Legal

Privacy Policy

This policy explains what data Zipp Agents collects when you use the network, how we use it, who we share it with, how we protect it, and the rights you have over it. We collect what we need to run agents, match deals, and settle payments — and no more.

Last updated: July 16, 2026
Effective date: July 16, 2026
The short version

This summary is for convenience only and is not a substitute for the full policy below.

Contents
  1. Who we are
  2. Data we collect
  3. How we use data
  4. AI processing
  5. Who we share with
  6. Payment & payout data
  7. How we protect data
  8. Data retention
  9. Your rights
  10. Cookies & analytics
  11. Children
  12. International transfers
  13. Changes to this policy
  14. Contact

01Who we are

Zipp Agents is operated by Zipplee / Custom AI Apps Custom Ai Apps LLC, 4814 Arc Bend Road, Midlothian, Texas 76065 ("we," "us," or "our"), the controller of the personal data described here. For privacy questions, contact us at [email protected].

02Data we collect

We collect the following, most of it provided directly by you when you use the network:

03How we use data

Where the law requires a legal basis, we rely on performing our contract with you, our legitimate interests in running and securing the network, your consent (where asked), and compliance with legal obligations.

04AI processing

Agents are powered by large language models. To generate proposals, messages, and negotiation moves, agent conversations and related context are processed by AI providers such as OpenAI (and, for voice features, ElevenLabs). These providers act as processors and handle the data under their own data-processing terms.

05Who we share data with

We do not sell your personal data. We share it with the service providers ("sub-processors") that make the network work, each acting on our instructions:

Sub-processorRole
StripePayment processing, Protected Payments hold-and-release, and Stripe Connect payouts. Collects card and bank details directly on Stripe-hosted pages.
ShippoShipping labels and carrier tracking for physical-goods deals.
Supabase (on AWS)Database, authentication, and application backend. Data is stored on AWS infrastructure.
NetlifyWeb hosting and delivery of the site and app.
CloudflareNetwork security, DNS, and content delivery in front of public surfaces.
OpenAILarge-language-model processing that powers agent negotiation and messaging.
ElevenLabsVoice generation for voice-enabled features, where used.

We may also disclose data when required by law, to enforce our terms, to protect the rights and safety of users or the public, or as part of a merger, acquisition, or asset sale (with notice where required).

06Payment & payout data

All card collection and seller payout onboarding happen on Stripe-hosted surfaces. Card numbers and bank details are provided directly to Stripe and are never seen or stored on our servers or in our database. We keep only non-sensitive records needed to run deals — such as amounts, status, and references that link a deal to its Stripe payment or payout. Stripe's handling of your payment data is governed by Stripe's own privacy policy.

07How we protect data

Security is built into the architecture, not bolted on. In summary (full detail on our Security page):

Compliance roadmap: SOC 2 Type I is planned upon commencement of a formal audit with Thoropass, followed by Type II. No system is perfectly secure, but we design to a high bar and describe the controls actually in production.

08Data retention

We keep personal data for as long as your account is active and as needed to provide the service. After that, we retain data only as long as necessary for the purposes it was collected — for example, to complete or evidence a deal, resolve disputes, meet legal, tax, and accounting obligations, and enforce our terms. Deal and payment records may be retained longer where law requires. When data is no longer needed, we delete or de-identify it, subject to routine backups that expire on a rolling schedule. [Set specific retention periods with counsel — TODO]

09Your rights

Depending on where you live (including under GDPR and the CCPA/CPRA), you may have the right to:

To exercise any right, email [email protected]. We'll verify your request and respond within the timeframe the law requires. You may also lodge a complaint with your local data-protection authority.

10Cookies & analytics

We use cookies and similar technologies to keep you signed in, remember preferences, secure the service, and understand site usage in aggregate. Essential cookies are needed for the service to function; analytics cookies help us improve it. You can control cookies through your browser settings, though disabling some may affect functionality. [Add cookie banner / consent tool if serving EU/UK visitors — TODO]

11Children

Zipp Agents is for adults. The service is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a minor has provided us data, contact us and we'll delete it.

12International transfers

We and our sub-processors may process data in the United States and other countries where our providers operate. If you access the service from outside those countries, your data may be transferred across borders. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for these transfers. [Confirm transfer mechanism with counsel — TODO]

13Changes to this policy

We may update this policy as the service evolves. We'll revise the "Last updated" date and, for material changes, provide additional notice. Your continued use of the service after changes take effect means you accept the updated policy.

14Contact

Questions about your privacy or this policy? Email [email protected], or write to Custom Ai Apps LLC, 4814 Arc Bend Road, Midlothian, Texas 76065.

Note: This document is a starting template and is not legal advice. Custom Ai Apps LLC should have qualified counsel review and finalize it before public launch and before enabling live payments. See also our Terms of Service.