Trust starts with privacy.

    Effective date
    September 4, 2026

    Last updated
    September 4, 2026

    How Carigar handles personal information.

    Carigar builds AI back-offices for small and medium-sized businesses. This policy explains how we collect, use, store, disclose, and protect personal information across our website, application, integrations, communications, and related services.

    Carigar is operated by Zurons, Inc. (“Carigar,” “we,” “us,” “our,” or the “Company”). The Services help businesses manage sales, inventory, finances, HR and payroll, surveillance, employee performance, customer retention, questions through our Ask feature, and other support and operational workflows.

    What This Policy Covers

    “Personal information” means information that identifies, relates to, describes, or can reasonably be linked to an individual or household, as defined by applicable law. Business records can contain personal information even when they belong to a business.

    This policy covers information about website visitors, prospective customers, business customers, authorized users, and people whose information businesses provide through the Services, including employees, contractors, customers, and store visitors.

    Information we manage for our own business. We generally determine how personal information is used for account administration, billing, website operations, security, and our own business communications. Applicable laws may describe us as a controller or business for these activities.

    Information we process for business customers. When a business connects its software, financial accounts, cameras, or other systems, we generally process the resulting information on that business’s behalf and according to its instructions and our agreement. Applicable laws may describe us as a processor or service provider for these activities. We refer to this information as “Customer Data.” The business generally determines which systems are connected, which workflows are enabled, and who may access resulting information.

    If your employer or a business you visit uses Carigar, that business’s privacy notices also apply. Requests about its employee, transaction, or surveillance records should generally be directed to that business. We assist with those requests as required by law and our agreements.

    This policy does not replace required workplace notices, recording notices, consents, or agreements. It also does not govern third-party services that independently collect or use information under their own policies.

    Personal Information We Collect

    The information processed depends on the Services used, connected systems, permissions granted, and information provided. Not every category is collected for every customer or individual.

    CategoryExamplesMain purposes
    Account and contact informationNames, work email addresses, phone numbers, business names, locations, roles, account identifiers, login credentials, and communication preferencesAccount setup, access administration, customer support, and business communications
    Sales and customer recordsTransactions, purchases, returns, receipts, customer contact details, service history, commissions, rebates, and payment statusSales reporting, reconciliation, commission tracking, customer support, and authorized retention workflows
    Inventory and supplier recordsProduct identifiers, stock levels, device serial numbers, inventory movements, purchase orders, and supplier contactsInventory management, discrepancy detection, purchasing support, and operational reporting
    Financial and banking informationAccount holder details, institution names, identifiers, balances, transaction descriptions, deposits, withdrawals, expenses, invoices, and accounting recordsBank reconciliation, expense categorization, cash-flow analysis, financial reporting, and authorized finance workflows
    HR, payroll, and employment informationNames, contact details, roles, schedules, attendance, hours, compensation, commissions, performance records, and required tax or direct-deposit detailsHR administration, payroll support, compensation calculations, and workforce reporting
    Surveillance and audio informationLive camera feeds, recorded video, still images, timestamps, camera or store identifiers, and audio or transcripts where enabled and lawfully providedActivity review, incident reporting, interaction summaries, service evaluation, and operational support
    Derived observations and reportsEstimated walk-ins, conversion rates, interaction summaries, activity classifications, performance observations, forecasts, and discrepancy alertsBusiness reporting, workflow support, and responses to customer questions
    Messages, files, and Ask contentPrompts, questions, uploaded documents, connected messages, support conversations, generated answers, and feedbackAnswering questions, retrieving records, completing authorized tasks, and support
    Integration and access informationAuthorization tokens, connection identifiers, permissions, connection status, and non-banking credentials required by supported integrationsConnecting systems, maintaining authorized access, and troubleshooting
    Subscription and billing informationBilling contact details, billing address, invoices, payment status, and payment method information received from a payment processorCollecting payment and administering subscriptions
    Device and usage informationIP addresses, browser and device information, pages or features used, timestamps, diagnostic records, and security logsOperating, protecting, troubleshooting, and improving the Services

    Certain financial, government identifier, communication, and other information may be sensitive personal information under applicable law. We process it only for the relevant authorized purposes and subject to applicable requirements.

