Effective Date: 01 Jan 2025
Last Updated: 27 April 2026
Version: 2.0
Website: https://zepychat.com
Brand Name: ZepyChat
Legal Entity: ZepyPay Technologies
Business Structure: Sole Proprietorship
This Privacy Policy explains how ZepyChat collects, uses, stores, processes, shares, and protects information when users visit our website, create accounts, purchase subscriptions, contact support, or use our services.
By accessing or using our website or services, you agree to this Privacy Policy.
1. Business Information
Legal Owner: Imran Khan
Legal Business Name: ZepyPay Technologies
Brand Name: ZepyChat
GST Registration Number: 09LXIPK1850Q1ZK
UDYAM Registration Number: UDYAM-UP-29-0200699
Registered Address:
KH No. 1113/1, Shanker Vihar, Lal Kuan, Near Shiv Mandir, Ghaziabad, Uttar Pradesh – 201001, India
General Contact: info@zepychat.com
Privacy Contact: privacy@zepychat.com
Support Requests: help@zepychat.com
Phone: +91 9990665076
2. Scope of This Policy
This policy applies to:
- website visitors
- registered users
- subscribers
- customers
- business users
- support inquiries
- prospective customers
3. Sources of Information
We may collect information from:
- data provided directly by users
- account registrations
- website usage activity
- cookies and tracking tools
- connected integrations
- support requests
- billing and payment events
4. Categories of Data We Collect
We may collect:
- personal data
- account data
- billing data
- technical data
- communication data
- analytics data
- support records
5. Personal Information
May include:
- full name
- email address
- mobile number
- business name
- billing address
- tax details where required
6. Account Information
May include:
- username
- login credentials (secured where applicable)
- profile details
- plan information
- user settings
7. Technical Information
May include:
- IP address
- browser type
- device type
- operating system
- login timestamps
- pages visited
- session activity
- diagnostics data
8. Payment Information
Payments may be handled by secure third-party processors.
We may receive limited information such as:
- payment status
- transaction ID
- invoice details
- masked payment method information
- billing cycle status
We do not intentionally store full card or sensitive banking credentials unless handled by authorized processors.
9. Auto Pay / ECS / Recurring Billing Data
If recurring billing is enabled, payment providers may process:
- auto debit instructions
- e-mandate status
- renewal attempts
- subscription renewals
- failed payment notifications
10. Communication Data
When users use messaging, CRM, chatbot, or automation tools, certain operational data may be processed such as:
- templates
- timestamps
- routing data
- delivery events
- support interactions
- automation triggers
11. How We Use Information
We may use data to:
- create accounts
- provide services
- activate subscriptions
- process billing
- send invoices
- provide support
- improve features
- detect fraud or misuse
- maintain security
- communicate updates
- comply with legal obligations
12. Lawful Basis of Processing
Depending on applicable laws, processing may rely on:
- consent
- contract necessity
- legitimate interests
- legal compliance
- fraud prevention
Rights and legal bases may vary depending on country or region.
13. Data Controller / Processor Roles
Where users upload or manage customer data:
- user or business may act as Data Controller
- ZepyChat may act as Data Processor for service delivery
Users remain responsible for ensuring lawful collection and use of their customer data.
14. Workspace / Team Admin Access
For multi-user accounts, authorized workspace owners or administrators may manage users, permissions, and certain workspace data.
15. User Responsibility for Imported Data
Users are responsible for ensuring that contacts, leads, customer lists, and uploaded data have been lawfully collected and may be used through the platform.
16. Third-Party Integrations
We may connect with:
- Meta services
- payment gateways
- cloud hosting providers
- analytics tools
- communication vendors
- API integrations
These third parties operate under their own policies and terms.
17. Cookies and Similar Technologies
We may use cookies, pixels, scripts, SDKs, or similar tools for:
- login sessions
- remembering preferences
- analytics
- security
- performance optimization
- campaign measurement
18. Cookie Controls
Users may manage cookies through browser settings. Blocking some cookies may affect certain functions.
