Privacy Policy

Last updated September 5, 2026 · All versions

Current policy
This version is not in effect yet. It takes effect on September 5, 2026. Until then the current policy (v2026-08-26) applies.

A Zinkosoft LLC Application

Privacy Policy

Last updated:
September 5, 2026
Effective:
September 5, 2026
Publisher:
Zinkosoft LLC, 400 N Tampa St, Ste 1550 PMB 113237, Tampa, FL 33602-4719

This Privacy Policy explains how Zinkosoft LLC collects, uses, discloses, and protects personal information in connection with the zblocks website builder. Please read it carefully.

1. Who We Are and What This Policy Covers

Zinkosoft LLC (“Zinkosoft,” “zblocks,” “we,” “us,” or “our”) is a limited liability company organized in the State of Florida, United States. We operate the zblocks website builder, available at zblocks.app and related subdomains, together with our marketing website, dashboard, and account services (collectively, the “Service”).

This Privacy Policy applies to:

  • Visitors to our marketing website at zblocks.app.
  • People who create an account and use the Service to build, manage, or publish websites.
  • People who contact us for support or other communications.

This Privacy Policy does not govern the websites that our customers create and publish using zblocks. Information you provide directly to a customer’s site is controlled by that customer, not by us. See Section 16, “Sites Built by Our Customers.”

By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Service.

2. The Two Roles We Play

Depending on the information involved, we act in one of two roles under data protection law.

As a controller. For personal information about our own account holders, billing contacts, and visitors to our marketing website, Zinkosoft is the “controller.” This means we decide why and how that information is processed, and this Privacy Policy describes those practices.

As a processor (service provider). When our customers use zblocks to collect information from visitors to the sites they build (for example, through a contact form or a newsletter sign-up), Zinkosoft acts as a “processor” or “service provider.” We handle that information only to provide the Service, acting on the customer’s instructions. In that situation, the customer is the controller of the information and is responsible for its own privacy practices. See Section 15.

3. Information We Collect

3.1 Information you provide to us

  • AI Input and AI Output. The prompts, instructions, source content, and documents you submit to an AI feature, and the generated text, images, translations, and answers that are saved to your account or site. See Section 7.
  • Account information. Your name, email address, password (stored only in hashed form), and your account and profile settings.
  • Billing information. Your billing name, billing address, subscription plan, and limited card details such as the card type and the last four digits. Full payment card numbers are collected and processed directly by our payment processor, Stripe, through its secure payment interface; they are not transmitted to or stored on our own systems.
  • Content. The text, images, and other materials you upload, create, or store while building and managing a site.
  • Communications. The messages, survey responses, and feedback you send when you contact us or interact with our support channels.
  • Authentication details. If you sign in using a third-party login (for example, Google) or a passkey, we receive the limited information needed to authenticate you, such as your email address and a unique identifier.
  • Connected calendar data. If you choose to connect a Google Calendar, we access a read-only view of your calendar events to display them on your site. This is described in detail in Section 6.

3.2 Information we collect automatically

  • Usage information. Pages and features viewed, actions taken, and timestamps, collected through our own first-party analytics.
  • Device and connection information. Your IP address, browser type, operating system, device identifiers, language settings, and the page that referred you.
  • Log data. Records generated automatically when you access the Service, which we use for security, troubleshooting, and abuse prevention.

We use only first-party analytics that we operate ourselves. We do not use third-party advertising networks, and we do not use third-party tracking technologies to follow your activity across other websites or services.

3.3 Website interaction information

Our first-party analytics record which pages are viewed, where a visit came from, roughly how long it lasted, and the general type of device used. On its own that record is anonymous. It is a count of visits, and it is not tied to anyone’s name.

There is one exception, and it happens only if you choose it. When you send us a form, our server creates a random code for that submission. The code is a jumble of letters and numbers that means nothing by itself. We save it beside your message in our database, and we pass it to our analytics, which uses it to label the visit you are in the middle of. We can then see, next to your message, the pages you viewed during that same visit, roughly how long you spent on them, where you arrived from, and whether you were on a phone or a computer. It helps us understand what you are asking about before we reply. Our customers can switch on the same feature for the sites they build; see Section 16.

