Privacy Policy
Last updated: 22 August 2026
This policy covers both parts of Zylinxo:
- Our marketing site — analytics and cookies on our public pages.
- The Zylinxo application — the data service providers and their customers entrust to us once signed in, and the third-party services that data reaches, including the QuickBooks Online integration.
Zylinxo is a field-service platform. Service providers (“providers”) are our customers; the people they serve (“end customers”) generally do not sign up with us directly. For data about end customers, the provider decides what is collected and why, and Zylinxo processes it on the provider's instructions. For provider account data, and for the marketing site, Zylinxo decides.
Part 1 — Marketing site analytics
What we collect
Zylinxo uses Google Analytics 4 (GA4) on our public marketing pages (/, /pricing, /privacy) to understand how visitors find and interact with our site. GA4 collects:
- Pages viewed and navigation paths
- Referrer URL and UTM campaign parameters
- Device type, browser, operating system, and screen size
- Approximate geographic location (country / region level)
- Click events on call-to-action buttons (e.g. “Start free”, “Sign up”)
- Signup conversion (anonymised, no personal details)
No personally identifiable information (PII) is sent to GA4 before you create an account. We do not collect names, email addresses, or payment details through analytics.
Cookies we set
| Cookie | Purpose | Expiry |
|---|---|---|
_ga, _ga_* | GA4 analytics (set only after consent) | 2 years |
zyl_first_touch | Stores your original referrer and UTM tags so we can attribute signups to their source | 90 days |
zyl_cookie_consent | Remembers whether you accepted or rejected analytics cookies | 1 year |
Where we track
The Google Analytics tracking described in this Part 1 runs only on our public marketing pages. We do not run marketing analytics inside the authenticated application (/dashboard, /app, /portal, /admin).
This is a statement about analytics, not about scope. The authenticated application handles a great deal of data, and it is fully covered by Part 2 below.
How to revoke consent
You can withdraw your analytics consent at any time by:
- Clearing the
zyl_cookie_consentcookie from your browser settings - Revisiting any marketing page and declining the cookie banner
- Enabling your browser's “Do Not Track” setting or using an ad blocker — our analytics script will not load
Analytics data retention
GA4 retains event data for 14 months. Aggregated reports are kept indefinitely. The zyl_first_touch cookie is cleared after signup or after 90 days, whichever comes first.
Third-party services
Analytics data is processed by Google LLC under their Privacy Policy. Google is the only third party that receives marketing-site analytics data. The separate list of services that receive application data is in Part 2.
We do not sell or rent any data — analytics or application — to anyone.
Part 2 — The Zylinxo application
What the application collects
From providers and their staff: name, email address, phone number, business name and address, role within the workspace, authentication credentials (passwords are stored hashed by our authentication provider, never in plain text), and two-factor authentication factors where enabled.
About the provider's end customers, entered by the provider or submitted through a provider's booking page: name, email address, phone number, service and billing address, job history, quotes, invoices, payment records, SMS message content, and photos taken on a job.
Operational data: worker location while a job is in progress (used for dispatch and routing), timestamps for clock-in and clock-out, and service-order checklists.
Payment card details are never collected by Zylinxo. Card numbers and security codes are entered directly into fields hosted by Stripe and travel from the cardholder's browser to Stripe. Our servers only ever see a Stripe token and the card's brand and last four digits.
Why we use it
- To operate the platform a provider signed up for — scheduling, dispatch, quoting, invoicing, and payments.
- To send transactional messages (booking confirmations, invoices, review requests) on the provider's behalf.
- To keep the service secure, prevent fraud and abuse, and diagnose faults.
- To meet legal, tax, and accounting obligations.
We do not use application data for advertising, we do not sell or rent it, and we do not use it to train machine-learning or AI models.
The QuickBooks Online integration
Connecting QuickBooks is entirely optional. Nothing is sent to Intuit unless a provider connects their QuickBooks company from /dashboard/integrations, and disconnecting stops all further exchange.
