Privacy Policy
Last updated: April 18, 2026
This Privacy Policy describes how Zappush ("Company," "we," "us," or "our") collects, uses, processes, and shares information in connection with the Unrestrict platform and related services ("Service"). This policy applies to merchants who use the Service ("Merchants") and to end-user shoppers whose data is processed through the Service ("Shoppers").
By using the Service, you agree to the practices described in this policy. If you do not agree, do not use the Service.
1. Overview of the Service
Unrestrict is a compliance and advertising infrastructure platform for e-commerce brands in health and wellness verticals. The Service enables merchants to send conversion events to Meta's Conversions API (CAPI) through compliant domain routing, keyword cleansing, and server-side event delivery. The Service also provides persistent shopper identity resolution and a full-funnel analytics dashboard.
The Service integrates with multiple e-commerce platforms, including but not limited to Shopify, WooCommerce, Wix, Kajabi, and custom-built websites. The specific data collected depends on your platform and integration method.
2. Data Processing Roles
Merchant Data
When we collect your account information, billing details, and dashboard usage data, Zappush acts as the data controller. We determine the purposes and means of processing this data to provide, secure, and improve the Service.
Shopper Data
When we process data about shoppers who visit your store or interact with your ads, you (the Merchant) are the data controller and Zappush acts as the data processor. We process shopper data solely on your behalf, according to your instructions as implemented through the Service, and in accordance with our Data Processing Agreement (available upon request).
As the data controller for shopper data, you are responsible for:
- Maintaining appropriate privacy disclosures on your website
- Obtaining any required consents from your customers for data collection and processing activities enabled by the Service
- Ensuring your use of the Service complies with applicable data protection laws in your jurisdiction
- Responding to data subject requests from your customers (we will assist you as required)
3. Information We Collect
3.1 Merchant Account Information
When you create an account, we collect your name, email address, company name, and payment information. This data is used to manage your account, process subscription payments, and communicate with you about the Service.
3.2 E-Commerce Store Data
When you connect your e-commerce store (Shopify, WooCommerce, Wix, Kajabi, or custom platform), we access order data, product information, and customer event data necessary for server-side event delivery and analytics. This includes:
- Order values, currency, and transaction identifiers
- Product names, categories, and prices
- Customer email addresses and phone numbers (for CAPI hashing)
- Checkout and fulfillment status
For Shopify stores, we access this data through Shopify's official API and webhook system with the permissions you grant during setup. For other platforms, data is collected through our JavaScript tracking script installed on your website or through platform-specific API integrations.
3.3 Shopper Behavioral Data
The Service collects behavioral data from shoppers who interact with your store through our tracking infrastructure. This includes:
- Events: Page views, add-to-cart actions, checkout initiations, purchase completions, and custom events configured by the Merchant
- Device information: Device type, browser name and version, operating system, screen resolution, and user agent string
- Network data: IP addresses (used for geo-enrichment, then truncated or discarded — full IP addresses are not stored long-term), approximate geographic location (country, region, city)
- Session data: Session identifiers, page URLs, referrer URLs, timestamps, and session duration
- Advertising identifiers: Click identifiers from advertising platforms (fbclid, gclid, ttclid) captured from URL parameters
- Identity signals: First-party cookie identifiers, hashed email addresses, hashed phone numbers, and browser fingerprint components used for cross-device identity resolution
3.4 Compliant Domain Data
When shoppers click Meta ads and pass through a compliant verification page hosted on a clean domain, we collect the referrer URL, click identifiers, user agent, IP address, and consent signals. This data is used to attribute the visit to the correct ad campaign and deliver compliant events to Meta.
3.5 Dashboard Usage Data
We collect standard analytics data about how Merchants use the Unrestrict dashboard, including pages visited, features used, and session duration. We may use third-party analytics tools for this purpose, which operate under their own privacy policies.
3.6 Newsletter Subscribers
If you subscribe to our newsletter, we collect your email address and optionally your first name. This data is used solely to send you marketing communications about Unrestrict. You may unsubscribe at any time by clicking the unsubscribe link in any email or contacting us.
4. How We Use Information
- Meta CAPI delivery:We send conversion events to Meta's Conversions API on behalf of the Merchant. Before delivery, event payloads undergo keyword cleansing (sensitive health-related terms like "CBD Oil" or "Weight Loss" are replaced with compliant alternatives such as "Wellness Product" or "Health Product"). Customer identifiers (email, phone, name, date of birth, city, state, zip code) are SHA-256 hashed before transmission to Meta as required by Meta's data sharing specifications.
