Privacy & Trust

Privacy Policy

Your privacy is our priority. We are committed to protecting your data and being transparent about our practices.

Last updated: October 7, 2026

1. Introduction

ZynfoAI, a product of Nodebridge Labs LLP ("we," "our," or "us"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI chatbot platform and related services (collectively, the "Service").

By using our Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.

2. Information We Collect

2.1 Information You Provide

We may collect information that you voluntarily provide to us, including:

  • Account information (name, email address, company name)
  • Contact information for support and communication
  • Payment information, processed by Dodo Payments for plans bought on zynfo.ai, or by Shopify for plans bought in the ZynfoAI app for Shopify. We do not store card details.
  • Content you upload or provide access to, including documents and knowledge base materials
  • Data from third-party integrations (Google Drive files, Shopify store data, Freshdesk/Freshsales CRM data)
  • Chatbot conversations and interactions
  • Feedback and survey responses

2.2 Information We Collect Automatically

When you use our Service, we may automatically collect:

  • Usage data (pages visited, features used, time spent)
  • Device information (IP address, browser type, operating system)
  • Log data (access times, error logs, performance data)
  • Cookies and similar tracking technologies
  • Analytics data to improve our Service

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our Service
  • Process transactions and send related information
  • Send technical notices, updates, and support messages
  • Respond to your comments and questions
  • Monitor and analyze usage patterns and trends
  • Detect, prevent, and address technical issues
  • Comply with legal obligations
  • Protect the rights and safety of our users and others

4. Google API Disclosure

ZynfoAI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Service: User Data Policy, including the Limited Use requirements.

Our app uses Google Drive access so you can choose documents for your AI agent to answer from. We index those documents to find relevant passages when a question is asked. We do not use them to train or fine-tune AI models, and we do not share them with third parties except as necessary to provide the Service.

5. Information Sharing and Disclosure

5.1 We Do Not Sell Your Information

We do not sell, trade, or otherwise transfer your personal information to third parties for monetary consideration.

5.2 When We May Share Information

We may share your information in the following circumstances:

  • With your explicit consent
  • With service providers who assist us in operating our Service (for example Firebase for authentication, cloud hosting providers, AI model providers, and Dodo Payments for payments)
  • To comply with legal obligations or court orders
  • To protect our rights, property, or safety
  • In connection with a business transfer or acquisition
  • With your organization if you're using an enterprise account
  • With third-party platforms you explicitly choose to integrate (Shopify, Freshdesk, Freshsales, etc.)

6. Data Security

We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit and at rest
  • Regular security assessments and updates
  • Access controls and authentication mechanisms
  • Employee training on data protection practices
  • Incident response procedures

7. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. When we no longer need your information, we will securely delete or anonymize it.

8. Your Rights and Choices

Depending on your location, you may have the following rights:

  • Access: Request access to your personal information
  • Correction: Request correction of inaccurate information
  • Deletion: Request deletion of your personal information
  • Portability: Request transfer of your data to another service
  • Objection: Object to processing of your information
  • Restriction: Request restriction of processing
  • Withdraw consent: Withdraw consent for data processing

To exercise these rights, please contact us at support@zynfo.ai. We will respond to your request within 30 days.

9. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience on our Service. You can control cookie settings through your browser preferences. However, disabling cookies may affect the functionality of our Service.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure that such transfers comply with applicable data protection laws and implement appropriate safeguards to protect your information.

11. Children's Privacy

Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you become aware that a child has provided us with personal information, please contact us immediately.

12. Shopify Stores

This section applies when a merchant installs the ZynfoAI app from the Shopify App Store. The merchant is the controller of their customers' personal information, and ZynfoAI processes it on the merchant's behalf.

