Legal information

Privacy Policy

This Policy describes the personal data processed when you visit zily.app, create an account, save research, configure alerts, purchase a plan, use the API, or contact us.

Effective and last updated: 11 August 2026

Plain-language summary

Zily uses the account, subscription, workspace, and technical data needed to run and secure the service. Payment card details are entered with Whop; Zily does not intentionally receive or store your full card number or CVV. We do not sell personal data.

1. Scope and controller

This Policy applies to Zily’s website, authenticated workspace, alerts, transactional email, and API. It does not govern third-party property portals or Whop’s independent marketplace experience.

The data controller is the Zily seller identified in your Whop order confirmation or account communications. For privacy questions or requests, contact [email protected]. If a seller identity is missing from your order record, include that issue in your message so it can be corrected.

2. Personal data we collect

  • Account data: Clerk user identifier, name, email address, verification status, profile image where provided, and account timestamps.
  • Membership data: plan, Whop customer and membership identifiers, checkout status, renewal period, cancellation state, and billing-management link. Whop and its payment providers process payment credentials.
  • Workspace data: saved listings, notes, alert criteria, saved analyses, API-key name and masked prefix, and feature preferences.
  • Usage and device data: IP address, browser and device type, requested URLs, timestamps, security events, API usage, error logs, and similar diagnostic information.
  • Communications: messages, support requests, privacy or refund requests, and related records.
  • Public professional data: attributed broker or source contact details contained in property records where lawfully provided by a connected source.

Please do not place passport details, payment credentials, health data, or other sensitive personal information in notes or alert names.

3. Where data comes from

We obtain personal data:

  • directly from you when you register, configure the workspace, use the API, or contact us;
  • from Clerk when it authenticates your account;
  • from Whop when it reports checkout, payment, membership, cancellation, or refund status;
  • automatically from your browser, device, and network when you use Zily;
  • from connected, attributed property-data sources where a record contains business contact information.

4. How and why we use personal data

PurposeTypical legal basis where required
Create accounts, provide features, synchronize paid access, and respond to supportPerform our contract or take requested pre-contract steps
Send saved-alert matches, receipts, security notices, and service messagesPerform the contract; comply with law; legitimate interests in operating the service
Prevent fraud, enforce plan limits, protect accounts, diagnose failures, and defend claimsLegitimate interests; legal obligations; establishment or defence of legal claims
Meet tax, accounting, consumer-protection, sanctions, and lawful authority requirementsLegal obligation
Optional marketing or non-essential tracking, if introducedConsent where required; you may withdraw it

We do not use personal data for unrelated purposes without a compatible legal basis and any notice or consent required by law.

5. Sharing and service providers

We disclose only what is reasonably necessary to:

  • Clerk for authentication and account management;
  • Whop and its payment providers for checkout, membership, billing support, refunds, and fraud prevention;
  • Resend for service and alert email;
  • Cloudflare for hosting, delivery, traffic security, and related infrastructure;
  • database, monitoring, support, legal, audit, or professional providers bound by appropriate duties;
  • authorities or other parties where required by law, necessary to protect rights and safety, or involved in a corporate transaction subject to confidentiality safeguards.

We do not sell personal data or share it for cross-context behavioural advertising.

6. International data transfers

Zily’s providers may process data in the UAE, United States, European Economic Area, or other locations. When transfer restrictions apply, we use an available lawful mechanism such as an adequacy decision, contractual safeguards, provider data-processing terms, or a permitted legal exception, together with technical and organizational protections appropriate to the risk.

7. Retention

We keep personal data only for as long as reasonably necessary for the purpose collected. Account and workspace data is generally retained while the account is active. On a valid deletion request, ordinary live data is deleted or de-identified, subject to technical completion time and limited backup rotation.

Billing, fraud, security, dispute, tax, and legal records may be retained longer where law or the defence of claims requires it. Retention decisions consider the data’s amount, sensitivity, risk, purpose, contract duration, statutory periods, and whether de-identification can meet the same need.

8. Security

Zily uses measures designed for the data and risk involved, including managed authentication, encrypted transport, access controls, secret hashing for API keys, provider webhook verification, billing-state reconciliation, and monitoring. No internet service is perfectly secure. Report a suspected incident to [email protected] and do not include passwords or full payment details.

9. Your privacy rights

Depending on where you live and which law applies, you may ask for access, correction, deletion, restriction, objection, portability, withdrawal of consent, or information about processing and disclosures. You may also complain to the competent regulator.

Send requests to [email protected] from the email associated with your account. We may verify identity and request clarification. We will respond within the period required by applicable law and explain if a lawful exception applies. See GDPR & Data Rights for more detail.

UAE users can review the official UAE data-protection overview and Federal Decree-Law No. 45 of 2021.

10. Cookies, alerts, and communication choices

Zily currently uses essential authentication and security technologies. We do not currently deploy our own behavioural-advertising or optional analytics cookies. See the Cookie Policy.

Deal-alert emails are requested service messages and can be stopped by disabling or deleting the alert. Essential account, billing, security, and policy messages may still be sent while you maintain an account or paid membership.

11. Automated analysis

Zily automatically calculates property figures and compares listing records. Those outputs concern properties, not a decision about your legal rights, credit, employment, insurance, or access to a public service. Zily does not make solely automated decisions about you that produce legal or similarly significant effects.

12. Children

Zily is intended for adults aged 18 and older and is not directed to children. If you believe a child provided personal data, contact [email protected] so we can investigate and delete it where required.

13. Policy changes and contact

We may update this Policy when the product, providers, law, or processing changes. The effective date will be revised, and material changes will receive additional notice where required. Changes do not create a new legal basis for materially different processing without any notice or consent required by law.

Contact: [email protected].

Privacy Policy | Zily