Legal
Privacy Policy
How ZingaSuite collects, uses, shares and protects personal data — on this website, in our apps, and for the data our customers trust us with. Last updated 13 September 2026.
At a glance
The short version
- We wear two hats. For this website and for your ZingaSuite account, we decide how personal data is used. For the contacts, orders, tickets, messages and test results you load into the apps, we act only on your instructions — that data is yours.
- We do not sell personal data, and we do not share it for cross-context behavioural advertising.
- Your data is not our marketing list. Contacts you bring into ZingaSuite are never used to market ZingaSuite to those people, and are never pooled with another customer's data.
- AI runs on your instruction. AI features send content to a model provider only when you ask for something specific, and those providers are not permitted to train on what we send.
- You can get your data out — or have it deleted. Email hello@zingasuite.com and we will act on it.
1. Who we are and what this policy covers
ZingaSuite is a business software suite — ZingaShop, ZingaConnect, Zingalify, Zingasolve and Zingalinks — operated by KKE Soteco Pvt. Ltd. ("ZingaSuite", "we", "us").
This policy explains what we do with personal data across:
- this website, zingasuite.com, including its regional and language editions;
- the ZingaSuite console, our point-of-sale and mobile apps, and our public APIs;
- our documentation and support site;
- the data our customers store and process inside the five apps.
It does not govern the storefronts, help centres, campaigns, short links or assessments that our customers run on ZingaSuite. Those belong to the business that operates them: that business decides what to collect and why, and its own privacy notice applies. Where we handle that data, we handle it for them.
2. Controller and processor — the two roles
Most of this policy turns on which role we are in.
- We are the controller for data about visitors to this website, people who contact us, and the account and billing records of the businesses that subscribe to ZingaSuite. We decide why and how that data is used, and this policy is our notice to you.
- We are a processor for everything a customer puts into their workspace — their contacts, orders, conversations, support tickets, test attempts, link analytics and uploaded files. The customer is the controller. We process it to run the service for them, on their instructions, and we do not decide what goes in or what it is used for.
If a business messaged you, sold you something, or asked you to take an assessment through ZingaSuite and you want your data corrected or removed, that business is the right first stop. If you come to us instead, we will route your request to them and support them in answering it.
3. What we collect
3.1 When you visit this website
- Technical and usage data — pages viewed, referring page, approximate country (derived from your IP address by our CDN so we can show the right language and currency), browser and device type, and timestamps. IP addresses appear in server and security logs.
- Your locale choice — if you pick a language or currency from the picker, we store that choice in a cookie so the site remembers it.
- What you submit — anything you type into a form. Our pricing and onboarding wizards collect a name, work email, phone number, business name, the apps and features you selected and the estimate they produced, so our team can follow up.
3.2 When you create an account
- Identity and sign-in — name, email address and/or phone number, a password stored only as a salted hash, multi-factor settings, and session and device records.
- Workspace and team — business name, country, the apps you enable, the teammates you invite, and the roles and permissions you give them.
- Billing — plan and subscription state, invoices, AI-credit balances and their ledger, and the transaction references our payment providers return. Card and bank details never reach our servers — they go directly to the payment provider you pay through.
- Developer credentials — API keys you create (stored hashed), their scopes, and when they were last used.
3.3 What you bring into the platform
This is the data our customers load or generate in their own workspaces. It varies by app, and can include contacts and their per-channel consent, customer accounts and addresses, orders and fulfilment records, email, SMS and WhatsApp conversations including any media attached to them, support tickets and their correspondence, assessment content and candidate attempts and results, short-link click records, and uploaded files and images.
We treat all of it as the customer's data. We access it to run the service, to investigate a fault, or when the customer asks us to help — not otherwise.
3.4 What the platform generates
- Audit and activity logs — who changed what, and when.
- Delivery telemetry — whether a message was accepted, delivered, opened, clicked, bounced or replied to.
- Usage meters — the counts we bill on, such as AI credits spent, messages sent, contacts stored and assessment attempts taken.
- Diagnostics — error traces and performance timings.
