/ 01Introduction & scope
This Privacy Policy explains how Zabcore Inc. ("Zabcore", "we", "us") collects, uses, and protects information when you visit zabcore.com or use our products, including PayGuard and AI Leak Guard.
We build privacy-first tools, which means we collect the minimum information needed to do the job and we tell you exactly what that is. This policy applies to all interactions with Zabcore, except where a separate product-specific notice is presented to you at the point of data collection.
/ 02What we collect
Marketing site (zabcore.com)
The Zabcore marketing site is hosted on Cloudflare Pages. We do not use Google Analytics, Mixpanel, PostHog, or any third-party analytics or advertising tracker on this site. Cloudflare may collect aggregated, anonymized traffic statistics (request counts, response codes, country-level origins) as part of normal CDN operation. We do not set non-essential cookies and we do not place tracking pixels.
PayGuard (paid SaaS)
When you create a PayGuard account or start a trial, we collect:
- Account information: your name, work email address, and the name of your organization.
- Authentication tokens: OAuth tokens from Microsoft 365 and QuickBooks, stored encrypted, used only to access the read-only scopes you have authorized.
- Invoice data: incoming invoice emails and attachments that PayGuard processes for fraud detection. This includes vendor identity, payment amounts, OCR-extracted text, and detected fraud signals.
- Audit log entries (ProofTrail): a record of every detection and team action, used to maintain the integrity log that PayGuard exists to provide.
- Billing data: handled by our payment processor (Stripe). Zabcore never sees or stores your full payment card number.
AI Leak Guard (free browser extension)
AI Leak Guard runs entirely in your browser. We do not collect, transmit, or have access to:
- The text you paste into AI tools
- The sensitive items that AI Leak Guard detects or masks
- Prompts you send to AI tools or responses you receive
- Your browsing history, URLs, cookies, or session data
- Any account identifier — the extension requires no registration
The extension makes one daily one-way outbound request to a static CDN to fetch updated detection patterns. This request transmits no user data, no usage statistics, and no identifiers beyond standard HTTP headers (which Cloudflare logs at an aggregate level only).
/ 03How we use information
We use information for the following specific purposes:
- To deliver the service: running fraud detection on invoices for PayGuard customers, serving the marketing site, providing customer support.
- To improve detection quality: aggregated, de-identified fraud signals (vendor identity patterns, bank account fingerprints, domain reputations) may be used to improve our Vendor Identity Network across all PayGuard customers. This data is anonymized and cannot be traced back to your organization.
- To communicate with you: transactional emails about your trial, subscription, billing, security incidents, and policy changes. Marketing emails only with your explicit opt-in.
- To meet legal obligations: respond to lawful legal process, enforce our Terms of Service, and protect against fraud or abuse of the service.
We do not: sell your data, share it with advertisers, use it to train AI models for unrelated products, or use it for any purpose not listed above.
/ 04Legal bases for processing
Where applicable (including under GDPR), our legal bases for processing personal data are:
- Contract: processing required to provide the PayGuard service you have signed up for.
- Legitimate interests: improving fraud detection quality through anonymized aggregated signals, responding to security incidents, preventing service abuse.
- Consent: marketing emails and any optional analytics, where applicable.
- Legal obligation: responding to lawful legal process and maintaining required records.
/ 06Data retention & deletion
PayGuard lifecycle
PayGuard data is retained according to the following lifecycle, enforced at the system level:
- Active trial or subscription: data retained and processed normally to deliver the service.
- Trial expired (read-only, up to 30 days): existing data is preserved but no new data is collected or processed. You can re-activate or export.
- Subscription cancelled (0–30 days): read-only access continues. Data is retained.
- Dormant archived (31–90 days): data is moved to cold storage. Access is suspended pending reactivation.
- Deleted (90+ days): tenant data is permanently deleted. Anonymous vendor-fraud intelligence (the Vendor Identity Network) remains in our systems in non-tenant-identifiable form.
AI Leak Guard
Because AI Leak Guard does not transmit user data to our servers, there is no server-side retention. The local counter and any extension settings are stored in your browser and removed when you uninstall the extension.
Marketing site & support emails
Email correspondence with hello@zabcore.com or support@zabcore.com is retained for as long as needed to support the conversation, plus up to 24 months for service-quality and compliance purposes.
/ 07Your rights
Regardless of where you live, you may request to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete personal data.
- Delete your personal data, subject to legitimate retention obligations.
- Export your data in a portable format.
- Object to certain processing.
- Withdraw consent where processing is based on consent.
To exercise these rights, email support@zabcore.com. We will respond within 30 days. We will not retaliate against you for exercising any of these rights.
/ 08US state-specific rights
If you reside in California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Iowa, Indiana, Tennessee, New Hampshire, New Jersey, Delaware, Minnesota, or other states with applicable consumer privacy laws, you have additional rights including:
- The right to know what categories of personal information we collect and the purposes for processing.
- The right to opt out of the "sale" or "sharing" of personal information for cross-context behavioral advertising. Zabcore does not sell or share personal information in this manner.
- The right to limit the use of sensitive personal information (where collected).
- The right to non-discrimination for exercising privacy rights.
For California residents specifically: in the preceding twelve months, we have not "sold" personal information as defined by the CCPA/CPRA. The categories of personal information we have collected are described in Section 2 above. You may exercise your CCPA/CPRA rights by emailing support@zabcore.com.
If you wish to designate an authorized agent to exercise rights on your behalf, the agent must provide signed authorization and we may require additional identity verification.
/ 09International users (GDPR baseline)
Zabcore is based in the United States, and personal data we process is stored on US infrastructure (AWS US-East). If you access our services from outside the United States, you understand that your information will be transferred to and processed in the United States.
For users in the European Economic Area, United Kingdom, or Switzerland: we rely on Standard Contractual Clauses and other legally recognized mechanisms for the transfer of personal data to the US. You have the rights described in Section 7 above. You also have the right to lodge a complaint with your local data protection authority.
/ 10Data security
We use industry-standard security measures, including encryption in transit (TLS 1.2+) and at rest (AES-256), restricted internal access on a need-to-know basis, and infrastructure hosted on AWS, which holds SOC 2 Type II certification for the underlying infrastructure.
An honest note: Zabcore itself does not hold SOC 2, ISO 27001, or other formal security certifications. We run on certified infrastructure and follow security best practices, but we do not claim certifications we do not hold. See our Security page for details on our actual posture.
No system is perfectly secure. If a security incident affects your data, we will notify you and applicable regulators as required by law.
/ 11Children's privacy
Zabcore's products are not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact support@zabcore.com and we will promptly delete it.
/ 12Changes to this policy
We may update this Privacy Policy to reflect changes in our practices, products, or applicable law. When we make material changes, we will update the "Effective" date at the top and, for PayGuard customers, notify you by email or in-product notice at least 30 days before the change takes effect.
Prior versions of this policy are available on request.
/ 13Contact us
If you have questions about this Privacy Policy, our data practices, or wish to exercise any of your rights:
Privacy inquiries: support@zabcore.com
General contact: hello@zabcore.com
Postal: Zabcore Inc., Florida, USA (full address available on request)