Privacy Policy
1. Who We Are
This Privacy Policy describes how SMBData LLC ("SMBData," "we," "us," or "our"), a Texas limited liability company, collects, uses, stores, and protects information when you use the ZuluKey platform ("Service"). ZuluKey™ is a patent-pending secure information relay platform operated by SMBData LLC.
This Privacy Policy applies to all users of the Service worldwide, regardless of location. By using ZuluKey, you consent to the data practices described in this Policy.
2. Information We Collect
We collect the minimum information necessary to provide the Service. Here is exactly what we collect and why:
| Data Type | What We Collect | Why We Collect It | Retention |
|---|---|---|---|
| Account Info | Email address | Authentication via magic link login | Until account deletion |
| Usage Data | Number of shares used per month, subscription tier | Enforce plan limits, billing | Until account deletion |
| Audit Metadata | Timestamp, code (not data), category, channel, hashed IP | Audit log, abuse prevention | Per plan (30 days to unlimited) |
| Shared Data Fields | The actual sensitive values you enter to share | Temporary transmission only | Deleted on retrieval or expiration |
| Technical Data | Browser type, device type (via standard web logs) | Service reliability and debugging | Up to 30 days in logs |
What we do NOT collect:
- We do not collect payment card numbers (payments handled by third-party processors)
- We do not collect or retain the content of shared data fields after deletion
- We do not collect social media profiles or third-party account data
- We do not use tracking pixels, behavioral advertising tags, or cross-site trackers
- We do not build advertising profiles based on your usage
3. How We Use Your Information
We use the information we collect solely to:
- Provide, operate, and improve the Service
- Authenticate your identity and maintain your account
- Enforce plan usage limits and process subscription billing
- Send transactional communications (login links, account notices) — we do not send marketing emails without your explicit consent
- Detect, investigate, and prevent fraudulent activity, abuse, and security incidents
- Comply with legal obligations and respond to lawful requests from government authorities
- Enforce our Terms of Service
- Generate anonymized, aggregated usage statistics to improve the Service
We do not use your information for automated decision-making or profiling that produces legal or similarly significant effects.
4. How Shared Data Is Handled
The sensitive data fields you enter into ZuluKey to share are handled with maximum care:
- Transmission: All data is transmitted over encrypted HTTPS/TLS connections
- Storage: Data fields are stored temporarily in our database pending retrieval, associated only with the access code and expiration time
- Single retrieval: Upon successful retrieval by the recipient, the data is immediately and permanently marked as accessed and purged from active storage
- Expiration: If not retrieved within the selected time window (default 5 minutes), data is permanently deleted from our systems
- No backups of data values: We do not create backup copies of shared data field values. Once deleted, recovery is not possible
- Audit logs never contain data values: Our audit logs record only metadata (timestamp, code identifier, category label, communication channel, hashed IP address) — never the actual content of what was shared
5. Information Sharing and Disclosure
We do not sell, rent, trade, or otherwise share your personal information with third parties for their marketing purposes. Period.
We may share your information only in the following limited circumstances:
- Service providers: Trusted vendors who assist in operating the Service (e.g., cloud hosting, email delivery) under strict confidentiality obligations and data processing agreements
- Legal compliance: When required by law, court order, subpoena, or other valid legal process, or when we believe disclosure is necessary to protect the rights, property, or safety of SMBData LLC, our users, or the public
- Business transfers: In connection with a merger, acquisition, or sale of all or substantially all of SMBData LLC's assets, in which case we will notify you and ensure the acquiring entity is bound by privacy commitments no less protective than this Policy
- With your consent: In any other circumstance, only with your explicit prior consent
6. Data Security
SMBData LLC implements commercially reasonable technical and organizational security measures designed to protect your information from unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encrypted data transmission via HTTPS/TLS for all Service communications
- Database-level security with managed PostgreSQL on enterprise infrastructure
- Hashed storage of IP addresses (one-way hash — original IPs are not recoverable)
- Time-limited authentication tokens for magic link login (15-minute expiry, single-use)
- Automatic purging of expired session data
Despite these measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security. YOU USE THE SERVICE AT YOUR OWN RISK. The transmission of information to and from the Service is at your own risk. You are responsible for ensuring that any device or network you use to access the Service is adequately secured. In the event of a data breach that affects your personal information, we will notify affected users as required by applicable law.
