← Back to Home

Privacy Policy

Last Updated: September 23, 2026

Overview

This Privacy Policy ("Policy") describes how Zarcore Technologies LLC ("Company," "Zarcore," "we," "us," or "our") collects, uses, stores, discloses, and protects information when you visit www.zarcore.com (the "Website"), register for an account, subscribe to or use any of our modular cloud software applications, APIs, or services (collectively, the "Platform"), or engage in consulting, advisory, or data migration services with us.

By accessing the Website, creating an account, or using the Platform, you acknowledge that you have read, understood, and agreed to the practices described in this Privacy Policy.

1. Roles and Scope: Data Controller vs. Data Processor

To understand how your information is handled, it is important to distinguish between two categories of data under global privacy laws (including GDPR and CCPA/CPRA):

  • Zarcore as a Data Controller (Account & Marketing Data): Zarcore acts as a Data Controller regarding the personal information we collect directly from visitors, prospective clients, and primary account owners (e.g., billing details, contact names, discovery call form submissions, and login credentials).
  • Zarcore as a Data Processor (Tenant Operational Data): Zarcore acts as a Data Processor with respect to all customer, employee, transaction, payroll, lead, inventory, and network data that our business clients ("Tenants") upload, input, or generate within their isolated Zarcore workspaces ("Customer Data"). The Tenant remains the Data Controller for their respective workspace data, and Zarcore processes such Customer Data solely pursuant to our Terms of Service and any applicable Data Processing Agreement (DPA).

2. Information We Collect

We collect information in three ways: directly from your submissions, automatically via system use, and through third-party services.

A. Information You Provide Directly

  • Account Registration & Contact Info: Full name, business email address, phone number, company name, website URL, physical mailing address, and login credentials.
  • Billing & Payment Details: Payment card details, billing address, and bank account information for payment processing. All credit card processing is handled securely by our payment partner, Stripe; Zarcore does not store full credit card numbers on our servers.
  • Form & Communication Submissions: Information submitted via our discovery call booking form, support tickets, survey responses, or direct email correspondence.
  • Tenant Business Records (Processed on Behalf of Clients): When operating active modules (CRM, Accounting, HR & Payroll, Inventory, IT Assets, Business Analytics), Tenants may store sensitive business data, including employee SSNs/tax IDs, bank routing details, customer contact lists, ledgers, and network configurations.

B. Information Collected Automatically

  • Log & Technical Data: IP addresses, browser type, operating system, device hardware details, referring/exit pages, access timestamps, and system performance metrics.
  • Usage & Analytics: Feature interaction logs, active module settings, API call counts, and session duration to ensure security, monitor platform load, and improve performance.
  • Security & Audit Logs: Role-based access logs, authentication attempts, and password reset activity.

2C. Cookies and Tracking Technologies

We prioritize privacy and performance. We use essential, functionally necessary cookies and local storage to manage user authentication, session security, and load distribution. We do not use invasive third-party tracking cookies or sell visitor behavior to advertising brokers.

2D. SMS / Text Messaging Communications

If you provide your mobile phone number and check the consent box on our Website's inquiry form, you agree to receive text messages from Zarcore Technologies LLC related to your inquiry, scheduling your discovery call, account notifications, customer support, and (where you have not opted out) occasional service updates. Message frequency varies depending on your interaction with us; you should expect no more than a few messages per month.

Message and data rates may apply, depending on your mobile carrier plan. Reply HELP to any message for assistance, or reply STOP at any time to opt out of future text messages. You may also request removal by contacting privacy@zarcore.com.

No Sharing for Marketing: Mobile phone numbers and SMS opt-in consent collected for text messaging purposes are never sold, rented, or shared with third parties for their own marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third party, except as necessary to deliver the message through our SMS service provider (Twilio).

Consent to receive text messages is never a condition of purchasing any goods or services from Zarcore.

Separate from the Website inquiry messages described above, our business clients may enable messaging and calling features inside their own CRM workspace. The information processed in that context, including phone numbers, message content, call records, and voicemail recordings, is described in Section 4D of this Policy.

