ZipClients

Privacy Policy

Effective date: Sunday, September 27, 2026 (Asia/Dubai)

Controller / Operator: MARKETING AND SALES L.L.C-FZ

License: 2644059.01

Address: Meydan Grandstand, Dubai, UAE (Free Zone)

Brand: ZipClients (zipclients.com), a sister CRM product under marketingandsales.com

Privacy contact: [email protected]

Important: This Privacy Policy explains how we handle personal data. It is not legal advice. If you use ZipClients to store contacts or send messages, you are typically the controller of that CRM data and must comply with laws that apply to your marketing and messaging (including TCPA, CAN-SPAM, GDPR, and UAE rules). Consult qualified counsel for your situation.

1. Scope

This Privacy Policy describes how MARKETING AND SALES L.L.C-FZ (“we,” “us,” “ZipClients”) collects, uses, shares, and protects personal data when you visit zipclients.com, create an account, or use our white-label CRM SaaS and related services (the “Service”).

It also explains the distinction between:

  • Account & platform data — information about you as our customer (we are typically the controller); and
  • Customer Data / CRM data — contacts, leads, messages, and other content you store in the CRM (you are typically the controller; we act as processor).

2. Roles: Controller vs Processor

2.1 When we are the controller

We determine the purposes and means of processing for data such as your account profile, billing records, support tickets, website analytics, and security logs related to operating ZipClients as a business.

2.2 When we are the processor

When you (or your agency end clients via sub-accounts) store contacts, pipelines, conversations, files, form submissions, and similar CRM content (“Customer Data”), you are the data controller (or equivalent). We process that Customer Data on your behalf to host and provide the Service, according to your configuration and instructions. Agencies that rebill or manage sub-accounts remain responsible for their contractual relationship with their end clients and for ensuring lawful processing of those end clients’ Customer Data.

3. Personal Data We Collect

Category Examples Source
Account data Name, email, phone, company, password/hash, role, seats You; your admin
Billing data Plan, invoices, partial payment details via Stripe You; Stripe
Customer Data (CRM) Contacts, tags, notes, deals, messages, appointments, media You / your users / your end clients
Usage & device IP address, browser, device, pages viewed, feature usage, logs Automatic
Communications Support emails, chat, feedback You
Cookies & similar Session, preference, analytics cookies Automatic / consent where required

We do not require you to provide special-category sensitive data to use the core Service. If you choose to store such data in Customer Data, you are responsible for lawful basis and safeguards.

4. How We Use Personal Data

We use personal data to:

  • Provide, maintain, secure, and improve the Service;
  • Create and manage accounts, seats, and sub-accounts;
  • Process subscriptions and payments (via Stripe);
  • Deliver transactional emails and product notices;
  • Provide customer support and troubleshoot issues;
  • Monitor abuse, prevent fraud, and enforce our Terms of Service;
  • Analyze aggregated usage to improve features;
  • Comply with legal obligations and protect rights and safety;
  • Power optional AI features you enable (see Section 8).

We process Customer Data only as needed to provide the Service you request (hosting, sending messages you trigger, automations you configure, backups, support when you authorize access, and similar), unless law requires otherwise.

5. Legal Bases (Where Applicable)

Depending on your location and applicable law (including UAE data protection principles and, where relevant, GDPR for EU/UK users), we rely on:

  • Contract — to provide the Service you subscribe to;
  • Legitimate interests — security, product improvement, fraud prevention (balanced against your rights);
  • Consent — where required (e.g., certain cookies or marketing emails to prospects);
  • Legal obligation — tax, accounting, lawful requests.

For Customer Data, you determine the legal basis for collecting and instructing us to process contacts’ data (e.g., consent for SMS marketing).

6. Cookies and Similar Technologies

We use cookies and similar technologies for:

  • Essential — authentication, security, load balancing, remembering preferences;
  • Analytics — understanding how the site and product are used so we can improve them;
  • Functional — remembering settings and improving UX.

You can control cookies through your browser settings. Disabling essential cookies may break login or core features. Where consent is required by law, we will request it before non-essential cookies.

7. Payment Processing (Stripe)

Subscription payments are processed by Stripe. Stripe receives payment card and billing details as an independent payment processor. We typically receive confirmation of payment, last-four digits or similar tokens, plan status, and invoice metadata — not your full card number. Stripe’s privacy policy applies to its processing. See stripe.com/privacy.

