Global Privacy Policy
This Policy explains how BROSH collects, uses, discloses, transfers, retains, and protects information across the Sites, CRM platform, applications, extensions, integrations, AI features, and related services.
1. Scope, Effective Date, and Acceptance
This Global Privacy Policy (the "Policy") applies to BROSH / ZAAPIT AS LTD corporation, including ZAAPIT AS LTD doing business as BROSH (collectively, "BROSH", the "Company", "ZaapIT", "ZAAPIT AS LTD", "we", "us", or "our"). We respect and protect the privacy of visitors to www.brosh.io, the other websites under the brosh.io domain (collectively, the "Sites"), and customers and users of our SaaS product, web design software, tools, applications, integrations, extensions, and related services (together with the Sites, the "Service").
This Policy is effective as of February 26, 2026. It explains how we collect, use, disclose, transfer, retain, and protect visitors' and users' information in connection with the Service. References to your use of the Service include visits to and interactions with the Sites and Services, whether or not you are a registered user of BROSH's SaaS product.
If you are a resident of the European Union, the European Economic Area, or Switzerland, please also read our EU and Swiss privacy information, including the privacy and security terms made available through BROSH's legal pages, for further information about our data collection practices and your rights. Capitalized terms not defined in this Policy have the meanings given to them in our Terms of Service.
By accessing or using the Service, you signify your acceptance of this Policy. If you do not agree with, or are not comfortable with, any aspect of this Policy, you should immediately discontinue access to and use of the Service.
2. Personal Information, Usage Data, and Aggregated Data
In this Policy, "Personal Information" means information, or an information set, that identifies or could reasonably be used to identify an individual directly or indirectly. Except as described in this Policy, BROSH will not give, sell, rent, or loan Personal Information to any third party.
"Usage Data" means encoded, anonymized, or aggregated information that we collect about a group or category of services, features, activity, or users and that does not contain personally identifying information. Usage Data helps us understand trends in use of the Service, consider new features, improve existing products, and tailor the Service.
In addition to collecting and using Usage Data ourselves, we may share Usage Data with third parties, including customers, partners, and service providers, for purposes such as understanding customer needs, improving the Service, advertising, and marketing, provided that the information is not shared in a personally identifying form.
3. Information You Provide and How We Use It
When you register for or use the Service, we may ask for Personal Information such as your name, email address, credit card information, or other billing information. You may also provide, at your discretion, related information such as your personal website name, social media websites, a list of skills, the date you started using the Service, and a description of yourself.
As you use the Sites or Service to create websites, records, pages, workflows, or other materials, the software may continuously save changes to our servers and may document activity such as when you are working, when you save changes, when you last opened the Designer, when sites are published, and when you perform certain tasks. We may retain the contents of messages you send to us or through the Service, and we may collect information you provide in user content that you post or upload to the Service ("User Content").
BROSH may use Personal Information to operate, improve, and personalize the Service; identify and authenticate users; process billing; communicate with you about the Service and your use of the Service; provide support; send marketing materials and research communications; conduct internal market research; analyze Site usage; troubleshoot problems; prevent fraud; enforce the Terms of Service; and improve the content and functionality of the Service.
We may combine Personal Information with third-party analytics information to build a broader profile of individual users, so that we can serve users better and provide more relevant, custom, and personalized content and information. We may also use Personal Information for identification, authentication, fraud prevention, internal analysis, troubleshooting, market research, enforcement, and any other purposes stated in this Policy.
BROSH will never email you to ask for your account information. If you receive an email that asks for account credentials or other sensitive account information, please forward it to support@brosh.io.
Financial information is used solely as authorized by you and in accordance with the Service. BROSH does not store your credit card information. Although BROSH uses commercially reasonable efforts to secure credit card information and other Personal Information, BROSH expressly disclaims liability for unauthorized access to or use of secure servers or any personal or financial information stored therein, and you agree to hold BROSH harmless for damages that may result from such unauthorized access or use to the maximum extent permitted by applicable law.
4. Information Received From and Shared With Third Parties
We may now or in the future receive Personal Information about you from third parties. For example, if you access the Site or Service through a third-party connection or login, or if you connect an application to BROSH, that third party may pass certain information about your use of its service to BROSH.
