Introduction
VMF Solutions LLC, doing business as ZapChat ("ZapChat," "we," "us," or "our"), operates the ZapChat service, a WhatsApp AI bot creation platform. We understand that you care about your personal privacy, and we take that seriously. This Privacy Policy describes our policies and practices regarding the collection and use of your personal data and sets forth your privacy rights.
Contact Information
For any questions about this Privacy Policy or our data practices, please contact us at:
Information We Collect
Account Information
When you create an account, we collect:
- Email address
- Name (optional)
- Password (encrypted)
- Payment information (processed securely through third-party payment processors)
Bot and Service Data
When you use our services, we collect:
- Bot configurations and settings
- Knowledge sources you upload (websites, PDFs, Q&A pairs)
- WhatsApp integration credentials (encrypted)
- WhatsApp user data including:
- Phone numbers (encrypted in transit and at rest)
- Profile names
- Messages exchanged with your bots
- Chat logs and conversation history
- Usage analytics and performance data
Automatically Collected Information
We automatically collect:
- IP addresses
- Browser type and version
- Device information
- Usage patterns and interaction with our service
- Cookies and similar tracking technologies
How We Use Your Information
We use your information to:
- Provide and maintain the ZapChat service
- Process your bot creation and management requests
- Enable WhatsApp integration and message processing
- Store and retrieve your knowledge sources for bot functionality
- Send service-related communications
- Improve our services and develop new features
- Ensure security and prevent fraud
- Comply with legal obligations
Important: We do NOT use your data, bot conversations, or knowledge sources to train AI models. Your data is used solely to provide you with the service.
Data Storage and Security
Location
Your data is stored on servers located in the northeastern United States (Virginia region) through our infrastructure providers:
- Supabase (database and authentication)
- Vercel (application hosting)
- Pinecone (vector database for knowledge retrieval)
Security Measures
We implement industry-standard security measures including:
- Encryption of sensitive data (including WhatsApp phone numbers) at rest and in transit
- TLS/SSL encryption for all data transmissions
- Regular security audits and updates
- Access controls and authentication mechanisms
- Secure API key management
Third-Party Services
We share data with the following service providers solely to operate our service:
- OpenAI: For AI language processing
- Pinecone: For vector storage and retrieval
- Supabase: For database and authentication
- WhatsApp/Meta: For WhatsApp Business API integration
- Firecrawl: For website content extraction
- LangChain: For AI orchestration
These providers are bound by their own privacy policies and we ensure they maintain appropriate security standards.
Data Retention
- Active Accounts: We retain your data for as long as your account remains active
- Chat History: Maintained while your account is active
- Deleted Accounts: Upon request, we immediately delete all associated data
- Knowledge Sources: Retained while your bot is active, immediately deleted upon request
Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Object to certain uses of your data
- Withdraw consent where applicable
To exercise these rights, contact us at help@zapchat.dev.
GDPR Compliance
While we are in pre-launch phase, we are committed to GDPR compliance for our European users. This includes:
- Lawful basis for processing (consent and legitimate interests)
- Data minimization principles
- Right to erasure ("right to be forgotten")
- Data portability
- Privacy by design
Children's Privacy
ZapChat is not intended for use by children under 18. We do not knowingly collect personal information from children.
International Data Transfers
If you access our service from outside the United States, your information will be transferred to and processed in the United States. By using our service, you consent to this transfer.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on our website and updating the "Last Updated" date.