Zipper

Privacy Policy

Effective July 30, 2026

This Privacy Policy (“Policy”) describes how Grace Journeys LLC dba Zipper (“Zipper,” “we,” “our,” or “us”) collects, uses, discloses, and otherwise processes personal information, as well as the rights and choices individuals may have regarding such personal information.

For additional information about the privacy choices you may have regarding your personal information, please review the Your Privacy Choices section below.

By using our Services (as defined below), you agree that your personal information will be handled as described in this Policy. Your use of our Services and any dispute over privacy is subject to this Policy and our Terms of Service, including their applicable terms governing limitations on damages and the resolution of disputes.

1. Scope

Except as otherwise described below, this Policy applies to our online and offline personal information processing activities including, but not limited to: users of our mobile applications for iOS and Android (the “App”), which are the primary way to access our services; visitors to our website where this Policy is posted, including https://zipper.travel (the “Site”); individuals who sign up for, or create an account with us to access and use certain features of our services; individuals who register for or participate in our events, surveys, research, and promotions conducted by us; individuals who subscribe to receive news, information, and marketing communications and materials from us; current, former, and prospective business partners, and service providers; and individuals who communicate or otherwise interact or engage with us or the services available through our App, Site, or other online services (collectively referred to as the “Services”).

2. Personal Information Collected

We collect personal information directly from you, from third-party sources, and automatically through your use of the Services. The personal information we collect varies depending upon your use of our Services and our interactions with you.

Personal Information Collected Directly. We may collect the following personal information directly from you:

Personal Information Collected from Third Parties. We may collect and receive personal information from third party sources, such as business partners, operating systems, public databases, customers and other users, and service providers or other third parties who provide services or perform functions on our behalf. We may collect the following information from third-party sources:

Personal Information Collected Automatically. We may automatically collect or derive personal information related to your use of our Services, including through the use of cookies, pixel tags, and other similar technologies. This may include:

For more information about our use of cookies and other similar technologies, please see the Cookies and Other Tracking Mechanisms section below.

3. How We May Use Personal Information

We may collect, use, disclose, and otherwise process personal information for the following purposes:

4. Disclosures of Personal Information

We may disclose the personal information we collect for the purposes described above and as follows:

5. Cookies and Other Tracking Mechanisms

We use cookies, pixels, local storage, log files, and other mechanisms to automatically collect browsing, activity, device, and similar information within our Services. We use this information to, for example, analyze and understand how users interact with our Services; identify and resolve bugs and errors in our Services; assess, secure, protect, optimize, and improve the performance of our Services; conduct marketing and analytics activities; and personalize content in our Services. Our App does not include third-party advertising or analytics SDKs, and the only third-party SDKs that send your information to anyone other than us are for secure, PCI-compliant collection of payment details and for payment fraud prevention. To manage your preferences regarding cookies and other tracking mechanisms within our Services, please see Your Privacy Choices below.

Cookies. Cookies are small text files that your browser stores on your device at our request. Some cookies make it easier for you to navigate our Services, while others enable a faster log-in process, support the security and performance of the Services, or allow us to understand activity and usage within the Services.

Pixel Tags. Pixel tags (sometimes called web beacons) are tiny invisible images embedded in web pages or emails that tell us when the content has been loaded. We may use them within our Services to understand user activity, manage content, and compile usage statistics, and in emails we send to measure open and response rates.

Browser Local Storage. Local storage is a browser feature that lets a website store data on your device that persists after you close your browser. We may use it to keep you signed in and to cache information so that pages load faster when you return. You can clear local storage through your browser settings.

First-Party Analytics. Information about how our Services are used, along with our logs and usage statistics, is collected and processed entirely by us using our own systems. We do not use third-party analytics providers, and we do not share this information with third-party analytics companies. Technical information about your device and your transactions is shared with our payment service providers solely for payment processing and fraud prevention, as described in Section 4.

6. SMS/Text Messaging Program

This Section 6 applies to personal information collected, used, or disclosed in connection with our SMS, MMS, RCS, or other text messaging programs (“Messaging Program”), specifically mobile phone numbers, text messaging opt-in data, and consent records (collectively, “Mobile Information”). To the extent any other provision of this Policy conflicts with this Section 6 with respect to Mobile Information, this Section 6 controls. Additional terms applicable to our Messaging Program are set forth in our SMS/MMS Terms.

No Sale or Sharing of Mobile Information for Marketing. No Mobile Information will be shared with third parties or affiliates for marketing or promotional purposes. We do not sell, rent, lease, or otherwise transfer your mobile phone number, text messaging opt-in data, or consent records to any third party for such purposes.

Permitted Service Provider Disclosures. We may disclose Mobile Information to subcontractors, vendors, and service providers that perform functions on our behalf solely as necessary to operate the Messaging Program, including messaging platform providers, SMS aggregators, telecommunications carriers, customer support providers, and technical infrastructure providers. These service providers are prohibited from using Mobile Information for their own marketing or promotional purposes, or for any purpose unrelated to delivering the services you have requested.

Travel Supplier Disclosures. To fulfill your travel bookings and reservations, we may share mobile phone numbers with travel suppliers (including airlines, hotels, cruise lines, tour operators, ground transportation providers, accommodation wholesalers, and global distribution systems) to allow the supplier to communicate with you about your reservation. Travel suppliers are independent third parties, not our service providers, and their use of your phone number is governed by their own privacy policies and terms.