Authorisation. We use Intuit's OAuth flow and request the com.intuit.quickbooks.accounting scope (plus basic profile). We never see or store QuickBooks sign-in credentials — a provider authenticates with Intuit directly and Intuit returns tokens to us.
What we write to QuickBooks, so a provider's books match their Zylinxo activity:
- Customers — display name, first and last name, company name, email address, phone number, and billing address of the provider's end customer.
- Invoices — line descriptions, amounts, and tax treatment.
- Payments — amount, date, and payment method note.
- Refund receipts — mirroring a refund already issued through Stripe.
What we read from QuickBooks: the company's tax codes, so invoice lines carry the correct tax treatment in the provider's books. We do not read a provider's existing customers, invoices, bank feeds, payroll, or any other data from their QuickBooks company.
Token storage. The OAuth access and refresh tokens and the QuickBooks company identifier (“realm id”) are encrypted with AES-256 at rest in our database and are used only to make the calls described above.
QuickBooks data is never sold, rented, shared for advertising, or used to train models. It is used solely to keep the provider's books in sync with their Zylinxo account.
Disconnecting. Disconnecting QuickBooks deletes our stored tokens and stops all further sync. Records already written into the provider's QuickBooks company remain there — they live in Intuit's system, inside the provider's own books, under the provider's control. Zylinxo does not delete them, and deleting a Zylinxo account does not remove them. To remove those records, delete them in QuickBooks, or ask Intuit.
Who else receives application data
These are our sub-processors. Each receives only what it needs to perform its function, and each is bound by its own agreement with us.
| Service | What it receives | Purpose |
|---|---|---|
| Intuit (QuickBooks Online) | End-customer name, email, phone, billing address; invoice, payment and refund records | Accounting sync, only if the provider connects it |
| Stripe | Payment card details (entered directly with Stripe), amounts, customer name and email, payout and Connect account details | Payment processing and payouts |
| Twilio | End-customer phone numbers and message content | Sending and receiving SMS |
| Supabase | All application data at rest, and authentication | Database, authentication, and file storage |
| Resend | Recipient email addresses and message content | Transactional email delivery |
| Service addresses and coordinates | Maps, geocoding, and route optimisation |
We may also disclose data where the law requires it, or to protect our rights, safety, or property. We will tell the affected provider unless we are legally barred from doing so.
How long we keep application data
- While the account is open: for as long as the provider's workspace is active, because it is the record of their business.
- After closure: deleted within 90 days of account closure.
- Financial records we are required to retain for tax and accounting purposes are kept for 7 years, then deleted.
- Stripe's own payment records are retained by Stripe under Stripe's policies and retention obligations, not ours.
- QuickBooks OAuth tokens are deleted as soon as the integration is disconnected, or on account closure.
- Backups roll off on their own schedule and are overwritten within 30 days of the corresponding deletion.
Access, correction, and deletion
Providers can view and correct most of their data directly in the application, and can close their workspace at any time. To request a copy of your data, a correction, or deletion, email admin@zylinxo.com. We respond within 30 days.
If you are an end customer of a business that uses Zylinxo, that business decides what data it holds about you. Please contact the provider directly; if you contact us instead, we will pass the request on to them and help them action it.
What deletion does not reach: records already written into a provider's QuickBooks company (see above), and records Stripe retains to meet its own legal obligations. Both live in those companies' systems rather than ours.
Security
Data is encrypted in transit (TLS) and at rest. QuickBooks OAuth tokens are additionally encrypted with AES-256 before storage. Access between workspaces is isolated at the database level, so one provider cannot read another's data. Optional two-factor authentication is available on provider accounts, and staff access is limited by role.
Changes to this policy
We will update the “last updated” date above whenever this policy changes, and will notify providers by email of any change that materially affects how their data is handled.
Contact
Questions about this policy? Email us at admin@zylinxo.com.