Legal

Privacy Policy

This Privacy Policy explains how ZumPages collects, uses, discloses, stores, and protects personal information when you visit our websites, use our software, scan a connected product, or otherwise interact with our services.

Last updated: 11 September 2026

Important: Depending on the context, ZumPages may act as a data controller or data fiduciary for its own business operations, or as a processor/service provider acting on a business customer's documented instructions.

1. Scope and who we are

This Policy applies to ZumPages websites, applications, product pages, QR experiences, personalization tools, analytics, communications, and related services (collectively, the “Services”). “ZumPages,” “we,” “us,” and “our” refer to the operator of the Services and its owners, affiliates, personnel, and authorized service providers, as applicable.

A brand or business using ZumPages may independently determine why and how information about its customers is processed. In that situation, the brand is generally the controller or data fiduciary and ZumPages processes information on its behalf. Questions about a brand's practices should also be directed to that brand.

2. Information we collect

We may collect the following categories of information, depending on how the Services are used:

  • Account and business information: name, organization, role, login details, contact information, subscription, billing status, and account preferences.
  • Product and campaign information: product URLs, descriptions, media, ingredients, usage instructions, FAQs, campaign attributes, audience settings, and content submitted to create personalized experiences.
  • Customer and interaction information: page views, QR scans, clicks, referral source, campaign identifiers, approximate location derived from IP address, language, device/browser data, session events, chat content, survey responses, and purchase or conversion signals provided by a customer.
  • Technical and security information: IP address, device identifiers, timestamps, log files, cookie or similar identifiers, authentication events, diagnostics, fraud indicators, and security records.
  • Communications: messages, support requests, feedback, call or meeting details, and information voluntarily provided to us.
  • Information from integrations and public sources: information received through services you connect, public product pages, social channels, marketplaces, and authorized data providers.

Please do not provide sensitive personal data unless it is necessary, lawful, and specifically requested for the relevant Service.

3. How we use information

ZumPages and its owners may use information as reasonably required to operate and develop the business, subject always to applicable law, contractual restrictions, and the purposes described in this Policy. These uses may include:

  • providing, personalizing, maintaining, and securing the Services;
  • creating product pages, recommendations, content variations, analytics, and customer experiences;
  • processing transactions, managing accounts, and providing support;
  • measuring engagement, attribution, conversion, retention, and product performance;
  • improving, testing, researching, and developing features, models, systems, and business operations using aggregated, de-identified, or otherwise lawfully processed data;
  • communicating service, security, support, and permitted marketing messages;
  • detecting abuse, fraud, unlawful activity, and violations of our Terms;
  • complying with law, enforcing agreements, establishing or defending legal claims, and protecting people, property, and rights; and
  • supporting a merger, financing, acquisition, restructuring, sale of assets, or similar business transaction, subject to lawful safeguards.

We do not claim an unrestricted right to use personal data for any purpose. Where privacy law requires a defined purpose, legal basis, notice, consent, opt-out, or data-minimization measure, we will process information accordingly.

4. Legal bases under GDPR and similar laws

Where the GDPR, UK GDPR, or a similar law applies, we rely on one or more of the following legal bases:

  • Contract: processing necessary to provide Services requested by you or to take steps before entering a contract.
  • Legitimate interests: operating, securing, improving, and marketing our business where those interests are not overridden by your rights.
  • Consent: where consent is required, including for certain marketing, cookies, precise personalization, or sensitive data. Consent may be withdrawn prospectively.
  • Legal obligation: processing needed to comply with applicable law or lawful requests.
  • Vital interests or public interest: where these bases are available and genuinely applicable.

5. India Digital Personal Data Protection Act

Where India's Digital Personal Data Protection Act, 2023 and implementing rules apply, ZumPages processes digital personal data for lawful purposes on the basis of consent or a recognized legitimate use. We aim to provide clear notice, collect only information reasonably necessary for the stated purpose, maintain reasonable security safeguards, enable applicable Data Principal rights, and erase data when retention is no longer necessary unless law requires otherwise.

