Privacy Policy

Last Updated: June 28, 2026

1. Introduction & Legal Identity

Zone OS CRM, a product of Zone OS CRM, LLC (operating in the United States), and its partner entity, McKenzie Group of Companies (MGC) (collectively, "Zone-OS", "we", "our", or "us"), are committed to protecting your privacy. This Privacy Policy explains how we collect, use, process, store, and disclose your personal information, Customer Data, and Employee Data when you use our multi-tenant SaaS ERP platform and related services, including payroll orchestration powered by Stripe Treasury.

Our Role: Zone OS operates strictly as a Data Processor (under GDPR and international data protection frameworks) and as a Service Provider (under U.S. state privacy laws, including the California Consumer Privacy Act and the New Jersey Data Privacy Act). For the Customer Data and Employee Data you process through Zone-OS, you — the subscribing business — act as the "Data Controller." Zone OS processes data exclusively on your behalf and pursuant to your documented instructions.

Because Zone OS functions as an API orchestrator — passing instructions to regulated financial partners such as Stripe and its partner banks — rather than custodying, settling, or directly holding funds, Zone OS does not require direct Financial Crimes Enforcement Network (FinCEN) registration or state Money Transmitter Licenses (MTLs). All regulated banking functions, including FDIC insurance and AML/KYC compliance, are performed by Stripe's partner banks.

2. Information We Collect

We collect the following categories of information to provide and improve our Service:

  • Account & Registration Information: Legal business name, contact name, email address, phone number, business address, industry classification, and billing information provided during account creation and subscription enrollment.
  • Usage Data & Device Information: IP addresses, browser types and versions, operating systems, device identifiers, login timestamps, session durations, page interaction metrics, and application error logs. This data is used for platform monitoring, security enforcement, and service improvement.
  • Customer Data (Tenant-Controlled): All data, contacts, records, documents, photos, and operational information you upload, input, or generate within the CRM regarding your own customers and business operations. This includes but is not limited to: customer contact records, rental/booking requests, invoices, signed contracts and waivers, delivery photos, communications (email, SMS, live chat), and marketing campaign data.
  • Employee & Payroll Data (Tenant-Controlled): If you use our time tracking, payroll, or workforce management features, you may input employee information including: legal full names, Social Security Numbers (SSNs) or Taxpayer Identification Numbers (TINs), Employer Identification Numbers (EINs), corporate addresses, bank account details (via Stripe Treasury tokenization), time logs, pay rates, tax withholding elections, and disbursement history.
  • Financial Onboarding Data (Stripe-Processed): When you connect to Stripe Treasury for payroll disbursement, identity verification data — including government-issued identification, biometric identity checks, and beneficial ownership information — is collected and processed directly by Stripe via the embedded ConnectJS onboarding component. This data is tokenized by Stripe at the point of entry and is never stored on Zone OS servers in unredacted form.
  • Digital Signature Attribution Data: When contracts, waivers, or legal documents are electronically signed through our platform, we capture: the signer's name, timestamp (UTC), authentication session identifiers, and signature image data. This data is retained as part of our tamper-evident cryptographic audit trail (see Section 8).

3. Cookies, Tracking Technologies & Consent

We use cookies, web beacons, and similar tracking technologies to monitor user activity, maintain session state, and provide analytics to improve your experience. You may instruct your browser to refuse all cookies; however, certain core features of the Service may not function properly without them.

Global Privacy Control (GPC): We honor the Global Privacy Control (GPC) browser signal as a valid universal opt-out mechanism in compliance with the California Consumer Privacy Act (CCPA/CPRA) and the New Jersey Data Privacy Act (NJDPA). When our systems detect a GPC signal from your browser, we will automatically process it as a request to opt out of the sale or sharing of your personal information.

4. Third-Party Integrations & Sub-Processors

Zone-OS allows you to connect third-party accounts and services. When you enable an integration, we may access, store, and use data from those platforms strictly to facilitate the integration you have authorized. Key sub-processors include:

  • Stripe, Inc. — Payment processing, Treasury (payroll disbursement), and identity verification (ConnectJS onboarding). Financial accounts are provided by Stripe's partner banks, Member FDIC.
  • Google Cloud Platform (Firebase) — Application hosting, database (Firestore), authentication, cloud functions, and file storage.
  • Google Cloud SQL — PostgreSQL-backed accounting ledger with automated daily backups and point-in-time recovery.
  • Twilio — SMS messaging and communications bridge services.
  • PayPal — Alternative payment processing for tenant invoicing.
  • Google Workspace / OAuth Providers — Email integration and authentication delegation.