The limits on this matter as much as the feature does:

  • Only when you send something. Browsing alone never triggers it. No code is created for a visitor who does not send a form.
  • Only that one visit. What we see is limited to the visit in which you wrote to us. We do not use this to follow you across other websites, and we do not build a profile of you from it.
  • Nothing is stored on your device. This adds no cookie, writes nothing to your browser storage, and does not fingerprint your device.
  • The code is all our analytics receive. Your name, your email address, and the words of your message stay in our own database. They are never sent to the analytics system.
  • It is off unless it is switched on. The setting is off to begin with. While it is off, no code is created and nothing is linked to your message.
  • Deleting the message deletes the link. The code is saved on the message itself, so when it is deleted the code goes with it. After that nothing of ours connects you to that visit.
  • It does not last forever. We delete form submissions that are more than two years old, and the code is deleted with them.

3.4 Information we receive from third parties

  • Payment processor. Confirmation of payment, subscription status, and limited billing metadata.
  • Authentication providers. Where you choose to sign in with a third-party account, the limited profile and verification information needed to complete sign-in.
  • No data brokers. We do not purchase personal information from data brokers or acquire it from advertising networks or similar third-party sources.

4. Cookies and Similar Technologies

  • Strictly necessary. To operate the Service, keep you signed in, protect the security of your session, and guard against automated abuse. This includes bot-protection technology that runs on our sign-in and form pages to confirm that a visitor is a human; it may store a limited token in your browser solely for that purpose. These technologies cannot be turned off through the Service, and we do not use them for advertising or to track you across other sites.
  • First-party analytics. To understand how the Service is used so we can maintain and improve it.

We do not place third-party advertising cookies or cross-site tracking technologies on our marketing website or within the application.

Working without cookies is not the same as recording nothing. Our analytics still note which pages are viewed and where a visit came from, and if you send us a form those notes can be linked to your message for that one visit. Section 3.3 explains how that works and where it stops.

Where required by law, we request your consent before placing non-essential cookies, and you can manage your preferences through your browser settings or through any cookie controls we provide. Note that customers may add their own cookies or tracking to the sites they build; those are governed by the customer’s own privacy notice. See Section 16.

5. How We Use Your Information

  • Provide, operate, and maintain the Service and your account.
  • Provide AI features, including generation, translation, the visitor AI concierge, document indexing, retrieval, moderation, and abuse prevention. See Section 7.
  • Process payments, manage subscriptions, and send billing-related messages.
  • Authenticate users and protect accounts, including through multi-factor authentication.
  • Respond to your support requests and communicate with you about the Service.
  • Send transactional and service messages, such as account, security, and billing notices.
  • Send product updates and marketing messages where permitted, which you can opt out of at any time.
  • Measure performance, understand usage, and improve and develop features.
  • Detect, prevent, and respond to fraud, abuse, security incidents, and technical problems.
  • Comply with our legal obligations and enforce our terms and agreements.

6. Google Calendar Integration and Google User Data

zblocks offers an optional feature that lets you display your calendar events on your site. If you choose to connect a Google Calendar, we access your Google Calendar data through Google’s APIs using the read-only scope https://www.googleapis.com/auth/calendar.events.readonly.

  • What we access. Only your calendar event details (such as event titles, dates, times, locations, and descriptions), and only for the calendar you authorize. We request read-only access.
  • Why we access it. Solely to display your events on the parts of your zblocks site where you have chosen to show them, such as a members-only page.
  • What we do not do. We do not create, edit, or delete your calendar events. We do not use Google user data for advertising or any other purpose beyond displaying your events. We do not sell it, and we do not share it with third parties except as strictly necessary to provide this feature to you.
  • Storage and control. We store the access credentials needed to keep your displayed events up to date, in encrypted form. You can disconnect the integration at any time from your zblocks dashboard, or revoke our access directly in your Google Account security settings, which immediately ends our access.

7. AI Features and Automated Processing

Some ZBlocks features use artificial intelligence. This section explains what those features do with your information. “AI Input” means the prompts, instructions, site content, and documents submitted to an AI feature. “AI Output” means the text, images, translations, layouts, and answers an AI feature produces in response.

7.1 AI generation

When you use an AI generation feature, we process the AI Input needed to fulfil your request and return AI Output. Depending on the feature, that may include your prompt, selected page or blog content, layout context, image prompts, and language settings.

7.2 AI concierge and knowledge sources

When a customer enables the visitor AI concierge, we process the pages, posts, and uploaded documents that customer selects, in order to build and maintain a searchable text index used to find relevant source material. That index is a keyword and full-text index held in our own database. We do not create embeddings, we do not send the content to a third-party embedding provider, and we do not use an external vector database for this feature. We re-index content when it changes and remove index entries when the source is deleted.