3. How We Use Your Information

We use the collected information for specific, legitimate business purposes:

  • To Provide and Maintain the Platform: Provisioning workspace accounts, activating requested modules, rendering reporting metrics, and maintaining backend synchronizations.
  • Payment & Transaction Management: Processing recurring subscription fees, module activation charges, and advisory retainers through Stripe.
  • Onboarding & White-Glove Data Migration: Executing client-approved CSV uploads, data sanitization, and system setup as part of our migration services.
  • System Security & Threat Detection: Preventing unauthorized login attempts, detecting anomalies, enforcing role-based access control, and mitigating cyber threats.
  • Customer Support & Communications: Sending transaction receipts, billing failure alerts, system downtime notices, automated workflow notifications, and responding to support tickets.
  • Legal Compliance: Complying with tax obligations, accounting laws, court orders, and law enforcement requests.

4. Data Sharing and Third-Party Processors

Zarcore does not sell, rent, broker, or trade personal information or Customer Data to third parties for marketing or advertising purposes.

We share data only with trusted third-party service providers ("Sub-processors") who assist us in operating our infrastructure, processing payments, and delivering services under strict confidentiality and security obligations, including:

  • Payment Processors (Stripe): Subscription billing and invoice processing. PCI DSS Level 1 certified.
  • Cloud Hosting & Infrastructure: Multi-tenant database hosting, encrypted file storage, and automated backups.
  • Google (Gmail, Google Calendar & Google Drive): For clients who connect a Google account, transactional/lead email and meeting scheduling are sent and synced through Google's infrastructure. Where Drive-backed document features are enabled, files created or opened through the Platform are stored in that user's own Google Drive. See Section 4A for full detail.
  • Microsoft (Outlook Mail, Calendar, OneDrive, SharePoint & Teams): For clients who connect a Microsoft account, email sending and reply capture, calendar and meeting sync, online meeting links, and document storage and retention are handled through Microsoft's infrastructure. See Section 4B for full detail.
  • Resend (Transactional Email Infrastructure, operated by Plus Five Five, Inc.): For clients who use our domain-verified email path instead of a connected Google or Microsoft account, outbound business email is authenticated and delivered, and inbound replies are received and routed back into the CRM, through Resend's infrastructure. See Section 4C for full detail.
  • Twilio (Cloud Communications and Carrier Connectivity): For clients who enable CRM messaging or calling, telephone numbers, SMS and MMS messages, voice calls, call forwarding, and voicemail capture are provisioned and transmitted through Twilio and the mobile carriers it connects to. See Section 4D for full detail.

We may also disclose information if required by law, subpoena, or government investigation, or in connection with a corporate merger, acquisition, or sale of business assets.

4A. Google User Data (Gmail, Calendar & Drive): Access, Use, Storage, Sharing, and Limited Use

Zarcore offers optional integrations that allow a Client or an individual authorized user ("you") to connect your own Google Account to your Zarcore workspace so that the CRM module can send email, receive replies, schedule meetings, and, where Drive-backed document features are enabled, attach or store documents using your own Google identity. Connecting a Google Account is always optional; the Platform remains fully usable without it, and Zarcore offers a non-Google email path (a domain-verified transactional email sender) as an alternative.

A. What Google user data we request, and why. When you connect your Google Account, Google presents a consent screen listing exactly the permissions requested. We request the narrowest set of permissions required to deliver the features you have activated:

  • See your primary Google Account email address (userinfo.email): Used solely to identify which Google Account you connected, to display that address back to you in Settings so you can confirm the correct account, and to send outbound CRM email from the correct identity.
  • Send email on your behalf (gmail.send): Used solely to send the CRM messages you or your team initiate or schedule from within the Platform, including sales quotes, invoices, contact outreach, meeting confirmations, and marketing campaigns you configure. We do not send email from your account for our own purposes.
  • View your email messages and settings (gmail.readonly): Used solely to read incoming replies to CRM conversations so that a customer's reply is captured and displayed in the correct contact's message thread inside your workspace, and so that reply activity can update that contact's CRM status. We do not read, index, catalogue, or analyze your mailbox generally, and we do not use this permission to build any profile of you or your correspondents.
  • View and edit events on all your calendars (calendar.events): Used solely to create, update, and cancel the meetings you schedule from within the CRM, to attach video conferencing links to those meetings, and to display your existing calendar events inside the Platform's calendar view so you can schedule without double-booking.
  • Access only the Google Drive files you open with, or create through, Zarcore (drive.file), where Drive-backed document features are enabled: Used solely to attach a Drive document you pick to a CRM, HR, or accounting record, and to save documents the Platform generates for you (such as quotes, invoices, and reports) back to your Drive. We do not request, and cannot obtain, broad access to your entire Drive; Google restricts this permission to the specific files you select or that Zarcore creates.

