This Privacy Policy explains how Zipline, Inc. ("Zipline," "we," "us") collects, uses, discloses, and safeguards information when you visit our website, use our services, or contact us. By using Zipline, you agree to this policy.
This policy covers information processed by Zipline as a controller - primarily data about visitors to our website, prospects, customer administrators, and other people we interact with directly. When Zipline processes data inside a customer's pipelines on their behalf, we act as a processor under our Data Processing Addendum (DPA) and the customer is the controller.
If you are in the EEA or UK, our legal bases for processing are: (a) contract, where processing is necessary to provide the service; (b) legitimate interests, including security, fraud prevention, and product improvement; (c) consent, where required (for marketing emails and certain cookies); and (d) legal obligation, where processing is required by law.
We do not sell personal information. We share information with:
An up-to-date list of sub-processors is maintained at /security. We notify customers in advance of material changes and offer the opportunity to object.
We retain personal information for as long as we have a relationship with you or as needed to provide the service, comply with legal obligations, resolve disputes, and enforce our agreements. Account data is deleted within 30 days of account closure, except where longer retention is legally required. Pipeline data flows through customer infrastructure and is not retained by Zipline.
Zipline operates in the United States. When we transfer personal data out of the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses or other lawful transfer mechanisms. EU data residency for the service plane is available on Enterprise plans.
Depending on where you live, you may have the right to access, correct, delete, port, or object to the processing of your personal information; to withdraw consent; and to lodge a complaint with a supervisory authority. To exercise these rights, email privacy@zipline.run. We respond within the time required by applicable law.
California residents have additional rights under the CCPA/CPRA. We do not sell or share personal information for cross-context behavioral advertising.
We use administrative, technical, and physical safeguards designed to protect your information, including encryption in transit and at rest, least-privilege access, audit logging, and annual SOC 2 Type II auditing. No system is perfectly secure; you can read more about our program at /security and report vulnerabilities to security@zipline.run.
We use a small number of strictly necessary cookies to authenticate sessions and remember preferences. We use first-party analytics to understand how the site is used. Where required, we ask for your consent before placing non-essential cookies. You can change cookie preferences at any time in our cookie settings.
Zipline is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has provided us information, please contact us and we will delete it.
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be communicated via email or in-product notice before they take effect.
Questions or requests can be sent to:
Zipline, Inc.
Attn: Privacy
privacy@zipline.run