    Where Information Comes From

    We collect information:

    • Directly from you, when you create an account, contact us, submit a question, upload information, or use the Services.
    • From business customers and their authorized users, including records about their employees, contractors, customers, and operations.
    • From connected systems, such as point-of-sale software, inventory platforms, accounting software, payroll systems, banking data providers, surveillance systems, and communication tools, according to the connection’s permissions.
    • Automatically through the Services, including technical logs and the cookies described below.
    • From service providers and business contacts, such as payment processors, support providers, and people who refer prospective customers to us.

    We may combine information from authorized sources to support a customer’s workflows—for example, matching bank deposits with sales records or comparing transaction counts with estimated store visits.

    How We Use Information

    We use personal information only for the purposes described in this policy, as necessary to:

    • Provide and administer the Services, accounts, subscriptions, integrations, and linked financial accounts.
    • Process sales and inventory records, reconcile financial information, and prepare reports.
    • Support authorized HR, payroll, commission, and workforce workflows.
    • Review connected surveillance information and produce activity summaries, alerts, and operational observations.
    • Support customer retention and follow-up communications requested by business customers.
    • Answer questions through Ask using information accessible to the requesting user.
    • Carry out authorized operational tasks and provide implementation, troubleshooting, and customer support.
    • Evaluate service quality, identify errors, maintain reliability, and develop improvements consistent with the AI and Customer Data limits below.
    • Protect accounts, investigate suspicious activity, prevent misuse, and maintain audit records.
    • Communicate with you about your account and the Services.
    • Comply with legal obligations, enforce agreements, and resolve disputes.

    We do not treat access to Customer Data as permission to use it for unrelated purposes. Where required, we provide additional notice and obtain consent before processing information for a materially different purpose.

    Connected Software and Banking Tools

    Connecting a system allows Carigar to access information within the permissions granted through that integration. Depending on the connection, access may be ongoing until revoked. Some workflows may also allow Carigar to create or update records in connected systems when authorized by the customer.

    Banking connections may provide transaction records, balances, account identifiers, and other information needed for enabled financial workflows. Connecting an account for data access does not, by itself, authorize Carigar to initiate payments or move money. Any such capability requires separate supported functionality and appropriate authorization.

    Carigar uses Plaid Inc. (“Plaid”) to connect your bank account. When you link an account, you provide consent through Plaid’s secure connection flow. We receive account details, balances, and transactions only with your consent and within the permissions granted. Plaid processes information under its End User Privacy Policy. We never see or store your bank login credentials.

    You may withdraw consent and unlink your bank account at any time by contacting info@carigar.ai or using available integration controls. You may also be able to revoke access through the connected provider. Revocation stops future access through that connection but does not automatically delete information already obtained. Previously collected information remains subject to the retention and deletion provisions below.

    Connected providers’ own collection, retention, and use of information are governed by their policies and agreements.

    AI Processing and Human Review

    Carigar uses AI to analyze records, classify activity, summarize information, answer questions, draft communications, and support authorized tasks. This may involve sending relevant inputs and context to third-party AI providers that help deliver the Services. Generated outputs may contain personal information from the underlying records or inferences about individuals.

    Authorized Carigar personnel and service providers may review relevant Customer Data, including records, footage, transcripts, and AI outputs, to provide operational support, check accuracy, troubleshoot, investigate incidents, and fulfill customer instructions. Access is restricted to personnel who need the information to operate the Services, protected by multi-factor authentication and appropriate confidentiality obligations.

    AI outputs can be inaccurate or incomplete. Activity labels, employee observations, customer counts, and similar outputs are estimates or assessments rather than conclusive facts. Customers should verify underlying information before relying on an output, particularly for payroll, disciplinary, employment, or other significant decisions.

    Surveillance, Audio, and Employee Performance

    When a business enables surveillance features, Carigar may process images, video, and, where enabled, audio from connected locations. The information may include employees, customers, visitors, and people incidentally captured in the monitored area.

