ZayZoon Canada – Privacy Policy
ZayZoon Inc. (together, “ZayZoon”,“we”or “us”) is a leading fintech provider that assists businesses in providing low cost, transparent, and innovative financial products and solutions to their employees. This Privacy Policy (“Policy”) covers the Personal Information that ZayZoon and its affiliates located in the United States (“Affiliates”) collect through zayzoon.com and other websites or applications (the ZayZoon apps (“Apps”) are the sub-domains of our Websites) that post a link to this Policy (collectively, our “Websites”).
This Policy informs you about how we collect, use, disclose, and store Personal Information in our role as a Controller of Personal Information when you:
- Interact or use our Websites, including when you download materials from our resources page, request a demo or ask us to contact you.
- Provide your Personal Information for the purposes of administering our services and managing our relationship with you in any manner (collectively “Services”) e.g. setting up an account or collecting your Personal Information to provide you with access to your accrued but as yet unpaid wages.
Availability of French Version / Disponibilité de la version française: For residents of Quebec, this privacy policy is also available in French. To access the French version, please visit: ca.zayzoon.com/fr-ca/privacy.
Definitions
Personal information means information that (either in isolation or in combination with other information) enables you to be directly or indirectly identified (“Personal Information” or “Personal Data”)
Data controller or a Business (“Controller”) is a party that sets out the purposes and means of processing of Personal Information. Data processor or a Service Provider/Contractor/Third Party (“Processor” or “Third Party”) is a party that processes Personal Information on the Controller’s behalf.
Personal Information ZayZoon Collects
Personal Information you provide to us
From Websites or Events: We collect Personal Information that you choose to provide to us, for example, on our “Get a free demo” (or similar) online form, when you interact with a chat bot on one of our Websites, or if you register for any Events. If you contact us through the Website, we will keep a record of our correspondence.
From the Services: We receive and store the Personal Information you provide directly to us, or through your payroll provider, employer, bank, or other third-party service. For example, when setting up new account and to provide you the services, we collect Personal Information, which may include, but is not limited to, name, e-mail address, postal address, phone number, job title, date of birth, employment information such as wages, time and attendance, and scheduling information. We may collect and store media, documents, or other information you provide to us. We collect commercial information, such as records of your use of the Services or information related to requests for demos.
Cookies
Our website and mobile app may utilize cookies and other tracking technologies in order for us to provide or advertise our Services, and to enable, optimize, and analyze operation of our Services. A cookie is a small text file that may be used, for example, to collect information about website and Service activity. Certain cookies and other technologies may serve to recall information, such as an IP address, previously indicated by a user.
- Browser Control. Most browsers allow you to control cookies, including whether or not to accept them and how to remove them. You may set most browsers to notify you if you receive a cookie, or you may choose to block cookies with your browser.
- Website Control. You may also set your cookie preferences on our website. If you are not logged in or your IP address is blocked, you may have to re-set your preferences on a subsequent visit when you are logged in or your address is unblocked. You may also have to do so on each device from which you access our Services.
Personal Information we automatically collect
When you use the Websites: When you visit our Websites, we collect Internet or other electronic network activity information through the use of cookies and other trackers. Depending on your tracking preferences, the information we collect may include for example your device’s Internet Protocol (“IP”) address, referring website, what pages your device visited, and the time that your device visited our Website. We also rely on analytics and tools used to prevent spam and other security risks related to the use of abusive automated software. You can choose your preferences with regards to the cookies and other trackers by accessing the preference centre on our Websites.
When you use the Services: Internet or other electronic network activity information is also collected when you use the Services:
- Identifying information – we collect information to identify you as part of our KYC/AML obligations, such as your first and last name, email address, phone number, date of birth and last four digits of your SSN.
- Employment information or financial-related information – we collect employment information such as pay information, time and attendance, and information relating to the account to which the pay is directed.
- Usage information – we keep track of user activity in relation to the types of Services our customers and their users use, the configuration of their computers, the performance metrics related to their use of the Services, and user interface information on our site or in our mobile application, such as keystrokes, mouse clicks, page flips, and what you viewed to provide faster and better user support and aid our engineering team in solving bugs and improving user experience.