Information received from a third-party service may include, without limitation, the user ID associated with your account, an access token necessary to access that service, information you have permitted the third party to share with us, and information you have made public in connection with that third-party service. You should always review and, if necessary, adjust your privacy settings on third-party websites and services before linking or connecting them to the Service.
BROSH may share Personal Information with third-party service providers, such as credit card processors, hosting partners, infrastructure providers, security providers, analytics providers, and support providers, to provide the hardware, software, networking, storage, and other services we use to operate the Service and maintain a high-quality user experience. We do not permit those service providers to use Personal Information we share with them for their own marketing purposes.
5. Application Integrations and App Credentials
To facilitate the exchange of data between third-party SaaS applications and BROSH, we may need to store certain information that helps us access those third-party SaaS application accounts on your behalf ("App Credentials"). We store App Credentials in encrypted form.
When we access third-party applications on your behalf, those applications may provide us with access to certain data. We will use, store, and disclose that data in accordance with this Policy. BROSH has no liability or responsibility for the privacy practices or other actions of any third-party applications for which you provide App Credentials or otherwise authorize access.
6. Log Files, Cookies, Device Identifiers, and Other Sharing
We collect certain technical information from visitors to our customers' websites. Information logged by our web servers about visitors to Service customers' sites may include Internet Protocol (IP) address, the date and time a webpage or feature is accessed, the user agent string identifying the browser or operating system to the server, installed fonts, mime-types, browser language and timezone, Silverlight data, installed plugins, HTTP headers, and screen resolution.
BROSH uses this technical information to monitor the volume of customer website traffic, for analytical purposes, to measure how many customers have used the Service, to create new products, and to improve existing products.
We may be required to disclose Personal Information to respond to subpoenas, court orders, law enforcement requests, governmental requests, investigations, or to establish or exercise legal rights or defend against legal claims. We may also share Personal Information when we believe it is necessary to investigate, prevent, or take action regarding illegal activity, suspected fraud, potential threats to the physical safety of any person, violations of our Terms of Service, or as otherwise required by law.
We use or may use information collected by cookies, log files, device identifiers, and public records to remember information so that you do not have to re-enter it during your visit or the next visit; provide custom and personalized content and information; provide and monitor the effectiveness of the Service; monitor aggregate metrics; diagnose or fix technology problems; help you efficiently access information after signing in; provide advertising to your browser or device; and automatically update the BROSH application on your mobile devices.
For more information about cookies, please see BROSH's Cookie Policy. We may share Personal Information with any member of the BROSH team, including any entity that controls, is controlled by, or is under common control with BROSH.
7. Links to Other Websites and Applications
The Service contains links to websites and applications other than the Service, including websites and applications operated by affiliates and other third parties. This Policy applies only to information collected by the Service.
BROSH does not endorse and is not responsible for the practices of third parties or their websites or applications. We do not determine and are not responsible for the privacy practices or the content of websites or applications operated by third parties. Your browsing and interaction on any third-party website or service, including any third-party service linked from our website, are subject to that third party's own rules and policies.
We are not responsible for and do not control any third parties that you authorize to access your User Content. If you use a third-party website or service and allow that third party to access your User Content, you do so at your own risk.
8. Public Forums and Public Areas
The Service may offer publicly accessible blogs, community forums, landing pages, web pages, or other public areas. If you elect to post something in a public area of the Service, any Personal Information or content that you voluntarily disclose for posting to the Service becomes available to the public, subject to any applicable privacy settings.
If you remove information that you posted to the Service, copies may remain viewable in cached or archived pages of the Service, or may remain available if other users have copied or saved that information. To request removal of Personal Information from our blog or community forum, contact us at support@brosh.io. In some cases, we may not be able to remove all Personal Information.
9. Customer Testimonials, Comments, and Reviews
From time to time, we may post customer testimonials, comments, or reviews on the Sites, and those materials may contain Personal Information. We obtain the customer's consent before posting the customer's name together with a testimonial. Please read our Terms and Conditions for more information.
10. Protection and Security of Information
BROSH is committed to protecting Personal Information. We use commercially reasonable technological, physical, and administrative security safeguards, including firewalls and carefully developed security features, to protect the confidentiality and security of Personal Information within the Service and Sites.
When you enter confidential information, such as login credentials or information submitted from within the Service, we encrypt the transmission of that information using secure socket layer technology (SSL). These technologies, procedures, and measures are used in an effort to ensure that data is safe, secure, and available only to you and to persons you authorize to access your data.
