Skip to main content

Privacy Policy

Last updated: September 28, 2026

1. Introduction

This Privacy Policy explains how BZAR Technologies, Inc.("bzar," "we," "us," or "our") collects, uses, shares, and protects personal information when you use bzar.app, our mobile apps, and related services (the "Service"). It also covers people who do not use the Service but whose information we process, such as people who email a vendor that uses bzar and businesses listed from public sources.

Vendors and organizers on bzar run their own businesses. When you buy from or share information with one of them, their own privacy practices apply to what they do with it. This policy does not cover them or third-party sites and services linked from bzar.

Our Terms of Service also apply to your use of the Service.

2. Information We Collect

Information you give us

  • Account information: name, email address, password (stored only as a hash), phone number, role (customer, vendor, or organizer), and zip code.
  • Business and event information: business name, description, services, products, prices, photos, videos, logos, location, service area, website and social links, event details, booth and ticket settings, and documents you upload (such as contracts, licenses, and insurance certificates).
  • Transactions: bookings, orders, tickets, booth applications, invoices, quotes, subscriptions, and refunds. Payment card and bank details are collected and stored by Stripe, not by us; we keep references to them, amounts, and payment status.
  • Communications: messages you send through the Service, reviews, questionnaire and form answers, and what you send to our support.
  • Identity and payout information that vendors and organizers give Stripe to receive payouts, which Stripe may share with us.

Information collected automatically

  • Device and usage data: IP address, browser and device type, pages viewed, links and buttons clicked, referring site, and timestamps.
  • Approximate location derived from your IP address, for example to check our service area on the waitlist form.
  • Cookies and similar technologies, described in Section 6.

Information from others

  • Other users, for example when a vendor adds you as a customer, an organizer invites you to an event, or someone sends you a message.
  • Accounts you connect, such as Google, Square, Shopify, or Instagram (Section 9).
  • Service providers, such as Stripe (payment and verification results) and sign-in providers (Google, Apple).
  • Public sources, such as business websites, map listings, event sites, and public social media (Section 11).

3. How We Use Information

  • Provide, operate, maintain, and personalize the Service.
  • Process payments, payouts, refunds, and subscriptions, and send receipts, tickets, and confirmations.
  • Let customers, vendors, and organizers find and communicate with each other.
  • Send account, transaction, and service messages, and, where the law allows, marketing messages you can opt out of.
  • Run AI features you use (Section 8) and connected-account features you turn on (Section 9).
  • Find and contact businesses that might want to sell on bzar (Section 11).
  • Understand how the Service is used, fix errors, and develop new features (Section 7).
  • Prevent, detect, and investigate fraud, abuse, security incidents, and violations of our Terms.
  • Comply with law, enforce our agreements, and protect the rights, property, and safety of bzar, our users, and others.

We may also create de-identified or aggregated information and use it for any lawful purpose.

4. How We Share Information

We do not sell personal information, and we do not share it for cross-context behavioral or targeted advertising. We share it only as follows:

  • With other users, as the Service requires. Public vendor and organizer profiles, listings, and events are visible to anyone. When you book, buy, apply, or message, the vendor or organizer receives what they need to serve you, such as your name, contact details, and order details.
  • With service providers who process information for us under contract (Section 5).
  • With services you connect or ask us to use, such as a mailbox, calendar, or store you connect (Section 9).
  • For legal reasons: to comply with law, legal process, or government requests; to enforce our Terms; or to protect the rights, property, or safety of bzar, our users, or others.
  • In a business transaction, such as a merger, acquisition, financing, or sale of assets, or in bankruptcy.
  • With your consent or at your direction.

5. Service Providers

We use service providers to run the Service. They receive the information needed for their work. Today they include:

  • Hosting, database, and storage: Supabase and Vercel.
  • Payments and identity verification: Stripe.
  • Email: Resend.
  • Analytics and monitoring: PostHog, Sentry, and Vercel Web Analytics (Section 7).
  • Maps, places, and sign-in: Google, and Sign in with Apple in our mobile apps.
  • AI processing: OpenRouter and the third-party AI model providers it routes to, such as Google (Gemini) and OpenAI (Section 8).
  • Account connections: Nango, which holds the access tokens for accounts vendors connect (Section 9).
  • Public data collection: Apify and similar tools that collect public event and business information (Section 11).
  • Internal team tools:Slack, where our team receives notices about vendor activity and new vendor sign-ups, which can include a vendor's name, business name, email address, and phone number; and Linear, for support and bug reports.
  • Security and reliability: Upstash (rate limiting) and ipapi.co (IP-based location on the waitlist form).
  • Notifications: push services run by your browser or device maker, and Expo for mobile app push notifications. Where we send text messages, an SMS provider such as Twilio.

This list may change as we add, replace, or remove providers.

6. Cookies and Similar Technologies

We use cookies, local storage, session storage, and similar technologies. We do not use advertising cookies or ad pixels. The technologies we use fall into two groups:

Necessary (always on)

These run the site, keep it secure, process payments, and remember your choices. The Service does not work without them.

