Privacy Policy for ZebisTech
Zebis Inc. (“Zebis,” “we,” “us,” or “our”) provides the ZebisTech Android application (“ZebisTech” or the “App”) for authorized Zebis employees and technicians. This Privacy Policy explains how the App accesses, collects, uses, stores, protects, retains, and shares information.
1. Information We Access or Collect
Employee account and authentication information
When you sign in, the App and Firebase Authentication may process:
- Your authorized Zebis employee email address;
- If you choose Google Sign-In, your selected Google account email address, account-provider identifier, authentication token, available first and last name, and available profile-photo URL or image;
- Your Firebase user identifier, linked authentication providers, and email-verification status;
- Your authentication credentials; and
- IP address, device platform, and user-agent information used for authentication security and abuse prevention.
Passwords are processed by Firebase Authentication and are not visible to Zebis in readable form. The App does not offer public account registration; employee access is restricted to accounts authorized by Zebis. A Google account that is not already associated with an authorized employee account must be linked by signing in with that employee account's existing email address and password. When available, the App uses the Google account's first and last name to fill blank local employee profile fields. While you are signed in, the App may load your available Google profile photo for display on the Employee Info button. Normal image loading may temporarily cache the photo.
Employee profile information
You may enter your:
- First and last name;
- Company or department information; and
- Telephone number.
This profile information is stored locally on your device and may be included in a support ticket that you choose to submit.
Support tickets, attachments, and diagnostic information
When you prepare and send a support ticket, the App may access and transmit:
- Your name, company or department, telephone number, employee email address, and Firebase user ID;
- The ticket subject, description, and other content you enter;
- Photos you explicitly take or select as optional ticket attachments, including the image contents, file name, media type, and file size;
- App version, device manufacturer, model, product or assigned device name, Android version, SDK version, and security-patch information;
- Available storage, battery status and level, sound mode and volume settings, Bluetooth state, SIM and carrier state, airplane-mode state, and developer or debugging settings;
- Network status and technical network information, including Wi-Fi network name, IP addresses, DNS addresses, connection type, and reported link speed;
- A list of launchable applications installed on the device;
- Approximate and precise location, including city, latitude, longitude, and a map link, only when you grant location permission; and
- The date, time, and time zone associated with the request.
We use this information to identify the employee requesting assistance, diagnose technical problems, provide support, respond to tickets, and maintain support and security records.
Location access is optional. If you decline location permission, you can still prepare and send a ticket without location information. You can also review and edit the ticket description before transmission.
Photo attachments are optional and are available on supported non-TV devices. The App opens the device camera or Android photo picker only after you select the corresponding option and receives only the photos you take or choose for the ticket. A photo captured through the App is temporarily stored in the App's private cache so it can be attached. A selected library photo remains with its existing Android content provider and is read only as needed to prepare and transmit the attachment. Selected attachments are uploaded to a private, employee-specific temporary location in Firebase Cloud Storage. The Zebis support-ticket service retrieves them for email delivery, and both the App and service attempt to delete the temporary cloud copies after the request is processed.
Usage, analytics, and diagnostic information
Google Analytics for Firebase may automatically collect:
- App launches, screen views, and interactions with App features and buttons;
- Notification and in-app-message delivery or interaction events;
- App version and installation source;
- Device category, model, operating-system version, language, and general geographic information;
- Firebase installation identifiers and related device or app identifiers; and
- Diagnostic and performance information made available by Firebase services.
We use this information to understand App usage, evaluate feature reliability, maintain security, and improve the App. We do not use it for third-party advertising.
Notifications, voicemail relay, messages, and remote configuration
Firebase Cloud Messaging, Firebase In-App Messaging, Firebase Remote Config, and the Zebis voicemail-notification relay may process:
- Firebase installation identifiers;
- Push-notification registration tokens;
- A random App installation identifier generated and stored by ZebisTech;
- App version and device metadata;
- A Firebase authentication token used to verify authorized requests to the Zebis relay;
- Notification titles and message bodies, alert type and identifier, and whether a mark-heard action is available;
- Requests to register the device, send a test notification, create a temporary pairing code, or submit a mark-heard action;
- Message-delivery and interaction events; and
- Configuration-request information.
We use these services to deliver employee notices, support information, outage or maintenance alerts, required-update notices, unheard-voicemail alerts, and remotely configured App content. When an authorized employee signs in, the App registers the device with the Zebis relay so notifications can be directed to that installation. An employee may also create a one-time pairing code for the configured voicemail checker, request a test notification, or submit a mark-heard instruction from an eligible alert. The App does not access or transmit voicemail audio through these features.
