Privacy
Policy

1. Overview

This Privacy Policy describes how Zooby ("we," "us," or "our") collects, uses, and protects your information when you use our real-time workplace HRMS platform and collaboration services, available at zooby.app.

Zooby provides integrations with Google Calendar, Google Drive, and Gmail to enable scheduling, document management, and communication features within the application. This policy covers all data collected through these integrations.

2. Information We Collect

To provide our platform, we collect the following categories of information:

  • Account Data: Name, work email address, phone number, physical address, profile picture.
  • Workspace Configurations: Organization profile information, department listings, member names, shift settings, break policies.
  • Attendance Records: Clock-in/out timestamps, duration of shifts, break intervals, IP address, and connection indicators for auto-punch-out mechanisms.
  • Task & Project Data: Task titles, descriptions, due dates, assignees, followers, project budgets, milestones, and related collaboration content.
  • Direct Messages: Chat messages, file attachments, and communication content exchanged between users within the platform.
  • Notifications: In-app notification content, reminder preferences, and notification delivery status.
  • Google Account Data: When you connect a Google account, we collect and store OAuth tokens (encrypted at rest) to access Calendar, Drive, and/or Gmail on your behalf, as authorized by you.

3. Google Integrations

Zooby provides integrations with Google Calendar, Google Drive, and Gmail to enable scheduling, document management, and communication features within the application. Each integration is independently authorized by you and can be connected or disconnected at any time.

3a. Google Drive Integration

Zooby allows users to connect their Google Drive account to manage project-related files directly within the application. Zooby only accesses files created through Zooby or files that you explicitly select and authorize through Google Drive.

  • What We Access: Files and folders you choose to manage through Zooby or explicitly select using Google Picker.
  • How We Use It: Drive data is used solely to provide document management and collaboration features requested by the user. Zooby does not use Google Drive data for advertising, marketing, profiling, or AI model training.
  • Data Retention & Deletion: Your OAuth tokens are stored in an encrypted format. Disconnecting the Google Drive integration immediately deletes all Google OAuth credentials from our database. No Drive file content is stored on Zooby servers.

3b. Gmail Integration

Zooby allows users to connect their Gmail account to send emails related to project collaboration directly from the application.

  • What We Access: With your permission, Zooby requests the restricted gmail.send scope to send emails on your behalf. We do NOT read, receive, modify, or delete any messages or threads in your Gmail inbox.
  • How We Use It: Gmail access is used exclusively to send user-initiated emails directly from the platform.
  • No Advertising or Profiling: Zooby does not read, analyze, or use Gmail content for advertising, marketing, profiling, or AI model training.
  • Data Retention & Deletion: Your OAuth tokens are stored in an encrypted format. Disconnecting the Gmail integration immediately deletes all Google OAuth credentials.

3c. Google Calendar Integration

Zooby allows users to connect their Google account to enable Google Calendar integrations.

  • What We Access: We only access, write, and read events specifically associated with calendars linked directly inside your Zooby workspace (e.g., shifts, public holidays, work calendars).
  • How We Use It: Access is used strictly to sync your workspace scheduling calendars and automatically publish shift rosters or holidays to your Google Calendar.
  • Data Retention & Deletion: Your OAuth tokens are stored in an encrypted format. Disconnecting the Google Calendar channel immediately deletes all Google OAuth credentials.

3e. Meta & Instagram API Integrations

Zooby provides direct integrations with Meta Platforms (Instagram Login and Facebook Graph API) to allow authorized business accounts to manage messages, publish posts, and view performance metrics within the Zooby Social Hub.

  • Permissions Requested: We request user-approved scopes including instagram_business_basic, instagram_business_manage_messages, instagram_business_manage_comments, and instagram_business_content_publish.
  • What We Access: Account ID, username, profile picture, direct message threads (to render in your organization's Social Inbox), and content metrics.
  • How We Protect Your Data: Access tokens are encrypted at rest using AES-256-GCM encryption. We do not sell, share, or use Meta user data for third-party advertising, profiling, or AI training.
  • Data Control & Revocation: You can disconnect your Instagram or Facebook account at any time through Zooby Social Settings or via your Instagram/Facebook App permissions settings. Disconnecting immediately deletes all stored OAuth credentials from our database.