- Identity resolution:We use a combination of first-party cookie identifiers, hashed email addresses, hashed phone numbers, advertising click IDs, and browser characteristics to resolve shopper identity across devices, browsers, and sessions. This allows accurate attribution when a shopper clicks an ad on one device and completes a purchase on another. Identity data is stored as a persistent shopper profile linked to the Merchant's store.
- Analytics dashboard: We process event and session data to provide Merchants with full-funnel analytics, including revenue tracking, funnel conversion rates, shopper journey mapping, order-level attribution, and performance insights.
- Compliant domain routing: We use ad click data and consent signals to route shoppers through compliant verification pages, ensuring Meta only receives data from clean domains.
- Service operation: We use Merchant account information to manage subscriptions, process payments, provide customer support, and send transactional communications.
- Service improvement: We analyze aggregated, anonymized usage patterns to improve the reliability, performance, and features of the Service.
5. Cookies and Tracking Technologies
5.1 First-Party Cookies (Shopper Tracking)
The Service sets first-party cookies on the Merchant's domain (or compliant domain) to maintain persistent shopper identity for attribution purposes. These cookies store a unique persistent identifier and are used solely for the Service's tracking and identity resolution functionality. They are not shared with third-party advertising networks.
These cookies are set directly by our JavaScript tracking script installed on the Merchant's website. The script can be installed directly, through a tag manager (such as Google Tag Manager), or through platform-specific app integrations. Regardless of installation method, the cookies are first-party cookies scoped to the Merchant's domain.
5.2 Cookie Details
- Persistent identifier cookie: Stores a unique shopper ID for cross-session identity resolution. Expires after 365 days. Essential for Service functionality.
- Session cookie: Tracks the current browsing session. Expires when the browser is closed or after 30 minutes of inactivity.
- Click ID cookies: Stores advertising click identifiers (fbclid, gclid) captured from URL parameters. Expires after 90 days.
5.3 Marketing Website Cookies
On our marketing website (zappush.com), we may use third-party analytics tools to understand how visitors interact with our site. These tools may set their own cookies in accordance with their respective privacy policies.
6. Information Sharing and Sub-Processors
6.1 Meta Platforms, Inc.
We send conversion event data to Meta via the Conversions API on the Merchant's behalf. Data sent to Meta includes: event type (e.g., Purchase, AddToCart), event parameters (value, currency, content IDs), and hashed customer identifiers (email, phone, name, location). All data undergoes keyword cleansing before delivery. Meta processes this data according to its own Data Policy.
6.2 Payment Processors
We use Stripe to process subscription payments. Stripe receives your payment card details directly — we do not store full card numbers on our servers. Stripe's privacy policy governs their handling of your payment data.
6.3 Infrastructure Providers
We use cloud infrastructure providers to host the Service and store data. These providers act as sub-processors and are bound by contractual data protection obligations.
6.4 E-Commerce Platforms
We exchange data with the Merchant's e-commerce platform (Shopify, WooCommerce, Wix, Kajabi, etc.) through their APIs to access store data necessary for the Service. These platforms have their own privacy policies governing their data handling.
6.5 No Data Selling
We do not sell, rent, lease, or trade shopper data or Merchant store data to any third party. We do not share data with data brokers. Data is shared only as described in this policy or as required by law.
6.6 Legal Obligations
We may disclose information if required to do so by law, regulation, legal process, or government request, or if we believe disclosure is necessary to protect our rights, the safety of others, or to investigate fraud.
6.7 Sub-Processor List
A current list of sub-processors used by the Service is available upon request. We will notify Merchants of any material changes to our sub-processor list at least 30 days in advance.
7. Data Retention
- Event and analytics data: Retained for the duration of your subscription plus 90 days following cancellation. After this period, event-level data is permanently deleted.
- Shopper identity profiles: Retained for the duration of your subscription. Persistent identity data is deleted 90 days after subscription cancellation.
- Account information: Retained for as long as your account is active and for up to 12 months after account closure for legal, tax, and dispute resolution purposes.
- Billing records: Retained for 7 years to comply with tax and financial reporting requirements.
- Newsletter subscriber data: Retained until you unsubscribe or request deletion.
- Aggregated data: Anonymized, aggregated data that cannot be linked to any individual may be retained indefinitely for analytics and service improvement.
