This Privacy Policy explains how ZiRoks (“ZiRoks”, “we”, “us”)
handles personal information in connection with our websites, FreeBot (our free website chatbot) and SmartBOS (our paid AI
communications platform) (together, the “Service”). The Service is offered in the United States to businesses
whose account holders are 18 or older. Our Terms of Service also apply.
1. Two roles
- Our own visitors, prospects and customers. For people who visit our websites, request a demo, sign up,
join our referral program or use a FreeBot or SmartBOS account, we decide how their information is used.
- Our customers’ customers. When people chat, email, text or call a business that uses the Service,
we process their information to provide the Service to that business. The business decides how that information is
used, is responsible for its own lawful collection and use of it, and is responsible for its own privacy notice.
We are responsible for our own handling of it.
2. Information we collect
Account and business information
Names, sign-in email addresses, business name and profile details, user roles and memberships. Passwords are stored only
as a one-way hash.
Forms on our websites
- Demo request form: name, email address, phone number, company, website, the service you are interested
in, a referral code if you enter one, and your message.
- FreeBot signup: email address, website address, an optional phone number, optional referral details,
your confirmation that you own the website, your acceptance of our Terms and this Privacy Policy (including which
versions you accepted), and your optional choice about product updates.
- Referral registration: business name, your name, email address, phone number, website and notes.
Communications we handle for a business
- Website chat: visitors’ messages, contact details they choose to give, and the replies written by
the AI Employee or the business’s staff.
- Email: the content and addresses of messages to and from the mailbox a business connects.
- Text messages (SMS): phone numbers and message content. Messages pass through our SMS gateway and a
mobile carrier, and a copy is kept in the gateway’s own database as well as in the business’s
conversation history.
- Phone calls: the caller’s number (caller ID), call times and duration, and a text record of the
conversation, kept in the business’s conversation history.
- Contact details such as name, phone number, email address, time zone and language, and appointment or service
requests.
Call recordings and voicemail
- Calls answered by an AI Employee begin with the announcement “This call is being recorded for quality assurance.
You are speaking with an AI employee.” Recording begins after the announcement.
- If a call is transferred to the business’s staff, the recording continues after a staff member answers.
- Outside a business’s hours, callers may reach voicemail. A voicemail message is an audio recording of what the
caller says, together with the caller’s number and name if available.
Business knowledge
Publicly available content from a business’s website, read at the business’s request, and documents the
business uploads.
Billing information
Plan, invoices, payments, refunds and disputes, and the billing name and email address. Card payments are handled by our
payment provider. We keep the provider’s reference numbers for the customer and the saved card, and the card brand,
last four digits and expiry date so that we can show which card is on file. We do not store full card numbers or security
codes.
Messaging preferences and consent records
Consents, opt-outs (including STOP replies), unsubscribes and phone-number verification records. Verification codes are
stored only in hashed form. Consent records can include the IP address and browser information at the time.
Referral and campaign information
If you arrive through a campaign or referral link: campaign (UTM) parameters, referral codes, the page you landed on, the
website that referred you, and a referral token that we store only in hashed form.
Technical and security information
IP address and browser information (user agent) when you submit a demo request, FreeBot signup or consent; security and
audit records; and application logs.
Cloudflare Turnstile
Our public forms use Cloudflare Turnstile to check that a real person is submitting them. Your browser loads
Cloudflare’s script, and Cloudflare receives your IP address and browser information. When you submit the form we send
Cloudflare the check’s result token and your IP address to confirm it. Cloudflare’s own privacy notice describes
how Cloudflare handles that information.
Connected services
Credentials and identifiers for a mailbox or Google Calendar a business chooses to connect, stored encrypted, and the
calendar events used for scheduling.
3. Cookies and browser storage
We use only first-party cookies that the Service needs to work:
- a session cookie that keeps you signed in and protects forms (it expires after a period of inactivity), and a
security token cookie;
- a “remember me” cookie, only if you choose to stay signed in;
- a campaign cookie, only when you arrive through a link carrying campaign or referral details (up to 90 days);
- a referral cookie, only when you arrive through a partner’s referral link (up to 30 days).
The website chat on a business’s site sets no cookie from us. It keeps a temporary chat-session identifier in your
browser’s session storage for the visit. Our dashboard keeps unsent reply drafts in session storage. We do not use
analytics, advertising or tracking cookies, and we do not use tracking pixels. Cloudflare Turnstile runs on our forms
as described above.
