Zeplin Privacy Policy

Effective Date: April 18, 2022

1. Purpose

This Privacy Policy is incorporated by reference into the Zeplin Terms of Service (the “Terms”). The terms “Zeplin,” “we,” and “us” means Zeplin, Inc. This Privacy Policy explains our online and offline information practices, the kinds of information we may collect, how we intend to use and share that information, and how you can opt-out of a use or correct or change such information. All other terms not defined in Section 14 (Definitions) below or otherwise herein will have the meanings set forth in the Terms.

2. Scope

This Privacy Policy applies to Personal Information that is Processed by Zeplin in the course of our business, including on Zeplin websites (each, a “Site”), mobile applications (each, an “App”), and other online or offline offerings (together with any and all future online and offline offerings operated by or on behalf of Zeplin, the “Services”). All individuals whose responsibilities include the Processing of Personal Information on behalf of Zeplin are expected to protect that data by adherence to this Privacy Policy. This Privacy Policy is intended to meet requirements globally, including those in North America, Europe, APAC, and other jurisdictions.

3. TRANSPARENCY/NOTICE — Types of Personal Information We Collect and How We Use It

The types of Personal Information we may collect (directly from you or from Third-Party sources) and our privacy practices depend on the nature of the relationship you have with Zeplin and the requirements of applicable law. Some of the ways that Zeplin may collect Personal Information include:

We endeavor to collect only that information which is relevant for the purposes of Processing. Below are the ways we collect Personal Information and how we use it.

3.1 Types of Personal Information We Collect

Zeplin collects Personal Information regarding its customers, users, and visitors to the Services (collectively “Individuals”).

3.2 How Zeplin Uses Your Information

We acquire, hold, use, and Process Personal Information about Individuals for a variety of business purposes, including:

3.3 Cookies, Pixel Tags/Web Beacons, Analytics Information, and Interest-Based Advertising

We, as well as Third Parties that provide content, advertising, or other functionality on our Services, may use cookies, pixel tags, local storage, and other technologies (“Technologies”) to automatically collect information through the Services. We use Technologies that are essentially small data files placed on your computer, tablet, mobile device, or other devices (referred to collectively as a “device”) that allow us to record certain pieces of information whenever you visit or interact with our sites, services, applications, messaging, and tools, and to recognize you across devices.

Our uses of such Technologies fall into the following general categories:

If you would like to opt-out of the Technologies we employ on our sites, services, applications, or tools, you may do so by blocking, deleting, or disabling them as your browser or device permits.

3.4 Third-Party Websites, Social Media Platforms, and Software Development Kits

The Zeplin Services may contain links to other websites and other websites may reference or link to our Services. These other domains and websites are not controlled by us, and Zeplin does not endorse or make any representations about Third-Party websites or social media platforms. We encourage our users to read the privacy policies of each and every website and application with which they interact. We do not endorse, screen or approve, and are not responsible for the privacy practices or content of such other websites or applications. Visiting these other websites or applications is at your own risk.

Zeplin’s Services may include publicly accessible blogs, community forums, or private messaging features. The Services may also contain links and interactive features with various social media platforms (e.g., widgets). If you already use these platforms, their cookies may be set on your device when using our Services. You should be aware that Personal Information which you voluntarily include and transmit online in a publicly accessible blog, chat room, social media platform or otherwise online, or that you share in an open forum may be viewed and used by others without any restrictions. We are unable to control such uses of your information when interacting with a social media platform, and by using such services you assume the risk that the Personal Information provided by you may be viewed and used by third parties for any number of purposes.

3.5 Third-Party Payment Processing

When you make purchases through the Services, we process your payments through Stripe (https://stripe.com), a Third-Party application. The Third-Party application may collect certain financial information from you to process a payment on behalf of Zeplin, including your name, email address, address and other billing information.

3.6 Data Storage and Processing

We use infrastructure and storage services from Third-Party infrastructure providers to provide you with Zeplin services. Zeplin uses Amazon Web Services (https://aws.amazon.com) for processing, data storage and other additional services as needed.

4. Onward Transfer — Zeplin May Disclose Your Information

4.1 Information We Share

We may share your information as described in this Privacy Policy (e.g., with our Third-Party service providers; to comply with legal obligations; to protect and defend our rights and property) or with your permission.

4.2 Data Transfers

All Personal Information collected via or by Zeplin may be stored anywhere in the world, including but not limited to the United States, the European Union, in the cloud, on our servers, on the servers of our affiliates or the servers of our service providers. Your Personal Information may be accessible to law enforcement or other authorities pursuant to a lawful request.

5. Opt-Out (RIGHT TO RESTRICT PROCESSING)

5.1 General

You have the right to opt out of certain uses and disclosures of your Personal Information. Where you have consented to Zeplin’s Processing of your Personal Information, you may withdraw that consent at any time and opt-out to further Processing by contacting support@zeplin.io. Even if you opt-out, we may still collect and use non-Personal Information regarding your activities on our Services and/or information from the advertisements on Third-Party websites for non-interest based advertising purposes, such as to determine the effectiveness of the advertisements.

5.2 Email and Telephone Communications

If you receive an unwanted email from us, you can use the unsubscribe link found at the bottom of the email to opt-out of receiving future emails. We will process your request within a reasonable time after receipt. Note that you will continue to receive transaction-related emails regarding products or services you have requested. We may also send you certain non-promotional communications regarding Zeplin and our Services and you will not be able to opt out of those communications (e.g., communications regarding updates to our Terms or this Privacy Policy).

