Last Updated: June 28, 2026
Zone OS CRM, a product of Zone OS CRM, LLC (operating in the United States), and its partner entity, McKenzie Group of Companies (MGC) (collectively, "Zone-OS", "we", "our", or "us"), are committed to protecting your privacy. This Privacy Policy explains how we collect, use, process, store, and disclose your personal information, Customer Data, and Employee Data when you use our multi-tenant SaaS ERP platform and related services, including payroll orchestration powered by Stripe Treasury.
Our Role: Zone OS operates strictly as a Data Processor (under GDPR and international data protection frameworks) and as a Service Provider (under U.S. state privacy laws, including the California Consumer Privacy Act and the New Jersey Data Privacy Act). For the Customer Data and Employee Data you process through Zone-OS, you — the subscribing business — act as the "Data Controller." Zone OS processes data exclusively on your behalf and pursuant to your documented instructions.
Because Zone OS functions as an API orchestrator — passing instructions to regulated financial partners such as Stripe and its partner banks — rather than custodying, settling, or directly holding funds, Zone OS does not require direct Financial Crimes Enforcement Network (FinCEN) registration or state Money Transmitter Licenses (MTLs). All regulated banking functions, including FDIC insurance and AML/KYC compliance, are performed by Stripe's partner banks.
We collect the following categories of information to provide and improve our Service:
We use cookies, web beacons, and similar tracking technologies to monitor user activity, maintain session state, and provide analytics to improve your experience. You may instruct your browser to refuse all cookies; however, certain core features of the Service may not function properly without them.
Global Privacy Control (GPC): We honor the Global Privacy Control (GPC) browser signal as a valid universal opt-out mechanism in compliance with the California Consumer Privacy Act (CCPA/CPRA) and the New Jersey Data Privacy Act (NJDPA). When our systems detect a GPC signal from your browser, we will automatically process it as a request to opt out of the sale or sharing of your personal information.
Zone-OS allows you to connect third-party accounts and services. When you enable an integration, we may access, store, and use data from those platforms strictly to facilitate the integration you have authorized. Key sub-processors include:
All sub-processors are bound by Data Processing Agreements (DPAs) that require them to implement security measures at least as protective as those described in this policy. Your use of third-party integrations is additionally governed by their respective privacy policies and terms.
We use your information for the following purposes:
We do not sell your personal information, Customer Data, or Employee Data to third parties. We do not use Employee Data or payroll records for advertising, profiling, or any purpose other than providing the Service as directed by you, the Data Controller.
We may share information with trusted sub-processors (listed in Section 4) strictly for the purpose of operating our Service. We may also disclose information:
We maintain a Written Information Security Program (WISP) consistent with the requirements of the FTC Safeguards Rule and the Gramm-Leach-Bliley Act (GLBA). Our security measures include:
No method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify affected Data Controllers within 72 hours of confirmed discovery, in accordance with our obligations under the FTC Safeguards Rule and applicable state breach notification laws.
To satisfy the requirements of the Electronic Signatures in Global and National Commerce Act (ESIGN Act) and the Uniform Electronic Transactions Act (UETA), our platform maintains a tamper-evident audit trail for all electronically signed documents and compliance-significant operations. Each signing event is recorded with:
Audit records are cryptographically sealed using SHA-256 hashing and are stored in append-only, write-once infrastructure that blocks all modification and deletion operations. Compliance audit trails are retained for a minimum of five (5) years following the close of the transaction file, independent of the operational user record lifecycle.
Zone OS maintains a decoupled data retention strategy that balances your right to data deletion with legally mandated record-keeping obligations:
When a validated deletion request is processed, the operational record is permanently deleted. The corresponding compliance record is stripped of its active identity linkage, flagged with a legal hold, and moved to an isolated, encrypted archive. This archived record is inaccessible to tenant dashboard views, search indexes, or automated processing — it is accessible exclusively via isolated audit export queries. An automated time-to-live (TTL) mechanism permanently destroys archived records four (4) years after the final day of the corresponding tax filing year or final disbursement cycle.
If you cancel your subscription, we initiate deletion of your operational Customer Data within 90 days of cancellation. Compliance and tax-related data subject to legal hold will be retained in the encrypted archive for the mandatory retention period described above.
Depending on your jurisdiction, you may have the following rights with respect to your personal information:
If you are a New Jersey resident, you have the right to: access your personal data; correct inaccuracies; delete your personal data (subject to legal retention requirements); obtain a portable copy of your data; and opt out of the sale of personal data, targeted advertising, and profiling. We will process opt-out requests within 15 calendar days. We honor the Global Privacy Control (GPC) browser signal as a valid universal opt-out.
Note: The NJDPA's 18-month "Right to Cure" grace period expires on July 15, 2026. After this date, violations are subject to direct enforcement by the New Jersey Division of Consumer Affairs without a cure opportunity.
If you are a California resident, you have the right to: know what personal information we collect and how it is used; request deletion of your personal information; opt out of the sale or sharing of personal information; and not be discriminated against for exercising your rights. We fulfill verified Data Subject Access Requests (DSARs) within 45 calendar days, with a lookback period extending to January 1, 2022. A single 45-day extension may be requested for complex, multi-tenant requests.
For users in jurisdictions with sovereign data protection legislation (including but not limited to the Cooperative Republic of Guyana), we comply with applicable data localization, cross-border transfer assessment, and Data Protection Commission registration requirements. A designated Data Protection Officer (DPO) is assigned for regions where required by law. Cross-border data transfer risk assessments are conducted before personal data is transferred between jurisdictions.
Regardless of your location, you may request access to, correction of, or deletion of your personal information by submitting a verified request to privacy@zone-os.co. For security purposes, all Data Subject Access Requests must be verified through our identity validation process, which may include multi-factor authentication, identity matching, and a perjury attestation declaration in compliance with the ESIGN Act. Requests that cannot be verified to a high degree of certainty will be denied with instructions for appeal.
We limit DSAR processing to a maximum of two (2) requests per consumer within a rolling 12-month period. Requests that conflict with mandatory legal retention holds (such as the 4-year tax record retention period) will be partially fulfilled, with the retained data categories and legal basis clearly disclosed.
Zone OS provides technology infrastructure for payroll calculation and disbursement orchestration. Zone OS is not a bank, does not hold deposits, and does not provide banking services. Financial accounts used for payroll disbursement are provided by Stripe's partner banks, which are Member FDIC institutions. All fund custody, settlement, and regulatory banking compliance is performed by these regulated financial institutions.
To mitigate fraud risk associated with ACH transactions, all incoming funds processed through Stripe Treasury are subject to a minimum holding period before outbound disbursement instructions are executed. This holding period is a platform-level risk control and does not constitute fund custody.
Our Service is designed for business use and is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have inadvertently collected personal information from a child under 16, we will take steps to delete that information promptly.
We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or regulatory guidance. We will notify you of significant changes by posting the updated policy on this page, updating the "Last Updated" date, and — for material changes — sending direct email notification to all active account administrators. Your continued use of the Service after changes are published constitutes acceptance of the revised Privacy Policy.
If you have any questions, concerns, or requests regarding this Privacy Policy, your data rights, or how we handle your information, please contact us:
For complaints regarding our data practices in New Jersey, you may also contact the New Jersey Division of Consumer Affairs at www.njconsumeraffairs.gov.