ZaaS App Privacy Policy

ZaaS Corporate Wellness Platform

Last Updated: July 6, 2026


This Privacy Policy explains how ZaaS (“ZaaS”) collects, uses, shares, and protects information in connection with the ZaaS corporate wellness platform, including our website, our mobile applications, and related services (collectively, the “Service”).

If your employer has made the Service available to you as an employee benefit (“your Organization”), please also refer to any additional notices your Organization provides, as your Organization’s own policies may supplement this Privacy Policy. In some cases, your Organization, rather than ZaaS, is the party primarily responsible for decisions about your personal information under applicable law; in that case, we act on your Organization’s behalf as described in our services agreement with them.

1. Our Commitment: No Data Monetization

We do not sell, lease, rent, or trade your health metrics, activity logs, or other personal information to third-party advertising networks or data brokers under any circumstances.

ZaaS’s business is built on organizations and their employees using and paying for a wellness service, not on monetizing personal data. This commitment applies to all personal information we collect through the Service, without exception, and is not diminished by any change in our corporate structure or ownership (see Section 13, Business Transfers).

2. Information We Collect

2.1 Account & Profile Information

Your name, work email address, employer/workspace affiliation, role, and profile photo (if you choose to provide one).

2.2 Wellness Activity Data

Information you log or that the Service generates as you use it, for example, daily habit check-ins, step counts and activity goals, exercise and active minutes, sleep duration and sleep quality, hydration logging, mindfulness and meditation sessions, and milestone or achievement records.

2.3 Usage & Device Information

Technical information generated automatically as you use the Service, such as device type, app version, and log data, is used to operate, secure, and improve the Service.

2.4 Communications

Messages you send us (support requests, feedback) and records of transactional messages we send you (for example, account confirmations or password-reset emails).

2.5 Health Connect and Apple Health Data


On Android devices, ZaaS can — only with your explicit, separate permission — read the following data from Google Health Connect: steps, exercise/active minutes, sleep, hydration, and mindfulness sessions. On iOS, ZaaS can read equivalent data from Apple Health with your permission.
We use this data solely to pre-fill your daily wellness check-in and to update your progress in wellness challenges you have voluntarily joined. We only read this data; ZaaS never writes any data to Health Connect or Apple Health.
This data is stored in your ZaaS account alongside your other check-in data, is visible only to you, and is never sold, never shared with third parties, and never used for advertising or to build advertising profiles. Aggregated wellbeing insights shared with your Organization never include individual health readings, as described in Section 4.
You can revoke ZaaS’s access at any time in the Health Connect app (Android) or the Health app (iOS), and you can delete your ZaaS account and all associated data at any time from your profile page in the app, or by contacting support@zaas.com.

What we don’t collect for advertising. We do not embed third-party advertising trackers or ad network SDKs in the Service, and we do not collect information to build advertising profiles about you.

3. How We Use Your Information

Any data we collect,  including daily habits, step goals, and milestone achievements, is used solely to (a) provide the Service to you and (b) generate aggregate reporting for your Organization as described in Section 4. Specifically, we use your information to:

  • create and maintain your account and authenticate your access to your Organization’s workspace
  • deliver the core wellness features you interact with (habit tracking, goal-setting, milestone recognition, and similar program features)
  • generate aggregate, organization-level reporting for your Organization, subject to the protections in Section 4
  • maintain the security, integrity, and reliability of the Service
  • respond to your support requests and communicate with you about your account
  • comply with applicable legal obligations

We do not use your individual wellness activity data for any purpose unrelated to operating the Service and your Organization’s wellness program, and we do not use it to build advertising profiles.

4. The Aggregate HR Firewall: How We Share Information With Your Employer

We built the Service around a simple principle: your day-to-day wellness activity belongs to you. Here is exactly how that works:

  • Your individual data is confidential. Specific daily data points,  including individual habit entries, step counts on a given day, hydration logs, and individual milestone completions, are not disclosed to your Organization’s management, HR team, or any individual at your Organization; however, specific metrics are shown on an individual level during the duration of an active challenge that you opt in to. 
  • Your Organization sees aggregate metrics only. Your Organization receives aggregate, anonymized organizational metrics describing your workplace as a whole. For example, “80% of the Marketing department met their hydration goal this week.” We only generate a reported metric for a group once it includes a minimum of 5 participants, so that no individual’s activity can reasonably be inferred from it; we do not report on groups below that minimum size.
  • No individual disclosure without your explicit opt-in. Individual data is never disclosed to corporate management without your explicit opt-in consent. Where the Service offers optional features that let you choose to share your own progress with others at your Organization. For example, in an opt-in leaderboard or a tracked challenge, participation is always your choice.
  • The firewall applies regardless of seniority. Even Organization administrators using the Service’s reporting tools see aggregate figures, not individual entries, unless you have separately opted in to a specific shared feature.

