What we collect today

Account email, name, and password (hashed, never stored in plain text); your zip code, used only to center radius-based searches; the details you provide to start a negotiation (category, target price, search scope, and category-specific details like a desired internet speed or vehicle type); the negotiation itself — every message sent to and received from a provider on your behalf; and, if you accept an offer, payment processing for our success fee.

What we don't collect

Payment card details never touch our servers at all — collected entirely by Stripe, our payment processor, directly from your browser. We only ever hold Stripe's own reference to your saved payment method, never the card number itself. We don't request or store government ID numbers, and we don't track your real-time location.

Who sees it

Providers you're negotiating with see only what's needed to negotiate on that specific account. If a provider has no existing relationship with you — most comparison-shopping inquiries — they never see your name at all, unless you specifically choose to include it. A provider you already have an account with, or one you ultimately accept an offer from, does learn who they're dealing with, since that's necessary to actually provide service. Your real contact details are never shared directly — all communication routes back through Zlora.

Data retention and deletion

You can delete your account at any time from Settings (except while a negotiation is actively in progress). Deleting your account removes your name, email, zip code, and saved payment method from our active systems immediately — your saved card is also deleted from our payment processor, not just unlinked. Records of past negotiations and payments are kept in de-identified form after deletion, for accounting, fraud-prevention, and dispute-evidence purposes; they're no longer tied to your name or contact information once your account is deleted.

Vendors and businesses we contact

We store a business's name and public contact information (found via public business listings, or submitted by the business itself if they ask to be added) so we can reach out on your behalf and avoid contacting the same business incorrectly in the future. Every outreach email includes a link for that business to opt out of future contact from Zlora entirely, and a way to flag that they aren't actually a relevant provider — either one stops us from reaching out to them again.

Cookies

We use cookies to keep you signed in and to remember your display preferences (like light/dark mode) — not to track you across other sites, and not for advertising. We don't currently use any third-party analytics or advertising cookies. If that changes, this section will be updated before it happens, not after.

What's missing from this draft

State-specific privacy law compliance (e.g. CCPA/GDPR-style formal request processes, as opposed to the self-service deletion already built) isn't addressed yet. See docs/legal-draft-for-review.md and SECURITY.md in the project repo for the fuller picture of what still needs legal review before this is a real policy.