7. Data Retention
We retain personal information only as long as necessary to provide the Service and comply with our legal obligations:
- Account data (email, tier, usage counts): Retained until you delete your account or request deletion
- Shared data field values: Cleared from the system upon retrieval or expiration — not retained beyond that point under any circumstances
- Audit log metadata: Retained for 90 days from creation, then automatically and permanently deleted
- Authentication tokens: Automatically expire after 15 minutes and are deleted upon use
- Web server logs: Retained for up to 30 days for security and debugging purposes
8. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate personal information
- Deletion: Request deletion of your account and associated personal information
- Portability: Request your data in a machine-readable format where technically feasible
- Objection: Object to certain processing of your personal information
- Withdrawal of consent: Where processing is based on consent, withdraw that consent at any time
To exercise any of these rights, contact us using the information at the bottom of this page or use the Delete my account button in your Dashboard to immediately delete your account and all associated data. We will respond to requests within 30 days. We may need to verify your identity before processing requests.
Users in certain jurisdictions may have additional rights regarding their personal data, including rights to access, correct, delete, or export their information. To make any data request, contact privacy@zulukey.com. We will respond within 45 days.
9. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know what personal information is collected, the right to delete personal information, the right to opt out of the sale or sharing of personal information, and the right to non-discrimination for exercising your privacy rights.
SMBData LLC does not sell personal information as defined under the CCPA/CPRA. We do not share personal information with third parties for cross-context behavioral advertising.
10. International Users and Data Transfers
ZuluKey is operated from the United States. If you are accessing the Service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country.
By using the Service, you consent to the transfer of your information to the United States. We implement appropriate safeguards for international data transfers as required by applicable law.
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you may have additional rights under the General Data Protection Regulation (GDPR) or equivalent legislation. Please contact us for information about our GDPR compliance measures.
11. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have inadvertently collected personal information from a child under 18, we will take steps to delete such information promptly. If you believe we have collected information from a child under 18, please contact us immediately.
12. Cookies and Tracking Technologies
ZuluKey uses minimal cookies necessary for the Service to function:
- Session cookies: Used to maintain your authenticated session. These are deleted when you sign out or close your browser.
- No advertising cookies: We do not use advertising, tracking, or third-party analytics cookies.
- No third-party trackers: We do not embed third-party tracking pixels or scripts from advertising networks.
13. Third-Party Services
We use third-party service providers for email delivery, cloud hosting, and payment processing. These providers access only the data necessary to perform their services and are contractually required to protect it.
The Service may use the following third-party services, each subject to their own privacy policies:
- Render.com: Cloud hosting provider where the Service is deployed. Subject to Render's Privacy Policy.
- Stripe: Payment processing provider used to handle subscription billing. Your payment card data is transmitted directly to Stripe and never stored on our servers. Subject to Stripe's Privacy Policy.
- Resend: Transactional email delivery service used to send magic login links. Email addresses are transmitted to Resend solely for this purpose. Subject to Resend's Privacy Policy.
- Google Fonts: Font delivery service. Google may log font requests per their privacy policy.
We are not responsible for the privacy practices of third-party services. We encourage you to review their respective privacy policies.
14. Your Data Portability Rights
Under the California Consumer Privacy Act (CCPA) and other applicable privacy laws, you have the right to receive a copy of the personal data we hold about you in a portable format.
To exercise this right, sign in to your account and visit your Dashboard → Download My Data. This will generate a JSON file containing your account information and activity log metadata.
Important note on content: ZuluKey does not retain the content of information you shared through the Service. Field values, policy numbers, account numbers, and any other data submitted through a share code are permanently deleted upon retrieval or expiry. This content cannot be included in your data export because it no longer exists on our servers — this is by design and is core to our privacy model.
For all other data rights requests (correction, deletion, opt-out of sale), please contact us at privacy@zulukey.com.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by updating the "Last Updated" date at the top of this page and, where appropriate, by sending notice to your registered email address. Your continued use of the Service after the effective date of any change constitutes your acceptance of the updated Policy.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
SMBData LLC — Privacy Contact
Company: SMBData LLC
Email: privacy@zulukey.com
State of Formation: Texas, United States
Product: ZuluKey™ (Patent Pending)
We aim to respond to all privacy inquiries within 30 days.
© 2026 SMBData LLC · All rights reserved