Zoho Middleware Sign in

Privacy Policy

Last updated: September 29, 2026

This policy explains what personal data Zoho Middleware ("we", "us") collects when you visit this website, request an account or use the service at this domain, how we use it, and the choices you have.

1. Data we collect

WhatDetails
Account detailsName, email address, company (optional), username (derived from your email) and the note you write when you sign up. Your password is stored only as a salted hash (PBKDF2).
Zoho connectionThe Zoho API Client ID and Client Secret you enter, OAuth access and refresh tokens, the data center and the scopes you grant.
Workspace configurationModules you map, allowed CORS origins and API keys (stored only as SHA-256 hashes).
Usage dataDaily API request counts per workspace, sign-in times, and technical logs kept by our hosting provider (IP address, user agent, request path, time) for security and troubleshooting.
Sign-up & contactThe IP address of sign-up and contact form requests (for abuse and rate limiting), and the messages you send us.
BillingFor the Paid plan: the PayPal transaction ID and any note you submit, plan status and paid-until date. We never receive or store your card or bank details; payments are handled by PayPal.

2. How we use it

We don't sell or rent your personal data, and we don't use it for advertising.

3. Your Zoho data

When your apps call the API, records from your Zoho Creator, CRM, Projects or Bookings account pass through the service to your app. We process them only to fulfil those requests. Field metadata (field names, types and options) may be cached for a short time to speed up responses; we don't keep copies of your records.

You can disconnect Zoho at any time from your workspace. On disconnect we revoke the tokens with Zoho and delete them.

4. Service providers

We rely on a small number of providers who process data on our behalf:

These providers may process data outside your country. Where required, transfers rely on appropriate safeguards such as standard contractual clauses.

5. Cookies

We use one strictly necessary cookie, zm_admin, to keep you signed in to the admin panel (HttpOnly, Secure, SameSite=Strict, expires after 12 hours). We don't use analytics, advertising or tracking cookies.

6. Security

Client secrets and OAuth tokens are encrypted at rest with AES-256-GCM, passwords are hashed and API keys are stored only as hashes. Each account's workspace is isolated from others. No system is perfectly secure, so please keep your password and API keys safe and revoke any key you think has leaked.

7. Retention

8. Your rights

Depending on where you live (for example under the GDPR or Vietnam's Decree 13/2023/ND-CP on personal data protection), you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to withdraw consent. To make a request, contact us using the details below. We'll reply within 30 days. You can also complain to your local data protection authority.

The service is intended for businesses and is not directed at children under 16.

9. Changes

We may update this policy. We'll change the "Last updated" date above and, for significant changes, notify account holders by email.

10. Contact

Questions or requests about your data? Use the contact form.