No internet, email, or other electronic transmission is ever fully secure or error-free. You should take care when deciding what information to send to us by electronic means. BROSH is not responsible for the functionality or security measures of any third party. Please read our Terms and Conditions for more information.
11. Hosting and Data Transfer
BROSH is based in Israel. Unless we expressly agree otherwise, including through our Terms, we may host, transfer, and process data, including Personal Information, in the United States, the United Kingdom, Israel, Germany, and other countries through BROSH and third parties that we use to operate and manage the Service. These countries may have data protection laws different from those of your country of residence.
BROSH uses a variety of safeguards, including contractual and technical measures, to protect data that we transfer. BROSH uses the country information you share with us during sign-up to choose the appropriate datacenter in order to comply with applicable local privacy law. If your company is based in the United Kingdom ("UK"), the European Union ("EU"), the European Economic Area ("EEA"), or Switzerland, BROSH will store your Personal Information in an EU country or in the UK.
Only the minimum necessary financially related information required by Israeli law, such as invoices and receipts, will be copied to a secured datacenter in Israel.
12. Choice, Cookies, and Advertising Opt-Outs
We process and store information on behalf of our customers. You may decline to submit Personal Information through the Service; however, if you do so, we may not be able to provide certain services to you.
Please refer to your mobile device or browser technical information for instructions on how to delete and disable cookies and other tracking or recording tools. Disabling cookies on your mobile device or browser may prevent us or our business partners from tracking browser activity in relation to the Service, but doing so may also disable many features available through the Service.
You may opt out individually from third-party vendors on their websites, but limitations on data sharing may make it difficult or impossible to provide the Service after an opt-out. You may also opt out of interest-based advertising provided by participating ad servers through the Digital Advertising Alliance at http://optout.aboutads.info/, the Network Advertising Initiative at http://optout.networkadvertising.org/?c=1, or the European Interactive Digital Advertising Alliance at http://www.youronlinechoices.eu.
California consumers may use the Digital Advertising Alliance tool to send requests under the California Consumer Privacy Act ("CCPA") for a web browser to opt out of the sale of personal information by some or all participating companies by visiting https://www.privacyrights.info/, or by downloading the DAA AppChoices mobile application opt-out at https://www.privacyrights.info/appchoices. The AppChoices app is not limited to CCPA opt-outs and may be used by anyone to limit collection of cross-app data for interest-based advertising by participating DAA member companies.
13. Correcting and Updating Your Information
Customers may update, delete, or change Personal Information provided to BROSH by logging in to the Service and providing additional information or deleting information where applicable. If you are not our customer and would like to gain access to, or request deletion of, information we have collected, please contact us at support@brosh.io. We will use commercially reasonable efforts to respond within a reasonable time.
BROSH has no direct relationship with the individuals or companies ("End Users") with whom our customers may interact using the Service. Any End User seeking access to, or seeking to correct, amend, or delete data that may be stored in the Service should direct the request to the applicable BROSH customer acting as the data controller for that information.
14. Data Retention
BROSH will retain Personal Information that we process on behalf of customers or collect directly from customers for as long as needed to provide the Service to our customers, subject to our compliance with this Policy, or as required or permitted under applicable law.
We may further retain and use Personal Information as necessary to comply with legal obligations; maintain accurate accounting, financial, and operational records; resolve disputes; and enforce our agreements. We have established internal policies for deletion of data from customer accounts following termination of a customer subscription to the Service.
15. Children's Personal Information
BROSH does not knowingly collect Personal Information from children under the age of 13. If you are under the age of 13, please do not submit Personal Information through the Service.
We encourage parents and legal guardians to monitor their children's internet usage and to help enforce this Policy by instructing children never to provide Personal Information through the Service without permission. If you have reason to believe that a child under the age of 13 has provided Personal Information to BROSH through the Service, please contact us, and we will use commercially reasonable efforts to delete that information from our databases.
16. California Privacy Rights
This section applies only to California residents. Pursuant to the California Consumer Privacy Act of 2018 ("CCPA"), this section summarizes the categories of Personal Information, as identified and defined by the CCPA, that we collect, the reasons we collect Personal Information, where we obtain Personal Information, and the third parties with whom we may share Personal Information.
