Z
Zeerus

Privacy Policy

Last updated: August 20, 2026

1. Scope

This policy explains how Zeerus collects, uses, and protects personal information. It covers two different groups of people:

  • Agency users: you and your team, who create Zeerus accounts to use the Service.
  • Your clients: the people whose information your agency enters into Zeerus (names, contact details, policy information). For your clients' data, your agency is the data controller and Zeerus acts as a processor; see our Data Processing Addendum for that relationship. This section still explains, transparently, what we do with that data on your behalf.

2. Information we collect

From agency users, directly:

  • Name, email address, and password (hashed; we never see or store your plaintext password);
  • Agency name and mailing address;
  • Billing information, handled directly by Stripe: we store a Stripe customer/subscription reference, not your card details;
  • Anything you enter into the Service, including notes, uploaded documents, and support/feedback messages;
  • If you choose to connect Google Calendar to your booking page (optional, see Section 6): the email address of the connected Google account, and an OAuth token that lets Zeerus read your calendar's busy/free times and create or remove events on it.

On behalf of agency users, about their clients:

  • Name, email, phone, mailing address;
  • Birthday and anniversary (used for reminders);
  • Insurance policy details: carrier, policy number, premium, renewal and review dates, commission information;
  • Notes and activity history your agency records (calls, emails, meetings);
  • Whether the client has consented to receive automated email reminders (required under CASL before we send any).

Collected automatically:

  • Standard web server logs (IP address, browser type, pages visited) for security and troubleshooting;
  • A session cookie used to keep you signed in, set by our authentication provider (Supabase).

3. How we use this information

  • To provide the Service: storing and displaying your book of business, sending renewal/reminder emails you've configured, processing your subscription payment;
  • To communicate with you about your account, billing, and material changes to the Service;
  • To maintain an audit log of changes made in your workspace, for your own accountability and dispute resolution; this log cannot be edited or deleted through the app;
  • To detect, investigate, and prevent fraud, abuse, or security incidents;
  • To improve the Service: we use Vercel Web Analytics, a cookieless, privacy-friendly page-view analytics tool, in addition to the essential session cookie described in Section 10. It does not use cookies or collect personal information, and cannot identify individual visitors.

We do not sell personal information, and we do not use your clients' personal information for any purpose other than providing the Service to your agency.

4. Legal basis and consent (PIPEDA)

We handle personal information in line with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA): we only collect what's reasonably needed to provide the Service, we don't use it for unrelated purposes, and we give you tools to access, correct, and delete data. For automated emails to your clients, the Service requires your agency to record that a client has consented before those emails are sent, in line with CASL.

5. Where your data is stored

Zeerus's database, file storage, and authentication are hosted on Supabase infrastructure in the ca-central-1 (Canada) region, all part of the same project, so they share that region together. Data at rest is encrypted (AES-256) automatically, with no separate configuration required.

The application itself (the code that runs when you use Zeerus) is hosted by Vercel, which does not guarantee execution in a single region; in practice, we've observed it running in both Canadian and U.S. locations. This means personal information can pass through U.S.-based compute infrastructure momentarily while a request is being handled, even though it is stored at rest in Canada. See Section 6 for where our other service providers process data.

6. Who we share information with

We share information with a small number of service providers who help us run Zeerus, each bound by their own privacy and security commitments:

  • Supabase: database, authentication, and file storage;
  • Vercel: application hosting;
  • Stripe: subscription billing and payment processing;
  • Resend: sending transactional and reminder emails on your behalf;
  • Sentry: error monitoring, hosted in the EU, to help us detect and fix bugs;
  • Google: only if you individually choose to connect your Google Calendar (see below).

Where each provider actually processes data: Supabase: Canada (ca-central-1); Vercel: not pinned to a single region, and has been observed running in both Canada and the United States; Stripe: United States (Stripe, LLC, per Stripe's own disclosures for customers in the Americas); Resend: United States (account data and email metadata; the email itself can be dispatched from a regional AWS location, but that doesn't change where the underlying account data is stored); Sentry: European Union (Germany); Google: United States (Google LLC), as part of Google's own global infrastructure. If your agency has a strict data-residency requirement, this is the section to review closely: not everything stays in Canada today.