4. Why we use personal data, and on what basis
- To provide the service you signed up for — creating your workspace, signing you in, running the apps, sending the messages you ask us to send, taking payment. Basis: performance of a contract.
- To keep the service safe and working — rate limiting, bot checks, fraud and abuse prevention, backups, capacity planning and debugging. Basis: our legitimate interest in a secure, reliable platform.
- To support you — answering tickets and emails, and working out what went wrong. Basis: contract, and legitimate interest.
- To improve ZingaSuite — aggregate usage analysis and product research. We use aggregated or de-identified data for this wherever it will do the job. Basis: legitimate interest.
- To market to businesses — following up on an enquiry, and sending product news to people who asked for it. Basis: consent, or a legitimate interest in business-to-business marketing where the law allows it. Every marketing message carries an unsubscribe link.
- To meet legal obligations — tax and accounting records, and responding to lawful requests. Basis: legal obligation.
Where we rely on consent, you can withdraw it at any time. That does not affect anything we did before you withdrew it.
5. Cookies and analytics
This website uses a small number of cookies and similar storage:
- Strictly necessary — sign-in and session state in the console, and the bot-check token our security provider sets on public forms. The service does not work without these.
- Preference — a locale cookie, set only if you choose a language or currency, and kept for about twelve months.
- Analytics — Google Analytics 4, which sets its own cookies to count visits and show us which pages are useful. We use it for aggregate reporting, not to identify you personally.
We do not run advertising, retargeting or cross-site tracking pixels on zingasuite.com. You can clear or block cookies in your browser, and Google publishes an opt-out add-on for Analytics; blocking analytics cookies does not degrade the site.
Storefronts and help centres that our customers publish through ZingaSuite may set their own cookies, including analytics or advertising tags that the customer configured. Those choices are theirs, and their notice applies.
6. AI features
Several parts of ZingaSuite can call a large language or image model — to draft a product description, suggest a reply, generate an assessment, or interpret a set of results. These features are deliberate: they run when you ask for them, and each run is metered against your AI-credit balance.
- When you invoke one, the content that request needs is sent to the model provider — currently Anthropic, OpenAI or Google, depending on the feature.
- We use their business APIs, under terms that do not permit them to train their models on what we send.
- We record that a run happened and what it cost in credits. We do not use your content to train models of our own.
- AI output can be wrong. Where it bears on a person — an assessment interpretation, for instance — it is a decision aid for a human reviewer, not an automated decision, and it should be read that way.
7. Email, SMS and WhatsApp
ZingaConnect sends messages on behalf of our customers. Two things follow from that:
- Consent belongs to the sender. The customer is responsible for having a lawful basis and, where required, opt-in for every person they message, on every channel. The platform records consent state and honours unsubscribes and opt-outs.
- Channel rules apply on top. WhatsApp Business messaging is governed by Meta's policies, which require prior opt-in for most outbound messages and limit what may be sent.
We process delivery receipts, opens, clicks, bounces and replies so senders can see what happened to a message. Inbound WhatsApp images and audio are archived so conversations stay readable, and are purged on a rolling schedule.
Email we send you about your own account — verification, invitations, receipts, security notices — is transactional. You cannot unsubscribe from it while you hold an account, because it is part of the service.
8. Payments
Subscriptions and credit purchases are processed by third-party payment providers — currently Razorpay, PayPal and PayU, depending on your country. You enter your payment details with them, not with us. We receive the confirmation, the amount and a transaction reference, and we keep the invoice records that tax law requires. Their own privacy policies govern what they do with your payment data.
9. Who we share data with
We share personal data with the service providers that help us run the platform, under contracts that limit them to our instructions. We do not sell it.
- Google Cloud — hosting, databases, file storage and push notification delivery.
- Cloudflare — DNS, CDN and edge caching, bot and abuse protection, and certificates for custom domains.
- Amazon Web Services — outbound email delivery, and SMS in some regions.
- Twilio — SMS delivery.
- DoubleTick and Meta Platforms — WhatsApp Business messaging.
- Anthropic, OpenAI and Google — the AI features described in section 6.
