Zulli

Privacy Policy

Last updated: August 25, 2026

This Privacy Policy explains what information Zulli (the "Service") collects, how we use it, and the choices you have. Zulli is operated by Zulli Platforms LLC. The Service lets event vendors publish a profile page, receive event inquiries through an inquiry form, and manage proposals, invoices, bookings, and payments with their clients.

1. Who this policy covers

We handle information about two groups of people:

  • Vendors: event professionals who create an account and use the dashboard.
  • Clients and visitors: people who view a vendor's public page, submit an inquiry, or interact with a proposal, invoice, or client portal a vendor shares with them.

A note for clients and visitors: when you submit an inquiry or respond to a proposal, your information is collected on behalf of the vendor you contacted, and that vendor decides how to use it for their business. We process it to deliver it to the vendor and operate the Service. For questions about how a specific vendor uses your information, contact that vendor directly.

2. Information we collect

From vendors

  • Account information: your email address and password. Passwords are stored only in hashed form, so we cannot see them.
  • Sign in with Google: if you use "Continue with Google," Google sends us your name and email address to create or sign in to your account. We never see your Google password.
  • Profile and page content: your name, business name, phone number, service area, license or credential details, tagline and page text, and images you upload (avatar, logo, gallery photos, backgrounds). If you publish your page, this content is publicly visible.
  • Business records: proposals, invoices, bookings, calendar entries, expenses, notes, and files you store in your file library.
  • Payment setup: if you enable online payments, your Stripe account identifier and connection status. Payment instructions you write (for example bank or payment-app details) are stored as part of your invoices.

From clients and visitors

  • Inquiry details: what you enter in a vendor's inquiry form, typically your name, email, and phone, and depending on the vendor's form, your company, event type and date, guest count, a message, and answers to the vendor's custom questions.
  • Questionnaire answers: what you enter when you fill out a questionnaire a vendor sends you.
  • Uploads: files, photos, and drawn signatures you attach to an inquiry or provide when responding to a proposal.
  • Payment details: if you pay an invoice online, your payment is processed by Stripe. Card details go directly to Stripe: we never receive or store your card number. We keep a record of the payment (amount, status, and reference).

Collected automatically

  • Page analytics: when you visit a vendor's public page, we record the visit and clicks on page elements (for example call, email, social, or booking links) so the vendor can see how their page performs. If the vendor shared their link with a tracking tag, we also record which channel the visit came from (for example "instagram"). We also resolve your approximate location (country and region only, not a precise address) from your IP address for the vendor's analytics; for this specific lookup, the IP address itself is discarded immediately afterward and not stored. To count unique visitors we set a randomly generated visitor cookie in your browser; it is not linked to your name or identity.
  • Account sessions: while a vendor is signed in, we periodically record the IP address and browser/device (user-agent string) used for that session, so the vendor can review and sign out their own active sessions from account settings. This is kept only for the life of the session.
  • Trusted devices: if a vendor turns on two-step sign-in and chooses not to be challenged on every sign-in, we keep a record of each browser that passes a challenge (including the IP address and browser/device at the time it was verified) so we know when to skip the next challenge. Vendors can review and remove trusted devices in account settings at any time.
  • E-signatures: when a contract is signed through the Service, whether by the vendor or their client, we record the typed legal name (and drawn signature image, if used) together with the IP address and browser/device used at the moment of signing. This is standard practice for electronic signatures and is kept as part of that contract's signing record (see Section 5).
  • Cookies and similar technologies: see Section 6.
  • Technical logs: like most web services, our servers may log basic request information (such as IP address, browser type, and timestamps) for security and troubleshooting.

3. How we use information

  • To provide the Service: publishing vendor pages, delivering inquiries to the right vendor, generating proposals and invoices (including PDF versions), processing bookings, and showing vendors their analytics.
  • To operate accounts: signing you in, resetting passwords, and sending service emails (for example password reset links and client-facing proposal or invoice notifications).
  • To keep the Service secure: preventing fraud, abuse, and unauthorized access.
  • To improve the Service: understanding how features are used, in aggregate.
  • To comply with legal obligations.

We do not sell your personal information, and we do not use client inquiry data for our own advertising.

