Skip to content
ZeroACE

Privacy Policy

Last updated: September 28, 2026

This Privacy Policy explains how Zero Core Studio LLC (“ZeroACE”, “we”, “us”) collects, uses, shares, and protects personal data when you visit our website, create a ZeroACE account, apply to our partner program, or ask to try our voice demo line.

ZeroACE provides an AI operator that businesses (“merchants”) use to talk to their customers and run their orders. When we handle the personal data of a merchant’s own customers on the merchant’s instructions, the merchant is the data controller and we act as a processor; that processing is governed by our Data Processing Agreement, not by this policy. This policy covers the data for which ZeroACE itself is the controller.

1. Who we are

The controller responsible for your personal data is Zero Core Studio LLC, a limited liability company organized under the laws of the State of Delaware, United States, with its registered address at 112 Capitol Trail, Suite A1598, Newark, DE 19711, United States.

For any privacy question or to exercise your rights, contact us at privacy@zeroace.ai.

2. Our two roles: controller and processor

ZeroACE acts in two distinct capacities, and it is important to understand which applies to you:

  • As a controller, when we decide how and why data is processed — for example, the account, billing, and usage data of merchants and partners, and the data of visitors to our website. This policy describes that processing.
  • As a processor, when a merchant uses ZeroACE to serve its own customers. In that case the merchant is the controller of its customers’ personal data (such as conversation content and order details), and we process it only on the merchant’s documented instructions under our Data Processing Agreement.

If you are a customer of a merchant that uses ZeroACE and have a question about your data, please contact that merchant, who is the controller of your data.

3. Personal data we collect

Data you provide

  • Account data — name, email address, business name, and the credentials used to sign in.
  • Billing data — the subscription plan you choose and billing details processed by our payment provider. We do not store full payment card numbers.
  • Provider connections — credentials and API keys you connect for your own providers (for example your payment, shipping, or accounting accounts). These are held encrypted in our key vault and used only to perform the actions you configure.
  • Support and communications — messages you send us, and the contents of support requests.
  • Partner-application data — the information you submit if you apply to our partner program (name, email, website or portfolio, and how you plan to refer merchants).
  • Voice-demo application data — the information you submit if you ask to try our voice demo line (business name, email address, store or website, the platform you sell on, your country, a short description of your business, and the phone number you will call the demo line from). The number is held for one purpose: so that the demo line recognises your call when it comes in. We do not call or message you on it.

Data we collect automatically

  • Usage data — how you interact with the console and website (pages viewed, features used, and similar activity).
  • Device and log data — IP address, browser and device type, and timestamps, collected through server logs and cookies or similar technologies.

Data we receive from systems you connect

When you connect a Connected Provider, we receive data from it so the assistant can answer accurately and so the operations you configure can run. We read only what those functions need, and we act on your instructions.

  • From your store platform (for example Shopify or WooCommerce) — your catalog and inventory, and your orders together with the customer details attached to them (such as name, contact details, and shipping address) so the assistant can answer questions about an order and, where you enable it, start a return or exchange. We also write back to your store platform where you ask us to, so that its record stays the only record.
  • From your accounting, shipping, courier, and messaging providers — the documents, labels, tracking events, and delivery results belonging to the orders we handle for you.

Connected Providers are your own accounts, chosen and controlled by you. Where the data concerns your customers, you are the controller of it and we process it as your processor under the Data Processing Agreement.

Regulatory identity checks — provided through us, held by our telephony provider

Some countries will not issue a phone number until the business that will use it has been identified to the regulator. Where that applies, the console opens a form supplied by our telephony provider and you complete it there — typically a business registration number, a business address, and a photograph of an identity document for the person authorised to act for the business.

That form is not ours. What you enter and upload in it goes to our telephony provider and is held in their systems in the United States; it does not reach ZeroACE. We see only whether the check is outstanding, approved, or rejected, and the reviewer’s reason where it is rejected, and we use that for one purpose: deciding whether a phone number can be issued to you. Because we never hold the documents themselves, they are not part of a data export, and closing your account does not delete them — our Data Deletion page explains how to have them removed.

We do not intentionally collect special categories of data (such as health or biometric data) about our account holders, and we ask that you not submit such data to us as a controller.