Data Principals may request access to information about processing, correction, completion, updating, erasure, grievance redressal, and nomination as available under applicable law. Consent may be withdrawn with the same general ease with which it was given, subject to the consequences of withdrawal and lawful retention.

6. Cookies, analytics, and personalization

We and authorized partners may use cookies, pixels, local storage, SDKs, and similar technologies for authentication, security, preferences, analytics, attribution, and personalization. Essential technologies support core operation. Where required, non-essential technologies are used with consent or another valid legal basis.

You may manage cookies through available consent controls and browser settings. Blocking technologies may affect functionality. Browser “Do Not Track” signals are not uniformly standardized; where legally required, we honor recognized opt-out preference signals such as Global Privacy Control.

7. How we disclose information

We may disclose information, only as reasonably necessary and legally permitted, to:

  • the business customer that configured the relevant product page or campaign;
  • cloud hosting, analytics, communications, payment, security, AI, storage, and professional service providers under appropriate obligations;
  • integrations and third parties you direct us to connect with;
  • affiliates, owners, advisers, investors, or transaction counterparties for legitimate business purposes;
  • government authorities or other parties when required by law or reasonably necessary to protect rights, safety, and security; and
  • a successor in connection with a merger, acquisition, financing, reorganization, insolvency, or sale of all or part of the business.

We may use and disclose aggregated or de-identified information for lawful business purposes where it cannot reasonably be linked back to an identifiable person. We do not sell personal data for money. If an activity is treated as a “sale,” “sharing,” or targeted advertising under applicable US state law, we will provide any required notice and opt-out right.

8. International data transfers

Information may be processed in countries other than where it was collected. Where required, we use safeguards such as adequacy decisions, standard contractual clauses, contractual commitments, and supplementary technical or organizational measures. Transfers from India will be handled subject to any applicable government restrictions.

9. Retention

We retain information for as long as reasonably necessary to provide the Services, fulfill the purposes described here, comply with law, resolve disputes, enforce agreements, protect security, and maintain legitimate business records. Retention depends on the data type, sensitivity, context, customer instructions, legal requirements, and operational need. We may retain de-identified information where lawful.

10. Security

We use reasonable administrative, technical, and organizational measures designed to protect information. No system, transmission, or storage method is completely secure, and we cannot warrant absolute security. You are responsible for protecting credentials, devices, and account access and for notifying us promptly of suspected misuse.

11. Your privacy rights

Depending on your location and applicable law, you may have rights to:

  • access or know about personal information and obtain a portable copy;
  • correct inaccurate or incomplete information;
  • delete or erase information;
  • restrict or object to certain processing;
  • withdraw consent without affecting prior lawful processing;
  • opt out of certain targeted advertising, sale, sharing, or profiling;
  • appeal a decision or complain to a regulator; and
  • receive equal service without unlawful discrimination for exercising privacy rights.

Submit requests to dan@zumpages.com. We may verify identity and authority before responding. If ZumPages processes data solely for a business customer, we may direct the request to that customer.

12. Children

The Services are not directed to children under 13, and we do not knowingly collect their personal information without legally valid authorization. Where higher age thresholds apply, including for consent-based processing in parts of the EEA or under India's DPDP framework, customers must obtain required parental consent and comply with restrictions on tracking, behavioral monitoring, or targeted advertising to children.

13. Third-party services

The Services may link to or integrate with third-party services. Their privacy practices are governed by their own notices, and ZumPages is not responsible for their independent conduct. Review those notices before providing information.

14. Changes and contact

We may update this Policy to reflect changes in law, technology, or business practices. The updated version will be posted with a revised date, and additional notice will be provided where legally required. Continued use after an update constitutes acknowledgment of the revised Policy, but does not replace consent where law requires consent.

For privacy questions, rights requests, or grievances, contact dan@zumpages.com. You may also lodge a complaint with the supervisory authority or Data Protection Board having jurisdiction over you.