4. How information is shared

  • With the vendor you contact: inquiries, uploads, signatures, and proposal/invoice responses are shared with the vendor they were submitted to, which is the purpose of the Service.
  • On public pages: content a vendor chooses to publish (profile, services, pricing, photos) is visible to anyone with the link. Proposal, invoice, and client-portal pages are not listed publicly but are accessible to anyone who has their unique link, so vendors and clients should share those links only with the intended recipient.
  • Service providers: we use third parties to run parts of the Service. Each receives only what it needs to perform its function and is governed by its own privacy policy:
    • Stripe processes client payments to vendors and vendors' Pro subscription payments to us. Card details go directly to Stripe.
    • Google provides two things: optional "Continue with Google" sign-in (we receive your name and email from Google), and Google Fonts, which loads display typefaces on vendor public pages, inquiry forms, questionnaires, and during signup. When a page loads a font this way, your browser requests it from Google's servers, which receive your IP address as part of that request.
    • Pexels powers the optional stock-photo search in the vendor page editor. When a vendor searches, the search terms are sent to Pexels and photo previews load from Pexels' servers. This is used only in the editor, never on public pages or by visitors.
    • Umami measures how people use Zulli's own website and dashboard (for example which pages are visited and whether someone signed up), so we can improve the product. It sets no cookies, doesn't identify you, and respects your browser's "Do Not Track" setting. It never runs on vendors' public pages, the client portal, or documents sent to clients.
    • PostHog helps us find where the product is confusing. On Zulli's own get-started flow and vendor dashboard it records which pages and buttons are used, linked to a vendor's account number (never an email address or anything about that vendor's clients). On the get-started flow only, it also makes a screen recording of that setup session so we can see where people get stuck; text typed into fields is hidden from the recording, and no recording is ever made of the dashboard, a vendor's public page, the client portal, or documents sent to clients. PostHog sets cookies to recognise a returning browser.
    • An email delivery provider sends account and service emails (such as password resets and client-facing notifications) on our behalf.
    Visitor location lookups for vendor analytics are performed on our own servers using MaxMind's GeoLite2 database; your IP address is not sent to MaxMind or any other third party for this.
  • Legal reasons: we may disclose information if required by law, or to protect the rights, safety, or property of our users or the Service.
  • Business transfers: if we are involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy.

5. Data retention

  • Vendor accounts and their data are kept while the account is active. Account deletion is scheduled with a 30-day grace period during which the vendor can sign back in to cancel it; after that, associated data is deleted or anonymized within a reasonable period, except where we must keep it for legal, accounting, or security reasons.
  • Files a vendor moves to the trash are permanently deleted after 30 days.
  • Inquiries and business records (proposals, invoices, bookings) are kept while the vendor's account is active so vendors can maintain their business history; vendors may delete individual records at any time.
  • Analytics records (individual page views and link clicks, including the coarse location described in Section 2) are kept for as long as the vendor's account is active so vendors can review page performance over time.
  • Session records (the IP address and device tied to a sign-in) are kept only for the life of that session and are cleared when it expires or the vendor signs out.
  • Trusted-device records (see Section 2) are kept until the vendor removes the device in account settings, turns off two-step sign-in's "don't ask every time" option, or the trust expires.
  • E-signature records (the IP address, device, and signature captured at the moment of signing) are kept for as long as the related contract is retained, since they are part of that contract's legal signing evidence.

6. Cookies

We use a small number of first-party cookies and local storage keys. All but the last are necessary for the Service to work:

  • Session cookie: keeps vendors signed in to their dashboard.
  • Security (CSRF) cookie: protects forms from cross-site request forgery.
  • Timezone cookie: remembers your timezone so dates and times display correctly.
  • Visitor cookie: a random identifier used only to count unique visitors on vendor pages; it is not tied to your identity.
  • Trusted-device cookie: set only when a vendor with two-step sign-in chooses not to be challenged on every sign-in; it lets us recognize that browser and skip repeat challenges for the interval the vendor picked.
  • Theme preference: stored in your browser's local storage to remember light or dark mode.
  • Product analytics cookie: set by PostHog (see section 4) on Zulli's own get-started flow and vendor dashboard, so that a series of visits reads as one person rather than several. It is not set on vendors' public pages, the client portal, or documents sent to clients, and it is the one cookie here the Service would run without.

We do not use advertising or cross-site tracking cookies.

7. Security

We take reasonable technical and organizational measures to protect your information, including hashed password storage, access controls, and unique, unguessable links for client-facing documents. No online service can guarantee perfect security, so please use a strong, unique password and keep shared links private.

8. Your rights and choices

  • Access and update: vendors can view and update their account and profile information in the dashboard settings at any time.
  • Deletion: vendors can delete content and records from the dashboard, and can delete their entire account from account settings (scheduled with a 30-day grace period, then permanent). Clients who want their inquiry or personal information removed should contact the vendor they submitted it to; you may also contact us and we will assist where we can.
  • Email: service emails (such as password resets) are necessary to operate your account.

Depending on where you live, you may have additional legal rights over your personal information, such as the right to access, correct, delete, or receive a copy of it, or to object to certain processing. To exercise these rights, contact us at the address below. We will not discriminate against you for exercising them.

9. Children

The Service is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.

10. International users

The Service is operated from, and your information is stored in, the country where we are established. If you use the Service from elsewhere, you understand that your information will be transferred to and processed there.

11. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will take reasonable steps to notify you (for example by email or a notice in the Service). The "Last updated" date at the top shows when it was last revised.

12. Contact

Questions or requests about your data? Contact Zulli Platforms LLC at support@zulli.io. You can also review our Terms of Service.

Terms · Privacy

2026 Zulli Platforms LLC · Zulli.io