Last Updated: 14 March 2026
This Privacy & Cookie Policy ("Policy") describes how ZF Solutions AB (reg. no. 559439-8116), trading as Zellify ("Zellify", "we", "our", "us"), collects, uses, stores, shares, and protects personal data when you use our website at zellify.app and the Zellify platform (collectively, the "Service").
Registered address: Minkvägen 46, 191 39 Sollentuna, Sweden
We comply with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Swedish Data Protection Act, the California Consumer Privacy Act ("CCPA"), the Health Insurance Portability and Accountability Act ("HIPAA"), and other applicable privacy laws. By using the Service, you acknowledge that you have read and understood this Policy.
For a detailed overview of our security controls, compliance certifications, and subprocessors, visit our Trust Center.
We collect the following categories of personal data:
Information you provide when creating an account or updating your profile:
Information collected automatically when you interact with the Service:
Payment information is processed securely by our third-party payment providers (Stripe, Paddle). We do not store full credit card numbers. We may receive and store:
Information you provide when contacting us:
When you connect advertising platform accounts to Zellify, we access and collect data from those platforms via their APIs. The data collected varies by platform but generally includes:
Meta (Facebook / Instagram): We access data through the Meta Marketing API with the following permissions: ads_read, ads_management, business_management, pages_show_list, pages_read_engagement, and public_profile, as well as Ads Management Standard Access.
TikTok Ads: We access campaign, ad group, ad, and performance data through the TikTok Marketing API.
Google Ads: We access campaign and performance data through Google's advertising APIs.
Zellify sends real-time conversion and attribution events (such as sign-ups, purchases, and subscription events) from your published funnels back to your connected advertising platforms. This allows the platforms to optimise ad delivery and accurately report on campaign performance. Data sent may include event type, event time, transaction value, and anonymised user identifiers. This data flows to:
When end users interact with funnels you have published through Zellify, we collect data on your behalf as a data processor. This may include:
You, as the funnel owner, are the data controller for this end user data. You are responsible for providing appropriate privacy disclosures and obtaining any necessary consents from your end users.
See Section 8 — Cookies and Tracking Technologies for details on data collected through cookies, Google Analytics, and PostHog.
We process your personal data for the following purposes:
| Purpose | Data categories used |
|---|---|
| Providing and operating the Service (funnel builder, editor, hosting, publishing) | Account data, usage data, your content |
| Hosting and serving your published funnels to your end users | Your content, end user data |
| Displaying and analysing advertising performance across connected platforms (Meta, TikTok, Google) | Advertising platform data |
| Performing ad management actions on your behalf (creating, editing, pausing campaigns, modifying budgets, changing ad creatives) | Advertising platform data, account data |
| Sending real-time attribution and conversion events to your connected ad platforms | End user data (anonymised), advertising platform data |
| Running A/B tests and experiments on your funnels | End user data, usage data |
| Processing payments from your end users through your Stripe or Paddle account | End user payment data (transaction confirmations only) |
| AI-powered analysis, funnel generation, and advertising insights | Advertising platform data, your content, usage data |
| Syncing subscription entitlements with RevenueCat | End user subscription data |
| Sending data to your connected CRM and marketing tools (Klaviyo, Mailchimp) | End user data, account data |
| Routing events to your connected analytics and workflow tools (Amplitude, Zapier, Segment) | End user data, usage data |
| Billing, invoicing, and subscription management for your Zellify account | Payment data, account data |
| Communicating with you about service updates, security alerts, and support | Account data, communication data |
| Improving and optimising the Service | Usage data, device data |
| Preventing fraud, abuse, and ensuring platform security | Usage data, account data, IP address |
| Complying with legal and regulatory obligations | All categories as required |
Under the GDPR, we rely on the following legal bases:
This section specifically addresses data collected from the Meta platform in accordance with Meta's Platform Terms and Developer Policies.
We use data obtained from the Meta Marketing API to:
We use Anthropic's Claude AI models to analyse your Meta advertising data and provide insights, recommendations, and summaries. When your data is sent to Anthropic for processing:
We do not sell, license, or otherwise commercially distribute any data obtained from the Meta platform to third parties. Meta platform data is used exclusively to provide the Service to you.