When you use the Site or Service, we generally collect identifiers such as name, address, unique personal identifier, email, phone number, device IP address, software identifiers, and identification numbers associated with devices; protected classifications such as gender; commercial information such as records of products or services purchased, obtained, or considered; internet or other electronic network activity information, including browsing history, the webpage visited before coming to our Site, length of visit, number of page views, click-stream data, locale preferences, mobile carrier, transaction date and time stamps, and system configuration information; audio recordings of your voice to the extent you call us and as permitted by applicable law; and professional or employment-related information.
We generally do not collect education-related information, biometric information, geolocation information, or inferences about preferences, characteristics, behavior, or attitudes. For more information about the Personal Information we collect and how we collect it, please refer to Sections 2 through 6 of this Policy. We collect Personal Information for the business purposes described in this Policy, including Section 3. The CCPA defines a "business purpose" as use of Personal Information for operational purposes or other notified purposes, provided that the use is reasonably necessary and proportionate to achieve the operational purpose for which the Personal Information was collected or another compatible operational purpose. The categories of third parties with whom we may share Personal Information are described in this Policy, including Sections 4 through 6.
If you are a California resident, you have rights in relation to your Personal Information, subject to certain exceptions. For example, we cannot disclose specific pieces of Personal Information if disclosure would create a substantial, articulable, and unreasonable risk to the security of the Personal Information, your account with us, or our network systems.
- Right against discrimination. You have the right not to be discriminated against for exercising the rights described in this section. We will not discriminate against you for exercising your right to know, delete, or opt out of sales.
- Right to know. You have the right to request in writing a list of categories of personal information, such as name, address, and email address, that a business has disclosed to third parties during the immediately preceding calendar year for those third parties' direct marketing purposes, and the names and addresses of those third parties. You also have the right to request the categories of personal information collected about you, the categories of sources from which personal information is collected, the business or commercial purpose for collection, the categories of third parties with whom we have shared personal information, and the specific pieces of personal information we hold about you. You may request a copy of the specific Personal Information collected about you during the 12 months before your request.
- Right to delete. You have the right to request that we delete Personal Information we have collected from you or maintain about you, subject to certain exceptions.
- Right to opt out of selling. As described in this Policy, in certain situations we may share Personal Information with third parties for marketing or other purposes. To the extent that sharing is considered a "sale" under the CCPA, California residents have the right to opt out of such sharing. If you would like us to no longer share Personal Information in this way, you may opt out through our Do Not Sell My Info page or by contacting us. If you opt out, we may be unable to offer some Services that require sharing Personal Information.
To assert your right to know or your right to delete Personal Information, please contact us as described in the "Contact Us" section below. To verify your identity, we may ask you to verify Personal Information already on file. If we cannot verify your identity from information on file, we may request additional information, which we will use only to verify identity and for security or fraud-prevention purposes.
California consumers may also use the Digital Advertising Alliance tool at https://www.privacyrights.info/, or the DAA AppChoices mobile application at https://www.privacyrights.info/appchoices, to send CCPA browser opt-out requests or to limit collection of cross-app data for interest-based advertising by participating DAA member companies.
In addition, under California Civil Code Sections 1798.83-1798.84, California residents may ask us for a notice identifying the categories of Personal Information we share with affiliates or third parties for marketing purposes and providing contact information for those affiliates or third parties. If you are a California resident and would like a copy of this notice, please submit a written request to support@brosh.io or by mail.
17. Processing of Personal Information Under Israeli Law
If you are located in Israel, or if BROSH processes personal information of individuals in Israel, we comply with the requirements of the Israeli Privacy Protection Law, 5741-1981, including Amendment No. 13 (2024) and applicable regulations issued by the Israeli Privacy Protection Authority ("PPA").
For purposes of Israeli privacy law, the data controller and/or database owner is ZAAPIT AS Ltd (trading as BROSH), with offices located at 87 Weizmann St., Kfar Saba 4464213, Israel. You may contact our Privacy Protection Officer / Data Protection Officer at support+privacy@brosh.io or by mail at 87 Weizmann St., Kfar Saba 4464213, Israel.
We collect and process personal information for the purposes described in this Policy, including provision of software services, user account management, support, and service improvement. When processing information subject to Israeli law, we rely on one or more lawful bases permitted by Israeli privacy law, including consent of the data subject, fulfillment of contractual obligations, compliance with legal requirements, or legitimate business interests consistent with privacy rights.
