Privacy Policy
Last updated 11 July 2026
Zorren is a lead capture and email broadcast platform for small businesses. This Privacy Policy explains how Zorren collects, uses, stores, discloses, and protects personal information. Zorren is operated from New South Wales, Australia by Ben Collins, ABN 67 688 063 018, trading as Zorren. For privacy or legal questions, contact legal@zorren.app.
Who this policy applies to
This policy applies to:
- business owners and account users who sign up for Zorren;
- people whose details are collected by a business using Zorren;
- visitors to Zorren's website, hosted capture pages, unsubscribe pages, and other public pages.
In this policy:
- Customer means the business owner or business using Zorren;
- Contact means a person whose name, email address, or other details are collected by a Customer using Zorren;
- Zorren, we, us, or our means the Zorren service operated by Ben Collins.
Zorren is designed for supported countries only. At launch, Zorren supports customers in Australia, New Zealand, the United Kingdom, Canada, and the United States. Zorren does not currently target customers in the European Union or European Economic Area.
Our role and the Customer's role
Zorren handles personal information in different ways depending on the type of data.
For account, billing, authentication, support, security, and platform administration data, Zorren acts as the organisation responsible for deciding how that information is handled.
For Contact lists, captured enquiries, broadcast recipients, and related Contact activity, the Customer is responsible for deciding why and how that information is used. Zorren processes that information on the Customer's behalf to provide the service.
Customers are responsible for making sure they have a lawful basis, permission, or consent to collect and email their Contacts.
Zorren's processing of Contact data is also governed by our Data Processing Terms, which form part of our agreement with each Customer.
Personal information we collect
We collect the information needed to operate Zorren.
Account information
When a Customer creates or uses an account, we may collect:
- login email address;
- business name;
- reply-to email address;
- business postal address;
- account settings;
- selected plan;
- billing status;
- Stripe customer, subscription, and price identifiers;
- authentication identifiers from our authentication provider;
- support, legal, and account correspondence.
We do not store payment card numbers. Payment card processing is handled by Stripe.
Contact information
When a person is added to a Customer's list, we may process:
- name;
- email address;
- source of the Contact;
- Contact status, such as active, unsubscribed, bounced, or complained;
- consent status, timestamp, and country where collected through a Zorren-hosted capture page;
- unsubscribe, bounce, complaint, and delivery event history;
- lightweight Customer-added notes or tags where available.
Hosted capture page information
If a person submits a Zorren-hosted capture page, we may collect:
- name;
- email address;
- any custom fields configured by the Customer;
- consent checkbox status, timestamp, and country where applicable;
- submission and processing records.
Customers must not configure hosted capture pages to collect sensitive personal information unless they have a lawful basis to do so and are legally responsible for that collection.
Customer website snippet information
Customers may install a Zorren snippet on their own website to capture form submissions.
The snippet is intended to collect the mapped name and email fields needed for Zorren to create a Contact. Customers are responsible for configuring their website forms, field mappings, consent wording, and privacy notices correctly.
Zorren temporarily stores raw form submission payloads only when field mapping has not yet been configured, so the Customer can identify and map their form fields. Once field mapping is configured or the submission is processed, raw payload data is cleared. An automated retention job deletes any remaining raw submission record after 30 days.
Broadcast and email activity information
When a Customer sends a broadcast through Zorren, we may process:
- broadcast subject and body;
- sender name, sender address, and reply-to address;
- recipient records;
- send status;
- delivery, bounce, complaint, unsubscribe, and open events;
- technical identifiers returned by email infrastructure providers.
Logo uploads
Customers may upload a logo for their hosted capture page. Uploaded logos are stored by Zorren's infrastructure provider.
Technical and security information
We and our service providers may process technical information needed to operate, secure, debug, and improve the service, such as log data, request information, device and browser information, and security events.
Information we do not intentionally collect
Zorren is not designed to collect sensitive personal information.
We do not intentionally collect:
- health information;
- government identifiers;
- financial account numbers;
- payment card numbers;
- children's information;
- passwords for Customer websites;
- attachments in broadcast emails;
- phone numbers, unless a Customer adds a hosted capture page custom field that asks for one.
Customers must not use Zorren to collect sensitive personal information unless they are legally permitted to do so and accept responsibility for that collection.
How we collect personal information
We collect personal information when:
- a Customer signs up, logs in, or updates account settings;
- a Customer enters business details, address details, or billing information;
- a person submits a Zorren-hosted capture page;
- a Customer's website sends mapped form information to Zorren through the snippet;
- a Customer manually adds a Contact;
- a Customer imports Contacts, where import functionality is available;
- a Customer creates or sends a broadcast;
- email providers send us delivery, open, bounce, or complaint events;
- a person unsubscribes or resubscribes;
- a person contacts us for privacy, legal, support, or account reasons;
- our service providers process information on our behalf.
