Legal

OverviewTerms of ServiceAcceptable Use PolicyAI TermsPrivacy PolicyRefund PolicyData Processing AddendumSub-processorsService Level AgreementCookies StatementData Act Addendum
Trust Center

Bourbon Science Inc.

Privacy Policy

Effective date: January 1, 2025 ยท Last updated: September 27, 2026

1. Who We Are and What This Covers

Bourbon Science Inc., a Delaware corporation trading as Zoko ("Zoko", "we", "our", "us"), takes the privacy of the people whose data we handle seriously. This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and what rights you have.

This Policy covers two different groups, and it is important to know which applies to you:

  • Our customers and website visitors. If you are a merchant, an agency, a team member on a Zoko Account, or a visitor to our website, Zoko is the controller of your personal data and this Policy describes how we handle it.
  • Our customers' end users. If you received a message from a business that uses Zoko, that business is the controller of your personal data. Zoko acts as its processor, handling data on its instructions. Your rights in that data are exercised against that business, not against Zoko, and Section 9 explains how we help.

This Policy forms part of the Zoko Terms of Service. Processing carried out on behalf of our customers is governed by the Data Processing Addendum. Our use of cookies is described in the Cookies Statement.

Age. The Services are sold to businesses and are not directed at children. Section 8 of the Terms of Service requires every user of a Zoko Account to be at least 18 years old, or the age of majority where they live if that is higher. We do not knowingly collect personal data from anyone under 18 in connection with an Account. If you believe someone under 18 has registered or provided us with personal data, contact contact@zoko.io and we will delete it.

Separately, the people our customers message may be of any age. Zoko processes their data as a processor on the customer's instructions and does not control who is messaged. Responsibility for age-appropriate communication, for any age verification the law requires, and for not marketing age-restricted goods or services to minors rests with the customer, under Section 5 of the Terms of Service and Sections 2 and 9 of the Acceptable Use Policy.

2. Personal Data We Collect

2.1 Data you give us

  • Account and identity data: name, business name, email address, phone number, job role, country, and password.
  • Billing data: billing address, tax identifiers, plan and transaction history, and the last four digits and expiry of a payment card. Full card numbers are handled by our payment processor and are never stored by Zoko.
  • Support and communications data: the content of your messages to us, support tickets, call notes, and survey or feedback responses.
  • Content you create: templates, flows, automations, prompts, catalogues, and campaign configurations.

2.2 Data from connected platforms

When you connect a third-party service, we receive data from it as needed to provide the Services. This typically includes your WhatsApp Business Account and phone number details, business profile, message templates and their status, and conversation content; and from Shopify, your store details, product catalogue, customer records, and order data. What we receive is determined by the permissions you grant and by that platform's own rules.

2.3 Data we collect automatically

  • Device and log data: IP address, device and browser type, operating system, language, referring pages, and timestamps.
  • Usage data: features used, pages viewed, actions taken in the product, message volumes, and error and diagnostic data.
  • Cookies and similar technologies, as described in our Cookies Statement.

2.4 End user data we process for our customers

On behalf of our customers, we process the contact details, message content, attachments, conversation metadata, order and cart data, tags and segments, and consent records of the people they message. We process this as a processor, on the customer's instructions, under the Data Processing Addendum. We do not use it for our own purposes, do not sell it, and do not use it to build profiles or advertise to those individuals.

3. Why We Use Personal Data, and Our Legal Bases

PurposeLegal basis (UK and EU GDPR)
Providing the Services, operating your Account, and delivering messages you sendPerformance of a contract
Billing, collections, and tax recordsContract, and legal obligation
Support, onboarding, and service notices such as outage alerts and billing remindersContract, and legitimate interests in supporting our customers
Securing the platform, preventing fraud and abuse, and enforcing our termsLegitimate interests in protecting the Services, our customers, and the public
Maintaining, troubleshooting, and improving the Services, including aggregated analyticsLegitimate interests in operating and improving our product
Marketing to business contacts about our own productsLegitimate interests, or consent where required by local law
Non-essential cookies and analytics on our websiteConsent
Complying with law, responding to lawful requests, and establishing or defending legal claimsLegal obligation, and legitimate interests

Where we rely on legitimate interests, we have considered whether those interests are outweighed by the rights of the individuals concerned. You may object to that processing as described in Section 8.

We do not sell personal data, and we do not share it for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act.

