Privacy Policy
Effective as of August 8 2026
1. Who we are and what this policy covers
Zigglz is a product of PestoAI Inc., a Delaware corporation ("PestoAI Inc.", "we", "us", "our"). Zigglz is a platform that lets a merchant sell its products and services through AI conversations.
A merchant signs up, creates a site on Zigglz, and connects its own accounts to it, for example a Shopify store so that Zigglz knows its products and prices, and a messaging account such as Meta WhatsApp, Instagram, Messenger or SMS so that conversations can happen on the merchant's own channels. The merchant then promotes that channel to its own customers, for example by putting its WhatsApp number on its website. Those customers can ask questions, place orders, book appointments and more, and the AI answers on the merchant's behalf.
Customers are usually dealing with the merchant, on the merchant's own number, account and branding, and will often not know that Zigglz is involved at all. That is by design: we are the technology behind the merchant's assistant, not a party to the merchant's relationship with its customer. It also means the merchant, not us, is the one who has to tell its customers that a provider like us processes their information. See section 12.
This policy explains what personal information we handle, why we handle it, who we share it with, how long we keep it, and what rights you have. It applies to our website at www.zigglz.com, the Zigglz console (on the web, iOS and Android), our APIs, and the AI conversation channels we operate on behalf of merchants.
It does not apply to the websites, apps or services of any business that uses Zigglz, or to any third party service you connect to your account. Those are governed by their own policies.
2. The three groups this policy covers, and our different roles
Please read the part that applies to you, because our responsibilities differ:
- Visitors - people who browse www.zigglz.com. We decide how this information is used, so we are the "controller" (or "business" under US state law).
- Merchants - the businesses that hold a Zigglz account, and the individual people at those businesses who sign in and operate a site. We also call them Platform Users in our Terms. We are the controller for their account information.
- Customers, also called subscribers - the end customers of those merchants, who talk to a merchant's AI assistant on a channel the merchant has connected, or are added to it by the merchant. "Customer" and "subscriber" mean the same thing. We say "customer" in this policy because that is what they are to the merchant, but the Zigglz console, our API and our documentation call the same person a "subscriber", so you will see both. Here we act as a "processor" (or "service provider") on behalf of that merchant. The merchant decides what to collect and why, and we handle it on their instructions. As explained in section 1, these customers are usually unaware that Zigglz is involved, because they are talking to the merchant.
If you are a Customer, the merchant you were dealing with is the first place to go with a privacy question or request, and that will normally be whoever owns the phone number, account or shop you were messaging. We will help that merchant respond, but we are generally not permitted to make decisions about their data on our own. See section 12.
3. Information we collect
We collect the following categories. Not all of it applies to every person.
- Account and contact information: first and last name, email address, phone number, postal address, password credentials (stored in hashed or otherwise protected form by our authentication provider), account and permission settings, and the identity of anyone you invite to your site.
- Merchant and site content: the products, services, prices, descriptions, images, policies, opening hours, service areas, locations and AI instructions a merchant puts into the platform or syncs from a connected store, along with any website content a merchant asks us to crawl so the AI can answer questions about it.
- Customer records (called subscriber records in the console and API): information about a merchant's own customers, created either by the merchant, through our API, through a connected store, or by the customer during a conversation. This can include name, email address, phone number, delivery and billing addresses, order and purchase history, appointments, linked physical devices such as an access card or serial number, loyalty or points balances, identifiers linking the customer to an account in the merchant's own system, and free text notes.
- Identifiers a merchant chooses to require: some merchants need a local identifier such as a national ID, licence or membership number to identify their customer. We store this only where the merchant has configured it. It can be sensitive, and it is collected on the merchant's instructions and under the merchant's own legal basis, not ours.
- Conversation content: the messages exchanged between a customer and the AI assistant, and between a customer and a human agent where a merchant uses handoff, including anything the person chooses to type into that conversation. Support requests and tickets are also recorded.
- Payment information: for merchants, our payment processor collects and holds card details for subscription billing. We do not store full payment card numbers, security codes or bank account numbers on our systems. Where a merchant processes payments through its own connected account or its own systems, we may hold only a non-sensitive representation of a payment method, meaning a label, the type, a display identifier such as the last four digits of a card, and an expiry date. That is a reference for the customer to choose from, not a means of payment.
- Technical and usage information: IP address, device and browser type, operating system, app version, pages viewed, features used, timestamps, referring pages, approximate location derived from IP address, crash and diagnostic data, and log records of API requests.