All sub-processors are bound by Data Processing Agreements (DPAs) that require them to implement security measures at least as protective as those described in this policy. Your use of third-party integrations is additionally governed by their respective privacy policies and terms.

5. How We Use Your Information

We use your information for the following purposes:

  • To provide, operate, maintain, and improve the Service, including AI-powered features (content generation, business analytics, and live chat assistance).
  • To process billing and subscription transactions.
  • To execute payroll calculations and instruct regulated financial partners (Stripe Treasury) to process disbursements on your behalf.
  • To provide customer and technical support.
  • To send administrative, security, and compliance notices.
  • To detect, prevent, and respond to fraud, security incidents, and technical issues.
  • To fulfill legal and regulatory obligations, including tax record retention and law enforcement requests.

We do not sell your personal information, Customer Data, or Employee Data to third parties. We do not use Employee Data or payroll records for advertising, profiling, or any purpose other than providing the Service as directed by you, the Data Controller.

6. Information Sharing and Disclosure

We may share information with trusted sub-processors (listed in Section 4) strictly for the purpose of operating our Service. We may also disclose information:

  • When legally required by a valid subpoena, court order, regulatory inquiry, or to comply with applicable law.
  • To protect our legal rights, enforce our Terms and Conditions, or investigate potential violations.
  • In connection with a merger, acquisition, or sale of assets, with notice provided to affected Data Controllers.
  • To law enforcement or regulatory agencies when we have a good faith belief that disclosure is necessary to prevent imminent harm, fraud, or illegal activity.

7. Data Security & Information Security Program

We maintain a Written Information Security Program (WISP) consistent with the requirements of the FTC Safeguards Rule and the Gramm-Leach-Bliley Act (GLBA). Our security measures include:

  • Encryption: All data is encrypted in transit (TLS 1.2+) and at rest using industry-standard encryption algorithms.
  • Access Controls: Multi-layered role-based access control (RBAC) with per-tenant data isolation, custom authentication claims, and field-level write restrictions enforced at the database level.
  • Webhook Integrity: All inbound billing and payment webhooks are verified using HMAC-SHA256 signature validation.
  • Audit Logging: All administrative, financial, and compliance-significant operations generate tamper-evident audit records (see Section 8).
  • Penetration Testing: We conduct annual penetration testing of our infrastructure and application layer.
  • Financial Data Isolation: Sensitive financial identifiers (SSNs, EINs, bank account details) processed via Stripe Treasury are tokenized by Stripe at the point of entry and are never stored in unredacted form on Zone OS infrastructure.

No method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify affected Data Controllers within 72 hours of confirmed discovery, in accordance with our obligations under the FTC Safeguards Rule and applicable state breach notification laws.

8. Cryptographic Audit Trail & Digital Signatures

To satisfy the requirements of the Electronic Signatures in Global and National Commerce Act (ESIGN Act) and the Uniform Electronic Transactions Act (UETA), our platform maintains a tamper-evident audit trail for all electronically signed documents and compliance-significant operations. Each signing event is recorded with:

  • The full text of the signed declaration or document reference.
  • The signer's typed or drawn name and timestamp (UTC, ISO 8601).
  • System attribution metadata including authentication session identifiers.

Audit records are cryptographically sealed using SHA-256 hashing and are stored in append-only, write-once infrastructure that blocks all modification and deletion operations. Compliance audit trails are retained for a minimum of five (5) years following the close of the transaction file, independent of the operational user record lifecycle.

9. Data Retention & Dual-Namespace Architecture

Zone OS maintains a decoupled data retention strategy that balances your right to data deletion with legally mandated record-keeping obligations:

  • Operational Data: User authentication records, application activity metrics, login sessions, device profiles, and non-tax demographic information. This data is subject to immediate hard-deletion upon a valid, verified erasure request.
  • Compliance & Tax Data: Legal full names, EINs, SSN references (tokenized), corporate addresses, payroll ledger history, and disbursement records. This data is subject to an immutable legal hold as required by the Internal Revenue Service (IRS) and the Fair Labor Standards Act (FLSA).

