At ZoraPro LLC ("we," "us," or "our"), we provide an artificial intelligence-powered website concierge, chatbot, and automated appointment scheduling platform known as Verve by ZoraPro (the "Services"). We are committed to respecting your privacy and protecting the data entrusted to us.
This Privacy Policy describes how we collect, process, protect, and disclose personal data across our web properties and client deployments.
IMPORTANT NOTICE: OUR ROLE AS A SERVICE PROVIDER
Because we engineer and deploy our Verve AI widget for client businesses ("Customers"), we distinguish between two primary categories of personal data:
- Corporate Data (Where we are the Data Controller/Business): Information regarding businesses and authorized representatives subscribing to ZoraPro Services (account management, billing, onboarding).
- End-User Data (Where we are the Data Processor/Service Provider): Information collected through the Verve chatbot widget on a Customer's website from visitors ("End-Users"). We process End-User Data strictly on behalf of our Customers solely to provide chatbot answering, lead qualification, and scheduling functionality. We do not sell or use End-User Data to train foundational AI models.
1. PERSONAL DATA WE COLLECT
A. Data Collected from Our Customers (Corporate Data)
If you are a business subscribing to or consulting with ZoraPro for Verve deployment, we collect:
- Account & Contact Information: Name, work email address, company name, phone number, and authorized administrative credentials.
- Billing & Payment Information: Billing address and payment details processed securely by accredited merchant processors (e.g., Stripe). We do not store full payment card numbers on our servers.
- Knowledge Base & Workflow Material: Documentation, FAQs, service menus, and scheduling rules provided to configure your RAG agent.
B. Data Collected from End-Users (End-User Data)
When a website visitor interacts with Verve on a Customer's website, we collect information on behalf of that Customer to provide direct assistance and complete bookings:
- Chat Transcripts: Text messages exchanged between the visitor and the Verve AI concierge.
- Lead & Scheduling Details: Contact information explicitly submitted by the visitor (name, email address, phone number, service address, and appointment notes) for calendar scheduling.
C. Automatically Collected Technical Data
- Log & Security Data: IP address, browser user agent, timestamp, and interaction telemetry necessary to ensure system uptime and prevent abuse.
- Cookies & Essential Storage: Strictly necessary session storage tokens required to maintain active conversation state across pages.
2. HOW WE USE PERSONAL DATA
How We Use Corporate Data:
- To deploy, configure, and maintain your Verve AI Concierge instance.
- To process transactions, issue invoices, and manage service agreements.
- To send critical technical notices, infrastructure updates, and security alerts.
How We Use End-User Data:
- Strict Customer Fulfillment: End-User Data is processed exclusively to answer visitor inquiries via the Customer's RAG knowledge base, qualify leads, and synchronize appointments into the Customer's calendar and CRM.
- No Training on Confidential Chat Logs: We do not use client or end-user conversation logs to train public foundational language models.
3. DISCLOSURE OF PERSONAL DATA
We do not sell or rent personal data. We disclose personal data only under the following limited conditions:
- To the Client Business (Customer): Transcripts, lead forms, and appointment bookings captured by Verve are transmitted directly to the business operating the website.
- Infrastructure Vendors: Accredited cloud infrastructure vendors (e.g., AWS, secure SMS reminders, transactional mail webhooks) operating under strict data protection addendums.
- Legal & Regulatory Compliance: When legally mandated by enforceable subpoena, judicial order, or to safeguard system security.
4. DATA RETENTION & SECURITY
We implement strict administrative, technical, and physical safeguards designed to secure personal data against unauthorized access, corruption, or disclosure—including TLS encryption in transit, AES-256 encryption at rest, and strict role-based engineering access.
Customer Corporate Data is retained while accounts remain active. End-User Data is retained on behalf of our Customers and deleted in accordance with client data retention schedules or contract termination.
5. YOUR PRIVACY RIGHTS & CONTACT INFORMATION
If you are a Customer subscribing to ZoraPro services, you may exercise access, modification, or deletion requests regarding your account by contacting our engineering and legal team directly.
If you are an End-User who interacted with a Verve concierge on a third-party client website, please direct privacy requests to that specific business, as their privacy policy governs your primary engagement.
CONTACT ZORAPRO LLC
For questions, security disclosures, or data protection inquiries regarding Verve or ZoraPro LLC:
Email: hello@zorapro.com
Entity: ZoraPro LLC • Custom Business Process Automation & AI Systems