Google Calendar is opt-in, per team member.A producer can connect their own Google Calendar from their booking page settings; nothing is shared with Google unless and until they do. Once connected, Zeerus reads that calendar's busy/free times (not event details or content) to keep the booking page's availability accurate, and creates or removes calendar events for bookings made through that producer's page. Disconnecting stops all of this immediately; events already created in Google Calendar are not automatically removed. This integration only ever touches the connecting producer's own calendar, never a client's or another team member's.

Separately, Zeerus offers an optional recruiting-network feature for agencies structured as a producer hierarchy. An agency owner can invite another agency to join their network; if, and only if, that agency's owner explicitly accepts (via an in-app screen that discloses exactly what will be shared before any decision is made), the recruiting agency can see the recruited agency's aggregateclient count, policy count, and total premium under management. Individual client names, contact details, or policy records are never shared this way, and accepting an invite does not change the recruited agency's plan, billing, or account in any other respect. This is the only circumstance in which one Zeerus customer can see any data belonging to another.

Aside from the service providers and recruiting-network sharing described above, we don't share personal information with anyone else, except where required by law or to protect the rights, safety, or property of Zeerus, our users, or the public.

7. Internal access and support

A small number of authorized Zeerus personnel can access account information across agencies for legitimate operational purposes: providing customer support, investigating a billing question, and administering subscription plans and trials. This access is restricted to specific individuals (currently only the Zeerus operator) through a controlled allowlist, separate from the roles your own team members hold within your agency.

What this access can include: looking up which agency a specific email address belongs to (name, email, and record type only, not policy, financial, or notes-level detail); viewing an agency's subscription and trial status and adjusting it directly (for billing support or promotional discounts); and, where an account needs to be closed on our end (for example, an abandoned signup that never had an owner), initiating that closure the same way an agency owner could themselves.

Every one of these actions is recorded in the affected agency's own Audit Log (see Section 3), the same permanent, unmodifiable record your own team's actions are logged to, so there is always a visible trail of when administrative access touched your account and what it did.

We do not use this access to read your clients' notes, documents, policy details, or communications, and no member of our team can act as, or sign into, your account as you or a member of your team.

8. Security

Every agency's data is isolated using row-level security in our database, so one agency cannot access another's records. Passwords are hashed, not stored in plain text. Data in transit is encrypted (HTTPS/TLS), and data at rest in our primary database and file storage is encrypted using AES-256, enabled automatically with no separate configuration. We maintain a written incident-response process covering detection, containment, assessment, and breach notification. No system is perfectly secure, and we can't guarantee absolute security, but we take reasonable technical and organizational measures to protect the information you trust us with.

9. Data retention and deletion

We retain agency and client data for as long as the agency's account is active. If an agency closes its account, we retain data for 30 days to allow export, then delete it. This matches the grace period actually enforced by the Service today. The audit log is retained for as long as the underlying account exists, as it exists specifically to provide an unmodifiable record of account activity.

10. Your rights

Under PIPEDA, you (or, where your agency is the controller, your clients through your agency) have the right to access the personal information we hold, request corrections, and request deletion, subject to our legitimate need to retain certain records (for example, billing history or the audit log). To make a request, contact support@zeerus.app.

11. Cookies

Zeerus uses a single essential session cookie to keep you signed in, plus a short-lived (10-minute) security cookie only when you connect Google Calendar, used to verify that request actually came from Zeerus. We also use Vercel Web Analytics for aggregate page-view statistics, which is cookieless and does not track individual visitors. We don't use advertising, third-party tracking, or cookie-based analytics.

12. Children

Zeerus is a business tool for licensed insurance professionals and is not directed at, or intended for use by, children.

13. Changes to this policy

If we make material changes to this policy, we'll notify agency owners (for example, by email or an in-app notice) before the changes take effect.

14. Contact

Questions or requests about this policy can be sent to support@zeerus.app.