How we use personal information
We use personal information to provide, secure, and manage Zorren.
For Customers, we use information to
- create and manage accounts;
- authenticate users;
- provide the dashboard and account features;
- process billing and subscriptions;
- enforce plan limits;
- send service, legal, billing, and account notices;
- provide support;
- detect abuse, spam risk, fraud, and security issues;
- comply with legal obligations.
For Contacts, we use information to
- capture enquiries and subscriptions for Customers;
- maintain Customer Contact lists;
- send Customer broadcasts;
- personalise broadcasts where the Customer uses supported fields, such as first name;
- add required footer and unsubscribe information to broadcasts;
- process unsubscribes, bounces, complaints, and resubscribe requests;
- maintain suppression records;
- keep compliance and audit records;
- provide delivery and open reporting to Customers.
We do not sell Contact lists.
Email broadcasts, unsubscribe, and suppression
Customers use Zorren to send commercial email broadcasts to their own Contacts.
Every broadcast sent through Zorren includes an unsubscribe link and the Customer's business postal address. Customers cannot remove the unsubscribe link from broadcasts.
When a Contact unsubscribes, bounces permanently, or submits a spam complaint, Zorren updates the Contact status and adds the email address to a suppression list for that Customer.
Suppression records are used to prevent future sending to that email address through the relevant Customer account. Suppression records may remain after Contact deletion or account deletion for the retention period described in this policy.
If a suppressed person submits a form again, Zorren does not automatically reactivate them. Reactivation requires a recipient-initiated resubscribe flow where available.
Customer responsibility for consent and lawful sending
Customers are responsible for making sure they have permission, consent, or another lawful basis to contact each person on their list.
Customers must not use Zorren for:
- cold outreach;
- purchased, rented, scraped, or harvested lists;
- third-party lead generation;
- affiliate promotions;
- political content;
- financial promotions or investment claims;
- crypto offers;
- any person with no prior relationship with the Customer.
Zorren is designed for businesses to contact people who have enquired about, subscribed to, purchased from, booked with, or otherwise had a legitimate relationship with that business.
For Zorren-hosted capture pages, Zorren requires a separate, unticked consent checkbox for non-US visitors. It identifies the Customer, explains the types of email the person agrees to receive, provides the Customer's contact details, states that they can unsubscribe, and records consent status, timestamp, and country.
For forms on a Customer's own website, the Customer is responsible for their own consent wording, privacy notice, form design, and legal compliance.
Open tracking
When open tracking is enabled, Zorren adds an invisible image to HTML broadcast emails.
Loading that image may record the recipient, broadcast, and date and time of an open. Our email provider may also supply technical information associated with the request, depending on the recipient's email client, device, privacy settings, and image-loading behaviour.
Open tracking is enabled by default. Customers can disable the default in Sending settings and can enable or disable it for an individual broadcast before sending. Disabling open tracking removes the tracking image and means open-rate and recipient opened-at reporting will not be available for that broadcast.
Open data is approximate. Open rates may be affected by image blocking, privacy protection tools, automatic preloading, spam filters, email client behaviour, and other factors outside Zorren's control.
Before enabling open tracking, Customers must provide any notices and obtain any consent or other authority required by laws that apply to them and their recipients. Zorren records the Customer's acknowledgement of this responsibility.
Recipients can reduce email tracking by blocking external images in their email client.
Zorren-hosted capture pages state that emails may use open tracking and link to the Customer's privacy policy where the Customer supplies one.
Service providers and subprocessors
We use third-party service providers to operate Zorren. These providers may process personal information only as needed to provide their services to us.
Our core providers include:
- Convex, for database, backend, serverless functions, and file storage;
- Clerk, for authentication;
- AWS SES, for email sending;
- AWS SNS, for email delivery event notifications;
- Stripe, for billing and payment processing;
- Vercel, for hosting and deployment.
We may update our service providers as Zorren changes. Material subprocessor changes will be handled under our Data Processing Terms.
International processing
Zorren is operated from Australia.
Personal information may be stored or processed in other countries, including the United States and other locations where our service providers operate.
Where required, we use contractual, technical, and organisational safeguards designed to protect personal information when it is processed outside the country where it was collected.
Customers are responsible for ensuring that their use of Zorren complies with any international transfer obligations that apply to them as the controller of their Contact data.
Data retention
We keep personal information only for as long as reasonably needed for the purposes described in this policy, unless a longer period is required for legal, tax, accounting, dispute, security, or compliance reasons.
Our current retention periods are:
- Customer account records: retained for the life of the account. Cancelling a paid subscription does not delete the account. After a verified account-deletion request is completed, account data is generally deleted or de-identified within 30 days, except for required records.