5. Other Parties We Share Information With

We use a limited number of service providers to operate the Service. These providers process information on our behalf, are bound by confidentiality and data protection obligations, and are not permitted to use your information for their own advertising purposes or to combine it with data from other sources for unrelated purposes. Categories of service providers we use include:

  • Cloud hosting and application infrastructure
  • Database hosting and management
  • Transactional and account-related email delivery
  • Marketing email delivery (for communications you can opt out of at any time)
  • Error monitoring and service-reliability tooling
  • Security, abuse-prevention, and rate-limiting infrastructure

We may also disclose information where required by law, to protect the rights, property, or safety of ZaaS, our users, or others, or in connection with a merger, acquisition, or sale of assets, subject to the protections described in Section 13.

6. International Data Transfers

If you access the Service from outside the United States,  your information will be transferred to, stored, and processed in that location. 

7. Data Retention

We retain personal information for as long as your account and your Organization’s subscription to the Service remain active, and for a limited period afterward as needed to comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods by data category are available on request at support@zaas.com. You or your Organization may request deletion of your information at any time, as described in Section 9. Health Connect and Apple Health data is deleted along with the rest of your account data when you delete your account from your profile page in the app or request deletion at support@zaas.com. Revoking Health Connect permission stops all further reading of that data immediately.

8. How We Protect Your Information

  • Database-level access controls: Your individual data is protected using database-level security rules that keep each organization’s data separate from every other organization’s. This isolation is enforced by the database itself, not solely by application code.
  • Encryption in transit: Data is encrypted in transit using industry-standard TLS.
  • Restricted administrative access: Access to production systems is limited to authorized personnel and requires multi-factor authentication.
  • Ongoing security practice: Our security architecture and practices are described in greater technical detail in our Security Whitepaper, available upon request. 

No method of transmission or storage is completely secure. If we become aware of a security incident affecting your personal information, we will notify you and/or your Organization as required by applicable law.

9. Your Privacy Rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain uses of it. To exercise these rights, contact us as described in Section 14, or, where the Service is provided through your Organization, you may also be able to exercise certain rights through your Organization’s own administrative tools.

  • Right to access the personal information we hold about you
  • Right to correct inaccurate information
  • Right to request deletion of your information
  • Right to receive a copy of your information in a portable format
  • Right to object to or restrict certain processing

10. Additional Rights for California Residents

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), gives you additional rights, including the right to know what personal information we collect, the right to delete it, the right to correct it, and the right to opt out of the “sale” or “sharing” of personal information.

ZaaS does not sell or share personal information as those terms are defined under the CCPA.

Because wellness and health-related information is considered “sensitive personal information” under California law, you also have the right to limit our use of it to purposes necessary to provide the Service. We do not use sensitive personal information for any purpose beyond providing the Service and the aggregate reporting described in Section 4, so there is no additional use for you to limit.

11. Children’s Privacy

The Service is intended for use by working adults through their employer’s wellness program and is not directed to children. We do not knowingly collect personal information from individuals under 18 years of age. If we learn that we have inadvertently collected such information, we will take steps to delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the Service, by email, or by other means before the changes take effect. The “Last Updated” date at the top of this policy reflects the most recent revision.

13. Business Transfers

If ZaaS is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction. Any successor entity will remain bound by the commitments in this Privacy Policy, including the No Data Monetization commitment in Section 1, with respect to information collected under this policy, unless you are provided with prior notice and an opportunity to exercise any rights you may have under applicable law.

14. Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at:

Email: support@zaas.com

Mailing Address: ZaaS, Ferry Building, 1, Ste 201, San Francisco, CA 94111

Governing Law: California