for a limited period before being permanently deleted.
Depending on your location and applicable laws, you may have certain rights regarding your personal data. We are committed to honoring these rights and providing you with control over your information.
To exercise any of these rights, please contact us at privacy@zatisfied.io. We will respond to your request within 30 days (or within the timeframe required by applicable law). We may need to verify your identity before processing your request to protect your privacy and security.
Please note that certain rights may be limited in some circumstances. For example, we may not be able to delete information that we are required to retain for legal purposes, or we may decline requests that are unreasonably repetitive, require disproportionate technical effort, or jeopardize the privacy of others.
Contact our privacy team - we'll respond within 30 days
Zatisfied is headquartered in the United States, and we process and store data primarily in the United States. If you are located outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States and other countries where our servers are located or where our service providers operate.
When we transfer personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to countries that have not been deemed to provide an adequate level of data protection, we ensure appropriate safeguards are in place to protect your information:
We use Standard Contractual Clauses (SCCs) approved by the European Commission as the primary mechanism for transferring personal data from the EEA to the United States and other third countries. We also enter into Data Processing Agreements with all sub-processors that include appropriate data protection clauses and security requirements.
For transfers from the United Kingdom, we rely on the UK International Data Transfer Agreement or UK Addendum to the EU SCCs, as appropriate. For transfers from Switzerland, we rely on the SCCs as approved by the Swiss Federal Data Protection and Information Commissioner.
Our Services are not intended for, and we do not knowingly collect personal information from, individuals under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect, maintain, or use personal information from children under 16 years of age, and no part of our Services is directed to children.
If we learn that we have collected personal information from a child under 16, we will take steps to delete that information as quickly as possible. If you are a parent or guardian and you believe that your child has provided us with personal information without your consent, please contact us immediately at privacy@zatisfied.io, and we will take steps to remove that information from our systems.
If you are between 16 and 18 years of age, you may only use our Services with the involvement and consent of a parent or legal guardian.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please don't hesitate to contact us. We are committed to addressing your inquiries promptly and thoroughly.
privacy@zatisfied.io
dpo@zatisfied.io
Greenwood Village, CO, USA
Zatisfied Inc.
Attn: Privacy Team
7600 E Orchard Rd, Greenwood Village, CO 80111
For users in the European Economic Area, you also have the right to lodge a complaint with your local data protection supervisory authority if you believe that we have not complied with applicable data protection laws. However, we encourage you to contact us first so we can try to resolve your concerns directly.
We will respond to all legitimate requests within 30 days, or within the timeframe required by applicable law. In some cases, we may need to request additional information from you to verify your identity before responding to your request.