Privacy Policy
Last updated: April 9, 2026
1. Introduction
Zappr Technologies Inc. ("Zappr", "we", "us", "our") is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Zappr platform (the "Service"). This policy complies with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Canadian privacy laws.
2. Information We Collect
Account Information
When you register, we collect your name, email address, password (hashed), and dealership information.
Vehicle & Inventory Data
We collect vehicle details (make, model, year, price, mileage, VIN, images) from your dealership's website through our inventory scraping feature, or as manually provided by you.
Payment Information
Payment processing is handled by Stripe. We do not store your full credit card number. We retain Stripe customer and subscription identifiers.
Browser Session Data
If you use the Zappr browser extension, we collect Facebook session cookies to facilitate marketplace posting on your behalf. These cookies are encrypted at rest and used solely for the purpose of posting vehicle listings.
Usage Data
We collect data about how you interact with the Service, including pages visited, features used, posting history, and error logs.
3. How We Use Your Information
We use your information to:
- Provide, operate, and maintain the Service
- Process transactions and manage subscriptions
- Create and post vehicle listings on third-party platforms on your behalf
- Generate AI-powered vehicle descriptions
- Send transactional emails (account verification, password resets, notifications)
- Improve the Service through aggregated analytics
- Respond to support requests
- Comply with legal obligations
4. How We Share Your Information
We do not sell your personal information. We may share information with:
- Stripe: for payment processing
- Meta/Facebook: vehicle listing data posted on your behalf to Facebook Marketplace
- Google (Gemini AI): vehicle details sent for AI description generation (no personally identifiable information is included)
- Resend: your email address for transactional email delivery
- Infrastructure providers (Vercel, Railway, Neon, Upstash): data stored and processed on their servers as required to operate the Service
- Legal authorities: when required by law, court order, or to protect our rights
5. Data Storage & Security
Your data is stored on servers located in North America, operated by our infrastructure providers. We implement industry-standard security measures including:
- AES-256 encryption for sensitive data at rest (e.g., browser cookies)
- TLS encryption for all data in transit
- Hashed passwords (bcrypt)
- JWT-based authentication with expiry
- Rate limiting on API endpoints
While we take reasonable steps to protect your information, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
6. Cookies & Tracking
The Service uses essential cookies for authentication and locale preferences. We do not use third-party advertising trackers. The Zappr browser extension collects Facebook session cookies solely for the purpose of posting vehicle listings and does not track your general browsing activity.
7. Your Rights Under PIPEDA
Under Canadian privacy law, you have the right to:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate information
- Withdrawal of consent: Withdraw your consent to the processing of your data (which may affect your ability to use the Service)
- Deletion: Request deletion of your personal data, subject to legal retention requirements
- Complaint: File a complaint with the Office of the Privacy Commissioner of Canada
To exercise any of these rights, contact us at the address below. We will respond within 30 days.
8. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you the Service. Upon account deletion, we will delete or anonymize your personal data within 90 days, except where retention is required by law or for legitimate business purposes (e.g., financial records).
9. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from minors.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 14 days before taking effect. Continued use of the Service after changes constitutes acceptance of the revised policy.
11. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at:
Zappr Technologies Inc., Montreal, Quebec, Canada