4. How and why we use your data

We use the personal data described above to:

  • Provide, operate, and maintain the ZeroACE service and your account.
  • Process subscriptions, calculate any commissions, and manage billing.
  • Provide support and respond to your requests.
  • Review a request to try our voice demo line and, where we approve it, allow the line to recognise the number you gave us when you call it. The demo line is inbound only: we do not use that number to call or message you, and it is not added to any marketing list.
  • Secure our systems, prevent fraud and abuse, and enforce our terms.
  • Improve and develop our products, using aggregated or de-identified data where possible.
  • Send you service and, where permitted, marketing communications, which you can opt out of at any time.

Where the GDPR or KVKK applies, we rely on the following legal bases: performance of a contract (to provide the service you signed up for); steps taken at your own request before any contract exists (to review a partner application or a voice-demo request you sent us, and to run the demo you asked for); our legitimate interests (to secure, support, and improve the service, balanced against your rights); your consent (for optional marketing and non-essential cookies); and compliance with legal obligations.

5. AI processing and model training

The ZeroACE service uses large-language-model providers to power conversations. When we act as a processor for a merchant, that processing is described in the DPA and performed on the merchant’s instructions.

We do not use your Customer Data to train our own or third parties’ foundation models, and we configure our AI sub-processors so that data sent through their APIs is not used to train their models. AI output can contain inaccuracies; it should be reviewed before it is relied upon (see our Terms of Service).

6. Cookies and similar technologies

We use strictly necessary cookies to operate the site and, subject to your choices, may use analytics or preference cookies. Details of the specific cookies we use are described in our Cookie Policy.

7. How we share data and our sub-processors

We do not sell your personal data. We share it only with:

  • Service providers (sub-processors) that help us run ZeroACE — including cloud hosting, email delivery, large-language-model providers, and telephony — under contracts that require them to protect your data and use it only to provide their service to us.
  • Payment processing — our payment provider processes subscription payments; ZeroACE does not store full card details.
  • Legal and safety — authorities or third parties where required by law, to enforce our terms, or to protect the rights, safety, and security of ZeroACE, our users, or the public.
  • Business transfers — a successor entity in the event of a merger, acquisition, or sale of assets, subject to this policy.

We publish a current list of our sub-processors, and what each one can see, at Sub-processors. Where we act as a processor, sub-processor changes are governed by the DPA.

Connected Providers — including your store platform (for example Shopify or WooCommerce) — are not our sub-processors. They are your own accounts, and we exchange data with them using the credentials you connect, on your instructions. Their handling of your data is governed by your agreement with them.

8. Government and law enforcement requests

A public authority may occasionally ask us to disclose personal data. We treat every such request as an exception that has to earn its way through, not as a routine disclosure. Our practice for each one is:

  • We review its legality before responding. We require valid legal process appropriate to the request — a subpoena, court order, warrant, or an equivalent instrument under applicable law — and we check that the requesting authority has jurisdiction over us and over the data it asks for.
  • We challenge or narrow requests we consider unlawful, overbroad, or improperly served, and we withhold data until the defect is cured.
  • We disclose the minimum necessary: only the specific data a valid request covers, never a broader export, and never a whole account or conversation history where a narrower set answers the question asked.
  • We document each request — what was asked, by whom, what we produced or refused, and the legal reasoning — and we keep that record.
  • We notify the merchant whose data is affected, so they can respond on their own customers' behalf, unless a court order, a statute, or an emergency involving a risk of serious harm prohibits or delays notice.

Where we process personal data as a merchant's processor, these steps operate alongside the DPA: we act on the merchant's documented instructions unless the law requires otherwise, and we tell them when it does, so far as we are permitted to.

9. Text messaging (SMS)

ZeroACE and the businesses that use it may send order-related SMS text messages — such as order confirmations, shipping and delivery updates, and order support — to customers who provide their mobile number and consent to receive them. Mobile numbers are used solely to send these messages.

We do not sell, rent, or share mobile numbers or SMS opt-in information with any third parties or affiliates for their own marketing purposes. Message frequency varies based on your order activity. Message and data rates may apply. You can opt out at any time by replying STOP, and reply HELP for help.

10. WhatsApp messaging

Businesses that use ZeroACE may connect their own WhatsApp Business account so their customers can message them there — to ask about products, place or track an order, and get support — and so the business can send order-related updates such as confirmations, shipping notices, and refund notices. WhatsApp is provided by Meta; when you message a business on WhatsApp, Meta also processes that message under its own terms and privacy policy.