- Cookies and similar technologies: see section 14.
We do not intentionally collect special category data (such as health, biometric, genetic, racial or ethnic origin, religious belief, trade union membership, sex life or sexual orientation data) or criminal offence data, and we ask that you do not put it into the platform. If a customer volunteers such information in a conversation it will be stored as part of that conversation.
4. Where the information comes from
- Directly from you, when you sign up, configure a site, contact support or take part in an AI conversation.
- From a merchant, when it uploads or syncs its customer records to us, including through our API.
- Automatically, from your device and browser when you use our website, apps or APIs.
- From messaging channels, when a customer messages a merchant on a channel such as WhatsApp, Instagram, Messenger or SMS that the merchant has connected. On those channels we receive the message and the sender's channel identifier, such as their phone number or account handle.
- From accounts a merchant connects to its site, such as a Shopify store, which is how we learn the merchant's products, prices and related information, and in some cases its customer and order records. The merchant authorises that connection and controls what it shares.
- From public web pages a merchant asks us to crawl so the AI can answer questions about that merchant.
5. How we use information, and our legal bases
We use information to:
- Provide, operate, secure and maintain the platform, including running AI conversations, processing orders and appointments, sending notifications, and keeping accounts and sites working.
- Authenticate users and protect against fraud, abuse, spam and security incidents.
- Bill merchants and manage subscriptions.
- Provide customer support and respond to requests.
- Understand how the platform is used so we can improve it, fix problems and develop new features.
- Send service messages about your account, and, where permitted, marketing about our own products. You can opt out of marketing at any time.
- Comply with law and enforce our terms.
Where the UK GDPR or EU GDPR applies and we act as controller, our legal bases are: performance of a contract (providing the service you asked for and billing for it); legitimate interests (securing the platform, preventing fraud and abuse, improving the service, and direct marketing to existing business customers, balanced against your rights); consent (non-essential cookies and certain marketing, which you can withdraw at any time); and legal obligation (tax, accounting and responding to lawful requests). Where we act as processor for a merchant, that merchant is responsible for having a legal basis for the data it asks us to handle.
6. Artificial intelligence, and its limits
The AI features of Zigglz work by sending the relevant parts of a conversation, together with context such as the merchant's product catalogue, settings and instructions, to an AI model provider so that a response can be generated. Today those providers are OpenAI and Amazon Web Services (through Amazon Bedrock). We use their business and API offerings, which as of the effective date of this policy do not use content submitted through the API to train their general purpose models by default. We may change or add AI providers, and will update this policy when we do.
Merchants can also connect their site to third party AI assistants and channels. Where a merchant does that, the conversation happens partly on the third party's platform and that third party's own privacy policy also applies.
AI output can be wrong. AI systems generate text by prediction, not by looking up guaranteed facts. Answers, prices, availability, descriptions, recommendations and other output may be inaccurate, incomplete, out of date or unsuitable, and may occasionally be presented confidently while still being wrong. Do not rely on AI output as professional, legal, financial, medical or safety advice. Merchants are responsible for reviewing and standing behind what their AI assistant tells their customers, and customers should confirm anything important with the merchant directly. Our liability for AI output is addressed in our Terms & Conditions.
We do not use AI to make decisions that produce legal effects concerning you, or that similarly significantly affect you, without human involvement. If that changes we will tell you and explain your rights.
We do not use the personal information in your account or your customers' records to train our own general purpose AI models.
7. Who we share information with
We share information with the following categories of recipient, only as needed:
- The merchant you are dealing with. If you are a customer, the merchant whose AI you talked to receives your information. That is the point of the service, and in most cases that merchant is the party you thought you were dealing with all along.
- Infrastructure and hosting: Amazon Web Services, for hosting, storage, databases, authentication, email delivery, push notifications, search and, where used, AI inference.
- AI model providers: OpenAI, and Amazon Web Services through Amazon Bedrock, as described in section 6.
- Payments: Stripe, for subscription billing and, where a merchant connects its own payment account, for payments between that merchant and its customers.
- Messaging channels: Meta (WhatsApp, Messenger and Instagram), Twilio, Glassix and Simasti, to deliver and receive messages on the channels a merchant has connected.
- Email and marketing tools: providers such as ActiveTrail and Mailchimp, where a merchant connects them.
- Commerce and website platforms: Shopify, where a merchant connects it, so that products, prices and related records can be synchronised.