B. How Google user data is stored and retained. Google access and refresh tokens are held encrypted by our underlying cloud platform and are never exposed to your browser or to any other tenant. Message content and calendar details are stored only to the extent needed to render the feature you requested: the body, subject, sender, and attachments of email exchanged with a CRM contact are stored in your isolated workspace as part of that contact's communication history, and meeting details are stored as CRM activity records. We do not create or retain a copy of your broader Google mailbox, contact list, or calendar beyond what is described here. All such data is subject to the retention, termination, and permanent-deletion schedule described in Section 6 of this Policy.

C. How Google user data is shared. We do not sell, rent, license, trade, or transfer Google user data to any third party. We do not share it with data brokers, advertising networks, advertising or marketing platforms, credit agencies, or any party conducting surveillance. Google user data is shared only with the cloud hosting and database infrastructure that stores your workspace on our behalf under confidentiality and security obligations, and only where compelled by valid legal process. Google user data is never combined across tenants and is never disclosed to another Zarcore Client.

D. Limited Use of Google user data. Zarcore's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, and without limitation:

  • We use Google user data only to provide or improve the user-facing features described in Section 4A(A) above, and only in the ways disclosed in this Policy.
  • We do not use Google user data for serving advertisements of any kind, including personalized, retargeted, or interest-based advertising.
  • We do not sell Google user data, and we do not transfer it to third parties except as strictly necessary to provide or improve the features above, to comply with applicable law, or as part of a merger or acquisition in which case we will continue to require compliance with these Limited Use commitments.
  • We do not use Google user data to develop, train, improve, or fine-tune generalized or non-personalized artificial intelligence or machine learning models. Where the Platform's AI features operate on a message you explicitly ask it to act on (for example, drafting a reply you requested), that processing serves only your immediate request within your own workspace and the content is not retained by any model provider for training.
  • We do not allow humans to read Google user data unless (i) we have your affirmative agreement for specific messages, (ii) it is necessary for security purposes such as investigating abuse, (iii) it is necessary to comply with applicable law, or (iv) our use is limited to internal operations and the data has been aggregated and de-identified.

E. How to review and revoke access. You may disconnect your Google Account from Zarcore at any time from Settings, Email Integration, within the Platform, which revokes our tokens and stops all further access. You may additionally, or alternatively, revoke access directly through your Google Account at https://myaccount.google.com/permissions. Revoking access stops any further reading of replies and any further sending or calendar activity through your Google Account. Communication history already captured into a CRM contact's thread remains in your workspace as a business record unless and until you delete it, or until it is purged under Section 6 of this Policy.

F. Changes to the data we request. If we ever intend to access a type of Google user data not disclosed in this Section, we will update this Policy and prompt you to consent to the new permission before that access occurs.

G. Microsoft equivalent. Where you instead connect a Microsoft Account (Outlook mail, Microsoft Calendar, OneDrive, SharePoint, or Microsoft Teams), materially equivalent commitments apply, as set out in full in Section 4B below.

4B. Microsoft Account Data (Outlook Mail, Calendar, OneDrive, SharePoint & Teams): Access, Use, Storage, Sharing, and Limited Use

Zarcore offers optional integrations that allow a Client or an individual authorized user ("you") to connect your own Microsoft work, school, or personal account to your Zarcore workspace so that the CRM module can send email, receive replies, schedule meetings, generate online meeting links, and, where OneDrive or SharePoint document features are enabled, attach or store documents using your own Microsoft identity. Connecting a Microsoft account is always optional; the Platform remains fully usable without it, and the Google path in Section 4A and the domain-verified email path in Section 4C are available alternatives. Where your organization's Microsoft tenant requires administrator approval for the requested permissions, your own Microsoft administrator controls whether the integration can be used at all.

