Privacy Policy
Last updated: September 29, 2026
This policy explains what personal data Zoho Middleware ("we", "us") collects when you visit this website, request an account or use the service at this domain, how we use it, and the choices you have.
1. Data we collect
| What | Details |
|---|---|
| Account details | Name, email address, company (optional), username (derived from your email) and the note you write when you sign up. Your password is stored only as a salted hash (PBKDF2). |
| Zoho connection | The Zoho API Client ID and Client Secret you enter, OAuth access and refresh tokens, the data center and the scopes you grant. |
| Workspace configuration | Modules you map, allowed CORS origins and API keys (stored only as SHA-256 hashes). |
| Usage data | Daily API request counts per workspace, sign-in times, and technical logs kept by our hosting provider (IP address, user agent, request path, time) for security and troubleshooting. |
| Sign-up & contact | The IP address of sign-up and contact form requests (for abuse and rate limiting), and the messages you send us. |
| Billing | For the Paid plan: the PayPal transaction ID and any note you submit, plan status and paid-until date. We never receive or store your card or bank details; payments are handled by PayPal. |
2. How we use it
- To create your account and private workspace, and to handle Paid plan requests and payments.
- To provide the service: authenticate your apps, call Zoho on your behalf and refresh tokens.
- To send service emails: welcome, Paid plan payment requests and activation, and replies to your support messages. We don't send marketing emails.
- To enforce plan limits, prevent abuse and keep the service secure.
- To comply with legal obligations.
We don't sell or rent your personal data, and we don't use it for advertising.
3. Your Zoho data
When your apps call the API, records from your Zoho Creator, CRM, Projects or Bookings account pass through the service to your app. We process them only to fulfil those requests. Field metadata (field names, types and options) may be cached for a short time to speed up responses; we don't keep copies of your records.
You can disconnect Zoho at any time from your workspace. On disconnect we revoke the tokens with Zoho and delete them.
4. Service providers
We rely on a small number of providers who process data on our behalf:
- Cloudflare — hosting (Cloudflare Workers), network and security.
- Neon or Cloudflare KV — encrypted storage of configuration and account data.
- Our email provider (for example Google Workspace / Gmail SMTP) — delivery of service emails.
- PayPal — payment processing for the Paid plan, under PayPal's own privacy policy.
- Zoho — the Zoho services you connect, under Zoho's own privacy policy.
These providers may process data outside your country. Where required, transfers rely on appropriate safeguards such as standard contractual clauses.
5. Cookies
We use one strictly necessary cookie, zm_admin, to keep you signed in to the admin panel (HttpOnly, Secure, SameSite=Strict, expires after 12 hours). We don't use analytics, advertising or tracking cookies.
6. Security
Client secrets and OAuth tokens are encrypted at rest with AES-256-GCM, passwords are hashed and API keys are stored only as hashes. Each account's workspace is isolated from others. No system is perfectly secure, so please keep your password and API keys safe and revoke any key you think has leaked.
7. Retention
- Account and workspace data: while your account exists. When an account is deleted, its Zoho tokens are revoked and its workspace data is removed.
- Declined sign-up requests: deleted on request, or removed during periodic clean-up.
- Daily usage counters: about 2 days. Email delivery log: the last 30 sends. Sign-up and contact rate-limit records: 1 hour.
- Support messages: up to 12 months, unless we need them longer to resolve an issue.
- Billing records: as long as required by tax and accounting law.
8. Your rights
Depending on where you live (for example under the GDPR or Vietnam's Decree 13/2023/ND-CP on personal data protection), you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to withdraw consent. To make a request, contact us using the details below. We'll reply within 30 days. You can also complain to your local data protection authority.
The service is intended for businesses and is not directed at children under 16.
9. Changes
We may update this policy. We'll change the "Last updated" date above and, for significant changes, notify account holders by email.
10. Contact
Questions or requests about your data? Email or useUse the contact form.