12.1 Data we access from Shopify

  • Store information: shop name, domain and the store owner's email, to set up the account.
  • Catalog and pages: products, inventory and online store pages, so the AI agent can answer from them.
  • Orders: when a signed-in shopper asks about their own order, we read that order (including name, email, phone, shipping address and status) to answer, cancel it or open a return request. Order details are read at the time of the request and are not stored.
  • Orders on the customer page: when a member of the store's team opens a customer in ZynfoAI, we look up that customer's recent orders by their email address and show the order number, status, total, date and number of items. These are read from Shopify at that moment and are not stored. No addresses or tracking details are shown.
  • Order attribution: for orders placed after a chat, we keep the order number, total and currency, with no customer details, to show the merchant sales from chat.
  • Checkouts and orders (automations): only while the merchant has an automation that uses them, when a checkout is started or updated, or an order is placed or fulfilled, we keep the cart or order value, item names and quantities, whether the buyer agreed to marketing, and the checkout recovery link, plus the buyer's email and phone number only while the merchant has emails outside the chat turned on. No names or addresses. This lets the merchant's automations send an abandoned-cart reminder or ask for feedback after the order ships. Checkouts are deleted after 30 days and orders after 90 days.

Messages outside the chat

Messages from a store's automations (an abandoned-cart reminder, a feedback request) are off until the merchant switches them on. They are marketing: we send them only to shoppers who agreed to marketing at checkout, with an unsubscribe link, within the per-shopper limit and quiet hours the store sets (by default one a day, and none between 21:00 and 08:00 in the store's time zone). Unsubscribing, or replying "STOP" on WhatsApp, stops them; we keep a coded record of the opt-out (not the address) so it keeps being honoured. WhatsApp messages follow Meta's opt-in and 24-hour messaging rules.

When a member of the store's team replies to a support ticket, we email that reply to the address on the ticket, from the store's name, with replies going to the store. These are support messages, not marketing, and they are sent only while the merchant has emails outside the chat turned on. We do not email addresses that bounced or reported our emails as spam. The reply is kept with the ticket and deleted with it.

12.2 Data shoppers give in the chat

Chat messages, and any name, email address or phone number a shopper chooses to share. We use this to answer the shopper, to let the merchant's team take over the conversation, and to create leads and support tickets for the merchant.

12.3 How we use it

Only to provide the ZynfoAI service to the merchant who installed the app. We do not sell shopper data, use it for advertising, or combine it across merchants. Merchant and shopper data is never used to train or fine-tune AI models. Messages are sent to our AI model provider only to generate a reply.

12.4 Service providers

  • Amazon Web Services: hosting, database, backups and logs
  • Cloudflare: app hosting, network and security
  • OpenAI, Anthropic and Google (Gemini): generating AI replies
  • Google Firebase: merchant sign-in
  • Resend: transactional email and store automation emails
  • Meta (WhatsApp): WhatsApp messages, when the merchant connects WhatsApp
  • PostHog: product analytics on merchant usage (no shopper chat content)

12.5 Retention and deletion

  • Conversations, leads and tickets are kept while the merchant uses ZynfoAI. Merchants can export conversations and leads from the app at any time, and can ask us to delete any of this data by emailing privacy@zynfo.ai.
  • When a merchant uninstalls the app, we remove the store's access immediately. 48 hours later, when Shopify sends its shop deletion request, we delete all of the store's data. If the store was linked to an existing ZynfoAI account, we remove the Shopify connection, the content synced from the store and the link to the store; the rest of that account stays under the merchant's ZynfoAI account.
  • When Shopify sends a customer deletion request, we delete that shopper's contact details, leads, tickets and stored checkouts and orders, and remove their chat messages. Customer data requests are handled for the merchant within 30 days.

12.6 Shoppers' rights

Shoppers should contact the store they bought from, which can export their data from ZynfoAI and ask us to delete it. Shoppers and merchants can also email privacy@zynfo.ai.

13. Contact us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Company: Nodebridge Labs LLP, India
Privacy: privacy@zynfo.ai
Support: support@zynfo.ai