Plain English summary

FranchiseZRM operates as a B2B SaaS platform for franchise headquarters. The personal information we collect is limited to what's needed to operate the platform, communicate with you, and improve our service. We do not sell personal information. We do not use your franchisee network's revenue or operational data for any purpose other than providing the service you've contracted for. If you have questions about how we handle information, you can reach us directly at the contact details at the bottom of this page.

Contents
01

Information we collect

FranchiseZRM collects information in three main categories: information you provide directly, information generated through your use of the platform, and information received from integrated third-party systems. We collect only what is necessary to operate the service and fulfil our contractual obligations.

👤
Information you provide directly
Collected when you create an account, request a demo, submit a form, or contact us.
Name, job title, and business email address
Company name, franchise brand(s), and number of locations
Account credentials (passwords are hashed and never stored in plain text)
Communications you send to us — including demo request details, support requests, and correspondence
Billing contact information and payment method details (processed by our payment provider; we do not store full card numbers)
📊
Platform and operational data
Generated through the use of ZRM by your HQ team and, where applicable, franchisees through the Zee Portal.
Franchise operations data: brand, entity, agreement, territory, and office records you create and manage within ZRM
CRM and sales data: lead records, pipeline activity, meeting notes, and agreement details entered or generated by your sales team and franchise business consultants
Revenue and royalty data: revenue figures, fee schedule applications, royalty calculations, and audit records — drawn from integrated systems or submitted via the platform
User activity logs: which features are accessed, actions taken, and timestamps — used for audit trail completeness and platform reliability
Franchisee-facing data entered or viewed through the Zee Portal (scoped to each franchisee's own record)
🔌
Data from integrated systems
Retrieved via read-only API connection to revenue systems in your franchise network, where integration is configured.
Revenue totals, period identifiers, and location references from POS systems (e.g. Square, Toast, Lightspeed), accounting platforms (e.g. QuickBooks, Xero), and payment processors (e.g. Stripe)
ZRM retrieves revenue summary data only — it does not access customer transaction records, employee data, or personally identifiable information from franchisee operating systems
Integration access is read-only; ZRM does not write to, modify, or delete records in source systems
🌐
Usage and technical data
Collected automatically when you access the ZRM platform or website.
IP address, browser type and version, operating system, and device type
Pages visited, features accessed, session duration, and navigation patterns
Referring URL and search terms (where applicable)
Error and diagnostic logs used to maintain platform stability
02

How we use information

We use the information we collect for specific, legitimate purposes directly related to operating the ZRM platform and fulfilling our obligations to you as a customer. We do not use your franchise operational data, revenue data, or CRM data for purposes other than service delivery.

  • Service delivery: operating the ZRM platform, processing royalty calculations, maintaining the franchise tree structure, and providing the Sales and FBC workspace, Royalty Automation engine, and Zee Portal
  • Account management: creating and administering your account, authenticating users, and managing your subscription
  • Communication: responding to your enquiries, sending service notifications, product updates, and (with your consent) information about ZRM features relevant to your use case
  • Audit and compliance: maintaining the audit trail required for royalty calculation records, supporting any regulatory or contractual review of financial records you are subject to
  • Platform improvement: using aggregated, de-identified usage data to understand how the platform is used and where improvements are needed — no individual franchise operational data is used for this purpose
  • Security and fraud prevention: detecting and preventing unauthorized access, abuse, or anomalous platform activity
  • Legal compliance: meeting obligations under applicable laws, including responding to lawful requests from regulatory authorities
  • Business operations: billing, financial record-keeping, and enforcing our Terms of Use
ℹ️
Your franchise network's operational data is yours. Revenue figures, royalty records, franchisee data, and CRM content you create in ZRM are not used to train models, shared with third parties for commercial purposes, or used in any way beyond operating the service you've contracted for. When your contract ends, you can request export of your data before deletion.
📱
SMS and text messaging (10DLC)
FranchiseZRM may send SMS and MMS text messages to mobile phone numbers you provide in connection with your account, demo requests, or platform communications. By providing a mobile phone number and consenting to receive text messages, you agree to receive SMS/MMS messages from FranchiseZRM related to your account, product updates, and service communications.
How we collect your number: phone numbers for SMS communications are collected only through explicit opt-in — via account registration, demo request forms, or other consent mechanisms on our website or platform. We do not obtain mobile numbers from third parties for unsolicited outreach.
How we use your number: we use mobile phone numbers solely to send the types of messages you have consented to receive. We do not send automated marketing messages without prior express written consent.
Sharing: we do not sell, rent, or share your mobile phone number with third parties for their own marketing purposes. Phone numbers collected for SMS communications are not shared with affiliates, partners, or data brokers. Message and data rates may apply.
Message frequency: message frequency will vary based on your account activity and communication preferences.
Opt-out: you may opt out of SMS communications at any time by replying STOP to any message you receive from us. After opting out, you will receive one final confirmation message and no further texts unless you re-subscribe. To re-subscribe, reply START.
Help: for assistance, reply HELP to any message or contact us at [email protected].
03

