Privacy Policy
Last revised: [effective date]
[LEGAL_ENTITY] ("Zerosat," "we," "us") provides the Zerosat satellite-tasking service at zerosat.io (the "Service"). This policy explains what personal information we collect, how we use and share it, and the choices you have. It covers the Service only.
Notice for state residents: see "Your state privacy rights" below for rights under California, Colorado, Connecticut, Virginia, Nevada, and other state privacy laws.
1. Personal information we collect
Information you provide:
- Contact data: name, email address, company name, and (if you provide it) billing address and phone number.
- Account data: the account you create to sign in. Passwords are handled by our authentication provider (Supabase); we do not store your password. If you sign in with GitHub (OAuth), we receive your GitHub email and basic profile as permitted by your GitHub settings.
- Order and content data: the proposals you create, including areas of interest and coordinates, sensor/collection requirements, and the plans and decisions generated for you. We treat coordinates and areas of interest as your confidential customer data.
- Transaction data: order identifiers, amounts, status, and history for the collections you approve and pay for.
- Communications data: information you provide when you contact support or otherwise communicate with us.
Payment data. Payments are processed by Stripe. Card details are collected and processed directly by Stripe; we do not receive or store your full card number. We receive limited confirmation data (e.g. payment status, Stripe identifiers). Stripe handles your payment data under its own privacy policy (https://stripe.com/privacy).
Information collected automatically. When you use the Service, we and our service providers may log:
- Device and log data: IP address, browser type and version, operating system, timestamps, and referring/exit pages.
- Usage data: pages or screens viewed, actions taken, and general interaction with the Service, used to operate and improve it and to enforce rate limits and security.
- [If you use an analytics provider (e.g. Plausible, Google Analytics), name it here and describe it; if you use none, say so. State whether general location (city/region from IP) is derived.]
We do not knowingly collect government-issued IDs, financial account numbers, precise device geolocation, or special-category data through the Service. (Coordinates you enter describe collection targets, not your location.)
2. How we use personal information
- Provide and operate the Service: create and manage your account, authenticate you, generate plans and decisions, process orders and payments, place vendor orders for paid collections, and provide support.
- Security and fraud prevention: protect the Service and our users, detect and prevent abuse, and enforce our Terms and rate limits.
- Improve the Service: understand usage and diagnose problems to improve reliability and features. Where we analyze usage we prefer aggregated or de-identified data.
- Communications: send transactional messages (order and account notices). [state whether you send any marketing email and how to opt out; if none, say the Service sends transactional email only.]
- Legal and compliance: comply with law, including export-control and sanctions screening, respond to lawful requests, and establish or defend legal claims.
We do not sell your personal information, use it for cross-context behavioral advertising, or use your confidential order data (areas of interest, coordinates) to train AI models.
3. How we share personal information
- Service providers / processors who act on our behalf, under contract: hosting and database (Supabase), payment processing (Stripe), the imagery vendors that fulfill your collections (e.g. UP42, SkyFi), email delivery, and error/monitoring. [confirm the full list and keep it current.]
- Imagery vendors. To fulfill a collection you order, we transmit the collection parameters needed to place the vendor order. The vendor processes that order under its own terms.
- Legal and safety. To comply with law or valid legal process, to enforce our Terms, or to protect the rights, property, or safety of Zerosat, our users, or others, including export-control and sanctions compliance.
- Corporate transactions. In connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
- With your direction or consent.
We do not share your personal information with third parties for their own marketing.
4. Retention
We retain personal information for as long as needed to provide the Service and for legitimate business or legal purposes, including tax, accounting, and export-compliance recordkeeping, and to establish or defend legal claims. Order and billing records may be retained longer where law requires. We then delete or de-identify it.
5. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information (including authenticated access, transport encryption, and least-privilege access to systems). No method of transmission or storage is completely secure; we cannot guarantee absolute security.
6. Your choices
- Account. You can access and update account information, or request account deletion, by [contacting privacy@zerosat.io / an in-product control].
- Cookies. See our Cookie Notice ([/cookies URL]) for how to control cookies.
- Communications. [opt-out mechanism for any non-transactional email.]
7. Your state privacy rights
Depending on your state of residence, you may have rights to access, correct, delete, and obtain a copy of your personal information, and to opt out of "sale," "sharing"/targeted advertising, and certain profiling. We do not sell or share personal information for targeted advertising, and we do not use it for profiling that produces legal or similarly significant effects.
- California (CCPA/CPRA): rights to know, delete, correct, and to opt out of sale/sharing (we do not sell/share); the right to limit use of sensitive personal information (we do not use SPI for the purposes that trigger this); and non-discrimination. Under Cal. Civ. Code §1798.83 ("Shine the Light"), California residents may request information about disclosures for third-party marketing (we make none).
- Colorado (CPA), Connecticut (CTDPA), Virginia (VCDPA): rights of access, correction, deletion, portability, and to opt out of sale, targeted advertising, and profiling.
- Nevada (NRS 603A): the right to direct us not to sell certain covered information (we do not sell it).
- [confirm current list of states with comprehensive privacy laws and add any others (e.g. TX, OR, MT, UT, IA, IN, TN, and later-effective laws).]
To exercise any right, contact [privacy@zerosat.io]. We will verify your request as required by law. You may appeal a denial by [appeal mechanism/email]. We do not discriminate against you for exercising these rights. You may use an authorized agent where the law permits.
8. Children
The Service is not directed to children under 13 (or under 16 where applicable) and we do not knowingly collect their personal information.
9. International users
The Service is operated in the United States. This policy is US-focused. [if you serve EU/UK/other users, add a GDPR/UK-GDPR section and a Data Processing Addendum (both available in the source template repo).]
10. Changes
We may update this policy. Material changes will be indicated by the "Last modified" date and, where appropriate, additional notice. Continued use after an update means you accept it.
11. Contact
[privacy@zerosat.io] · [LEGAL_ENTITY], [ADDRESS].