Remote Screen Share queue, viewing, and pointer guidance
Authorized technicians can view a queue of member-initiated Remote Screen Share sessions and accept one of those sessions. The queue and session service may process:
- The member's available display name, Firebase user identifier, and device manufacturer and model;
- The technician's Firebase user identifier;
- Random room and session identifiers;
- Session creation, expiration, heartbeat, assignment, and status information;
- The live screen video the member has chosen to share; and
- Normalized screen coordinates when the technician taps the viewer to display a pointing hand on the member device.
Screen video and pointer coordinates are transported in real time through LiveKit Cloud using WebRTC. A shared member screen may display account information, notifications, content from other apps, or other personal or sensitive information. Technicians must access it only for the authorized support purpose.
This feature is not configured to record or export the member's screen. ZebisTech does not publish microphone audio or camera video in the session. A technician's tap produces a temporary visual marker only; the App cannot tap, type, or otherwise remotely control the member device. When the member grants Android's “Display over other apps” permission, the member device also shows a small movable “Screen sharing” control with a pulsing red status square and a Stop action for the duration of the session. The indicator does not mean that screen video is being recorded.
2. How We Use Information
We use information described in this policy to:
- Authenticate authorized Zebis employees and technicians;
- Display the signed-in user's available Google profile photo on the Employee Info button;
- Prevent fraud, abuse, and unauthorized access;
- Provide, operate, maintain, and improve ZebisTech;
- Receive, investigate, and respond to support tickets;
- Transmit photos that an employee voluntarily attaches to a support ticket;
- Diagnose device, application, network, and configuration problems;
- Deliver operational notifications and employee announcements;
- Register authorized devices for voicemail alerts and process test, pairing, and mark-heard requests;
- Display and manage member-initiated Remote Screen Share sessions;
- Transmit the member-authorized live screen view to the assigned technician; and
- Send optional visual pointer guidance to the member device;
- Measure App usage and feature performance;
- Protect the security and integrity of Zebis systems; and
- Meet legal, regulatory, accounting, employment, or contractual obligations.
Zebis does not sell personal or sensitive user information. The App does not contain third-party advertising.
3. When Information Is Shared
Google and Firebase
We use Google Sign-In, Android Credential Manager, Firebase Authentication, Google Analytics for Firebase, Firebase Cloud Messaging, Firebase In-App Messaging, and Firebase Remote Config. Google processes information to provide account selection, authentication, analytics, messaging, configuration, security, and fraud-prevention services.
Additional information is available in Firebase Privacy and Security and the Google Privacy Policy.
Zebis also operates support-ticket and notification-relay services hosted on Google Cloud Functions. The support-ticket service verifies the signed-in employee, validates ticket destinations and attachments, temporarily retrieves selected attachments from Firebase Cloud Storage, and submits the message to the email-delivery provider. For device registration, the notification-relay service receives the random App installation identifier, push-notification token, App version, and Firebase authentication token. It also processes the test-notification, temporary pairing-code, and mark-heard requests described above.
Email-delivery and support providers
After authentication and validation by the Zebis support-ticket service, support tickets are transmitted through an email-delivery provider, currently SMTP2GO, and delivered to authorized Zebis support personnel. SMTP2GO processes the message, diagnostic content, and any photos you choose to attach as necessary to transmit the ticket. SMTP2GO credentials are held by the server-side service and are not included in the App.
LiveKit
We use LiveKit Cloud to establish and transport Remote Screen Share sessions. LiveKit may process screen video, participant and room identifiers, pointer-coordinate data, connection information, IP addresses, and technical service logs as necessary to route, secure, troubleshoot, and operate the WebRTC session. Zebis does not enable LiveKit recording or export for this feature. Information about LiveKit's practices is available in the LiveKit Privacy Policy.
Android location and geocoding services
If you grant location permission and include location in a ticket, Android location and geocoding services may process coordinates to determine the device’s location or city.
Legal, security, and business disclosures
We may disclose information when reasonably necessary to comply with law, legal process, or governmental requests; enforce agreements; investigate misconduct, fraud, or abuse; or protect the rights, safety, and security of employees, Zebis, customers, or others.
Information may also be transferred as part of a merger, acquisition, reorganization, financing, or sale of business assets, subject to appropriate confidentiality and data-protection requirements.