A. What Microsoft account data we request, and why. When you connect your Microsoft account, Microsoft presents a consent screen listing exactly the permissions requested. We request the narrowest set of Microsoft Graph permissions required to deliver the features you have activated:

  • Read your basic profile and primary account address (User.Read): Used solely to identify which Microsoft account you connected, to display that address back to you in Settings so you can confirm the correct account, and to send outbound CRM email from the correct identity.
  • Send mail as you (Mail.Send): Used solely to send the CRM messages you or your team initiate or schedule from within the Platform, including sales quotes, invoices, contact outreach, meeting confirmations, and campaigns you configure. We do not send email from your mailbox for our own purposes.
  • Read your mail (Mail.Read): Used solely to read incoming replies to CRM conversations so that a customer's reply is captured and displayed in the correct contact's message thread inside your workspace, and so that reply activity can update that contact's CRM status. We do not read, index, catalogue, or analyze your mailbox generally, and we do not use this permission to build any profile of you or your correspondents.
  • Read and write your calendars (Calendars.ReadWrite): Used solely to create, update, and cancel the meetings you schedule from within the CRM, to attach conferencing details to those meetings, and to display your existing calendar events inside the Platform's calendar view so you can schedule without double-booking.
  • Create and manage online meetings (OnlineMeetings.ReadWrite), where Teams meeting features are enabled: Used solely to generate a meeting link for a meeting you schedule through the Platform.
  • Read and write the files you open with, or create through, Zarcore (Files.ReadWrite), where OneDrive or SharePoint document features are enabled: Used solely to attach a document you pick to a CRM, HR, or accounting record, and to save documents the Platform generates for you (such as quotes, invoices, and reports) back to your own storage. We do not seek indiscriminate access to your entire OneDrive or to unrelated SharePoint sites.
  • Maintain access to data you have granted access to (offline_access): Used solely to refresh our access token so that scheduled sends, reply capture, and calendar sync keep working without asking you to sign in repeatedly.

B. How Microsoft account data is stored and retained. Microsoft access and refresh tokens are held encrypted by our underlying cloud platform and are never exposed to your browser or to any other tenant. Message content and meeting details are stored only to the extent needed to render the feature you requested: the body, subject, sender, and attachments of email exchanged with a CRM contact are stored in your isolated workspace as part of that contact's communication history, and meeting details are stored as CRM activity records. We do not create or retain a copy of your broader Microsoft mailbox, contact list, calendar, or file storage beyond what is described here. All such data is subject to the retention, termination, and permanent-deletion schedule described in Section 6 of this Policy.

C. How Microsoft account data is shared. We do not sell, rent, license, trade, or transfer Microsoft account data to any third party. We do not share it with data brokers, advertising networks, advertising or marketing platforms, credit agencies, or any party conducting surveillance. It is shared only with the cloud hosting and database infrastructure that stores your workspace on our behalf under confidentiality and security obligations, and only where compelled by valid legal process. Microsoft account data is never combined across tenants and is never disclosed to another Zarcore Client.

D. Limited use of Microsoft account data. Our use of information received through Microsoft APIs is limited as follows:

  • We use Microsoft account data only to provide or improve the user-facing features described in Section 4B(A) above, and only in the ways disclosed in this Policy.
  • We do not use Microsoft account data for serving advertisements of any kind, including personalized, retargeted, or interest-based advertising.
  • We do not sell Microsoft account data, and we do not transfer it to third parties except as strictly necessary to provide or improve the features above, to comply with applicable law, or as part of a merger or acquisition in which case we will continue to require compliance with these commitments.
  • We do not use Microsoft account data to develop, train, improve, or fine-tune generalized or non-personalized artificial intelligence or machine learning models. Where an AI feature operates on a message you explicitly ask it to act on (for example, drafting a reply you requested), that processing serves only your immediate request within your own workspace and the content is not retained by any model provider for training.
  • We do not allow humans to read Microsoft account data unless (i) we have your affirmative agreement for specific messages, (ii) it is necessary for security purposes such as investigating abuse, (iii) it is necessary to comply with applicable law, or (iv) our use is limited to internal operations and the data has been aggregated and de-identified.

