PRIVACY

Privacy Policy

Effective date: May 13, 2026

This Privacy Policy explains how Zap Business LLC collects, uses, shares, and protects information when you use the ZapBz website, WhatsApp transcription service, WhatsApp bot, wallet billing, translation, and AI command features.

1. Who We Are

Zap Business LLC operates the ZapBz service at https://zap.bz. You can contact us about privacy or data deletion requests at info@zap.bz.

2. Information We Collect

  • Account information, including name, email address, phone number, password hash, account status, and language preferences.
  • WhatsApp authorization records, connected WhatsApp account status, phone identifiers, QR or linked-device setup metadata, and session status.
  • Messages, voice notes, transcripts, translated text, chat metadata, group metadata, timestamps, and delivery or processing status needed to provide transcription and translation.
  • ZapBot messages, account questions, `/zap` and `/question` AI prompts, AI responses, and command usage records.
  • Wallet and billing records, including signup credits, PayPal top-ups, transcription charges, AI command charges, payment provider references, and account balance.
  • Security and audit data, including login events, IP address, browser/device signals, failed login attempts, admin actions, and system logs.

Counterparty notice. When you pair a WhatsApp account with ZapBz, ZapBz can read voice notes other people send to your connected number. Those people did not register with ZapBz. We process their audio only to deliver the transcription/translation you requested as the account owner, and we do not share their content with other ZapBz users. By pairing your account you confirm that you have an appropriate legal basis to process incoming messages in your jurisdiction.

3. How We Use Information

  • To create, secure, and manage user accounts.
  • To connect authorized WhatsApp accounts and process messages or voice notes for transcription, translation, and account support.
  • To operate ZapBot, answer account questions, provide signup instructions, send payment links, and respond to active paid AI commands such as `/zap` and `/question`.
  • To calculate wallet balances, process payments, bill usage, prevent unpaid usage, and maintain financial records.
  • To detect abuse, troubleshoot errors, improve reliability, protect accounts, and comply with legal obligations.

4. WhatsApp and Meta

ZapBz currently connects authorized WhatsApp accounts through WhatsApp linked-device pairing using the open-source whatsapp-web.js library, which automates a WhatsApp Web session on our server. This is an unofficial integration: WhatsApp does not endorse it, and Meta may suspend or restrict the paired number at any time without notice. We are working to migrate the service to the official WhatsApp Business Cloud API; until that migration is complete, you accept the additional account-availability risk that comes with linked-device pairing.

You must only connect a WhatsApp account that you own or are authorized to connect. If you connect a WhatsApp account, you authorize ZapBz to access the messages, voice notes, and metadata needed to provide the service. When you message ZapBz through WhatsApp, WhatsApp and Meta also process your information under their own terms and privacy policies.

5. AI, Transcription, and Translation Sub-Processors

ZapBz uses OpenAI as its current sub-processor for speech-to-text (default model gpt-4o-mini-transcribe), translation (default model gpt-4o-mini), and paid /zap//question AI answers. Audio bytes, transcript text, language hints, and prompt context are transmitted to OpenAI to perform these operations. OpenAI processes that data under its own enterprise data policy; ZapBz does not knowingly use the data to train third-party models.

AI responses may be incorrect, incomplete, or culturally inappropriate and should not be treated as legal, medical, financial, immigration, or emergency advice.

5a. Auto-Posted Transcripts

When the account owner enables auto-post-to-chat, ZapBz writes the transcript back into the same WhatsApp conversation prefixed with 📝 [Auto-transcript]. By default the message does not include a ZapBz promotional footer; the account owner must explicitly opt in before any branded text is added. Counterparties can ask the account owner to disable auto-post-to-chat at any time.

5b. Operational Keyword Alerts

ZapBz administrators may configure an optional keyword-alert list. When a transcript contains a configured keyword (for example, words that may indicate fraud, urgent disputes, or legal action) ZapBz can send an internal email to the account owner or administrator. This feature is off by default and is scoped to the account owner's own conversations. Where it is enabled, the list of monitored keywords is available on request to the account owner at info@zap.bz.

6. Payments

PayPal may be used to process wallet top-ups. ZapBz stores payment status, amount, provider reference, and wallet ledger records. We do not store full credit card numbers or PayPal login credentials.

7. When We Share Information

  • With service providers that help operate ZapBz, including hosting, database, email, WhatsApp, AI, and payment providers.
  • With administrators and authorized staff who need access to support users, audit activity, and operate the service.
  • When required by law, legal process, fraud prevention, security, or to protect ZapBz, users, or the public.

We do not sell personal information.

8. Retention

  • Raw audio: deleted immediately after a successful transcription job. Failed jobs may be retained up to the duration configured by RAW_AUDIO_FAIL_RETENTION_HOURS (default 24 hours) for troubleshooting, then deleted.
  • Transcripts & translations: retained for as long as the account is active so users can search past conversations. Deleted on user request or 90 days after account deletion.
  • Billing & wallet records: retained for at least 7 years to meet US tax and accounting obligations.
  • Audit logs: retained for 12 months for security and abuse investigation, then purged.
  • WhatsApp session data: retained in encrypted-at-rest Docker volumes only while the account is paired; deleted on disconnect, account deletion, or after extended inactivity by our session janitor.

9. Your Choices and Data Requests

  • You can request access, correction, deletion, or account deactivation by emailing info@zap.bz.
  • You can stop using ZapBot messages by replying `stop` or by blocking the ZapBz WhatsApp number.
  • You can disconnect a WhatsApp account from the ZapBz dashboard or from WhatsApp linked-device settings.
  • Deleting some information may limit or end your ability to use the service.

10. Security

We use technical and administrative safeguards designed to protect account access, sessions, payment records, transcripts, and audit logs. No internet service is completely secure, so you should not send highly sensitive information such as Social Security numbers, bank account numbers, government IDs, health records, or emergency messages through ZapBot or WhatsApp.

11. Children

ZapBz is not directed to children under 13, and we do not knowingly collect information from children under 13.

12. Third-Party Policies

Your use of ZapBz may also involve third-party services. Review their policies: WhatsApp Privacy Policy, OpenAI Privacy Policy, and PayPal Privacy Statement.

13. Changes

We may update this Privacy Policy as ZapBz changes. The updated policy will be posted at https://zap.bz/privacy with a new effective date.