- Geolocation data – If you have chosen to sign up for Automatic Work Verification, we also collect a very limited portion of your location data. The times of entry and exit at your place of work are the only data that we collect and retain. We use solely use this geolocation tracking to record when you arrive and leave your place of work.
- Log information – we log information about our customers and their users when they use one of our Services, including login credentials, browser type, service provider, or operating system, and their IP addresses.
- Information collected by cookies and other tracking technologies – we use various technologies to collect information, including saving cookies to users’ computers.
- Customer feedback – We collect your communications with ZayZoon via chat or telephone to provide customer service. While using the Services, you may be asked to provide feedback (e.g., in the software directly or after receiving help from our support team). Providing this feedback is entirely optional.
Information we collect from trusted third parties
If your Personal Information has been collected as (i) you interacted or used our Website, or (ii) part of the Services, your Personal information, as stored in our CRM service provider, may be enriched or updated to ensure it is accurate and up to date, and we achieve the purpose for which it was originally collected. Please note that we will also obtain non-personal information related to your organization’s name, structure, industry, and similar attributes through the use of third parties’ data sets, for the purpose of enriching or updating your Personal Information we already hold.
We may obtain information about you, such as mailing address, gender, age, marital status, and job status from third-party data providers. We may use this information for marketing purposes and research purposes.
- Marketing. We may use this info to market our products and services to you.
- Research. We may use this info to provide aggregated, anonymized insights to third-party entities for the purpose of determining the impact of Services on user financial wellness.
How and on what grounds do we use your Personal Information?
Personal Information we collect directly from you via our Websites
We use the Personal Information we collect through our Websites for the purposes of:
- administering our Websites and for internal operations, including troubleshooting, data analysis, testing, statistical and survey purposes.
- improving our Websites so the content is presented most effectively for you and your device, including system maintenance and repair.
- trend monitoring, marketing, and advertising.
- purposes made clear to you at the time you submit your Personal Information, for example, to fulfill your "Get a free demo", to provide you with access to one of our webinars or whitepapers, to provide you with information you have requested about our Services, or to provide you with information on Services we think might be of interest to you.
- data security and integrity, including fraud or illegal activity prevention and detection.
- providing the Services, including verifying customer information, processing or fulfilling transactions, processing payments.
- customer service.
- For research and development of new products or improvement of existing products.
Personal Information we collect directly from you as part of the administration of our Services
We use the Personal Information we collect, directly or indirectly, from our customers, in connection with the Services we provide for the following reasons:
- Set up a user account.
- Provide, operate and maintain the Services.
- Process and complete transactions, and send related information, including transaction confirmations
- Manage our customers’ use of the Services, respond to inquiries and comments, and provide customer service and support.
- Send customers technical alerts, updates, security notifications, and administrative communications.
- Investigate and prevent fraudulent activities, unauthorized access to the Services, and other illegal activities. Undertake analysis of conversion rates, sales, system usage, marketing effectiveness and other analytics projects.
- For any other purposes about which we notify customers and users.
- Cookies: When ZayZoon customers access the Services, we use strictly necessary cookies and other trackers to provide authentication tools, enhance security, and prevent fraud. The preferences signaled on our Websites (through the cookie banner and preference centre) will be reflected on the Apps. For example, if you choose to accept performance cookies on one of our Websites, these will be active in the Apps unless you modify your choices by resurfacing the preference center.
We use your Personal Information in this context to provide the Services to you or our legitimate interests, typically, either for security purposes or business practice improvement (e.g., the prevention and investigation of fraudulent activities). We may use your designated email address or mobile phone number to: (i) send you updates or news regarding the Services; and/or (ii) respond to a Contact Us or administrative requests (for example, to change your password).
In an ongoing effort to better understand and service ZayZoon’s customers, at times ZayZoon conducts research on its customer demographics, interests and behavior based on the personal information and other information provided to us. This research may be compiled and analyzed on an aggregate basis and ZayZoon may share this aggregate data with its affiliates, agents, and business partners. This aggregate information does not identify you personally and is not considered to be personal information.