- Maps and address services: Google, for address lookup, address completion and time zone information.
- Analytics and marketing measurement on our own website: Google Analytics and Google Tag Manager. See section 14.
- App distribution and push notifications: Apple and Google.
- Professional advisers: lawyers, accountants, auditors and insurers, under duties of confidentiality.
- Legal and safety: courts, regulators, law enforcement and other parties, where we believe in good faith that disclosure is required by law or is necessary to protect the rights, property or safety of PestoAI Inc., our users, or the public. Where we are legally permitted, we will try to notify the affected merchant before disclosing their data.
- Business transfers: an acquirer or successor, in connection with a merger, acquisition, financing, reorganisation or sale of assets, subject to this policy continuing to apply to the transferred information.
When a merchant connects a third party service to its site, that merchant chooses to do so and is responsible for that transfer and for the third party's handling of the data.
Our service providers are bound by contract to use the information only to provide services to us and to keep it secure.
8. We do not sell your personal information
We do not sell personal information, and we do not share it for cross-context behavioural advertising or targeted advertising, as those terms are defined under California and other US state privacy laws. We have not done so in the preceding twelve months. We do not knowingly sell or share the personal information of anyone under 16.
9. International transfers
We are based in the United States and our infrastructure and service providers may process information in the United States and other countries. Those countries may have data protection laws that differ from those where you live.
Where we transfer personal information out of the United Kingdom, the European Economic Area or Switzerland, we rely on an appropriate safeguard, normally the European Commission's Standard Contractual Clauses together with the UK Addendum, and we carry out a transfer risk assessment where required. You can ask us for a copy of the safeguards we use by contacting us at the address in section 17.
10. How long we keep information
We keep personal information for as long as it is needed for the purpose it was collected for.
- Merchant account data: for as long as the account is open, and normally for up to 12 months after closure, so an account can be recovered and disputes resolved.
- Customer records, orders, appointments and conversations: for as long as the merchant keeps them on the platform. In the ordinary course we do not delete a merchant's data on our own initiative and we do not put a time limit on it, but see the reservation below. A merchant controls deletion in these ways: deleting an individual customer record; deleting the site, which removes that site's customers, orders, appointments and conversations along with it; or closing the Zigglz account, which removes the merchant's own information and every site under it. A customer can also ask the AI to delete their account where the merchant has enabled that. Step by step instructions are on our Data Deletion page. Until a merchant takes one of those steps, we continue to hold that information, including order history, on the merchant's behalf.
We reserve the right to delete data ourselves. We may suspend, terminate and delete an account, a site and everything held under it where the merchant is in default on payment, is in breach of our Terms, is using the Service unlawfully, where the account has been inactive for an extended period, or where we otherwise decide the account must be closed. See section 16 of our Terms & Conditions. Where we lawfully can, we will give notice and an opportunity to export first, but we are not obliged to retain data for a merchant we have terminated.
- Billing and tax records: for as long as tax and accounting law requires, normally seven years.
- Security and system logs: normally up to 12 months.
- Backups: deleted data may persist in encrypted backups for a limited period before being overwritten on our normal backup cycle.
We may keep information for longer where we are required to by law, or where it is needed to establish, exercise or defend legal claims.
11. How we protect information
We use technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls and least privilege, network isolation, separate storage of integration credentials, logging and monitoring, and regular patching. Payment card details are handled by our payment processor and do not reach our servers.
No system is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your login credentials, API keys and integration tokens confidential, and for telling us promptly if you believe your account has been compromised. If we become aware of a personal data breach affecting you, we will notify you and the relevant regulators where the law requires it, and within the timescales the law sets.
12. Merchants are responsible for their own customers
This is important, so we want to be clear about it.
A merchant that uses Zigglz decides what personal information to collect from its own customers, what to use it for, how long to keep it, and who else to share it with. That merchant is the controller of that information. We act on its instructions.
Because a merchant's customers are dealing with the merchant and will often not know that Zigglz exists, they will usually never see this policy. It is the merchant's job, not ours, to tell them. Each merchant is responsible for its own privacy policy, its own terms and conditions, and its own notices and consents to its customers. That includes disclosing in its own privacy policy that a provider such as PestoAI Inc. processes their information on the merchant's behalf, and obtaining any consent needed to send marketing, to message them on channels such as WhatsApp, Instagram, Messenger or SMS, to record and process conversations with an AI, or to collect an identifier such as a national ID number.