- Razorpay, PayPal and PayU — payments.
- Google Analytics — website analytics.
Some integrations are engaged only when a customer switches them on — syncing a product catalogue to Google Merchant Center, Meta Commerce or Amazon, sending storefront conversion events to Meta, or connecting your own email, SMS or WhatsApp provider in place of ours. Turning one on sends the relevant data to that vendor under their terms.
We may also disclose data to our professional advisers; to comply with a law, court order or lawful request; to enforce our terms; to protect the rights and safety of people or of the platform; or to an acquirer as part of a merger or sale of the business — in which case we will tell affected customers.
10. International transfers
ZingaSuite is operated from India and runs on cloud infrastructure and vendors that operate internationally, including in the United States and the European Union. Personal data may therefore be transferred to, stored in, or accessed from a country other than your own.
Where data protected by European, UK or Indian law moves abroad, we rely on the safeguards those laws recognise — most commonly the European Commission's standard contractual clauses, or an adequacy decision — and we contract with our providers on that basis.
11. How long we keep data
- Account and workspace data — while the account is open, and for a short wind-down period after it closes so the data can still be recovered or exported.
- Customer data in the apps — for as long as the customer keeps it. Customers delete records inside their workspace, and can ask us to delete a whole workspace.
- Invoices and tax records — for the period tax and company law requires, typically several years, even after an account closes.
- Message media — inbound WhatsApp media is purged on a rolling schedule (currently about 90 days).
- Logs and diagnostics — short retention, measured in days to months.
- Sales enquiries — until the enquiry is no longer live, or you ask us to remove it.
Backups lag deletion: a deleted record can persist in an encrypted backup for a short window before it rolls off.
12. How we protect data
- Traffic is encrypted in transit with TLS. Passwords are stored as salted hashes, and API keys as hashes with scoped permissions.
- Access inside a workspace is governed by roles, model access rules and record rules, so a teammate sees only what their role allows.
- Administrative access to production is restricted, and privileged actions are logged.
- Public endpoints are rate limited and protected by bot checks.
- Data is backed up, and backups are encrypted.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant regulator as the law requires.
13. Your rights
Depending on where you live, you may have the right to:
- ask what personal data we hold about you, and get a copy;
- have inaccurate data corrected, and incomplete data completed;
- have data erased, or its use restricted;
- receive data you gave us in a portable format;
- object to processing we base on legitimate interests, including direct marketing;
- withdraw consent you previously gave;
- complain to your data protection authority.
If you are in India, the Digital Personal Data Protection Act also gives you the right to nominate someone to exercise your rights in the event of death or incapacity, and the right to a grievance process — see section 16.
If you are in California or another US state with a comprehensive privacy law, you may have the right to know, delete and correct, and to opt out of the sale or sharing of personal information. We do not sell personal information, and we do not share it for cross-context behavioural advertising. We will not discriminate against you for exercising a right.
To exercise any of these, email hello@zingasuite.com. We may need to verify who you are before we act, and we aim to respond within 30 days. If your request concerns data a ZingaSuite customer holds about you, we will pass it to that customer, who is the controller.
14. Children
ZingaSuite is a product for businesses, not for children, and we do not knowingly collect personal data from children directly.
Assessments built in Zingalify may be administered to people under the age of majority by the business running them. In that case the business is responsible for any parental consent the law requires, and for telling candidates and their guardians what is collected.
15. Changes to this policy
We update this policy as the platform changes. The version on this page is always the current one, and the date tells you when it last changed. If a change materially affects how we use your personal data, we will give account holders notice — by email or in the console — before it takes effect. This version is dated 13 September 2026.
16. Contact us
For any privacy question, request or complaint, email hello@zingasuite.com with "Privacy" in the subject line and it will reach the team responsible. ZingaSuite is operated by KKE Soteco Pvt. Ltd..
If you are in India and you are not satisfied with our response, you may escalate the same way, marking your message "Grievance", and then to the Data Protection Board of India. If you are in the European Economic Area or the UK, you may complain to your local supervisory authority.