You authorize your wireless carrier to use or disclose information about your account your wireless device, if available, to us or our service provider for the duration of your business relationship solely to help them identify you or your wireless device and to prevent fraud.
How do we share and disclose Personal Information to third parties?
We do not sell your data. Our use and sharing of the data is solely limited to what is reasonably required for providing, developing, marketing, and improving the Services. We share and disclose information, including Personal Information, about our customers in the following limited circumstances:
Vendors, consultants, and other service providers
We may share your Personal Information with our affiliates, vendors, consultants, and other Processors we employ to perform services on our behalf. These Processors include our payment processing providers (e.g. Interchecks), website analytics providers (e.g., Google), tools we use to prevent spam and other security risks related to the abusive automated software (e.g., Cloudflare), online activities, product feedback or help desk software providers (e.g., Intercom), CRM service providers (e.g., Hubspot), and e-mail service providers (e.g., Twilio). These transfers will typically be based on our legitimate interests, such as to provide and improve our Services, to create insights about our users, to contact you in connection with the Services and certain programs, features or offerings that you may have registered for, to advertise our Services, and to identify and authenticate your access to the parts of the Services that you are authorized to access.
Marketing operations
Our use of cookies and other tracking technologies in our marketing operations is based on the choices you make in our preference centers which you may access from the footer of our Websites or by clicking on a cookie icon that appears on our Websites. We process your Personal Information through the tools provided to us by Google Analytics and Meta Events Manager to provide and enhance our advertising services. Our use of Personal Information collected for marketing operations is limited to the following purposes:
- Targeting specific audiences based on users’ location and interests related to the search query.
- Personalizing the ads that users see based on their search queries.
- Optimizing our campaigns based on front-end metrics provided by Google Ads (e.g. clicks and webpage impressions).
- Tracking the performance of our campaigns and measuring key metrics such as clicks, conversions, and return on investment to understand how our campaigns are performing and make data-driven decisions.
- Adopting Brand Safety protection: ensuring we are not displaying our ads on unsafe or inappropriate websites, to protect our brand reputation.
- Adopting of fraud prevention in our campaigns to protect our campaigns from online fraud (e.g. click fraud).
Direct marketing
We may send you direct marketing communications as permitted by law, including by email. Our direct marketing purposes are based on your consent. For example when you contact us directly, create an account with us, agree to receive communications after an Event, and similar circumstances. We may also rely on our legitimate interests to contact you to offer related services that may be of interest to you based on your employer and/or your payroll provider offering our Services as an employee benefit. You always have the right to opt out of any direct marketing by using the unsubscribe link in our emails, or texting STOP in response to any text messages.
Business transfers
We may choose to buy or sell assets and may share and/or transfer customer information, including Personal Information, in connection with the evaluation of and entry into such transactions and based on our legitimate interests. Also, if we or our assets are acquired, or if we go out of business, enter bankruptcy, or go through some other change of control, Personal Information may be one of the assets transferred to or acquired by the third party.
ZayZoon group companies
We may also share your Personal Information within the ZayZoon family of companies for the purposes consistent with this Policy and based on our legitimate interests or contractual necessity.
Protection of ZayZoon and others
We reserve the right to access, read, preserve, and disclose any Personal Information as necessary to i) administer our Services, ii) comply with a law, regulation, legal process or a governmental request, iii) enforce or apply our Terms with you and other agreements, including investigations and of potential violations thereof, or iv) protect the rights, property, or safety of ZayZoon, our employees, our users, yourself, or others.
Disclosures for national security or law enforcement
Under certain circumstances, we may be required to disclose your Personal Information in response to valid requests by public authorities, including to meet national security or law enforcement requirements, based on our legitimate interests or legal obligations.
Use of anonymous information
We may create anonymous data from personal information by excluding information that makes the data personally identifiable, and use that anonymous data for our lawful business purposes, including to provide workforce insights to our employer clients.
How long do we store your Personal Information?