Under Israeli law, individuals whose data is processed by BROSH have the right to access personal data held about them in BROSH databases; request correction, deletion, or blocking of personal data that is inaccurate, incomplete, unclear, or outdated; withdraw consent to processing where consent is the legal basis; and receive information about the purpose of processing, the types of data held, and to whom data has been disclosed. Requests may be submitted to our Privacy Protection Officer using the contact details above, and BROSH will respond in accordance with the timelines and procedures required by Israeli privacy law.
If BROSH maintains a database that includes sensitive personal information, such as health, biometric, genetic, religious, or financial data, or that exceeds thresholds defined by the Privacy Protection Authority, BROSH will comply with applicable registration or notification obligations under Amendment No. 13 and maintain appropriate technical and organizational security measures to safeguard that data.
Where personal information is transferred outside Israel, BROSH ensures that the receiving country provides an adequate level of protection required under Israeli law, or that appropriate contractual or organizational safeguards are in place to protect the data. Such transfers are performed only for the purposes described in this Policy and in accordance with applicable Israeli data-protection requirements.
BROSH applies strict data security controls designed to protect personal information against unauthorized access, loss, or misuse. In the event of a personal data breach involving Israeli data subjects, BROSH will assess whether notification to the Israeli Privacy Protection Authority and affected individuals is required under applicable law and will act accordingly.
18. AI Features and AI Processing
BROSH may provide optional artificial intelligence ("AI") features designed to assist users in analyzing information, generating content, automating workflows, or producing recommendations within the Service. When a user actively initiates an AI request within the Service, BROSH may transmit certain information from the user's current workspace to an external AI processing service selected by the user or configured within the Service.
Depending on the user's actions and the content visible at the time of the request, information transmitted for AI processing may include CRM records and structured data entered by the user; contact details, notes, activities, and communications stored in the workspace; files or attachments displayed in the current interface; and prompts, instructions, or questions submitted by the user. Such information is transmitted solely for the purpose of generating the requested AI output and is not transmitted in the absence of a user-initiated AI action.
AI processing may be provided through third-party cloud-based AI services, which may include, depending on configuration or user selection, OpenAI, Microsoft Azure AI Services, Google Cloud AI Services, Amazon Web Services AI Services, and Anthropic. These providers process data on BROSH's behalf solely to generate AI responses and return results to the user. BROSH does not use AI providers to sell user data or build advertising profiles. Data transmitted for AI processing is used only to provide the requested AI functionality within the Service.
Users remain responsible for ensuring that information they choose to submit to AI features complies with applicable data protection laws and their own organizational policies. Where required by applicable law, BROSH will obtain user consent before transmitting data to third-party AI processing services.
19. Changes to This Policy
We may, in our sole discretion, modify or update this Policy from time to time. If we make material changes to this Policy, we will endeavor to notify you by email or by posting a prominent notice on the Sites before the change becomes effective. We encourage you to review this page periodically for the latest information about our privacy practices.
Your continued use of the Service constitutes acceptance of changes to this Policy. If you do not accept the terms of this Policy, you should immediately discontinue use of the Service.
20. Business Transactions
BROSH may assign or transfer this Policy, and your user account and related Personal Information, to any person or entity that acquires all or substantially all of the business, stock, or assets of BROSH, or that is merged with BROSH. We may also transfer or assign such information in connection with corporate divestitures, mergers, acquisitions, bankruptcies, dissolutions, or similar transactions or proceedings, provided that the recipient of the information will continue to be bound by this Policy.
21. LinkedIn and Gmail Extension
When you use the BROSH LinkedIn and Gmail extension, BROSH may collect usage information. Such information is kept inside your BROSH account, and you have control over that data. Your BROSH user, and potentially other users from your company who use BROSH, may have access to that saved personal information.
If needed, you can delete personal information and disable that sync. Saved personal information is stored under your account, specifically under the following objects: contacts, accounts, and activities.
22. Contact Us
If you have questions regarding this Policy or the privacy practices of BROSH, please contact us by email at support@brosh.io, or by mail at ZAAPIT AS Ltd (trading as BROSH), 87 Weizmann St., Kfar Saba 4464213, Israel.