We do not store visitor conversations. A visitor’s message and the concierge’s reply are processed to answer that request and are not written to a ZBlocks conversation store. We keep aggregate message counters and abuse-prevention metadata only.

The concierge identifies itself to visitors as an automated AI system. Customers who enable it are responsible for keeping that disclosure in place and for any additional notice their own visitors are owed.

7.3 Private sources

If a customer configures members-only or private documents as knowledge sources, ZBlocks is designed to apply the relevant access controls when retrieving content. Customers are responsible for configuring permissions correctly. No system can guarantee absolute security.

7.4 AI training and model improvement

We do not use your content, AI Input, AI Output, or visitor concierge conversations to train generalized AI models, and we do not license or sell that material to any third party for model training.

Our AI providers are engaged under paid commercial terms that contractually prohibit the use of submitted content to train their models. Providers may retain prompts and responses for a limited period solely to detect and prevent abuse and to enforce their own usage policies.

We use AI-related data only to provide the features you request, to operate and secure the Service, to detect and prevent abuse and fraud, to troubleshoot errors, and to produce aggregated or de-identified statistics that do not identify you, your visitors, or the content of any prompt or conversation. We may review a specific prompt, output, or conversation when you ask us to for support, when investigating a suspected violation of our Acceptable Use Policy or a security incident, or when required by law.

We do not train ZBlocks-specific models on customer content. If that ever changes, we will give advance notice and an opt-in choice first.

Automated decision-making. We do not use AI features to make decisions about you that produce legal or similarly significant effects.

8. Legal Bases for Processing (EEA and UK)

If you are located in the European Economic Area or the United Kingdom, we rely on the following legal bases to process your personal information:

  • Performance of a contract. To provide the Service you have requested and to administer your account.
  • Legitimate interests. To operate, secure, analyze, and improve the Service, where those interests are not overridden by your rights and freedoms.
  • Consent. Where we rely on your consent (for example, for certain cookies, marketing, or connecting a calendar). You may withdraw your consent at any time.
  • Legal obligation. To comply with applicable laws and lawful requests.

9. How We Share Information

We do not sell your personal information. We share it only in the limited circumstances described below.

Service providers and subprocessors. We rely on a limited set of trusted third parties to operate the Service. As of the date of this Policy, our subprocessors are:

  • Stripe for payment processing, subscription billing, and related fraud prevention.
  • Railway for application hosting and origin infrastructure.
  • Cloudflare for content delivery, DNS, custom-domain hosting, object storage, edge security, and bot and spam protection.
  • Resend for delivery of account, security, and transactional email.
  • Upstash for managed Redis used for rate limiting and caching.
  • Anthropic for AI text generation, rewriting, blog drafting, translation, and visitor concierge responses. Engaged under Anthropic’s Commercial Terms of Service, which prohibit training on customer content.
  • Google for AI image generation through the Gemini API, and for optional authentication and Google Calendar integration when you choose to connect them. Image generation runs on Google’s paid Gemini API services, under terms that prohibit using prompts and responses to improve Google’s products.

Concierge retrieval involves no third-party AI provider. The search index the concierge queries is built and stored on our own infrastructure, and our analytics is self-hosted rather than provided by a third party.

These providers may access personal information only as needed to perform their functions for us, and they are bound by confidentiality and data protection obligations.

Legal and safety. We may disclose information when we believe it is reasonably necessary to comply with applicable law or a lawful request, to enforce our agreements, or to protect the rights, property, or safety of Zinkosoft, our users, or others.

Business transfers. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, personal information may be transferred as part of that transaction. We will take reasonable steps to notify you of any change in ownership or in how your personal information is used.

With your direction or consent. We share information when you ask us to or otherwise give your consent.

10. Your Choices and Controls

  • Marketing emails. You can opt out of marketing messages by using the unsubscribe link in those messages or by contacting us. We will still send necessary transactional and service messages.
  • Cookie preferences. You can manage cookies through your browser settings or through any consent controls we provide.
  • Connected calendars. You can disconnect any connected calendar at any time from your dashboard, or revoke access in your Google Account settings.
  • Account information. You can review and update much of your account information directly through your account settings.

11. Data Retention

We retain personal information for as long as your account is active and for as long as we need it to provide the Service. After your account is closed, we retain certain information for a limited period to comply with legal, tax, accounting, and dispute-resolution obligations, after which we delete or anonymize it. Backup copies may persist for a limited time before they are overwritten in the ordinary course. Credentials for a connected calendar are deleted promptly when you disconnect the integration or close your account.

