Back home

Legal · Privacy

Privacy Policy.

Draft · under legal reviewLast updated · May 2026

This draft Privacy Policy describes how the SubZero service ("SubZero", "we", "us") collects, uses, discloses, and protects personal information in connection with the SubZero website, applications, and services (the "Service"). It applies to visitors, account holders, and end users whose data is submitted to the Service. Capitalised terms not defined here have the meaning given in our Terms of Service.

For data we process on behalf of business customers (e.g. workspace admins ingesting transactions for their team), we act as a processor and our Data Processing Addendum governs that processing. For data we collect directly from you (e.g. your account, billing, marketing interactions), we act as a controller and this Policy governs.

1. Information we collect

a. Information you provide

  • Account data — name, work email, password hash (or SSO identifier via Clerk), organisation name, role.
  • Billing data — billing contact details and payment references returned by Razorpay. Payment instruments are collected by Razorpay rather than the SubZero application.
  • Support and marketing — messages you send us, newsletter subscriptions, event registrations.

b. Information you authorise us to ingest

  • Optional connector data — data you choose to provide through a connector marked Live or Beta. The setup flow describes the requested data and permissions before connection.
  • Imported subscription data — records entered manually or provided through a supported CSV import.

c. Information collected automatically

  • Product telemetry — page views, feature events, performance metrics, error logs.
  • Device and network data — IP address, browser / device type, referrer, approximate location derived from IP.
  • Cookies and similar technologies — strictly necessary (session, CSRF), preference (theme, locale), and analytics cookies. See our cookie banner for granular control.

2. What we do not collect

  • Bank, brokerage, or payroll login credentials.
  • Email content outside of receipt patterns.
  • Government-issued identifiers, biometric data, or special-category data (race, health, sexual orientation, etc.) unless required by law (e.g. KYC for billing in certain jurisdictions).
  • Children under 16. The Service is not directed to children.

3. How we use information

We process personal information for the following purposes:

  • Service delivery — operating the Service, detecting subscriptions and generating recommendations or draft vendor messages for you to review. Legal basis: contract.
  • Security and fraud prevention — abuse detection, rate limiting, audit logs. Legal basis: legitimate interest.
  • Product improvement — aggregated and de-identified analytics, debugging, A/B testing. Legal basis: legitimate interest; consent where required by law.
  • Communications — service notifications, billing receipts, security alerts (transactional); newsletters and product updates (consent-based, with one-click unsubscribe).
  • Legal compliance — tax reporting, lawful requests from authorities, enforcement of our Terms.

We do not sell personal information, and we do not share it with advertisers, data brokers, or third parties for their independent marketing.

4. Disclosures and sub-processors

We share personal information only with the categories of recipients listed below, under written agreements that require confidentiality and appropriate security:

  • Sub-processors that operate parts of the Service (cloud hosting, authentication, payments, transactional email, bank / email / SMS connectors, analytics). The current list is maintained on our DPA page and is updated when changes are made.
  • Professional advisers — auditors, lawyers, insurers, bound by professional confidentiality.
  • Authorities — when compelled by valid legal process or to protect rights, safety, or property. We narrowly scope responses and notify affected users where lawful.
  • Successors — in connection with a merger, acquisition, financing, or asset sale, subject to equivalent protections.

5. International transfers

SubZero's current infrastructure may process data outside your country. The final policy will identify applicable transfer mechanisms after legal review and before this draft becomes binding.

6. Data retention

  • Account data — while the account is active and for the verified deletion period published before launch.
  • Subscription data — while needed to provide the service or until the account owner requests deletion, subject to the final retention policy.
  • Operational and billing records — for the period required to operate the service and meet applicable legal duties.

7. Security

We maintain administrative, technical, and physical safeguards designed to protect personal information, including HTTPS for public network traffic, authenticated application access, scoped connector permissions, and code review. Details are summarised on our Security page. No system is perfectly secure; we will notify affected users and regulators of qualifying incidents without undue delay.

8. Your rights

Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to our processing of your personal information, and to withdraw consent at any time. EU/EEA, UK, and Swiss residents have rights under the GDPR / UK GDPR; California residents under the CCPA/CPRA; Indian residents under the DPDP Act; and similar rights apply in other jurisdictions.

You can exercise most rights directly from Settings → Privacy (export, delete, consent toggles). For anything else, contact privacy@subzero.app. We respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority.

9. Automated decision-making

SubZero generates recommendations (e.g. likely-unused subscriptions), but no decision with legal or similarly significant effect on you is made automatically. Cancellation guidance must be reviewed and completed with the vendor by the user.

10. Changes to this Policy

We may update this Policy from time to time. Material changes will be notified by email and via in-product banner at least 14 days before they take effect. The "Last updated" date above always reflects the current version.

11. Contact

Privacy questions: privacy@subzero.app
Data Protection Officer: dpo@subzero.app
EU representative and India grievance officer details will be published here on appointment.

This is a strengthened working draft intended as a starting point for external counsel review. It is not legal advice and is not yet binding. The DRAFT label will be removed only when counsel-approved wording is published here and linked from in-product Settings.