Zavacs

Privacy Policy

Last updated: September 10, 2026

Zavacs is retail operations software for independent retailers. This Privacy Policy explains how information is collected, used, stored and shared when you use the Zavacs website, private beta service and optional connected services.

Information you provide

When you contact Zavacs, create or use an account, upload files, configure settings, or otherwise use the service, Zavacs may receive information you provide such as your name, email address, business information, uploaded files, configuration choices and support communications.

Website and technical information

The public website and service may receive technical information needed to operate, secure and troubleshoot the service, such as IP address, browser and device information, request logs, timestamps and security events.

Connected retail and business services

Zavacs allows users to optionally connect supported third-party retail and business services. Zavacs accesses information from a connected service only after the user authorizes the connection and only to provide the Zavacs functionality associated with that connection.

Google API Data

When a user chooses to connect Google, Zavacs may access Google Business Profile information authorized by that user. Depending on the permissions granted and the features used, this may include Business Profile accounts and locations, business and location details, customer reviews and reply status, and Business Profile performance or visibility information such as Search and Maps discovery metrics and customer actions.

How Zavacs uses Google data

Authorized Google data is used only to provide user-facing Zavacs features requested by the user, including displaying customer reviews, identifying recurring customer feedback, preparing review insights or reply drafts, and presenting business-performance and visibility insights. Zavacs does not use Google user data for advertising and does not sell Google user data.

Zavacs may use automated processing providers where necessary to provide requested analysis or drafting features. Google review replies are not automatically published. A reply is sent to Google only after an authorized user explicitly approves and submits it.

Google authorization credentials

Zavacs may securely store OAuth authorization credentials, including refresh tokens, so that a user can maintain a Google connection without re-authorizing for every request. These credentials are used only to access the Google services the user has authorized for Zavacs.

Google data storage and retention

Google Business Profile API content is treated as a temporary performance cache. Zavacs refreshes or removes cached copies within 28 days, below Google's 30-calendar-day maximum. This cache limit does not mean Insights is limited to 28 days of history. Where Google continues to make historical reviews or performance periods available through its APIs, Zavacs can request that information again when needed. Trend, Topic Scorecard, Weekly Insights and comparison calculations are generated from current Google data and temporary cache data as needed rather than being kept as a permanent warehouse of Google Business Profile API content.

Google Limited Use

Zavacs' use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Sharing and service providers

Zavacs does not sell personal information. Information may be processed by service providers only where necessary to host, secure, operate, support or provide user-requested Zavacs functionality. Service providers are not permitted to use connected-service data for their own advertising purposes.

Disconnecting services and requesting deletion

Users can disconnect supported integrations from Zavacs. When Google Business Profile is disconnected, Zavacs attempts to revoke the Google authorization, removes the saved local Google access credentials, and deletes cached Google Business Profile reviews, profile data, visibility data and temporary Google-derived Insights data from Zavacs. If Google does not confirm revocation, the user can also revoke Zavacs through their Google Account permissions. To request deletion of other account information or connected-service data stored by Zavacs, contact tim@zavacs.com.

Security

Zavacs uses reasonable technical and organizational safeguards appropriate to the private-beta service to protect account and connected-service information. No method of storage or transmission can be guaranteed to be completely secure.

Data retention

Zavacs retains information only for as long as reasonably necessary to provide the service, meet legal obligations, resolve disputes, enforce agreements, or satisfy applicable connected-platform requirements. Different categories of connected-service information may have shorter retention limits.

Changes to this policy

This policy may be updated as Zavacs develops or as connected services, legal requirements or data practices change. The date at the top of this page will show the latest revision.

Contact

Questions about privacy or data requests can be sent to tim@zavacs.com.

← Back to ZavacsTerms of ServiceSupportData & Security