  • sb-… (auth token)

    Keeps you signed in and secures your session.

    Provider: bzar (Supabase) · Duration: Up to 400 days

  • bzar_consent

    Remembers your cookie choices.

    Provider: bzar · Duration: 1 year

  • bzar-active-org, bzar-onboarded, bzar-sidebar-collapsed, bzar-setup-destination

    Remember your selected organization, onboarding status, layout, and where to return after setup.

    Provider: bzar · Duration: Up to 1 year

  • bzar_app_mode

    Tells the site it is running inside the bzar app.

    Provider: bzar · Duration: 30 days

  • bzar-cart, bzar-event-cart, bzar-event-wizard and similar (local and session storage)

    Save carts, drafts, and in-progress forms on your device.

    Provider: bzar · Duration: Until cleared or completed

  • __stripe_mid, __stripe_sid, and Stripe.js storage

    Payment processing and fraud prevention on checkout pages.

    Provider: Stripe · Duration: 30 minutes to 1 year

  • Google Maps and Places

    Maps and address search on pages that use them; Google may set its own cookies.

    Provider: Google · Duration: Set by Google

Analytics and session replay (only with your consent)

These help us understand and improve the Service. They are off until you choose "Accept all" or turn them on in cookie settings.

  • ph_…_posthog (cookie and local storage)

    Product analytics, heatmaps, and vendor session replay: a random device ID, session ID, and, once you sign in, your account ID.

    Provider: PostHog · Duration: Up to 1 year

  • sentryReplaySession (session storage)

    Session replay for diagnosing errors.

    Provider: Sentry · Duration: Browser session

  • bzar_acq

    First-visit attribution: the campaign or referring site that brought you, reduced to a short label.

    Provider: bzar · Duration: 90 days

Without cookies

Vercel Web Analytics counts page views without cookies or a persistent identifier. Sentry error monitoring, which reports errors and performance problems, runs as part of operating and securing the Service; it sets no cookies, and records session replays only with your consent. Our fonts are served from our own domain.

Your choices

  • Change your choice at any time with the "Cookie settings" link in our site footer or here: . Your choice is saved for this browser for one year.
  • Global Privacy Control. If your browser sends a Global Privacy Control (GPC) signal, we treat it as a choice of necessary cookies only, for that browser.
  • Do Not Track.Browsers' older "Do Not Track" setting has no agreed standard, so we do not respond to it; we do honor GPC.
  • You can also block or delete cookies in your browser settings. Some parts of the Service may then not work.

7. Analytics, Session Replay, and Error Monitoring

  • PostHog (with your consent in the browser). Your browser sends page views, clicks, and heatmap data. Once you sign in, events are linked to a PostHog person profile with your account ID and, for vendors and organizers, details such as name, email, role, and business name. We filter out passwords, payment details, form values, message contents, and private link tokens, and on business dashboards we strip on-screen text from clicks.
  • Vendor session replay. For signed-in vendors who have consented, PostHog may record a replay of how the vendor dashboard is used: a reconstruction of the page, not a video, with typed input and on-screen text masked and sensitive areas (such as messages, customer records, documents, and payment forms) blocked. It does not record sign-in, payment, or customer-facing pages.
  • Server events. Our servers also record key actions in PostHog, such as signing up, submitting an application, buying a ticket, or changing a subscription, with your account ID, to run and measure the Service. You can ask us to exclude your account from product analytics by emailing hello@bzar.appwith the subject "Analytics opt-out".
  • Sentry. When an error occurs we send Sentry the error, technical context, your IP address, and your account ID and email. With your consent, Sentry also records masked session replays for a sample of sessions and for sessions with an error.

8. AI Features

Some features use AI. When they run, the content they need is sent through OpenRouter to third-party AI model providers, such as Google (Gemini) and OpenAI, and the result comes back to us. Which provider handles a request may change.

  • Setup import:materials a vendor gives us to set up a storefront, such as documents, menus, price sheets, images, the vendor's website, and public Instagram content.
  • Baz and drafting: the messages, customer records, reviews, and other content the vendor asks Baz to work with.
  • Inbox sorting:emails in a vendor's connected mailbox, including sender, subject, and body, from people who may not use bzar.
  • Document autofill: text from documents a vendor uploads, such as insurance certificates and licenses, to suggest expiration dates and other fields.
  • Event and business listings: public information we collect (Section 11).

bzar does not use your content to train AI models. The providers handle content under their own terms and policies. We keep records of AI requests for cost, quality, and abuse monitoring. We do not use AI to make decisions that produce legal or similarly significant effects about you.

9. Connected Accounts and Google Data

Vendors can connect outside accounts, such as Gmail, Google Calendar, Google Business Profile, Instagram, Square, and Shopify. Connections run through Nango, which holds the access tokens on our behalf; we do not receive your passwords for those accounts. Depending on what a vendor connects, we read and store data such as emails and attachments, calendar events, reviews and business listing data, Instagram media and messages, and catalog, customer, and order data, and we act on the vendor's instructions, for example sending an email, a reply, or a calendar event. A connected mailbox can include emails from people who do not use bzar; we process those for the vendor.