    Depending on the enabled features, we may generate summaries and observations about visits, customer interactions, service quality, attendance, store activity, and employee performance. These results may be combined with other authorized business records to produce operational reports.

    The business is responsible for establishing a lawful basis for its monitoring, providing required notices, obtaining any necessary consent, and configuring monitoring appropriately. This includes requirements concerning employees, audio recording, and areas where people reasonably expect privacy. Carigar remains responsible for its own applicable obligations.

    This general policy is not a substitute for signs at monitored locations or workplace-specific notices. Viewing this policy or entering a location does not, by itself, establish consent to audio recording or other processing that requires specific consent.

    Customer Retention and Communications

    Business customers may use Carigar to organize contact records, draft or send messages, and support customer follow-up through enabled channels such as email, text messages, or calls.

    For these workflows, we process contact details, communication content, delivery information, responses, and consent or opt-out records as needed to carry out the business’s instructions. Businesses are responsible for the lawfulness of their contact lists and campaigns and for obtaining required permissions. Carigar remains responsible for obligations applicable to its own activities.

    Recipients may unsubscribe or opt out using the instructions in a message or by contacting the sending business. Where supported, text recipients can reply STOP. Businesses and Carigar may retain limited suppression records to help prevent further unwanted marketing.

    Carigar also sends necessary account, security, billing, and service notices. These are separate from customer retention communications sent on a business customer’s behalf.

    How We Disclose Information

    We disclose information only as needed to operate the Services for you and our business customers, as directed by an authorized customer, or as required by law. Recipients are limited to the following categories, as relevant to their role:

    • The business customer and its authorized users. Administrators and users may access information and reports according to their assigned permissions.
    • Service providers. Providers such as Plaid, cloud hosting providers, and providers of storage, AI processing, security, infrastructure, communications, support, operations, and billing may process only the information needed for their services under contracts that protect your data.
    • Customer-directed integrations and recipients. We may transmit relevant records, reports, or messages to connected systems and recipients designated by the customer.
    • Legally required recipients. We disclose information to authorities, courts, or other parties when required by applicable law or legal process.

    We do not sell your personal or financial data. We do not share your information with third parties for advertising, including cross-context behavioral advertising, or for their independent marketing.

    Cookies and Similar Technologies

    We use cookies and similar technologies as needed for authentication, maintaining sessions, remembering preferences, and protecting the Services. If enabled, analytics technologies help us understand usage and service performance.

    You may manage cookies through your browser. Disabling necessary cookies may affect functionality. Where required by law, we request consent before using nonessential technologies.

    We honor legally required opt-out preference signals, including Global Privacy Control where applicable to our processing. Traditional browser Do Not Track signals are distinct from these legally recognized signals.

    Security

    We maintain administrative, technical, and organizational measures designed to protect personal information against unauthorized access, use, alteration, loss, and disclosure. Our protections include:

    • Encryption of all data in transit using TLS 1.2 or higher and encryption at rest.
    • Access restricted to personnel who need the data to operate the Services, protected by multi-factor authentication.
    • Secure, certified cloud infrastructure.
    • Security monitoring, logging, and an incident response process.

    No method of transmission or storage is completely secure. Customers and authorized users should protect their credentials, assign appropriate permissions, and promptly report suspected unauthorized access. We provide security incident notifications as required by applicable law and our agreements.

    Data Retention and Deletion

    We keep personal information while your account is active and only for as long as needed to provide the Services, subject to the limited retention periods and legal exceptions below. An active account does not mean every record must be kept for the life of the account.

    If you close your account or ask us to delete your data, we delete the applicable information from our production systems within 30 days, except where the law requires us to keep certain records. Where we process information for a business customer, deletion requests are handled with that customer as described in Section 14.