When a validated deletion request is processed, the operational record is permanently deleted. The corresponding compliance record is stripped of its active identity linkage, flagged with a legal hold, and moved to an isolated, encrypted archive. This archived record is inaccessible to tenant dashboard views, search indexes, or automated processing — it is accessible exclusively via isolated audit export queries. An automated time-to-live (TTL) mechanism permanently destroys archived records four (4) years after the final day of the corresponding tax filing year or final disbursement cycle.

If you cancel your subscription, we initiate deletion of your operational Customer Data within 90 days of cancellation. Compliance and tax-related data subject to legal hold will be retained in the encrypted archive for the mandatory retention period described above.

10. Your Privacy Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal information:

A. New Jersey Data Privacy Act (NJDPA)

If you are a New Jersey resident, you have the right to: access your personal data; correct inaccuracies; delete your personal data (subject to legal retention requirements); obtain a portable copy of your data; and opt out of the sale of personal data, targeted advertising, and profiling. We will process opt-out requests within 15 calendar days. We honor the Global Privacy Control (GPC) browser signal as a valid universal opt-out.

Note: The NJDPA's 18-month "Right to Cure" grace period expires on July 15, 2026. After this date, violations are subject to direct enforcement by the New Jersey Division of Consumer Affairs without a cure opportunity.

B. California Consumer Privacy Act (CCPA/CPRA)

If you are a California resident, you have the right to: know what personal information we collect and how it is used; request deletion of your personal information; opt out of the sale or sharing of personal information; and not be discriminated against for exercising your rights. We fulfill verified Data Subject Access Requests (DSARs) within 45 calendar days, with a lookback period extending to January 1, 2022. A single 45-day extension may be requested for complex, multi-tenant requests.

C. International Data Protection (Guyana & Other Jurisdictions)

For users in jurisdictions with sovereign data protection legislation (including but not limited to the Cooperative Republic of Guyana), we comply with applicable data localization, cross-border transfer assessment, and Data Protection Commission registration requirements. A designated Data Protection Officer (DPO) is assigned for regions where required by law. Cross-border data transfer risk assessments are conducted before personal data is transferred between jurisdictions.

D. General Rights (All Jurisdictions)

Regardless of your location, you may request access to, correction of, or deletion of your personal information by submitting a verified request to privacy@zone-os.co. For security purposes, all Data Subject Access Requests must be verified through our identity validation process, which may include multi-factor authentication, identity matching, and a perjury attestation declaration in compliance with the ESIGN Act. Requests that cannot be verified to a high degree of certainty will be denied with instructions for appeal.

We limit DSAR processing to a maximum of two (2) requests per consumer within a rolling 12-month period. Requests that conflict with mandatory legal retention holds (such as the 4-year tax record retention period) will be partially fulfilled, with the retained data categories and legal basis clearly disclosed.

11. Financial Data & Payroll Processing Disclosures

Zone OS provides technology infrastructure for payroll calculation and disbursement orchestration. Zone OS is not a bank, does not hold deposits, and does not provide banking services. Financial accounts used for payroll disbursement are provided by Stripe's partner banks, which are Member FDIC institutions. All fund custody, settlement, and regulatory banking compliance is performed by these regulated financial institutions.

To mitigate fraud risk associated with ACH transactions, all incoming funds processed through Stripe Treasury are subject to a minimum holding period before outbound disbursement instructions are executed. This holding period is a platform-level risk control and does not constitute fund custody.

12. Children's Privacy

Our Service is designed for business use and is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have inadvertently collected personal information from a child under 16, we will take steps to delete that information promptly.

13. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or regulatory guidance. We will notify you of significant changes by posting the updated policy on this page, updating the "Last Updated" date, and — for material changes — sending direct email notification to all active account administrators. Your continued use of the Service after changes are published constitutes acceptance of the revised Privacy Policy.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, your data rights, or how we handle your information, please contact us:

For complaints regarding our data practices in New Jersey, you may also contact the New Jersey Division of Consumer Affairs at www.njconsumeraffairs.gov.