You remain responsible for your own advertising/media spend and messaging usage costs tied to your business use of the CRM, which may be billed by third parties separately from your ZipClients subscription.

8. Email, SMS, and Messaging Processors

To send email, SMS, and related communications that you initiate from the CRM, we use and/or integrate with providers such as LeadConnector, Mailgun, and telephony/SMS carriers or aggregators. These processors receive message content, recipient contact details, and delivery metadata as needed to transmit messages you request.

You are responsible for consent, opt-outs, content legality, and compliance with TCPA, CAN-SPAM, CASL, GDPR/ePrivacy, UAE marketing rules, and carrier policies. ZipClients provides tools; it does not supply legal clearance for your campaigns.

9. AI Features

Optional AI features may process prompts, conversation snippets, or CRM fields you select to generate suggestions or automations. AI providers may process that input to return outputs. Do not submit data you are not authorized to process. We do not use Customer Data to train public foundation models for unrelated third parties except as disclosed in product documentation or with your instruction/consent. AI outputs may be wrong; review before use.

10. How We Share Information

We do not sell your personal data. We share data with:

  • Service providers / processors — hosting, Stripe, email/SMS (LeadConnector, Mailgun, carriers), analytics, AI vendors, support tools — under contracts requiring appropriate protection;
  • Agency / sub-account relationships — if you are invited to an account, the account owner and their admins can access your seat activity; if you operate sub-accounts, you control access for those end clients;
  • Corporate events — merger, acquisition, or asset sale, subject to confidentiality and continued protection;
  • Legal — to comply with law, lawful requests, or to protect rights, safety, and the Service;
  • With your direction — integrations you connect or exports you request.

11. International Transfers

We are based in Dubai, UAE (Free Zone). Personal data may be processed in the UAE and in other countries where our providers operate (for example, the United States or EU for Stripe, Mailgun, or cloud hosting). Where required, we use appropriate safeguards such as contractual clauses and vendor due diligence.

12. Retention

  • Account & billing data — retained for the life of the account and thereafter as needed for audits, taxes, dispute resolution, and legal compliance (typically up to several years as required by UAE/Dubai commercial practice and applicable law).
  • Customer Data — retained while your subscription is active and for a reasonable period after termination or deletion request to allow export, backups to expire, and legal holds if any. You should export needed data before cancelling. We may delete or anonymize Customer Data after that period.
  • Logs & security data — retained for security and operational periods appropriate to risk.
  • Marketing preferences — until you unsubscribe or we no longer need them.

13. Security

We implement commercially reasonable technical and organizational measures (access controls, encryption in transit where applicable, monitoring, and employee confidentiality). No method of transmission or storage is 100% secure. You are responsible for strong passwords, seat permissions, and securing API keys and connected integrations.

14. Your Rights and Choices

Depending on applicable law, you may have rights to access, correct, delete, restrict, or port personal data we hold as controller, and to object to certain processing or withdraw consent. To exercise rights regarding your account data, email [email protected].

If you are an end customer or contact stored in a ZipClients customer’s CRM, contact that business (the controller) first. We will assist our customers with reasonable data-subject requests relating to Customer Data they control.

You may unsubscribe from our marketing emails via the link in those emails. Transactional and service messages related to your account may still be sent.

15. Children’s Privacy

The Service is not directed to individuals under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will take appropriate steps to delete it.

16. Third-Party Links and Integrations

The Service may link to or integrate with third-party sites and apps. Their privacy practices are their own. Review their policies before connecting or sharing data.

17. Changes to This Policy

We may update this Privacy Policy from time to time. The “Effective date” at the top will change when we do. Material changes will be posted on this page and, where appropriate, notified by email or in-product notice. Continued use after the effective date constitutes acceptance of the updated Policy, except where consent is required by law.

18. Governing Law

This Privacy Policy is governed by the laws of the United Arab Emirates as applicable in the Emirate of Dubai. Disputes related to privacy and this Policy are subject to the courts of Dubai, UAE (including jurisdiction applicable to Dubai Free Zone entities), consistent with our Terms of Service, without limiting mandatory rights you may have under other applicable data-protection laws.

19. Contact Us

For privacy questions, requests, or complaints:

MARKETING AND SALES L.L.C-FZ
License: 2644059.01
Meydan Grandstand, Dubai, UAE (Free Zone)
Email: [email protected]
Web: zipclients.com