5.3 Mobile devices

Zeplin may occasionally send you push notifications through our App. You may at any time opt-out from receiving these types of communications by changing the settings on your mobile device. Zeplin may also collect location-based information if you use our App. You may opt-out of this collection by changing the settings on your mobile device.

5.4 “Do Not Track”

Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. DNT is a way for users to inform websites and services that they do not want certain information about their webpage visits collected over time and across websites or online services. Please note that we do not respond to or honor DNT signals or similar mechanisms transmitted by web browsers.

5.5 Cookies and Interest-Based Advertising

As noted above, you may stop or restrict the placement of cookies on your computer or remove them from your browser by adjusting your web browser preferences. Please note that cookie-based opt-outs are not effective on mobile applications, including our App. However, on many mobile devices, App users may opt out of certain mobile ads via their device settings.

The online advertising industry also provides websites from which you may opt-out of receiving targeted ads from their advertising partners that participate in self-regulatory programs. These partners may include some of our data partners. You can access these, and also learn more about targeted advertising and consumer choice and privacy, at http://optout.networkadvertising.org, or https://www.youronlinechoices.eu and http://optout.aboutads.info.

Further information may be found on the Zeplin support page at https://support.zeplin.io/en/articles/3413009-opt-out.

To be clear, whether you are using our opt-out or an online industry opt-out, these cookie-based opt-outs must be performed on each device and browser that you wish to have opted-out. For example, if you have opted-out on your computer browser, that opt-out will not be effective on your mobile device. You must separately opt-out on each device. Advertisements on Third-Party websites that contain the AdChoices link and that link to this Privacy Policy may have been directed to you based on de-identified, non-Personal Information collected by advertising partners over time and across websites. These advertisements provide a mechanism to opt-out of the advertising partners’ use of this information for interest-based advertising purposes.

6. Rights of Access, Rectification, Erasure, and Restriction

For purposes of the California Consumer Privacy Act of 2018 (“CCPA”), we do not sell your Personal Information.

In accordance with applicable law, you may have the right to: (i) request confirmation of whether we are processing your Personal Information; (ii) obtain access to or a copy of your Personal Information; (iii) receive an electronic copy of Personal Information that you have provided to us, or ask us to send that information to another company (the “right of data portability”); (iv) restrict our uses of your Personal Information; (v) seek correction or amendment of inaccurate, untrue, incomplete, or improperly processed Personal Information; and (vi) request erasure of Personal Information held about you by Zeplin, subject to certain exceptions prescribed by law. If you would like to exercise any of these rights, please contact us at support@zeplin.io. We will process such requests in accordance with applicable laws. To protect your privacy, Zeplin will take steps to verify your identity before fulfilling your request.

7. Data Retention

Zeplin retains the Personal Information we receive as described in this Privacy Policy for as long as you use our Services or as necessary to fulfill the purpose(s) for which it was collected, provide our Services, resolve disputes, establish legal defenses, conduct audits, pursue legitimate business purposes, enforce our agreements, and comply with applicable laws.

8. Security of Your Information

We take steps to ensure that your information is treated securely and in accordance with this Privacy Policy. Unfortunately, the Internet cannot be guaranteed to be 100% secure, and we cannot ensure or warrant the security of any information you provide to us. We do not accept liability for unintentional disclosure.

By using the Services or providing Personal Information to us, you agree that we may communicate with you electronically regarding security, privacy, and administrative issues relating to your use of the Services. If we learn of a security system’s breach, we may attempt to notify you electronically by posting a notice on the Services or sending an email to you. You may have a legal right to receive this notice in writing.

9. International Users

By using the Services, Zeplin will transfer data to the United States. By choosing to visit the Services, utilize the Services or otherwise provide information to us, you agree that any dispute over privacy or the terms contained in this Privacy Policy will be governed by the laws of the state of California and the adjudication of any disputes arising in connection with Zeplin or the Services will be in accordance with the Terms.

If you are visiting from the European Union or other regions with laws governing data collection and use, please note that you are agreeing to the transfer of your information to the United States and to the Processing of your data globally.

Where applicable and required, the standard contractual clauses annexed to the European Commission’s Decision (EU) 2021/914 of 4 June 2021 (“Model Clauses”) will govern the collection, use, and retention of Personal Information transferred from the European Union and Switzerland to the United States.

10. Children’s Privacy

The Services are not directed to children under 13 (and in certain jurisdictions under the age of 16) years of age, and Zeplin does not knowingly collect Personally Identifiable Information from children under 13 (and in certain jurisdictions under the age of 16) years of age. If we learn that we have collected any Personal Information from children under 13 (and in certain jurisdictions under the age of 16), we will promptly take steps to delete such information.

11. Redress/Compliance and Accountability

If you have any questions about our privacy practices, this Privacy Policy or how to lodge a complaint with the appropriate authority, please contact Zeplin by email at support@zeplin.io. We will address your concerns and attempt to resolve any privacy issues in a timely manner.

12. Other Rights and Important Information

12.1 Changes To Our Privacy Policy and Practices

This Privacy Policy may change from time to time. You understand and agree that you will be deemed to have accepted the updated Privacy Policy if you use the Services after the updated Privacy Policy is posted on the Services. If at any point you do not agree to any portion of the Privacy Policy then in effect, you must immediately stop using the Services.

12.2 California Privacy Rights

California law permits users who are California residents to request and obtain from us once a year, free of charge, a list of the Third Parties to whom we have disclosed their Personal Information (if any) for their direct marketing purposes in the prior calendar year, as well as the type of Personal Information disclosed to those parties. Except as otherwise provided in this Privacy Policy, Zeplin does not share Personal Information with Third Parties for their own marketing purposes.

13. Definitions

The following capitalized terms shall have the meanings herein as set forth below.