Ziplinezipline
Platform
Pipelines Declare a pipeline in one file Connectors 30 sources and sinks Observability Metrics, logs, and lag per table Assistant Ask Pip about your pipelines
Evaluate
Security SOC 2 Type II and HIPAA Roadmap What we are building next Compare Zipline against the rest
Try the CLI A real simulator, in your browser Run commands against a sandbox. Nothing touches a runtime. Open the playground
Move data
Database replication Keep a second database current Warehouse loading Land changes in the warehouse Lakehouse & Iceberg Append to object storage
Power applications
Event-driven services Publish changes as events Search index sync Keep an index in step Cache invalidation Expire on write, not on a timer AI agent context Give agents current data
Build
CLI Drive the control plane TUI cockpit Six screens in a terminal Playground A simulated CLI to poke at Reference Every command and flag
Reference
API HTTP control plane SDKs Build your own connector Handbook How the runtime fits together Config Every configuration key
Follow
Changelog What shipped, and when Customers Teams streaming with Zipline
PricingDocs
Sign in Start free
Product PipelinesConnectorsObservabilityAssistantSecurityRoadmapCompare Open the playground
Use cases Database replicationWarehouse loadingLakehouse & IcebergEvent-driven servicesSearch index syncCache invalidationAI agent context
Developers CLITUI cockpitPlaygroundReferenceAPISDKsHandbookConfigChangelogCustomers
PricingDocs Sign in Start free

Privacy Policy

Last updated: April 24, 2026 · Effective immediately
Draft - under legal review This document is a working draft. Final language is being reviewed by counsel and will be posted before general availability. For binding terms applicable to your account, contact legal@zipline.run.

This Privacy Policy explains how Zipline, Inc. ("Zipline," "we," "us") collects, uses, discloses, and safeguards information when you visit our website, use our services, or contact us. By using Zipline, you agree to this policy.

Contents

  1. Scope
  2. Information we collect
  3. How we use information
  4. Legal bases (EEA/UK)
  5. How we share information
  6. Sub-processors
  7. Data retention
  8. International transfers
  9. Your rights
  10. Security
  11. Cookies and tracking
  12. Children
  13. Changes to this policy
  14. Contact

1. Scope

This policy covers information processed by Zipline as a controller - primarily data about visitors to our website, prospects, customer administrators, and other people we interact with directly. When Zipline processes data inside a customer's pipelines on their behalf, we act as a processor under our Data Processing Addendum (DPA) and the customer is the controller.

2. Information we collect

Information you provide

  • Account information: name, work email, company, role, and password hash.
  • Billing information: billing contact, address, and the last four digits of payment cards (full card data is handled by our payment processor).
  • Communications: support tickets, sales conversations, and survey responses.

Information we collect automatically

  • Usage data: pages viewed, features used, dashboard interactions, error reports, and session metadata.
  • Device data: IP address, browser type and version, operating system, and timestamps.
  • Cookies and similar technologies: see Cookies and tracking.

Information from third parties

  • Identity providers (Google, Microsoft, Okta) when you sign in with SSO.
  • Marketing and enrichment providers, where permitted by law.

3. How we use information

  • Provide, maintain, and improve the Zipline service.
  • Authenticate users and protect against fraud and abuse.
  • Process payments and manage subscriptions.
  • Send service announcements, security notices, and operational updates.
  • Send marketing emails about features and events (you can opt out at any time).
  • Conduct research, analytics, and product development.
  • Comply with legal obligations and enforce our agreements.

4. Legal bases (EEA/UK)

If you are in the EEA or UK, our legal bases for processing are: (a) contract, where processing is necessary to provide the service; (b) legitimate interests, including security, fraud prevention, and product improvement; (c) consent, where required (for marketing emails and certain cookies); and (d) legal obligation, where processing is required by law.

5. How we share information

We do not sell personal information. We share information with:

  • Sub-processors who help us operate the service (see below).
  • Professional advisors (lawyers, auditors, accountants) under confidentiality.
  • Acquirers, in the context of a merger, financing, or sale, with notice to affected users.
  • Authorities, when required by valid legal process, after challenging overbroad requests where appropriate.

6. Sub-processors

An up-to-date list of sub-processors is maintained at /security. We notify customers in advance of material changes and offer the opportunity to object.

7. Data retention

We retain personal information for as long as we have a relationship with you or as needed to provide the service, comply with legal obligations, resolve disputes, and enforce our agreements. Account data is deleted within 30 days of account closure, except where longer retention is legally required. Pipeline data flows through customer infrastructure and is not retained by Zipline.

8. International transfers

Zipline operates in the United States. When we transfer personal data out of the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses or other lawful transfer mechanisms. EU data residency for the service plane is available on Enterprise plans.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or object to the processing of your personal information; to withdraw consent; and to lodge a complaint with a supervisory authority. To exercise these rights, email privacy@zipline.run. We respond within the time required by applicable law.

California residents have additional rights under the CCPA/CPRA. We do not sell or share personal information for cross-context behavioral advertising.

10. Security

We use administrative, technical, and physical safeguards designed to protect your information, including encryption in transit and at rest, least-privilege access, audit logging, and annual SOC 2 Type II auditing. No system is perfectly secure; you can read more about our program at /security and report vulnerabilities to security@zipline.run.

11. Cookies and tracking

We use a small number of strictly necessary cookies to authenticate sessions and remember preferences. We use first-party analytics to understand how the site is used. Where required, we ask for your consent before placing non-essential cookies. You can change cookie preferences at any time in our cookie settings.

12. Children

Zipline is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has provided us information, please contact us and we will delete it.

13. Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be communicated via email or in-product notice before they take effect.

14. Contact

Questions or requests can be sent to:

Zipline, Inc.
Attn: Privacy
privacy@zipline.run

Ziplinezipline

Real-time data streaming for teams who can't afford to lose a message.

Product
Connectors Pipelines Observability Security Roadmap
Use cases
Database replication Warehouse loading Lakehouse & Iceberg Event-driven services Search index sync Cache invalidation AI agent context
Developers
Docs CLI reference API reference SDK reference Changelog Compare
Company
About Customers Careers Partners Press Contact
Compliance
SOC 2 Type II HIPAA FedRAMP DPA Trust center
© 2026 Zipline, Inc. · Privacy · Terms · DPA status.zipline.run · ● all systems operational