4. Aggregated and Anonymised Data

We create aggregated and anonymised statistics from the operation of the Services, for example benchmark response and conversion rates, delivery and read rates, and feature adoption across our customer base. This data is created so that it does not identify, and cannot reasonably be used to identify, any customer, end user, or individual, and does not reveal the content of any message. We use it for product development, benchmarking, research, and marketing. Section 4.1 of the Terms of Service governs this.

5. Who We Share Personal Data With

  • Sub-processors and service providers who help us run the platform, listed with their purposes and locations in our Sub-processor List. They act on our instructions under written contracts.
  • Platforms you connect, including Meta and Shopify. Data sent to them is handled under their own terms and privacy policies. Section 13 of the Terms of Service explains that Zoko is not responsible for how they handle it.
  • Payment processors, for billing and fraud prevention.
  • Professional advisers, including lawyers, auditors, and insurers, under duties of confidentiality.
  • Authorities and third parties where we reasonably believe disclosure is necessary to comply with law or legal process, enforce our agreements, prevent fraud or abuse, or protect the rights, property, or safety of Zoko, our users, or the public.
  • In a corporate transaction, such as a merger, acquisition, financing, or sale of assets, personal data may be disclosed to the counterparty and its advisers under confidentiality obligations, and may transfer as part of the transaction. We will notify you of any change in control that materially affects how your data is handled.

6. International Transfers

Zoko is established in the United States and our sub-processors are located in the United States and elsewhere. Where we transfer personal data out of the United Kingdom, the European Economic Area, or another jurisdiction with transfer restrictions, we rely on an appropriate safeguard, which is ordinarily the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, supported by a transfer risk assessment and appropriate technical measures.

You can request details of the safeguard applying to a particular transfer by contacting contact@zoko.io.

7. How Long We Keep Data

CategoryRetention
Account and profile dataFor the life of the Account, then deleted in the ordinary course after closure
Customer Content, including conversations and contactsFor the life of the Account, subject to any retention period you configure, then deleted after the export window in Section 12 of the Terms of Service
Billing and tax recordsAs required by tax and accounting law, ordinarily seven years
Support correspondenceFor as long as needed to resolve the matter and to handle any related query or claim, then deleted in the ordinary course
Security, audit, and access logsFor as long as needed for security monitoring, incident investigation, and compliance, then deleted in the ordinary course
Aggregated and anonymised dataIndefinitely, as it no longer identifies anyone

If an Account is inactive for eighteen consecutive months we may notify you and, if you do not respond within thirty days, close it and delete its data. We may retain data for longer where we are required to by law or where it is needed to establish or defend a legal claim.

8. Your Rights

Depending on where you are, you may have the right to access your personal data, to correct it, to delete it, to restrict or object to how we use it, to receive it in a portable format, to withdraw consent, and not to be discriminated against for exercising these rights. Residents of the European Economic Area and the United Kingdom have these rights under the GDPR and UK GDPR; residents of California, Brazil, and other jurisdictions have comparable rights under their local law.

To exercise a right, contact contact@zoko.io. We will respond within the period required by applicable law, ordinarily one month. We may need to verify your identity first. There is no charge unless a request is manifestly unfounded or excessive.

If you are unhappy with how we have handled your data, you may complain to your local supervisory authority. In the United Kingdom that is the Information Commissioner's Office; in the European Economic Area it is the authority in your country of residence. We would appreciate the chance to address your concern first.

9. If You Received a Message From a Business Using Zoko

If a business contacted you on WhatsApp using Zoko, that business decided to message you, holds your contact details, and is the controller of your data. Zoko only carries the message on its behalf.

To stop receiving messages, reply to the business directly with STOP, or use whatever opt-out method the message offers. To access, correct, or delete your data, contact that business. If you are not sure who they are or cannot reach them, contact us at contact@zoko.io and we will pass your request to the relevant customer and support them in responding, which is what the Data Processing Addendum requires of us. We cannot action the request ourselves without that customer's instruction, because the data is theirs.

If you believe a business is misusing the platform, you can report it under Section 11 of the Acceptable Use Policy.

10. Security

We operate an information security management system aligned to ISO 27001 v2022, including encryption in transit and at rest, access control on a least-privilege basis, logging and monitoring, vulnerability management, and personnel confidentiality obligations. Current detail is published in our Trust Center at https://zoko.trust.site/.