We store your Personal Information for different time periods depending on the category of Personal Information and the nature of relationship that you have with us. We determine how long we need Personal Information on a case-by-case basis, but our goal is to keep your Personal Information for as short period as possible to achieve the purpose for which Personal Information is collected. We consider the following criteria when we are making decisions on how long we will retain your Personal Information:
- The category of Personal Information.
- Whether the Personal Information is typically deleted based on specific schedules, such as marketing information.
- Whether the Personal Information is necessary to operate or provide our services.
- How long we need to retain the Personal Information to comply with our legal obligations.
- Our legitimate interests or legal purposes, such as network improvement, fraud prevention, record-keeping, promoting safety, security and integrity, or enforcing our legal rights.
Security, certifications, and location of your information
We use appropriate technical, organizational, and administrative security measures to protect any Personal Information we store from loss, misuse, and unauthorized access, disclosure, alteration, and destruction. Our servers are located in the United States and to provide you with the Services, we may store, process and transmit information in the United States. As such, in certain circumstances the courts, law enforcement agencies, regulatory agencies or security authorities in the U.S. may be entitled to access your personal information. Personal information may also be stored locally on the device you use to access the Services.
No company or service can guarantee complete security. Unauthorized entry or use, hardware or software failure, and other factors may compromise the security of user’s Personal Information at any time. Among other practices, your account is protected by a password for your privacy and security. You must prevent unauthorized access to your account and Personal Information by selecting and protecting your password appropriately (including but not limited to selecting a unique password that you have not previously used for any other account) and limiting access to your computer or device and browser by signing off after you have finished accessing your account.
In the event that personal information is compromised as a result of a breach of security, ZayZoon will notify those persons whose personal information has been compromised to the extent required by applicable law.
How can I exercise my privacy rights?
You may have certain rights relating to your Personal Information, depending on your location and subject to local applicable laws. These rights may include, subject to any exceptions or limitations:
- The right to know what Personal Information is being collected and for what purpose.
- The right to know what Personal Information is being “sold” or “shared”, for what purpose and the categories of recipients of your Personal Information.
- The right to access your Personal Information.
- The right to have your Personal Information rectified, corrected or updated.
- The right to have your Personal Information deleted, including from any third parties where your Personal Information has been sold, shared or disclosed.
- The right to opt out of the “sale” or “sharing” of your Personal Information.
- The right to object to the processing of your Personal Information.
- The right not to be subject to any automated decision making and profiling.
If you would like to access, review, update, correct, and delete any Personal Information we hold about you, or exercise any other privacy rights available to you, you can contact our customer success team through online chat at our Website. Our privacy team will review your verifiable privacy rights request (“Privacy Rights Request”) and respond to you as quickly as possible. If we are unable to comply with your request due to an exception or limitation, we will explain this in writing. If we need more time, we will inform you of the reason and extension period in writing.
Opting In and Opting Out. You may choose to receive promotional and advertising text messages from us by providing us with your written consent directly or through your employer. You may choose not to receive future promotional or advertising emails or text messages from us by selecting an unsubscribe link at the bottom of such emails or by texting STOP to opt-out of such text messages. If you opt-out of receiving the foregoing emails or text messages, we may still send you a response to any live chat request as well as administrative emails necessary to facilitate your use of our Services (for example, in connection with a password reset request, an email/text message verification, or a payment-related email/text message).
Do Not Track. Some Internet browsers may be configured to send “Do Not Track” signals to the online services that you visit. Privacy regulations in the United States, such as the laws of California and Delaware, require ZayZoon to indicate whether it honors your browser’s “Do Not Track” settings concerning targeted advertising. ZayZoon adheres to the standards set out in this Policy and does not monitor or respond to Do Not Track browser requests. To find out more about “Do Not Track,” please visit www.allaboutdnt.com.