4. How We Process & Use Data

We use the information we collect to operate, maintain, and provide the features of Zooby, including:

  • Providing the real-time collaboration hub, workspace attendance feeds, task boards, and project management tools.
  • Calculating shift times, tracking breaks, and updating organization dashboard metrics.
  • Authenticating users and syncing shift calendars with your personal/work Google Calendar.
  • Managing Google Drive files for project documentation, uploads, sharing, and collaboration.
  • Sending emails through Gmail for project-related communication.
  • Sending system notifications, alerts, reminders, and critical emails regarding your workspace updates.
  • Providing direct messaging and team communication features.

5. Cookies & Tracking

Zooby uses cookies and similar technologies for the following purposes:

  • Authentication Cookies: Required to maintain your session and verify your identity while using the platform.
  • Session Cookies: Used to remember your preferences, active workspace, and navigation state within a browsing session.
  • Security Cookies: Used to protect against cross-site request forgery and ensure secure API communication.

Zooby does not use third-party advertising or analytics cookies. You can control cookie settings through your browser preferences.

6. Data Retention

  • Account Data: Retained while your account remains active. Deleted upon account deletion, subject to legal obligations.
  • Workspace Data: Retained for the duration of your organization's active subscription. Removed upon organization deletion or account closure.
  • OAuth Tokens: Removed immediately when you disconnect a Google integration. No refresh tokens are retained after disconnection.
  • Attendance Records: Retained for the period required by applicable labor laws and organizational policies.
  • Messages & Notifications: Retained while your account is active. Deleted upon account deletion.
  • Google Drive Files: No file content is permanently stored on Zooby servers. We only store references to files you choose to manage through the platform.
  • Gmail Content: Zooby does not read or cache your inbox. We only transiently process outgoing emails to send them via the Gmail API, and no email content is stored on Zooby servers.

7. Your Rights

You have the following rights regarding your data:

  • Disconnect Google Integrations: You can disconnect any Google integration at any time. This immediately revokes Zooby's access.
  • Delete OAuth Tokens: Upon disconnection, OAuth tokens are permanently deleted.
  • Request Account Deletion: Email [email protected] to request full account deletion.
  • Request Deletion of Stored Data: Request deletion of specific data at any time by contacting us.
  • Data Portability: Request a copy of your personal data in a commonly used format.
  • Access Your Data: Request information about what personal data we hold and how it is used.

8. Security & Encryption

We employ robust administrative, technical, and physical security measures to protect your personal and workspace information:

  • All network communications are encrypted in transit using Transport Layer Security (TLS/HTTPS).
  • Sensitive keys, including Google OAuth tokens and credentials, are encrypted at rest using AES-256 encryption.
  • Database tables containing secure user profiles are protected with strict access-control filters.
  • Access to production systems is restricted to authorized personnel only.

9. International Transfers

Your data may be processed on servers located outside of your country. By using Zooby, you consent to the transfer of your information to countries where our infrastructure providers operate.

10. Children's Privacy

Zooby is not intended for use by individuals under the age of 13. We do not knowingly collect personal information from children. If we learn we have collected data from a child, we will delete it promptly.

11. Sharing & Third-Parties

We do not sell, rent, or trade your personal data under any circumstances.

We only share information with third-party providers to the extent necessary to perform their services for us, including Google APIs, hosting, and email delivery providers.

12. Data Deletion

Zooby provides the following mechanisms for data deletion:

  • Disconnect Google Integrations: Disconnecting a Google service immediately removes all associated credentials and tokens.
  • Account Deletion: Request account deletion by emailing [email protected].
  • Organization Deletion: Administrators may request deletion of the entire organization workspace.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

ZoobyZooby

All-in-one workspace for teams to communicate, collaborate, manage work and grow together.

© 2026 ZOOBY. All Rights Reserved.