For these conversations the business is the controller of its customers' data and ZeroACE acts as its processor. We process the WhatsApp identifier the business's customer messages from, the content of that conversation, and the related order information needed to answer it.

We use conversation content only to operate the assistant and deliver the business's messages. We do not use WhatsApp conversation data to train our own or any third party's AI models, and we configure our AI sub-processors so that data sent through their APIs is not used to train their models. We do not use it to build or enrich advertising or user profiles, and we do not sell, rent, license, or otherwise share it with third parties for their own purposes.

ZeroACE's assistant is a business assistant, scoped to the connected business's own catalogue, orders, and customer service. It is not a general-purpose AI assistant offered to WhatsApp users.

You can stop business-initiated marketing messages at any time by replying STOP in the chat. To have your data deleted, contact the business you were messaging, or contact us at privacy@zeroace.ai — deletion removes your conversations, call recordings and contact data from ZeroACE, and we pass your request to that business so it can act on the records it holds. WhatsApp itself is Meta's service: what Meta keeps is governed by the business's own agreement with Meta, to which we are not a party. Step-by-step instructions are on our “How to delete your data” page.

11. International data transfers

ZeroACE is operated from the United States, and your data may be processed in the United States and in other countries where our sub-processors operate. These countries may have data-protection laws that differ from those in your country.

Where we transfer personal data out of the European Economic Area, the United Kingdom, or Türkiye, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum), and the transfer mechanisms permitted under the KVKK, together with supplementary measures where needed.

12. Data retention

We keep personal data only for as long as necessary for the purposes described in this policy, to comply with our legal obligations, resolve disputes, and enforce our agreements. Account data is retained for the life of your account and for 90 days after it is closed, unless a longer period is required by law. You may request deletion as described below.

A few working copies are deleted on a fixed schedule rather than on request: the raw messages and delivery updates that messaging and shipping providers send us (30 days); saved answers from a business's providers, such as invoice and label links, kept so that a retried request is never carried out twice (at least 97 days); conversations that cannot be tied to an order or a phone number (90 days, or 180 with a call recording); contact details held while a delivery problem is being resolved (3 days); and system logs (up to 90 days). Backups are kept for up to 35 days and are not used for anything else in the meantime.

If you ask to try our voice demo line, we keep your request while we review it. Where we approve it, we keep the phone number you gave us for as long as the demo access lasts, so the line can recognise your call, together with a record of the calls placed to the line from that number — the time, how long the call lasted, and whether it was answered. We do not run an automatic purge on these records: we keep them until you ask us to delete them, and you can ask at any time through our Data Deletion page or at privacy@zeroace.ai. We do not reply to requests we do not take forward, so if you have not heard from us your request was not approved — you can still ask us to delete what you sent.

13. How we protect your data

We apply technical and organizational measures designed to protect personal data, including encryption of provider credentials in a key vault with a separate key per business, tenant-scoped access controls, and least-privilege authentication throughout our systems. No method of transmission or storage is completely secure, but we work to protect your data and to detect and respond to incidents. Further detail is available on our Security page.

14. Your privacy rights

Depending on where you live, you may have some or all of the following rights over your personal data: to access it; to correct it; to delete it; to restrict or object to its processing; to data portability; and to withdraw consent. Under the KVKK, you also have the right to learn whether your data is processed and to request that the consequences of any unlawful processing be remedied. Under U.S. state privacy laws such as the CCPA/CPRA, you may have rights to know, delete, correct, and opt out of “sale” or “sharing” of personal information; we do not sell personal data.

To exercise any of these rights, contact us at privacy@zeroace.ai. We will respond within the timeframe required by applicable law. You also have the right to lodge a complaint with your local data-protection authority (in Türkiye, the KVKK Board).

15. Children’s data

ZeroACE is a business product not directed to children, and we do not knowingly collect personal data from children under the age required by applicable law. If you believe a child has provided us with personal data, please contact us so we can delete it.

16. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the “Last updated” date and, where required, notify you. Your continued use of ZeroACE after an update means you accept the revised policy.

17. How to contact us

For any question about this policy or your personal data, contact Zero Core Studio LLC at privacy@zeroace.ai or by mail at 112 Capitol Trail, Suite A1598, Newark, DE 19711, United States.