E. How to review and revoke access. You may disconnect your Microsoft account from Zarcore at any time from Settings, Email Integration, within the Platform, which revokes our tokens and stops all further access. You may additionally, or alternatively, revoke access directly through Microsoft, at https://myapps.microsoft.com for work or school accounts or at https://account.live.com/consent/Manage for personal accounts, and a Microsoft tenant administrator may revoke consent for an entire organization at any time. Revoking access stops any further reading of replies and any further sending, calendar, meeting, or file activity through your Microsoft account. Communication history already captured into a CRM contact's thread remains in your workspace as a business record unless and until you delete it, or until it is purged under Section 6 of this Policy.

F. Microsoft's own role. Microsoft acts as an independent controller of its own service data under the Microsoft Services Agreement, the Microsoft Product Terms, and the Microsoft Privacy Statement, which govern your relationship with Microsoft directly. Your own Microsoft licensing, mailbox sending limits, retention policies, and tenant configuration remain under your or your administrator's control, and international transfers of Microsoft account data rely on Microsoft's own published transfer mechanisms.

G. Changes to the data we request. If we ever intend to access a type of Microsoft account data not disclosed in this Section, we will update this Policy and prompt you to consent to the new permission before that access occurs.

4C. Transactional Email via Resend (Custom Sending Domains and Inbound Reply Capture)

For clients who prefer not to connect a Google or Microsoft mailbox, or who want business email to originate from their own corporate domain rather than an individual user's mailbox, Zarcore offers a domain-verified transactional email path delivered through Resend, the email service operated by Plus Five Five, Inc. ("Resend"), acting as our email infrastructure sub-processor. Clients do not contract with Resend directly.

A. What is processed on this path. Outbound CRM messages, quotes, invoices, statements, system notifications, and permitted campaigns are transmitted through Resend's sending infrastructure. Inbound replies addressed to the client's configured reply subdomain are received through Resend's inbound processing and routed back into the correct CRM contact thread inside that client's isolated workspace. The information necessarily processed to accomplish this includes sender and recipient email addresses, message headers and envelope data, subject lines, message bodies, attachments, and delivery, bounce, complaint, and error events.

B. Domain setup information. To activate this path, the client designates a sending domain and a reply subdomain it owns or lawfully controls, and publishes verification, SPF, DKIM, and inbound MX records at its own DNS provider. We create and manage the corresponding sending domain configuration with Resend on the client's behalf, and store the domain name, sending address, reply subdomain, the DNS records to be published, and the resulting verification status inside that client's workspace. Outbound sending remains blocked until domain verification succeeds, and inbound reply capture remains disabled until the MX record is verified.

C. Storage, sanitization, and retention. Message content stored for the CRM communication history lives only in the sending or receiving client's isolated workspace, is never combined across tenants, and is never disclosed to another client. Inbound message bodies are sanitized to neutralize active content before being displayed. Message content held by us is subject to the retention, termination, and permanent-deletion schedule in Section 6 of this Policy. Resend maintains its own transmission logs and retention practices under its published terms, including its Data Processing Addendum at https://resend.com/legal/dpa and its subprocessor list at https://resend.com/legal/subprocessors, and its infrastructure providers process message data on its behalf under those terms.

D. How this data is used and shared. Email content on this path is used solely to deliver, receive, thread, and display the client's own business correspondence and to report delivery outcomes. We do not sell it, do not use it for advertising, do not use it to train generalized artificial intelligence or machine learning models, and do not share it other than with Resend and our cloud hosting infrastructure for the purpose of delivering the feature, or where compelled by valid legal process.

E. Roles and client responsibility. With respect to personal data contained in email sent and received through this path, the client is the controller and Zarcore is a processor acting on the client's instructions. The client is responsible for owning or lawfully controlling the domain it configures, for the accuracy and upkeep of its DNS records, for having a lawful basis or consent to contact each recipient, for honoring unsubscribe requests, and for compliance with the CAN-SPAM Act, CASL, GDPR and ePrivacy rules where applicable, and mailbox-provider bulk-sender requirements. Deliverability and inbox placement are determined by receiving mail providers and are not guaranteed by Zarcore.

F. Deactivation. When the integration is deactivated, or the workspace is cancelled, suspended, or terminated, we may delete the client's sending domain and inbound routing configuration from Resend, after which sending and reply capture on that domain stop. The client is responsible for removing the corresponding DNS records from its own zone. Email records already captured into the workspace remain the client's records until deleted by the client or destroyed under Section 6.