Scope of Your Consent. Your consent to receive text messages from us under our Messaging Program applies solely to communications from us. Travel suppliers with whom we share your information to fulfill your bookings may separately contact you regarding your travel, subject to their own policies and any consent you have provided to them directly. We do not transfer your consent to our Messaging Program to any travel supplier, third party, affiliate, or other business.

Legal Disclosures. We may disclose Mobile Information when required by law, legal process, subpoena, court order, or governmental request, or where we reasonably believe disclosure is necessary to protect our rights, property, or the safety of any person, in accordance with Section 4. These disclosures are not subject to the marketing-purposes restriction above.

7. Google User Data

This Section 7 applies to information we receive from Google APIs (“Google User Data”) when you choose to connect your Google account to the Services. To the extent any other provision of this Policy conflicts with this Section 7 with respect to Google User Data, this Section 7 controls.

Data We Access. With your consent, granted through Google’s OAuth consent flow, we request the following access:

How We Use Google User Data. We use Google User Data solely to provide and improve the user-facing features described above. We do not use Google User Data for advertising or marketing purposes of any kind, we never share it with advertising platforms, and we do not use it to train artificial intelligence or machine learning models.

Storage. We do not store your Gmail messages or Google Calendar event data in our databases or logs; this data is processed transiently to provide and improve the features described above. We store only the loyalty program membership numbers identified from your messages, which are saved to your wallet within the Services and remain subject to the restrictions described in this Section 7.

Limited Use. Zipper’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Sharing. We do not transfer Google User Data to third parties except: (i) as necessary to provide the user-facing features described above, with your consent (for example, when you make a booking, we share the relevant loyalty program membership numbers from your wallet with the travel supplier, such as an airline or hotel, to apply your membership to the reservation, and we use service providers, such as cloud hosting providers, that process data on our instructions to operate the Services); (ii) for security purposes, such as investigating abuse; (iii) to comply with applicable law; or (iv) as part of a merger, acquisition, or sale of assets, after obtaining your explicit prior consent. We never sell Google User Data, never transfer it to data brokers, advertising platforms, or information resellers, and never use it to determine creditworthiness or for lending purposes.

Human Access. Our personnel do not read your Gmail messages or Google Calendar data except: (i) with your affirmative agreement to view specific messages or data; (ii) as necessary for security purposes, such as investigating a bug or abuse; (iii) as necessary to comply with applicable law; or (iv) where the data has been aggregated and is used for internal operations in accordance with applicable law.

Revoking Access and Deletion. You can disconnect your Google account from the Services at any time, or revoke Zipper’s access via Google Security Settings. You may also request deletion of loyalty numbers saved to your wallet or any other associated data by contacting us at privacy@zipper.travel.

8. Your Privacy Choices

We make available several ways that you can manage your privacy choices and submit privacy requests related to your personal information. Some of these choices are browser and device specific, which means that you need to set the preference for each browser and device you use to access our Services. In addition, if you delete or block cookies, you may need to reapply these preferences to each browser and/or device used to access our Services.

These options include:

Our Service may contain links to third-party websites or features or provide certain third-party connections or integrated services. Any access to and use of such linked websites, features, or third-party services is not governed by this Policy. We are not responsible for the information practices of such third parties, including their collection, use, and disclosure of your personal information. You should review the privacy policies and terms for any third parties before proceeding to those websites or using those third-party features or services.

10. Children’s Privacy

Our Services are not designed for children, we do not knowingly allow children under 18 to create accounts, and we do not knowingly collect personal information directly from children under 18. When a parent, guardian, or other adult books travel for a child, we collect the traveler information needed to complete the booking (such as the child’s name, date of birth, and passport or other identification details) and use it solely to provide the requested travel services, including sharing it with travel suppliers as described in Section 4. If you are a parent or legal guardian and you believe we have collected your child’s information in violation of applicable law, please contact us using the contact information in the Contact Us section below.

11. Security

We have implemented safeguards intended to protect personal information from loss, misuse, unauthorized access, disclosure, alteration, or destruction. Please be aware that despite our efforts, no data security measures can guarantee security.

12. Additional Information for California Residents

Shine the Light Law

Under California’s “Shine the Light” law (Cal. Civ. Code § 1798.83), California residents who provide us certain personal information are entitled to request and obtain from us, free of charge, information about the personal information (if any) we have shared with third parties for their own direct marketing use. Such requests may be made once per calendar year for information about any relevant third-party sharing in the prior calendar year. To submit a “Shine the Light” request, email us using the Contact Us information below, and include in your request a current California address and your attestation that you are a California resident.

13. Changes to this Policy

This Policy is current as of the effective date set forth above. We may change this Policy from time to time, so please be sure to check back periodically. We will post any updates to this Policy on this page. If we make material changes to how we collect, use, or disclose the personal information we have previously collected, we will provide you prior notice, such as by emailing you or posting prominent notice on our website or within the Services. If we change how we handle Google User Data, we will notify you and obtain your consent before the change applies to your Google User Data.

14. Contact Us

If you have any questions or concerns regarding this Policy or our privacy practices, you may contact us at privacy@zipper.travel.