EFFECTIVE Terms

Privacy policy

This policy covers zontalabs.com: the public website, its updates form and the developer portal behind Log in. It explains what we collect and why.

It also says what happens when you book a demo, which goes through Cal.com, and what you can do about any of it.

The portal is early and under construction. When Zonta ships a product that handles customer data, that product will get its own terms, and we will link them here.

  1. Who we are

    The site is run by Zonta Labs Inc. We are the controller of the personal data collected through it.

    You can reach us about anything in this policy at hello@zontalabs.com.

  2. What we collect

    Reading the public pages needs no account and sets no cookies.

    The site has one form, to sign up for updates. What you type into it is the personal data we hold from it. If we add a form to request a demo or send a message, we will list it here before it goes live.

    Book a demo opens a booking page on Cal.com, a scheduling service. What you enter there reaches us as the booking. If you email us, we hold what you send.

    If you create an account for the developer portal, we hold the details of that account.

    Separately, the servers that answer requests see your IP address. We use it for rate limiting on the form endpoint, and our hosting provider records it in ordinary server logs.

    • Updates: email address.
    • Demo booking on Cal.com: your name, email address, the time you pick and anything you add to the booking.
    • Email to us: your address and what you write.
    • Developer portal account: the details you sign up with, such as your email address and name, plus the session and security data the sign-in provider records, such as sign-in times, IP address and browser.
    • Server logs and rate limiting: IP address, request path, timestamp, browser user agent.
  3. How we use it

    We use what you give us to do the thing you asked for, and for nothing else.

    We do not build profiles, score visitors, or combine what you send with data from anywhere else.

    • To reply to a message you sent us.
    • To hold a demo call you booked.
    • To send updates you asked for, until you tell us to stop.
    • To run your developer portal account: sign you in, keep you signed in, and protect the account from misuse.
    • To keep the updates form working, which includes throttling repeated requests from one address.
  4. Where it goes

    Sign-ups for updates are not written to a database we run. Your email address goes into a contact list held with Resend, a transactional email provider. That list is what we send updates from and what unsubscribes are removed from. We may also send ourselves a notice of the sign-up by email, through Resend.

    Demo bookings are made on Cal.com. Cal.com holds the booking under its own privacy policy and sends us the details so we can hold the call.

    Developer portal accounts are held by Clerk, the sign-in provider we use. Clerk stores your account details and handles passwords and sign-in for us. We never see or store your password.

    The IP addresses used for rate limiting are held only in server memory and expire after a short window. We do not write them to disk.

  5. Cookies, analytics, and tracking

    The public pages set no cookies and load no analytics or tracking scripts. There is no advertising pixel, no session recording and no fingerprinting.

    Book a demo links open Cal.com in a new tab. Cal.com sets its own cookies there, under its own policy. Nothing from Cal.com loads on our pages.

    The sign-in, sign-up and developer portal pages load Clerk's script, and Clerk sets cookies there that keep you signed in and protect your session. They are strictly necessary for the portal to work, and they are set only when you visit those pages.

    If that changes, we will update this policy before the change goes live and, where the law requires it, ask before setting anything.

  6. How long we keep it

    Emails and demo bookings stay in our inbox and calendar for as long as we need them to handle the conversation and any follow-up you would reasonably expect. After that we delete them, or you can ask us to. Cal.com keeps its copy of a booking for the period set by its own policies.

    Addresses on the updates list stay there until you unsubscribe or ask us to remove you.

    Developer portal accounts stay until you ask us to delete yours, or until we close the account or the portal. Clerk then removes the account data within the period set by its own policies.

    Rate-limiting data expires after a short window and does not survive a restart. Server logs kept by our hosting provider are held for the period set by that provider, which we do not extend.

  7. Who we share it with

    We do not sell personal data. We do not rent it, trade it, or hand it to advertisers.

    We share it only with the service providers that make the site work, and only as far as needed for that. Each processes data on our instructions.

    We would also disclose data if the law required it, for example in response to a valid legal order, and we would tell you if we were allowed to.

    • Vercel, which hosts the site and keeps server logs.
    • Resend, which holds the updates list and sends sign-up notices to our inbox.
    • Cal.com, which takes demo bookings.
    • Clerk, which runs sign-in and stores developer portal accounts.
    • Our email provider, where our inbox lives.
  8. Where it is stored

    Vercel, Resend, Cal.com and Clerk are based in the United States, so what you send through the site or the booking page is processed there. If you are visiting from elsewhere, anything you submit is transferred to the United States.

    Where a transfer needs a legal mechanism, for example from the European Economic Area, the United Kingdom, or Switzerland, we rely on the standard contractual terms our providers offer or on your consent for the specific submission.

  9. Your rights

    Depending on where you live, you may have some or all of the rights below. We extend them to everyone who asks, regardless of location.

    To exercise any of them, email hello@zontalabs.com. We will need enough to confirm the request came from you, which is usually a reply from the address in question. We will answer within the time the law gives us, and sooner where we can.

    • Access: ask what we hold about you.
    • Correction: ask us to fix something that is wrong.
    • Deletion: ask us to delete what we hold, including a developer portal account, subject to anything we are required to keep.
    • Withdraw consent: unsubscribe from updates at any time, using the link in any email or by writing to us.
    • Complaint: raise a complaint with the data protection authority where you live. We would rather hear from you first, but you do not have to.
  10. Children

    This site and the developer portal are not directed at anyone under 16, and we do not knowingly collect personal data from them.

    If you believe a child has signed up for updates, booked a demo or created an account, tell us and we will delete what was sent.

  11. Changes to this policy

    We will revise this policy when what the site does changes. The effective date at the top tells you which version you are reading.

    For a material change, such as adding analytics or launching a product, we will note it on this page. Continued use of the site after a change means the new version applies.

Questions

For anything about this policy, or to exercise a right listed above, write to us. The founders read the inbox.

hello@zontalabs.com