4D. CRM Telephony via Twilio (SMS, MMS, Voice Calls, Call Forwarding & Voicemail)

Where a business client enables messaging and calling inside its CRM workspace, those features are delivered through Twilio Inc. ("Twilio"), acting as our underlying cloud communications and carrier connectivity provider, together with the mobile carriers Twilio connects to. Zarcore is an independent software vendor and reseller of that connectivity; clients do not contract with Twilio directly.

A. What is processed. To provision and operate these features, the following information is processed: the telephone numbers assigned to each CRM seat; each agent's own forwarding phone number; the phone numbers of the people the client's agents message or call; the content of outbound and inbound SMS and MMS messages; call metadata including direction, start time, duration, status, and carrier error codes (call detail records); browser softphone session data; audio recordings of voicemail messages left by callers; and messaging consent and opt-out records.

B. A2P 10DLC registration information. United States application-to-person messaging requires registration of the sending business and its messaging use case. To enable messaging for a client, we submit client-provided business information, which may include legal entity name, Employer Identification Number or other tax identifier, business address, website, industry, contact name, contact email, contact phone number, use case description, and sample message content, to Twilio, to The Campaign Registry, and onward to the mobile carriers and their aggregators. This information is submitted for regulatory and anti-spam registration purposes only, is not used for marketing, and is required by the carriers before messaging can operate.

C. Voicemail recordings and recording consent. Voicemail messages left by callers are captured and stored so that the client's agents can review them. Recordings are not publicly addressable; playback occurs only through an authenticated, tenant-scoped request by a user of that workspace. Recordings are retained on a rolling automated schedule and are purged automatically once the applicable retention period elapses, unless a user affirmatively marks a specific voicemail to be kept, in which case an extended retention period applies. All recordings are destroyed with the rest of the workspace under Section 6 of this Policy. Where our client records or captures voice communications, that client is the controller of those recordings and is solely responsible for providing any legally required recording notice and for obtaining any consent required by applicable federal and state wiretapping, eavesdropping, and all-party consent laws. If you are a caller or recipient with a question or objection about a recording or message, please direct it to the business you were communicating with, which is the controller of that record.

D. How this data is used and shared. Telephony data is used to deliver the client's own business communications, to display message and call history inside that client's workspace, to calculate usage and billing, to enforce usage allowances, to detect fraud and abuse, and to respond to carrier, registry, or lawful regulatory and law enforcement requests. Message and call content is never sold, is never used for advertising, and is never used to train generalized artificial intelligence or machine learning models. It is disclosed only to Twilio and the carriers as technically necessary to transmit the communication, to our cloud hosting infrastructure that stores the workspace, to the registries and carriers for the registration purpose described above, and where compelled by valid legal process. Telephony data is isolated per tenant and is never disclosed to another Zarcore client.

E. Retention. Message logs, call detail records, and consent records are stored in the client's isolated workspace and are subject to the retention and deletion schedule in Section 6 of this Policy; voicemail audio is additionally subject to the rolling purge described in Section 4D(C). We may retain minimal billing and abuse-investigation metadata where required by law or by our carrier obligations. Twilio and the carriers retain their own transmission records under their own policies and legal obligations.

F. Opt-out and important limitations. Recipients of a client's CRM messages may opt out at any time by replying STOP to that client's number, and may reply HELP for assistance; opt-outs are recorded and enforced. Message and data rates may apply, and carriers are not liable for delayed or undelivered messages. Please note that the Platform's messaging and calling features are not a replacement for traditional telephone service and do not provide access to 911, E911, or any other emergency or public safety calling service, as described in Section 6A of our Terms of Service.

5. Data Security

Zarcore maintains a multi-layered security infrastructure designed to protect your business records:

  • Encryption: Data in transit is encrypted using modern TLS (Transport Layer Security) protocols, and data at rest (database rows, backups, uploaded files) is protected using strong encryption.
  • Access Control: Multi-tenant architecture with logical isolation and strict Role-Based Access Control (RBAC) ensures users only access data permitted by their admin.
  • Threat Monitoring & Audit Trails: Ongoing monitoring for brute-force attempts, unauthorized API calls, and anomalous database interactions, with security audit logs retained for review.
  • Backups: Rolling, encrypted disaster recovery snapshots are taken on an automated schedule.

