Privacy Policy
Effective Date: January 1, 2026 · Last Updated: April 1, 2026
This Privacy Policy describes how 智服AI ("Company," "we," "us," or "our") collects, uses, discloses, and protects information in connection with the 智服AI platform ("Service"). This Policy applies to Merchants (business operators) who use our Service and to end customers who interact with Merchant-configured phone ordering systems powered by our platform.
1. Information We Collect
A. Merchant Account Data
- Name, email address, and contact information provided during registration
- Business name, address, and phone numbers
- Payment and billing information (processed by our payment provider; we do not store full card numbers)
- Login credentials (passwords are hashed and never stored in plaintext)
B. Configuration Data
- Menu items, pricing, availability rules, and operating hours you configure in the platform
- AI prompt templates, greeting scripts, and store-level settings
C. Call and Order Data
- Inbound call metadata (caller ID, call duration, timestamps)
- Call recordings and transcripts (if Merchant enables call recording feature)
- Order details including items ordered, customer name, and pickup time
- AI interaction logs, including prompts sent to AI models and structured responses received
D. Technical Data
- IP addresses, browser type, and device information for admin portal access
- Log files and error reports for debugging and service improvement
- Cookies and session tokens (see Section 6)
2. How We Use Your Information
- Service delivery: Process phone orders, route calls, generate AI responses, and display order history in the admin portal.
- Billing: Charge subscription fees and maintain payment records.
- Support: Respond to support requests and diagnose technical issues using logs and call data.
- Service improvement: Analyze aggregated, anonymized usage patterns to improve AI accuracy and platform features. We do not use your customers' personal information to train AI models without your explicit consent.
- Legal compliance: Retain records as required by applicable law and respond to valid legal requests.
- Security: Detect and prevent fraud, abuse, and unauthorized access.
3. Call Recording and Voice Data
If you enable the call recording feature, calls processed through your store's phone lines will be recorded and stored on our servers. You are solely responsible for notifying callers that their call may be recorded, as required by applicable law (see our Terms of Service, Section 4). Voice recordings are retained for up to 90 days by default and may be deleted earlier at your request. Transcripts may be retained longer for order accuracy and audit purposes.
4. Information Sharing and Disclosure
We do not sell your personal information. We may share information in the following circumstances:
-
Service providers: We share data with trusted third-party vendors necessary to operate the Service, including:
- Telephony providers (e.g., Twilio) — for call routing and recording infrastructure
- AI model providers (e.g., OpenAI) — for speech-to-text and natural language processing
- Cloud hosting providers — for data storage and computing
- Payment processors — for subscription billing
All service providers are bound by data processing agreements and may only use your data to provide services to us.
-
Legal requirements: We may disclose information when required by law, court order, or government authority, or when we believe disclosure is necessary to protect our rights or the safety of others.
-
Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the successor entity, subject to the same privacy protections.
5. Data Retention
We retain data for as long as necessary to provide the Service and comply with legal obligations:
- Account data: retained for the duration of your subscription plus 2 years after termination
- Order records: retained for 7 years for tax and audit compliance
- Call recordings: 90 days (configurable, deletable on request)
- AI decision logs: 1 year
- Server access logs: 90 days
6. Cookies and Tracking
The admin portal uses session cookies to maintain authenticated sessions. We do not use third-party advertising cookies or cross-site tracking. You can disable cookies in your browser, but this will prevent you from logging into the admin portal.
7. California Privacy Rights (CCPA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You may request deletion of personal information we have collected, subject to certain exceptions.
- Right to Opt-Out of Sale: We do not sell personal information. No opt-out is necessary.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
To exercise these rights, contact us at privacy@zhifood.com. We will respond within 45 days.
8. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR):
- Legal basis for processing: We process your data based on contract performance (to provide the Service), legitimate interests (security, fraud prevention), and legal obligations.
- Right of access: Request a copy of your personal data.
- Right to rectification: Request correction of inaccurate data.
- Right to erasure ("right to be forgotten"): Request deletion of your data, subject to legal retention requirements.
- Right to data portability: Request your data in a machine-readable format.
- Right to object: Object to processing based on legitimate interests.
- Right to lodge a complaint: You may lodge a complaint with your local supervisory authority.
International data transfers: Your data may be transferred to and processed in the United States. We implement appropriate safeguards including Standard Contractual Clauses (SCCs) for transfers from the EEA.
To exercise GDPR rights, contact our Data Protection contact at privacy@zhifood.com.
9. Security
We implement industry-standard security measures including TLS encryption in transit, AES-256 encryption at rest for sensitive data, access controls, and regular security reviews. However, no system is completely secure. In the event of a data breach affecting your rights, we will notify you as required by applicable law.
10. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected data from a minor, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification at least 14 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
12. Contact Us
For privacy-related inquiries, data requests, or to report a concern:
智服AI — Privacy Team Email: privacy@zhifood.com For urgent security matters: security@zhifood.com
© 2026 智服AI. All rights reserved. · Terms of Service