- Contact records: retained for the life of the Customer account, then generally deleted or de-identified within 30 days after a verified account-deletion request is completed.
- Raw snippet submission payloads: stored temporarily only when field mapping has not yet been configured, to allow the business owner to identify and map their form fields. Once field mapping is configured or the submission is processed, raw payload data is not retained. Where no mapping exists, raw payloads are retained until the mapping is configured or for a maximum of 30 days, whichever comes first. This limit is enforced by an automated daily deletion job.
- Contact event logs: retained for the life of the account, then generally deleted or de-identified within 30 days after a verified account-deletion request is completed.
- Raw email delivery event logs: retained for up to 90 days, enforced by an automated daily deletion job.
- Uploaded logos: deleted when the account is deleted.
- Billing and tax records: retained for up to 7 years where required for tax, accounting, or legal reasons.
- Suppression records: retained for up to 2 years after account deletion to help honour unsubscribe, bounce, and complaint history.
- Account deletion tombstones: minimal records may be retained indefinitely to record that an account existed and was deleted.
We may retain limited information longer where necessary to prevent abuse, resolve disputes, comply with law, enforce agreements, or protect Zorren, Customers, Contacts, or others.
Account deletion
Customers can request account deletion by contacting legal@zorren.app. Self-serve account deletion is not currently available.
After a deletion request is verified, Zorren disables access and follows a documented deletion process covering application data, uploaded files, authentication access, billing links, and sending resources. Account data is then deleted or de-identified according to the retention periods in this policy.
Deleting an account does not immediately remove records that Zorren must retain for legal, tax, accounting, security, dispute, suppression, or compliance reasons.
Privacy rights and requests
Depending on where a person is located, they may have rights to request access, correction, deletion, portability, objection, restriction, or withdrawal of consent.
Customers can access and manage certain account and Contact information through the Zorren dashboard.
Contacts should usually contact the Customer first because the Customer controls the Contact list and decides why the Contact's information is used.
If a Contact sends a privacy request to Zorren, we may forward the request to the relevant Customer. If the Customer is unresponsive within a reasonable period, or if the Customer account no longer exists, Zorren may handle the request directly where legally appropriate.
Privacy requests can be sent to legal@zorren.app. We may need to verify identity before acting on a request.
Security
We use reasonable technical and organisational measures designed to protect personal information.
These measures include:
- HTTPS/TLS for data in transit;
- provider-managed encryption at rest where supported by our infrastructure providers;
- Clerk authentication;
- account-level access controls;
- signed unsubscribe tokens;
- Stripe-hosted payment processing;
- Stripe and Clerk webhook signature verification;
- AWS SNS signature and topic verification for email events;
- email event validation using message ID correlation;
- honeypot, timing, and rate-limit controls on public capture endpoints;
- automated deletion of time-limited raw payload and event data.
No online service is completely secure. Customers are responsible for maintaining the security of their own login credentials, devices, websites, forms, and authorised users.
Data incidents
If we become aware of a data incident affecting personal information, we will assess the incident, take reasonable steps to contain and remediate it, and notify affected Customers where required.
Where legally required, we will notify affected Customers without undue delay and, where applicable, within 72 hours of becoming aware of the incident.
Customers are responsible for assessing whether they need to notify their own Contacts, regulators, or other parties.
Children
Zorren accounts are for users aged 18 or older.
Zorren is not intended for children, and Customers must not knowingly use Zorren to collect children's personal information unless they are legally permitted to do so and have any required consent or authority.
Cookies and similar technologies
Zorren uses cookies and similar technologies for authentication, security, session management, service operation, and related purposes.
Broadcast emails also include open-tracking pixels as described in this policy.
More information is available in our Cookie Policy.
Changes to this policy
We may update this Privacy Policy as Zorren, our providers, our practices, or applicable laws change.
If we make material changes, we will take reasonable steps to notify Customers, such as by email, dashboard notice, or updating the date at the top of this policy.
Privacy complaints and contact
For privacy, legal, or data protection questions, contact legal@zorren.app.
If you make a privacy complaint, please include enough detail for us to understand the issue and respond properly.
We will review privacy complaints and aim to respond within a reasonable time.
If you are not satisfied with our response, you may be able to complain to the privacy regulator in your country, including:
- the Office of the Australian Information Commissioner in Australia;
- the Information Commissioner's Office in the United Kingdom;
- the Office of the Privacy Commissioner of Canada in Canada;
- the Office of the Privacy Commissioner in New Zealand;
- the Federal Trade Commission or relevant state regulator in the United States, depending on the issue.
Where the complaint relates to Contact data controlled by a Customer, we may refer the complaint to that Customer or work with them to respond.
This policy was last reviewed 11 July 2026. For questions contact legal@zorren.app.