6. Data Retention, Suspension, and Deletion Schedule

In accordance with Section 6 of our Terms of Service, Zarcore enforces an automated lifecycle for account termination, non-payment, and data destruction:

  • Active Accounts: We retain Customer Data for as long as a Tenant maintains an active, paid subscription to the Platform.
  • Post-Termination / Non-Payment Grace Period (30 Days): Upon voluntary cancellation, suspension for non-payment, or account termination, Client data transitions to an isolated, read-only status for thirty (30) calendar days (the "Data Retrieval Window"). Tenants remain solely responsible for exporting their data during this window.
  • Automated Permanent Purge (Day 31+): Following the close of the Data Retrieval Window, our automated backend protocol permanently deletes tenant records, database rows, and object-storage files from production systems.
  • Disaster Recovery Backup Rotation: Residual encrypted data fragments within rolling disaster recovery snapshots are rotated out and overwritten in the ordinary course, consistent with the timeline described in our Terms of Service.
  • Voicemail Recordings: Voicemail audio captured through the CRM telephony features is purged automatically on a rolling retention schedule, and is retained for an extended period only where a user of the workspace has affirmatively marked a specific voicemail to be kept. All voicemail audio is destroyed with the rest of the workspace under the schedule above.
  • Communications Logs and Registration Records: Email delivery, bounce, and complaint events, SMS and call logs, consent and opt-out records, and A2P messaging registration records are retained for the life of the workspace and destroyed under the schedule above, except for minimal billing, tax, anti-fraud, and carrier-compliance metadata that we are required to retain by law or by our provider obligations. Google, Microsoft, Resend, Twilio, and the mobile carriers retain their own transmission records under their own policies.

Note: Zarcore retains basic administrative metadata, Stripe invoice history, and corporate financial transaction logs solely as required by federal, state, and tax accounting regulations.

7. Your Privacy Rights and Choices

Depending on your jurisdiction (including under GDPR, CCPA/CPRA, and state privacy acts), you may have the following rights regarding your personal information held directly by Zarcore:

  • Right to Access / Know: Request details regarding the categories and specific pieces of personal information we maintain about you.
  • Right to Correction: Request correction of inaccurate or incomplete personal records.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal account information, subject to statutory tax and administrative retention exceptions.
  • Opt-Out of Marketing: Unsubscribe from promotional email communications via the link in any marketing message. Transactional and account security alerts will continue to be sent.

Submitting Requests: Primary account owners may exercise these rights by submitting a request to privacy@zarcore.com. If you are an employee or customer of a Zarcore Tenant business, please direct your privacy request directly to that business (the Data Controller for that workspace).

8. International Data Transfers & Compliance

Zarcore is headquartered in the United States and operates cloud infrastructure that may span multiple regions. Information collected via the Platform may be transferred to, stored, and processed in the United States or other jurisdictions where our cloud providers maintain facilities. When transferring data internationally, we rely on approved legal mechanisms, including Standard Contractual Clauses (SCCs) and GDPR-compliant Data Processing Agreements where applicable, together with the transfer mechanisms published by our sub-processors, including Stripe, Google, Microsoft, Twilio, and Resend (whose Data Processing Addendum incorporates the EU and UK Standard Contractual Clauses).

9. Children's Privacy

The Platform is an enterprise B2B operational system and is not directed to, intended for, or designed to attract individuals under eighteen (18) years of age. We do not knowingly collect or maintain personal information from minors.

10. Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our operational practices, module features, or legal requirements. When updates occur, we will revise the "Last Updated" date at the top of this page. For material changes affecting account management or data retention schedules, we will notify primary account owners via email or a prominent in-app notification prior to the change taking effect.

11. Contact Us

If you have questions, concerns, or legal inquiries regarding this Privacy Policy or our data protection practices, please contact us:

  • Zarcore Technologies LLC
  • Attention: Data Privacy & Compliance Officer
  • Website: www.zarcore.com
  • Email: privacy@zarcore.com (or submit an inquiry via our Website contact form)