Notice of a security breach. If a security incident results in unauthorised access to personal data for which Zoko is the controller, and it is likely to result in a risk to your rights and freedoms, we will notify you without undue delay after becoming aware of it. That notice will describe the nature of the breach, the measures taken to mitigate its effects, and the steps we have taken to prevent recurrence. Where Zoko processes personal data on a customer's behalf, notification is handled under Section 8 of the Data Processing Addendum and the customer is responsible for notifying the individuals concerned.

No system is completely secure. You are responsible for safeguarding your own credentials and for the security obligations in Section 2.2 of the Terms of Service, including notifying us promptly of any suspected compromise.

11. US State Privacy Rights

This Section applies if you are a resident of California, or of another US state with a comprehensive privacy law such as Virginia, Colorado, Connecticut, Utah, or Texas. It supplements the rights in Section 8.

11.1 Categories of personal data

In the twelve months before the date of this Policy, we have collected the categories of personal data described in Section 2, namely identifiers such as name, email address, phone number, and IP address; commercial information such as subscription and transaction records; internet and network activity such as usage and device data; and the content you create or submit through the Services. We collect these from the sources described in Section 2 and use them for the purposes described in Section 3.

We disclose these categories for business purposes to the providers listed in our Sub-processor List, and to the other recipients described in Section 5.

11.2 No sale or sharing

ZOKO DOES NOT SELL PERSONAL DATA, AND DOES NOT SHARE PERSONAL DATA FOR CROSS-CONTEXT BEHAVIOURAL ADVERTISING, AS THOSE TERMS ARE DEFINED UNDER THE CALIFORNIA CONSUMER PRIVACY ACT. WE HAVE NOT SOLD OR SHARED PERSONAL DATA IN THE TWELVE MONTHS BEFORE THE DATE OF THIS POLICY. WE DO NOT KNOWINGLY SELL OR SHARE THE PERSONAL DATA OF ANYONE UNDER 16.

11.3 Sensitive personal information

We do not collect sensitive personal information for the purpose of inferring characteristics about you, and we do not use or disclose it beyond the purposes permitted without a right to limit. Please do not submit sensitive personal information to the Services.

11.4 Your rights

Subject to your state's law, you may request to know the personal data we hold about you and how we use and disclose it, request a copy in a portable format, request correction or deletion, opt out of any sale, sharing, or targeted advertising, limit the use of sensitive personal information, and opt out of profiling that produces legal or similarly significant effects. Submit a request to contact@zoko.io. We will verify your identity before responding, and will respond within the period your state's law requires.

Authorised agents. You may use an authorised agent to submit a request. We may ask the agent for proof of your written permission and may ask you to verify your identity directly.

Appeals. If we decline a request, you may appeal by replying to our decision with the subject line "Privacy Appeal". We will respond with our decision and reasons within the period your state's law requires. If your appeal is denied you may contact your state attorney general.

11.5 Non-discrimination

We will not discriminate against you for exercising these rights. We will not deny you goods or services, charge different prices or rates, provide a different level or quality of service, or suggest that you will receive a different price or level of service, except as permitted by law.

11.6 Do Not Track

Some browsers transmit a Do Not Track signal. Because no common industry standard for these signals has been adopted, we do not currently alter our practices when we receive one. You can manage cookies and tracking through our cookie preferences tool and the controls described in our Cookies Statement.

12. GDPR Compliance

ZOKO IS GDPR COMPLIANT. OUR COMPLIANCE STATUS IS PUBLISHED AND CONTINUOUSLY MONITORED IN OUR TRUST CENTER.

The General Data Protection Regulation is the comprehensive data protection law of the European Union, and governs how organisations must protect personal data and privacy. It applies to Zoko both as a controller of our own customer and website data, and as a processor of the end user data our customers handle.

The table below maps each principal obligation to where it is met in this Policy and in our Data Processing Addendum. The internal policies, controls, and evidence behind it are published in our Trust Center, described in Section 13.