Our website may not respond to all browser “Do Not Track” signals.
19. Marketing Communications
We may send service notices, billing alerts, feature updates, or promotional communications where permitted. Users may unsubscribe from optional marketing messages.
20. Data Sharing
We do not sell personal data as our primary business model.
We may share data where reasonably necessary with:
- service providers
- payment processors
- hosting partners
- analytics vendors
- advisors
- authorities when legally required
21. Legal Requests and Disclosures
We may disclose information where reasonably necessary to comply with lawful requests, court orders, legal obligations, fraud investigations, or protection of rights and security.
22. Subprocessors
We may use external vendors or subprocessors for hosting, communication, analytics, billing, support, or technical operations. Such providers may change from time to time.
23. International Data Transfers
Some data may be stored or processed in different countries depending on infrastructure or service providers.
24. Data Retention
We retain information only as long as reasonably necessary for:
- service delivery
- billing records
- tax compliance
- legal obligations
- dispute handling
- fraud prevention
- security logs
25. Backup Retention
Deleted or modified data may remain in backups or archives for a temporary period before final removal.
26. Account Closure Data
If an account is closed, certain records may remain retained for compliance, taxation, fraud prevention, or legitimate business purposes.
27. Data Minimization
We aim to collect and process only information reasonably necessary for legitimate business and service purposes.
28. Data Accuracy
Users should keep their account, billing, and contact information accurate and updated.
29. Security Measures
We use commercially reasonable safeguards such as:
- secure systems
- access controls
- monitoring systems
- encryption in transit where applicable
- restricted internal access
30. Security Incident Response
If a suspected security incident occurs, we may take reasonable steps to investigate, mitigate risks, and protect systems.
31. No Absolute Security Guarantee
No internet-based system can guarantee complete security at all times.
32. User Responsibilities
Users should:
- keep passwords secure
- protect devices
- use accurate information
- notify us of unauthorized access promptly
33. API Credentials
Users are responsible for protecting API keys, tokens, passwords, and connected account credentials.
34. Analytics and Improvement
We may use aggregated or anonymized insights to improve services, features, support quality, and user experience.
35. AI Features Notice
Where AI-assisted features are used, submitted prompts or content may be processed to deliver requested functionality.
AI outputs should be reviewed and not solely relied upon for legal, financial, medical, or critical decisions.
36. Beta Features
Experimental or beta features may have limited functionality and may change, pause, or be removed.
37. Sensitive Data Notice
Users should avoid uploading highly sensitive personal data unless lawfully authorized and necessary.
38. Automated Decision-Making
We do not intentionally rely solely on automated decision-making for decisions producing legal or similarly significant effects unless separately disclosed.
39. User Rights
Where applicable, users may request:
- access
- correction
- deletion
- restriction
- objection where legally applicable
- account closure
Requests may require identity verification.
40. Request Response Timing
We aim to review privacy requests within a reasonable period, subject to complexity and legal requirements
41. Withdrawal of Consent
Where processing is based on consent, users may withdraw consent. Some services may become limited if consent is withdrawn.
42. Children’s Privacy
Our services are not intended for persons under 18 years of age.
43. Third-Party Links
Our website may contain links to external websites. We are not responsible for third-party websites or services.
44. Business Transfer
If our business is reorganized, merged, sold, or transferred, relevant data may be transferred subject to applicable law.
45. Complaint Resolution
Users are encouraged to contact us first regarding privacy concerns so we may attempt to resolve the matter promptly.
46. Language Interpretation
If translated, the English version may govern in case of material inconsistency.
47. Policy Updates
We may update this Privacy Policy from time to time. Updated versions become effective when published on the website.
48. Related Policies
This policy should be read together with our Terms of Service, Refund Policy, and GDPR & Cookie Policy.