4. How we use information
- to provide, operate, secure and support the Service;
- to generate AI replies and route conversations to a business’s staff;
- to verify email addresses, phone numbers and accounts;
- to bill and collect payment;
- to send service messages, such as verification, security, billing, legal notices, service status, support and account
messages;
- to prevent fraud, spam and abuse;
- to understand how people found us and to run our referral program;
- to meet legal obligations; and
- to send you product updates about ZiRoks if you have chosen to receive them. You can stop them at any time.
Stopping them does not stop service messages.
5. AI processing
- To write a reply, the relevant conversation, the customer’s message and the business’s information are sent
to the AI model provider that powers the Service. Some processing uses models hosted on ZiRoks-operated
servers.
- On phone calls, the caller’s speech is converted to text on ZiRoks-operated servers. That text is sent to
the AI model provider to write the reply, and the reply text is sent to a text-to-speech provider, which may be an
AI provider, to produce the spoken reply.
- The AI providers we use may change over time.
- We do not use your conversations or recordings to train general-purpose AI models without your explicit authorization.
Any such authorization would be a separate, specific choice. Accepting our Terms or this Privacy Policy is not
authorization.
6. Aggregated and de-identified information
We may use aggregated or de-identified information to operate and improve the Service, including for reliability,
security and fraud detection, usage measurement, performance and capacity planning. We do not try to re-identify people from
it or use it to target them.
7. How we share information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We
share it only:
- with service providers that help us run the Service, in these categories: hosting and infrastructure; AI model and
text-to-speech providers; payment processing; email delivery; telecommunications, voice and SMS carriers;
security and anti-abuse (Cloudflare Turnstile); and backup storage;
- with the business you are communicating with;
- with services a business chooses to connect, such as a calendar or mailbox provider;
- when required by law, or to protect rights, property and safety; and
- as part of a reorganization, merger, financing, or sale of all or part of our business, subject to applicable privacy
obligations.
Mobile phone numbers and text-messaging consent are not shared with third parties for their own marketing.
8. How long we keep information
- Call recordings are kept for 30 days and are then deleted automatically. Copies inside the voice
system’s disaster-recovery backups may last until those backups are replaced on their normal cycle.
- Voicemail messages are kept until the business deletes them.
- Account data, contacts and conversation history (including the text of calls) are kept while the
account is active, so the business can use its history.
- FreeBot signups that are never verified are deleted automatically shortly after the verification
period ends.
- When an account is closed, there is a 30-day wind-down period during which it can be reopened. We do
not currently promise a specific date after that by which data is deleted.
- Records we keep for legal, tax, billing, fraud-prevention, security, audit or dispute purposes —
including invoices and payments, records of acceptance of our Terms and this Privacy Policy, consent and opt-out
records, and security and audit records — are kept after an account closes.
- Other records, such as demo requests and referral records, are kept for as long as we need them for the purposes
above. We have not yet set fixed periods for these records and will update this policy when we do.
- Backups are kept on a rotating schedule and expire automatically.
9. Your choices and rights
- Text messages: reply STOP to stop texts from a business. The Service records your opt-out and the
business cannot override it.
- Email: use the unsubscribe link in a marketing email.
- Product updates from us: they are optional and off unless you choose them. You can stop them at any
time through our contact form.
- If you are a customer of a business that uses the Service, please contact that business about your
information first. We will help it respond.
- Access, correction and deletion: depending on the state you live in, you may have rights to access,
correct or delete your personal information. To make a request, use our contact form
and say that it is a privacy request. We may need to verify your identity. We will not treat you differently for
making a request.
10. Security
We use encrypted connections, one-way hashed passwords, encrypted storage for connected-service credentials, access
controls, audit logging and regular backups. No system is perfectly secure, and we cannot guarantee the security of
information.
11. Health information and other sensitive information
The Service is not designed for protected health information, payment card numbers or other sensitive or regulated data,
and we do not offer HIPAA-covered services or sign business associate agreements. Please do not share card numbers or health
details in chats, texts or calls. The Service is not an emergency service.
12. Children
The Service is for businesses, and account holders must be 18 or older. It is not directed to children, and we do not
knowingly collect personal information from children under 13.
13. Changes to this policy
Each version of this policy has a version number and an effective date, shown at the top. We will give appropriate notice
of material changes.
For questions or privacy requests, please use our contact form or our website chatbot.
We do not publish an email address on our websites.