Privacy Policy

Last updated: June 2026

1. Who We Are

Zorah ("we", "us", "our") is a SaaS subscription management platform built and operated in Europe. We help companies track, manage, and optimise their software spend. Zorah is the data controller for the personal data processed through our platform.

2. Data We Collect

Account data

Name, email address, company name, and role — collected during sign-up via our authentication provider (Clerk).

Subscription data

Tool names, costs, billing cycles, renewal dates, departments, owners, and tags — entered by you manually or imported via CSV.

Accounting data (optional integration)

If you connect an accounting integration, we receive transaction data to detect and track subscriptions:

  • Fortnox: accounting and supplier-invoice data from your Fortnox account — only with your explicit authorisation, which you can revoke at any time.

Access and refresh tokens for this integration are encrypted at rest. We never receive your credentials — authentication happens directly with the provider.

We also keep an inbound email log (sender address, subject, processing status) when you forward subscription receipts to your dedicated Zorah inbox address.

Payment data

Subscription payments to Zorah are processed by Stripe. We do not store credit card numbers. Stripe's privacy policy applies to payment processing.

Usage data

Feature usage, page views, and interaction events within the app, collected for product improvement. We use PostHog(EU-hosted) for product analytics. See Section 11 (Cookies & Analytics) for details on consent.

3. Legal Basis for Processing (GDPR Art. 6)

  • Contract performance (Art. 6(1)(b)): Processing your account, subscription, and transaction data to provide the Zorah service.
  • Legitimate interest (Art. 6(1)(f)): Product analytics within the dashboard (via PostHog) for product improvement; fraud prevention; security monitoring.
  • Consent (Art. 6(1)(a)): Analytics on our public website (PostHog) — only activated after you accept cookies via our consent banner.
  • Legal obligation (Art. 6(1)(c)): Retaining billing records as required by tax and accounting regulations.

4. How We Use Your Data

  • Provide and maintain the Zorah platform
  • Send renewal alerts, trial notifications, and team invitation emails
  • Detect duplicate and wasteful subscriptions via AI-powered analysis
  • Process subscription payments via Stripe
  • Improve our product based on aggregated, anonymised usage data

We do not sell, rent, or share your data with third parties for marketing or advertising purposes.

5. Third-Party Processors

We use the following sub-processors to deliver the service. All are bound by data processing agreements:

ProviderPurposeData location
SupabaseDatabase hosting (PostgreSQL)EU
VercelApplication hostingEU edge
ClerkAuthentication & session managementUS (SCCs in place)
StripePayment processingUS (SCCs in place)
Berget AIAI analysis of subscription dataEU (Sweden)
ResendTransactional & inbound emailUS (SCCs in place)
PostHogProduct analyticsEU
FortnoxAccounting integration (opt-in)EU (Sweden)
Logo.devVendor logo lookup (domain only, no personal data)US

6. AI Processing

When you use the AI Assistant or import transactions, relevant data (subscription names, costs, merchant names) is sent to Berget AI (an EU-based AI provider hosted in Sweden) for analysis. Data is processed under Berget AI's terms and is not used for model training.

  • No personal identifiers (name, email) are included in AI requests
  • AI requests contain only merchant names, amounts, and dates
  • Data is not retained by Berget AI beyond the API request lifecycle

7. Data Security

  • Encryption at rest: Sensitive data is encrypted using AES-256-GCM with a dedicated encryption key
  • Encryption in transit: All connections use TLS 1.2 or higher
  • Authentication: Handled by Clerk with support for multi-factor authentication
  • Access control: Role-based permissions (admin, manager, member) restrict who can view and modify data
  • Security headers: HSTS, CSP, X-Frame-Options, and other headers are enforced on all requests
  • Rate limiting: API endpoints are rate-limited to prevent abuse
  • Infrastructure: Hosted on SOC 2 Type II certified providers (Vercel, Supabase)

9. Your Rights (GDPR)

Under the General Data Protection Regulation, you have the right to:

  • Access (Art. 15): Request a copy of your personal data — every user can export their own data in Settings → Privacy → Export my data. Admins can additionally export the full company dataset.
  • Rectification (Art. 16): Update or correct your data at any time in Settings
  • Erasure (Art. 17): Individual members can permanently remove their own account (Settings → Privacy → Remove my account), which also erases the associated identity record at our authentication provider. Admins can delete the entire company and all associated data (Settings → Privacy → Delete my account).
  • Portability (Art. 20): Export your data in machine-readable JSON format
  • Restriction (Art. 18): Request restriction of processing by contacting us
  • Objection (Art. 21): Object to processing based on legitimate interest

To exercise any of these rights, use the self-service tools in Settings or contact us at privacy@zorah.app. We will respond within 30 days as required by GDPR.

10. Data Retention

  • Active accounts: Data is retained for as long as your account is active
  • Account deletion: All data is permanently and irreversibly deleted upon request (immediate for application data, including the linked authentication record, and up to 30 days for backups)
  • Audit logs & email logs: Retained for a configurable window (default 1 year) and automatically purged by a daily retention job once they exceed it
  • Billing records: Retained for 7 years as required by EU tax regulations

11. Cookies & Analytics

Essential cookies

Authentication and session cookies (via Clerk) are required for the Service to function. These are set automatically and do not require consent.

Product analytics (PostHog)

When you are logged in and using the Zorah dashboard, we collect product usage data (feature usage, page views, interactions) via PostHog, an EU-hosted analytics provider. This data is processed under our legitimate interest (Art. 6(1)(f)) to improve the product and does not require separate cookie consent. PostHog data is hosted in the EU and is not shared with third parties.

Public website analytics (PostHog)

On our public website (outside the dashboard), PostHog analytics are only activated after you give explicit consent via our cookie banner. If you decline, no analytics data is collected on the public website. You can change your preference at any time by clearing your cookies and revisiting the site.

We do not use advertising pixels, retargeting trackers, or sell analytics data to third parties.

12. International Data Transfers

Our primary database and application are hosted in the EU (Supabase and Vercel, EU regions), and our AI processing runs on Berget AI in Sweden. Some sub-processors (Clerk, Stripe, Resend, Logo.dev) are based in the United States. For these transfers, we rely on EU Standard Contractual Clauses (SCCs) as approved by the European Commission, ensuring an adequate level of data protection.

13. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via email or an in-app notification. The "Last updated" date at the top of this page indicates the most recent revision.

14. Contact & Data Protection

For privacy-related inquiries, data access requests, or to report a concern:

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.