AI-related retention. Visitor concierge conversations are not stored at all. Saved AI Output is retained like your other site content, until you delete it or close your account. Documents you upload as an AI knowledge source are kept until you delete them or the site is deleted, and the search index built from them is rebuilt when the source changes and removed when the source is deleted. AI usage records hold counters, cost, and timestamps only, never prompt or output text.

12. Data Security

We use technical and organizational measures designed to protect personal information, including encryption of data in transit, encryption of sensitive credentials at rest, access controls, and authentication safeguards (such as multi-factor authentication, which is available on all accounts and required on certain plans).

No method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. If we become aware of a security incident that affects your personal information, we will notify you and the relevant authorities as required by applicable law.

13. International Data Transfers

We are based in the United States, and your personal information may be processed and stored in the United States or in other countries where we or our service providers operate. These countries may have data protection laws that differ from those in your country. Where required, we use appropriate safeguards for cross-border transfers, such as Standard Contractual Clauses.

14. Your Privacy Rights

14.1 European Economic Area and United Kingdom

If you are located in the EEA or the UK, you have the right to: access your personal information; correct inaccurate information; delete your information; restrict or object to certain processing; obtain a portable copy of your information; and withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local supervisory authority.

14.2 California

If you are a California resident, you have the right to: know and access the categories and specific pieces of personal information we have collected; delete personal information; correct inaccurate personal information; and not be discriminated against for exercising your rights. We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law.

14.3 Other United States states

Residents of other United States states that have comprehensive privacy laws may have similar rights to access, correct, delete, and obtain a copy of their personal information, and to opt out of certain processing, to the extent those laws apply to us.

14.4 How to exercise your rights

To exercise your rights, contact us at privacy@zblocks.app. We will verify your request and respond within the time required by applicable law. You may also manage certain information directly through your account settings. You may use an authorized agent to submit a request on your behalf, subject to verification.

15. Do Not Track and Global Privacy Control

Some browsers offer a “Do Not Track” signal. Because there is no common industry standard for how to respond to these signals, our marketing website does not currently respond to them. Since we do not engage in cross-site tracking, this has limited practical effect on your information. Where required by applicable law, we honor recognized opt-out preference signals, such as Global Privacy Control.

16. Sites Built by Our Customers

Our customers use zblocks to create and publish their own websites. When you visit a site built with zblocks, any information you provide to that site (for example, through a contact form, a newsletter sign-up, or any other feature on that site) is collected by, and under the control of, the customer who operates the site, not by Zinkosoft.

For that information, Zinkosoft acts only as a service provider or processor on the customer’s behalf, handling it solely to deliver the Service under our agreement with the customer.

Customers are responsible for their own privacy practices, notices, and legal compliance, including any cookies, integrations, or tracking they choose to add to their sites.

A customer can switch on the feature described in Section 3.3, which links a form you send to the pages you viewed during that same visit. It works the same way and keeps the same limits: only for people who send something, only that one visit, nothing stored on your device, and only a random code reaching the analytics. It is off unless the customer turns it on. When it is on, what they see belongs to them, not to us, and the privacy notice on their own site governs it.

If you are a visitor to a customer’s site and wish to exercise privacy rights regarding information you provided there, please contact the operator of that site directly. We will support our customers in responding to such requests as required by applicable law.

17. Children’s Privacy

The Service is not directed to children, and we do not knowingly collect personal information from children under the age of 16. If you are under 16, please do not use the Service or provide any personal information to us. If you believe a child has provided us with personal information, please contact us and we will take appropriate steps to delete it.

18. Third-Party Links

The Service, and sites built by our customers, may contain links to third-party websites or services that we do not operate or control. This Privacy Policy does not apply to those third parties, and we are not responsible for their content or privacy practices. We encourage you to review the privacy policies of any third-party sites you visit.

19. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will post the updated version with a new “Last updated” date and, where required by law, provide additional notice. Your continued use of the Service after the changes take effect constitutes your acceptance of the updated Privacy Policy.

20. Contact Us

If you have questions about this Privacy Policy or our privacy practices, or if you would like to exercise your rights, please contact us:

Zinkosoft LLC
400 N Tampa St, Ste 1550 PMB 113237
Tampa, FL 33602-4719, United States
Email: privacy@zblocks.app