RequirementHow we meet it
Lawful basis for processingSet out for each purpose in Section 3. We rely on contract, legal obligation, legitimate interests, or consent, depending on the purpose.
TransparencyThis Policy, our Cookies Statement, and our Sub-processor List, all published and kept current.
Controller and processor rolesDefined in Section 1. Zoko is controller for its own customer and website data, and processor for the end user data its customers handle.
Processor obligations (Article 28)The Data Processing Addendum, which applies automatically to every customer and requires processing only on documented instructions.
Data subject rightsSection 8 for data we control. Section 9 explains how requests reach the right party where a customer is the controller, and Section 7 of the Data Processing Addendum sets out the assistance we give.
Security (Article 32)Section 10 of this Policy and Section 4 of the Data Processing Addendum. We are ISO 27001 v2022 compliant, and our controls are documented in our Trust Center.
Personal data breaches (Articles 33 and 34)Section 10 of this Policy for data we control, and Section 8 of the Data Processing Addendum where we process on a customer's behalf.
International transfers (Chapter V)Section 6 of this Policy and Section 6 of the Data Processing Addendum, using the Standard Contractual Clauses and the UK International Data Transfer Addendum.
Sub-processors (Article 28(2) and (4))General written authorisation, a published list, and thirty days' notice of changes with a right to object.
Storage limitationSection 7, which sets out how long each category is kept.
Data protection by designControls available to customers for consent capture, opt-out handling, retention, and access management, described in the Terms of Service.
Records of processing (Article 30)We maintain records of processing activities and data flow maps, listed in our Trust Center and available to customers on request.
Assistance with impact assessmentsSection 3 of the Data Processing Addendum.
Automated decision-making (Article 22)Restricted under Section 10 of the Zoko AI Terms.
Portability and switchingSection 12 of the Terms of Service, and for EU customers the Data Act Addendum.

12.1 What our customers are responsible for

Where Zoko acts as processor, our customers remain the controllers of their end users' personal data. They are responsible for having a lawful basis and any required consent, for providing privacy notices to the people they message, for honouring opt-outs and data subject requests, and for deciding what data they send to the Services and to any platform they connect. Sections 5 and 8 of the Terms of Service set out those obligations, and the Data Processing Addendum governs the relationship.

12.2 Contacting us about data protection

For any data protection question, to exercise a right, to request our Data Processing Addendum, or to raise a concern, write to contact@zoko.io with the subject line "Data protection". We will route your request to the person responsible.

You may also complain to your local supervisory authority, as described in Section 8.

13. ISO 27001 Information Security

ISO 27001 v2022: COMPLIANT.

Zoko recognises that the confidentiality, integrity, and availability of the information and data we create, maintain, and host are vital to the success of our business and to the privacy of our partners. We operate an information security management system aligned to ISO 27001 v2022, monitored continuously, and covering data security, network security, application security, endpoint security, and corporate security.

13.1 Our Trust Center

We publish our security posture, compliance status, controls, and documentation in our Trust Center at https://zoko.trust.site/. It is the authoritative and current source for all of it, and we encourage you to review it before and during your use of the Services.

What you will find there:

  • Compliances. Our current status against ISO 27001 v2022 and the GDPR.
  • Controls. The operating controls behind that status, grouped into data security, network security, application security, endpoint security, and corporate security, covering matters such as encryption of data at rest, transmission confidentiality, data backups, anomalous behaviour detection, malicious code protection, device and container encryption, endpoint security validation, access on termination of employment, and security and privacy awareness training.
  • Policies. Our full set of information security and data protection policies and procedures, including the Data Protection Policy, Privacy By Design Policy, Data Retention Policy, Data Classification Policy, Data Breach Notification Policy and Personal Data Breach Notification Procedure, Information Security Policy, Access Control Policy and Procedure, Encryption Policy, Endpoint Security Policy, Communications and Network Security Policy, Incident Management Policy and Procedure, Vendor Management Policy and Procedure, Risk Assessment and Management Policy, Business Continuity and Disaster Recovery Policy, Asset Management Policy and Procedure, HR Security Policy and Procedure, Physical and Environmental Security Policy, Operations Security Policy, Media Disposal Policy, System Acquisition and Development Lifecycle Policy, Compliance Policy, Code of Business Conduct Policy, and Organization of Information Security Policy.
  • Documents available on request. Our ISMS Manual, ISMS Scope Document, ISMS Information Security Roles and Responsibilities, and our Records of Processing Activities and data flow maps.

To request access to a document that is not publicly viewable, use the request access option in the Trust Center, or write to contact@zoko.io.

14. Changes and Contact

We may update this Policy from time to time. We will change the effective date at the top, and where changes are material we will notify you by email or in-product notice before they take effect.

Governing law

This document forms part of the Zoko Terms of Service and is governed by the laws of the State of Delaware, USA, in accordance with Section 24 of those Terms. Disputes follow the escalation path and arbitration provisions in Sections 23 and 24 of the Terms of Service.

Bourbon Science Inc., trading as Zoko
Attn: Privacy
8080 Westpark Drive, STE 50836
Houston, TX 77063, USA
Email: contact@zoko.io