    InformationRetention and deletion
    Account and service recordsOnly as needed to provide the Services while the account is active; deleted from production systems within 30 days of account closure or a deletion request, except legally required records.
    Security logsKept for 90 days and then deleted; earlier deletion follows the 30-day commitment unless retention is legally required.
    Raw media, transcripts, reports, and Ask contentSubject to the same necessity and 30-day production deletion limits.
    Records required by lawRetained for the legally required period and deleted when that requirement ends.

    Backup copies may remain until scheduled expiry and remain protected and restricted from ordinary use.

    Unlinking a bank account or another integration stops future access through that connection but does not by itself delete previously collected information. You can separately request deletion by emailing info@carigar.ai. Carigar cannot delete records that a third-party provider independently retains outside our control; that provider’s privacy policy and rights procedures apply.

    Aggregated and De-Identified Information

    We may use aggregated or de-identified information to understand service performance and improve the Services, where permitted by our customer agreements and applicable law. Such information must not reasonably identify an individual. We maintain required safeguards and do not attempt to re-identify information except as permitted by law to assess the effectiveness of de-identification.

    This section does not authorize disclosure of identifiable or confidential customer records.

    Your Privacy Rights and Choices

    Depending on where you live, the laws applicable to Carigar—including the CCPA and GDPR where applicable—and our role in processing the information, you may have rights to:

    • Know whether we process your personal information and access or obtain a copy of it.
    • Correct inaccurate personal information.
    • Request deletion, subject to applicable exceptions.
    • Obtain information in a portable format where applicable.
    • Opt out of a sale, cross-context behavioral advertising, targeted advertising, or certain profiling where those activities occur and the right applies.
    • Limit certain uses or disclosures of sensitive personal information where applicable.
    • Withdraw consent or object to or restrict certain processing where applicable.
    • Appeal a denied request where provided by law.
    • Exercise applicable rights without unlawful discrimination or retaliation.

    To submit a request, email info@carigar.ai. We may need to verify your identity and authority using information proportionate to the request. Where permitted by law, an authorized agent may act on your behalf, subject to verification of authorization.

    We verify and respond to privacy requests within 30 days, or sooner where required by applicable law. We explain any refusal and any further steps needed to address the request. To appeal a decision where an appeal right applies, email the same address and identify your original request. You may also contact the relevant privacy regulator or attorney general.

    If your request concerns information we process for a business customer, we may refer the request to that business and assist it in responding. If you do not know which business is responsible, contact us with enough context to help identify the relevant account or location.

    California residents. If the California Consumer Privacy Act applies to our processing, the applicable rights above include rights to know, delete, correct, and opt out of sale or sharing, and the right to limit qualifying uses of sensitive personal information. The categories, sources, purposes, and recipients are described in Sections 2–9.

    International Processing

    Personal information may be processed in the United States and in other countries where Carigar’s authorized personnel and service providers operate. Laws in those countries may differ from the laws where you live.

    Where applicable law requires safeguards for international transfers, we use legally recognized safeguards appropriate to the transfer.

    Children’s Information

    Carigar’s Services are intended for business users aged 18 or older. We do not knowingly collect personal information directly from minors registering for or using the Services. Anyone under 18 should not create an account or submit personal information directly to Carigar.

    Business-provided records or surveillance feeds may incidentally include minors, such as children accompanying customers at a store. We process such information only within the applicable business workflow and subject to relevant legal requirements. This differs from a child directly registering for the Services.

    If you believe a child has directly provided information to Carigar improperly, contact info@carigar.ai so we can investigate and delete information collected improperly or take other appropriate action.

    Changes to This Policy

    We may update this policy as the Services or our practices change. We will publish the updated version with a revised date. If we make material changes, we will notify you in the app or by email.

    Continued use of the Services after an update means you acknowledge the updated policy. Where a change requires consent, we will obtain it before applying the change; continued use alone does not supply that consent. Posting an updated policy does not itself authorize retroactive uses of previously collected information that require additional permission.

    Contact Us

    For questions about this policy or to submit a privacy request:

    Legal entity
    Zurons, Inc., operating Carigar
    Website
    carigar.ai
    Privacy email
    info@carigar.ai
    Mailing address
    131 Continental Dr, Suite 305, Newark, DE 19713