Online Tracking Opt-Out. There are a number of ways to opt-out of having your online activity and device data collected:
- Blocking cookies in your browser. Most browsers let you remove or reject cookies, including cookies used for interest-based advertising. To do this, follow the instructions in your browser settings. Many browsers accept cookies by default until you change your settings. For more information about cookies, including how to see what cookies have been set on your device and how to manage and delete them, visit www.allaboutcookies.org
- Blocking advertising ID use in your mobile settings. Your mobile device settings may provide functionality to limit use of the advertising ID associated with your mobile device for interest-based advertising purposes
- Using privacy plug-ins or browsers. You can block our websites from setting cookies used for interest-based ads by using a browser with privacy features, like Brave, or installing browser plugins like Privacy Badger, DuckDuckGo, Ghostery, or uBlock Origin, and configuring them to block third-party cookies/trackers
- Platform opt-outs. The following advertising partners offer opt-out features that let you opt-out of use of your information for interest-based advertising:
- Google: https://adssettings.google.com
- Hotjar: https://www.hotjar.com/legal/policies/privacy/
- Twitter: https://twitter.com/settings/account/personalization?lang=en
- Sailthru: https://getstarted.sailthru.com/audience/managing-users/user-optout-levels/#Opt-out_Management
- Advertising industry opt-out tools. You can also use these opt-out options to limit use of your information for interest-based advertising by participating companies:
- Digital Advertising Alliance: http://optout.aboutads.info
- Network Advertising Initiative: http://optout.networkadvertising.org
Note that because these opt-out mechanisms are specific to the device or browser on which they are exercised, you will need to opt-out on every browser and device that you use.
If you would like an authorized agent to make a Privacy Rights Request on your behalf, the agent may do so by filling out this request form. We will ask for written, signed permission that the agent has been authorized to act on their behalf. Once written authorization is provided, we will review your Privacy Rights Request and respond to you as quickly as possible. We will respond directly to the e-mail address provided by the authorized agent regarding the fulfillment of the Privacy Rights Request.
ZayZoon does not discriminate against you for exercising your privacy rights. We remind you that you have a right to lodge a complaint with a supervisory authority should you feel unsatisfied with our treatment of your Personal Information.
Children
ZayZoon does not knowingly collect personal information from children under the age of 16. If you are under the age of 16, please do not submit any personal information through the Services. If you have reason to believe that a child under the age of 16 has provided personal information to ZayZoon through the Services, please contact us, and we will endeavor to delete that information from our databases.
Linked websites
For your convenience, hyperlinks may be posted on the Websites that link to other websites (“Linked Sites”). We are not responsible for, and this Policy does not apply to, the privacy practices of any Linked Sites or of any companies that we do not own or control. Linked Sites may collect information in addition to that which we collect on the Websites. We do not endorse any of these Linked Sites, the services or products described or offered on such Linked Sites, or any of the content contained on the Linked Sites. We encourage you to seek out and read each Linked Site’s privacy notice to understand how the Personal Information about you is used and protected.
Changes to this Policy
We are constantly trying to improve our Websites and Services, so we may need to change this Policy from time to time. Any modifications to this Privacy Policy will be effective upon our posting the modified version (or as otherwise indicated at the time of posting). We will alert you about material changes by, for example, placing a notice on our Website and/or sending you an e-mail (if you have registered your e-mail with us) when we are required to do so by applicable law. You can see when this Policy was last updated by checking the date at the top of this page. You are responsible for periodically reviewing this Policy. Your continued use of the Services thereafter means that you accept those changes.
Contact us
If you have questions or concerns regarding this statement, or if you have any questions or suggestions, please contact support@zayzoon.com, or by writing to us at the following address:
ZayZoon Inc.
Attn: General Counsel
685 Centre St S, Suite 1900
Calgary, AB Canada T2G 2C7
We have procedures in place to receive and respond to questions, complaints or inquiries about our handling of personal information, our compliance with this policy, and with applicable privacy laws. If you are not satisfied with our handling of any such questions, complaints or enquiries, you may also contact the relevant privacy commissioner:
Office of the Privacy Commissioner of Canada (https://www.priv.gc.ca/en/contact-the-opc/)
Office of the Information and Privacy Commissioner for British Columbia (https://www.oipc.bc.ca/about/contact-us/)
Office of the Information and Privacy Commissioner for Alberta (https://www.oipc.ab.ca/about-us/contact-us.aspx)
Commission d’accès à l’information du Québec (https://www.cai.gouv.qc.ca/a-propos/nous-joindre/)