Each merchant is also responsible for having a lawful basis for what it asks us to process, for responding to its customers' privacy requests, and for complying with the consumer protection, advertising, e-commerce and messaging laws that apply to it.
How a merchant acts on a customer's deletion request. A merchant can delete an individual customer record, delete the site (which removes that site's customers, orders, appointments and conversations with it), or close its Zigglz account (which removes the merchant's own information and every site under it). Those are the merchant's own controls, and it is for the merchant to use them when a customer asks. See our Data Deletion page. Until it does, we continue to hold that information on the merchant's behalf, including order history. We do not ordinarily delete it for them, though we reserve the right to delete an account and its data as described in section 10 and in our Terms & Conditions.
PestoAI Inc. does not assume responsibility for a merchant's privacy practices, its terms, its notices, its consents, or its compliance with law, and is not the controller of the customer information it asks us to handle. If you are a customer of a merchant and you have a question or a request about your information, contact that merchant first. We will support them in responding, and we will pass on requests we receive directly.
Where a merchant needs a data processing agreement with us, contact us at the address in section 17.
13. Your privacy rights
If you are in the United Kingdom, the European Economic Area or Switzerland, you have the right to access your personal information, to have it corrected, to have it erased, to restrict or object to how we use it (including objecting to direct marketing at any time), to data portability, and to withdraw consent where we rely on it. Withdrawing consent does not affect processing carried out before you withdrew it. You also have the right to complain to your local supervisory authority, though we would appreciate the chance to address your concern first.
If you are in California, you have the right to know what personal information we collect, use, disclose and (if applicable) sell or share, and the categories of source and recipient; the right to a copy of your personal information; the right to correct inaccurate information; the right to delete; the right to opt out of sale or sharing (we do not sell or share, as explained in section 8); the right to limit the use of sensitive personal information; and the right not to receive discriminatory treatment for exercising your rights. You may use an authorised agent, and we may ask for proof of their authority.
If you are in another US state with a comprehensive privacy law, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware and others as they take effect, you have broadly equivalent rights to access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale and certain profiling. Where the law provides it, you may also appeal a decision we make about your request by replying to our response.
Wherever you are, you may ask us the questions above and we will do our best to help, whether or not the law where you live requires it.
To exercise a right, email us at support@zigglz.com. We will verify your request, usually by confirming control of the email address or phone number on the account, and we will respond within the time the applicable law allows, normally one month in the UK and EEA and 45 days in the United States, and we will tell you if we need longer. There is no charge unless your request is manifestly unfounded or excessive.
If your request concerns information we hold on behalf of a merchant, we will refer you to that merchant or forward your request to them, as described in section 12. We do not decide what happens to a merchant's customer records, so a deletion request normally has to be actioned by the merchant. That is separate from our own right to terminate and delete an account, which is described in section 10.
14. Cookies, analytics and tracking
On www.zigglz.com we use cookies and similar technologies that are strictly necessary to make the site work, and analytics and marketing measurement cookies provided by Google Analytics and Google Tag Manager, which help us understand how the site is used.
Where the law requires consent for non-essential cookies, we ask for it through the cookie banner on the site, and you can change your choice at any time using the same banner. You can also block or delete cookies in your browser settings, though parts of the site may then not work properly.
We honour the Global Privacy Control signal where the law requires us to treat it as an opt out. We do not currently respond to browser "Do Not Track" signals, because there is no common standard for them.
The Zigglz console and the AI conversation channels use only the storage necessary to keep you signed in and to run the service.
15. Children
Zigglz is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16, and merchant accounts are only for people aged 18 or over. If you believe a child has given us personal information, contact us and we will delete it. A merchant that uses Zigglz in a way that reaches children is responsible for complying with the laws that apply to that, including the Children's Online Privacy Protection Act in the United States and the equivalent rules on children's consent under the UK and EU GDPR.
16. Changes to this policy
We may update this policy from time to time. When we do, we will change the effective date at the top of the page and post the new version here. If the change is significant, we will give merchants reasonable notice by email or through the console before it takes effect. Please review this page periodically.
17. How to contact us
PestoAI Inc. (operator of Zigglz)
Email: support@zigglz.com
For privacy questions, requests, data processing agreements, or to ask for a copy of the safeguards we use for international transfers, please use the address above and tell us what you need. If you are in the UK or EEA and wish to raise a matter with a supervisory authority, you may do so in the country where you live or work.
