Privacy Policy

Last updated: April 9, 2026

1. Introduction

Zappr Technologies Inc. ("Zappr", "we", "us", "our") is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Zappr platform (the "Service"). This policy complies with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Canadian privacy laws.

2. Information We Collect

Account Information

When you register, we collect your name, email address, password (hashed), and dealership information.

Vehicle & Inventory Data

We collect vehicle details (make, model, year, price, mileage, VIN, images) from your dealership's website through our inventory scraping feature, or as manually provided by you.

Payment Information

Payment processing is handled by Stripe. We do not store your full credit card number. We retain Stripe customer and subscription identifiers.

Browser Session Data

If you use the Zappr browser extension, we collect Facebook session cookies to facilitate marketplace posting on your behalf. These cookies are encrypted at rest and used solely for the purpose of posting vehicle listings.

Usage Data

We collect data about how you interact with the Service, including pages visited, features used, posting history, and error logs.

3. How We Use Your Information

We use your information to:

  • Provide, operate, and maintain the Service
  • Process transactions and manage subscriptions
  • Create and post vehicle listings on third-party platforms on your behalf
  • Generate AI-powered vehicle descriptions
  • Send transactional emails (account verification, password resets, notifications)
  • Improve the Service through aggregated analytics
  • Respond to support requests
  • Comply with legal obligations

4. How We Share Your Information

We do not sell your personal information. We may share information with:

  • Stripe: for payment processing
  • Meta/Facebook: vehicle listing data posted on your behalf to Facebook Marketplace
  • Google (Gemini AI): vehicle details sent for AI description generation (no personally identifiable information is included)
  • Resend: your email address for transactional email delivery
  • Infrastructure providers (Vercel, Railway, Neon, Upstash): data stored and processed on their servers as required to operate the Service
  • Legal authorities: when required by law, court order, or to protect our rights

5. Data Storage & Security

Your data is stored on servers located in North America, operated by our infrastructure providers. We implement industry-standard security measures including:

  • AES-256 encryption for sensitive data at rest (e.g., browser cookies)
  • TLS encryption for all data in transit
  • Hashed passwords (bcrypt)
  • JWT-based authentication with expiry
  • Rate limiting on API endpoints

While we take reasonable steps to protect your information, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.

6. Cookies & Tracking

The Service uses essential cookies for authentication and locale preferences. We do not use third-party advertising trackers. The Zappr browser extension collects Facebook session cookies solely for the purpose of posting vehicle listings and does not track your general browsing activity.

7. Your Rights Under PIPEDA

Under Canadian privacy law, you have the right to:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate information
  • Withdrawal of consent: Withdraw your consent to the processing of your data (which may affect your ability to use the Service)
  • Deletion: Request deletion of your personal data, subject to legal retention requirements
  • Complaint: File a complaint with the Office of the Privacy Commissioner of Canada

To exercise any of these rights, contact us at the address below. We will respond within 30 days.

8. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you the Service. Upon account deletion, we will delete or anonymize your personal data within 90 days, except where retention is required by law or for legitimate business purposes (e.g., financial records).

9. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from minors.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 14 days before taking effect. Continued use of the Service after changes constitutes acceptance of the revised policy.

11. Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at:

support@getzapper.ca

Zappr Technologies Inc., Montreal, Quebec, Canada