8. Data Security
We implement industry-standard technical and organizational security measures to protect your data, including:
- Encryption in transit (TLS 1.2+) for all data transmission
- Encryption at rest for sensitive data stored in our databases
- SHA-256 hashing of all personally identifiable information (PII) before transmission to Meta
- Server-side architecture that minimizes client-side data exposure
- Role-based access controls limiting employee access to customer data
- Regular security reviews of our infrastructure and codebase
- Automatic retry and delivery confirmation for events sent to Meta CAPI
9. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will:
- Notify affected Merchants without undue delay and, where feasible, within 72 hours of becoming aware of the breach
- Provide details of the nature of the breach, the categories of data affected, the approximate number of records involved, and the measures taken or proposed to mitigate the breach
- Cooperate with Merchants to fulfill their own breach notification obligations under applicable law
10. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request that we correct inaccurate or incomplete data
- Deletion: Request that we delete your personal data, subject to legal retention requirements
- Portability: Request your data in a structured, machine-readable format
- Restriction: Request that we restrict processing of your data in certain circumstances
- Objection: Object to certain processing activities, including processing based on legitimate interests
- Withdrawal of consent: Where processing is based on consent, withdraw your consent at any time without affecting the lawfulness of prior processing
To exercise any of these rights, contact us at support@zappush.com. We will respond within 30 days (or within the timeframe required by applicable law).
For shopper data: because Zappush processes shopper data on the Merchant's behalf, shoppers should direct data subject requests to the Merchant whose store they interacted with. We will assist Merchants in fulfilling these requests as required.
11. Rights for EEA, UK, and Swiss Residents (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the following additional provisions apply:
Legal Bases for Processing
- Contract performance: Processing Merchant account data to provide the Service as described in our Terms of Service
- Legitimate interests: Processing aggregated usage data to improve the Service, ensuring network security, and preventing fraud
- Data processing agreement:Processing shopper data on behalf of Merchants as a data processor, pursuant to the Merchant's instructions
- Consent: Sending marketing communications (newsletter), where applicable
International Data Transfers
Your data may be transferred to and processed in the United States, where our servers are located. For transfers of personal data from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other legally recognized transfer mechanisms, to ensure adequate data protection.
Data Protection Authority
If you believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with your local data protection authority.
Data Processing Agreement
We offer a Data Processing Agreement (DPA) that governs our processing of personal data on behalf of Merchants in compliance with GDPR requirements. To request a DPA, contact us at support@zappush.com.
12. Rights for California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with specific rights regarding your personal information:
- Right to know: You may request disclosure of the categories and specific pieces of personal information we have collected, the categories of sources, the business purpose for collection, and the categories of third parties with whom we share data.
- Right to delete: You may request deletion of your personal information, subject to certain exceptions.
- Right to correct: You may request correction of inaccurate personal information.
- Right to opt out of sale or sharing: We do not sell personal information. We do not share personal information for cross-context behavioral advertising. There is no need to opt out, but you may still make a request by contacting us.
- Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.
To exercise these rights, contact us at support@zappush.com. We will verify your identity before processing your request and respond within 45 days.
In the preceding 12 months, we have collected the following categories of personal information: identifiers (name, email, IP address), commercial information (order data, subscription details), internet activity (browsing behavior, event data), and geolocation data (approximate location from IP). We collect this information for the business purposes described in Section 4 of this policy.
13. Consent Management
The Service supports regional consent management for shopper data collection. Consent behavior may vary by jurisdiction:
- In regions where prior consent is required (e.g., the EEA under GDPR), the Service can be configured to respect consent signals before collecting and transmitting shopper data
- In regions where an opt-out model applies (e.g., the United States under CCPA), the Service processes data by default and provides mechanisms for opt-out
Merchants are responsible for implementing consent banners and mechanisms on their own websites that comply with applicable law. The Service will honor the consent signals passed by the Merchant's consent management solution.
14. International Data Transfers
Your data may be processed in the United States or other jurisdictions where our servers and service providers are located. We take appropriate safeguards to protect data during international transfers, including the use of Standard Contractual Clauses where required by applicable law.
15. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us at support@zappush.com and we will promptly delete it.
16. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Service at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy. We encourage you to review this policy periodically.
17. Contact
If you have questions about this Privacy Policy, our data practices, or wish to exercise your data protection rights, please contact us:
- Email: support@zappush.com
- Company: Zappush
For GDPR-related inquiries or to request a Data Processing Agreement, please email support@zappush.com with the subject line "Data Protection Inquiry."