Disconnecting an account stops future imports. Data already imported stays in the vendor's account until the vendor deletes it or asks us to. If you emailed a vendor and want your information removed, contact hello@bzar.app; you do not need a bzar account.

Google user data

bzar's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. In particular, for data from Gmail (read and send), Google Calendar, and Google Business Profile:

  • We use it only to provide and improve the user-facing features the vendor turned on: showing and sorting their email, sending email they write or approve, syncing their calendar, and managing their reviews and listing.
  • We transfer it to others only as needed to provide those features (including to AI model providers for inbox sorting and drafting, as Section 8 describes), for security, to comply with law, or in a merger or acquisition.
  • We do not use it for advertising, do not sell it, and do not use it to train generalized AI or machine-learning models.
  • People do not read it unless the vendor gives us permission for specific messages, it is needed for security or to comply with law, or it has been aggregated and anonymized for internal operations.

10. Data Vendors Bring to bzar

Vendors can import customer lists, orders, and contacts from connected platforms or files, and manage their customers in bzar. We process that information on the vendor's behalf to provide the Service to the vendor, and not for our own marketing. We honor customer and shop deletion requests that Shopify sends us, as Shopify requires. If a vendor imported your information and you want to see, correct, or delete it, contact the vendor, or email us at hello@bzar.app and we will help.

11. Public Business and Event Information

We collect information that businesses and organizers have made public, from sources such as Google Places, Eventbrite, business websites, and public Instagram profiles, to list local events and to find and contact businesses that might want to sell on bzar. This can include a business name, contact name, business email and phone number, website, social handles, location, photos, and event details. We may contact those businesses about bzar.

If you are listed or contacted and want us to stop, or to correct or remove your information, email hello@bzar.app or use the unsubscribe link in our email.

12. Our Mobile Apps

If you use our mobile apps, we may also collect a push notification token (to send notifications you allow), information from Sign in with Apple or Google, your device's location (with your permission, for features such as nearby events and check-in), and access to your camera or photos (with your permission, for example to scan tickets or upload images). You can change these permissions in your device settings.

Our apps also use PostHog for product analytics (screens viewed, actions taken, and app lifecycle events, linked to your account once you sign in) and Sentry for crash and error reports. The apps do not record session replays. Pages of the website shown inside the app do not run web analytics unless you have opted in.

13. Retention

We keep personal information for as long as we need it for the purposes in this policy, including to provide the Service, to meet legal, tax, accounting, and reporting obligations, to resolve disputes, to prevent fraud and abuse, and to enforce our agreements. How long depends on the kind of information and why we hold it. Our providers, such as Stripe, PostHog, and Sentry, keep data under their own retention settings. When we no longer need information, we delete, de-identify, or aggregate it.

14. Security

We use reasonable administrative, technical, and physical measures designed to protect personal information, such as encryption in transit, access controls, and keeping payment card data with Stripe. No method of transmission or storage is completely secure, and we cannot guarantee the security of your information. You are responsible for keeping your password safe.

15. Your Choices

  • Account information: update your profile and settings in your account. You can ask us to delete your account.
  • Marketing email: use the unsubscribe link in any marketing email. We will still send transactional and account messages.
  • Notifications and device permissions: change them in your settings or your device.
  • Cookies and analytics: see Section 6.

16. State Privacy Rights

Depending on where you live, and where a state's privacy law applies to bzar, you may have the right to:

  • confirm whether we process your personal information and access it;
  • correct inaccurate personal information;
  • delete personal information;
  • get a copy in a portable format; and
  • opt out of the sale of personal information, targeted advertising, and certain profiling. We do not sell personal information, use it for targeted advertising, or use it for profiling that produces legal or similarly significant effects.

To make a request, email hello@bzar.app. We will need to verify your identity, usually by asking you to write from the email address on your account, and may decline a request where the law allows. An authorized agent may make a request for you with proof of their authority. If we decline your request, you may appeal by replying to our decision; if we deny the appeal, you may contact your state attorney general. We will not discriminate against you for exercising these rights.

17. Children

The Service is not directed to children, and accounts are for people 18 and older. We do not knowingly collect personal information from children under 13. If you believe a child has given us personal information, contact hello@bzar.app and we will delete it.

18. Where Information Is Processed

bzar is based in and intended for use in the United States. We and our providers process information in the United States and in other countries where our providers operate, whose laws may differ from those where you live.

19. Changes to This Policy

We may change this policy at any time. Changes take effect when we post the updated policy here with a new "Last updated" date, unless the law requires otherwise. If the law requires notice or consent for a change, we will provide it.

20. Contact

BZAR Technologies, Inc.
16192 Coastal Highway
Lewes, DE 19958
Email: hello@bzar.app