We share personal data only with the following categories of recipients, and only to the extent necessary:
| Recipient | Purpose | Data shared |
|---|---|---|
| Meta Platforms, Inc. | Ad management and attribution (Conversions API) | Campaign instructions, conversion events |
| TikTok | Attribution (Events API) | Conversion events, anonymised user identifiers |
| Attribution (Analytics / Tag Manager) | Conversion events, anonymised browsing data | |
| Anthropic | AI-powered analysis, funnel generation, and insights | Aggregated campaign/performance data, funnel content |
| Amazon Web Services (AWS) | Cloud infrastructure and data storage | All categories (encrypted) |
| Supabase | Database hosting and authentication | Account data, platform data |
| Vercel | Application hosting and deployment | Usage data, access logs |
| PlanetScale | Database services | Account data, platform data |
| GitHub | Code hosting and build security | No customer personal data |
| Stripe / Paddle | Payment processing (your account and your end users') | Payment and billing data |
| RevenueCat | Subscription entitlement sync (when connected by you) | End user subscription status |
| Klaviyo / Mailchimp | CRM and email marketing (when connected by you) | End user data, event data |
| Amplitude | Analytics (when connected by you) | End user interaction data |
| Zapier / Segment | Workflow automation and data routing (when connected by you) | Event data as configured by you |
| Calendly | Appointment scheduling (when embedded in funnels) | End user name, email, booking data |
| PostHog | Product analytics | Anonymised usage data |
| Google Analytics | Website analytics (landing page) | Anonymised browsing data |
| Law enforcement / regulators | Compliance with legal obligations | As legally required |
We never sell your personal data.
All third-party processors are bound by data processing agreements (DPAs) that require them to protect your data in accordance with applicable laws. Where processors handle protected health information (PHI), Business Associate Agreements (BAAs) are in place as required by HIPAA.
A full, up-to-date list of our subprocessors is available on our Trust Center.
We retain your personal data according to the following principles:
You have the right to request deletion of your personal data at any time. To make a request, contact us at:
Email: [email protected]
Please include your account email address and specify what data you would like deleted (e.g., your full account, Meta platform data only, or specific categories). We will process your request within 30 days.
When you request full account deletion:
When you disconnect any third-party platform (Meta, TikTok, Google, or other integrations) from Zellify without deleting your Zellify account:
If you submit a data deletion request through a connected platform (e.g., via Facebook Settings or TikTok Privacy Settings), we will process the request in accordance with that platform's terms and delete all data derived from that platform associated with your account.
We use cookies and similar technologies to operate and improve the Service.
Cookies are small text files stored on your device that allow us to recognise your browser, remember preferences, and analyse how the Service is used.
| Type | Purpose | Examples |
|---|---|---|
| Essential | Required for the site to function (authentication, security tokens, session management) | Login session, CSRF tokens |
| Analytics | Help us understand how users interact with the Service | PostHog (in-app), Google Analytics (landing page) |
| Functional | Remember your preferences and settings | Language, theme, dashboard layout |
When you first visit our site, you will be asked to consent to non-essential cookies. You can change your preferences at any time through the cookie settings or your browser settings.
Essential cookies cannot be disabled as they are strictly necessary for the Service to function.
We use Google Analytics on our landing page to understand website traffic and visitor behaviour. Google Analytics uses cookies to collect anonymised data such as pages visited, time on page, and referral source. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.
We use PostHog for product analytics within the Zellify application. PostHog collects anonymised interaction data to help us improve the user experience.
ZF Solutions AB is based in Sweden (EU). Some of our processors and infrastructure providers are located outside the European Economic Area ("EEA"), including in the United States.
When personal data is transferred outside the EEA, we ensure appropriate safeguards are in place:
Zellify is compliant with the Health Insurance Portability and Accountability Act (HIPAA). We maintain administrative, physical, and technical safeguards to protect electronic protected health information (ePHI) in accordance with the HIPAA Security Rule and Privacy Rule.
Our HIPAA compliance programme includes 74 security controls spanning:
Where third-party processors handle ePHI on our behalf, we enter into Business Associate Agreements (BAAs) that require them to implement appropriate safeguards, report breaches within required timelines, and comply with HIPAA requirements.
In the event of a breach of unsecured ePHI, we will notify affected individuals, the U.S. Department of Health and Human Services, and (where applicable) the media, in accordance with the HIPAA Breach Notification Rule.
We maintain business continuity and disaster recovery plans, including emergency ePHI access procedures, backup and restore testing, and emergency operations continuity.
For detailed information about our HIPAA controls and compliance status, visit our Trust Center.
We implement comprehensive technical and organisational measures to protect your personal data, maintained and monitored through our compliance programme:
Meta API access tokens are stored securely and encrypted. All credentials and secrets are managed through secure storage mechanisms.
While we strive to protect your data, no method of electronic storage or transmission is 100% secure. If you discover a security vulnerability, please report it to [email protected].
If you are in the EU, EEA, or UK, you have the following rights:
If you are a California resident, you have the right to:
If your data includes electronic protected health information (ePHI), you have the right to:
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days (GDPR/HIPAA) or 45 days (CCPA).
The Service is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at [email protected] and we will promptly delete it.
We may update this Policy from time to time to reflect changes in our practices, the Service, or applicable laws. When we make material changes, we will:
We encourage you to review this Policy periodically.
For any questions, concerns, or data requests, contact:
ZF Solutions AB Minkvägen 46, 191 39 Sollentuna, Sweden
Email: [email protected]