4. Data Storage and Security
We use reasonable administrative, technical, and organizational safeguards intended to protect personal and sensitive information, including:
- Encryption in transit where supported;
- Authentication and access controls;
- Short-lived, room-specific LiveKit access tokens that permit technicians to view but not publish screen media;
- Encrypted network transport for screen media, signaling, and pointer data;
- Limiting access to authorized personnel and service providers who require it for their duties;
- Application-private storage for locally saved employee profile information; and
- Application-private storage for the random App installation identifier and temporary cache files; and
- Security monitoring, abuse prevention, and incident-response procedures.
Firebase Authentication processes data in the United States. Other Firebase services may use Google’s global infrastructure. Support tickets may be processed wherever Zebis and its service providers operate.
No storage or transmission system is completely secure, and we cannot guarantee absolute security.
5. Data Retention and Deletion
We retain information only as long as reasonably necessary for the purposes described in this policy:
- Locally stored employee profile information remains on the device until it is changed, the App’s data is cleared, or the App is uninstalled. Android backup services may retain a backup according to the device user’s Google account and backup settings.
- The random App installation identifier remains locally until the App's data is cleared or the App is uninstalled. Related device-registration information is retained by the notification relay only as long as reasonably necessary to deliver alerts, maintain the service, and protect its security.
- One-time voicemail-checker pairing codes expire after approximately 10 minutes.
- Remote Screen Share queue records contain session metadata rather than recorded screen video. Active sessions have a maximum duration of two hours, stale entries are removed through automated cleanup, and related operational logs or backups may remain for the applicable provider retention period.
- Temporary copies of photos captured through the App and cached Google profile images may remain in the App's private cache until Android clears the cache, the App's data is cleared, or the App is uninstalled. Ticket attachments temporarily uploaded to Firebase Cloud Storage are deleted after processing when cleanup succeeds; if cleanup is delayed, they may remain temporarily until removed. Photos included in submitted tickets follow the support-ticket retention period below.
- Firebase Authentication account information is retained while employee access remains active and until the account is disabled or deletion is requested, subject to security, employment, contractual, and legal exceptions.
- Support tickets and associated diagnostic information are retained for up to 24 months after resolution, unless a longer period is reasonably necessary for an ongoing support matter, customer relationship, security investigation, legal obligation, or dispute.
- Analytics information is retained for up to 14 months, subject to aggregated or de-identified reporting.
- Authentication, security, and fraud-prevention records may be retained for up to 12 months, or longer when reasonably necessary to investigate misuse or comply with law.
- Service-provider backups may persist for a limited period after deletion before being securely overwritten.
When information is no longer required, we delete it, anonymize it, or securely isolate it until deletion is possible.
6. Your Choices and Privacy Rights
You may:
- Decline location permission and submit tickets without location information;
- Decline notification permission;
- Choose not to take or select photos for a support ticket, and remove selected attachments before submission;
- Choose whether to request voicemail test notifications, pairing codes, or mark-heard actions;
- Choose whether to accept a member's Remote Screen Share session or send visual pointer guidance;
- End an active Remote Screen Share session at any time;
- Review or change locally stored employee profile information in the App;
- Review ticket content before choosing whether to transmit it;
- Clear locally stored information by clearing the App’s data or uninstalling it; and
- Request access to, correction of, or deletion of personal information controlled by Zebis.
To request account or data deletion, email support@zebis.com with the subject “ZebisTech Privacy Request.” We may need to verify your identity and employment authorization before completing the request.
A verified deletion request will permanently delete the authentication account and associated personal information controlled by Zebis, except information that must be retained for legal compliance, security, fraud prevention, accounting, employment or contractual obligations, or the establishment or defense of legal claims. We will explain any applicable retention when responding to a request.
Depending on where you live, applicable law may provide additional rights, including rights to access, correct, delete, restrict, or receive a copy of personal information, or to object to certain processing.
7. Children’s Privacy
ZebisTech is an internal business application intended for authorized Zebis employees and technicians. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13 through the App. If you believe a child has provided personal information through ZebisTech, contact us so we can investigate and delete it where appropriate.
8. External Websites and Applications
ZebisTech may open third-party websites, the Google Play Store, device settings, or other installed applications at an employee’s direction. It may also open the device camera or Android photo picker when an employee chooses to add a ticket attachment. Those services operate under their own privacy policies and practices. Zebis is not responsible for the privacy practices of third-party services that you choose to open.
9. Changes to This Policy
We may update this Privacy Policy to reflect changes to ZebisTech, our practices, legal requirements, or service providers. We will update the “Last updated” date and provide additional notice when required.
10. Contact Us
For privacy questions, requests, or complaints, contact:
Zebis Inc.Email: support@zebis.com
Telephone: +1 239-437-9324
Website: https://www.zebis.com