Information sharing

We do not sell personal information. We do not share franchise operational data, revenue data, or CRM data with third parties for marketing, advertising, or commercial purposes. Sharing is limited to the following circumstances:

🔧
Service providers (sub-processors)
We engage third-party vendors who process data on our behalf to operate the platform. All sub-processors are subject to contractual obligations requiring confidentiality and appropriate security measures.
Cloud infrastructure providers (hosting and data storage)
Payment processing providers (for billing only — not franchise revenue data)
Email and communication delivery providers
Analytics and monitoring services (using de-identified or aggregated data only)
Customer support tooling
⚖️
Legal requirements
We may disclose information where required by law or in good faith belief that disclosure is necessary to:
Comply with a legal obligation, court order, or valid request from a regulatory authority
Protect the rights, property, or safety of FranchiseZRM, our customers, or the public
Investigate or prevent fraud, security incidents, or illegal activity
🏢
Business transfers
In the event of a merger, acquisition, asset sale, or reorganisation involving FranchiseZRM, customer data may be transferred as part of that transaction. We will provide notice before any such transfer and before your data becomes subject to a materially different privacy policy.
With your explicit consent
We may share information for purposes not covered above where you have given explicit, informed consent for that specific use.
04

Data security

We implement technical and organisational measures designed to protect the information we hold against unauthorised access, disclosure, alteration, or loss. No system is entirely immune from risk, but we maintain a layered security posture appropriate to the sensitivity of franchise operational and financial data.

  • Encryption in transit: all data transmitted between your browser, the ZRM application, and our infrastructure is encrypted using TLS
  • Encryption at rest: data stored in ZRM databases and file storage is encrypted at rest
  • Authentication controls: access to the ZRM platform requires authenticated login; administrative access to production systems is restricted to authorised personnel only and subject to multi-factor authentication
  • API credential handling: credentials used to connect ZRM to revenue integration systems are encrypted at rest and never stored in plain text or exposed in application logs
  • Role-based access: within your ZRM account, access to data is scoped by role — leadership, sales, FBC, and franchisee (Zee Portal) views are each restricted to appropriate data
  • Audit logging: access to sensitive records — including royalty calculations, agreement data, and revenue records — is logged with timestamps and user references as part of the platform's built-in audit trail
  • Incident response: we maintain procedures for detecting, investigating, and responding to security incidents, including notification to affected customers where required by law
🔒
If you become aware of a security concern relating to your ZRM account or data, please contact us immediately at [email protected]. We treat all security reports seriously and will respond promptly.
05

Your rights

Depending on your location and applicable law, you may have rights regarding the personal information we hold about you. We respect these rights and will respond to valid requests promptly. To exercise any of the rights below, contact us at [email protected].

Right What it means How to exercise it
Access Request a copy of the personal information we hold about you and how it is being used. Email us at [email protected]. We will respond within the timeframe required by applicable law.
Correction Request correction of inaccurate or incomplete personal information. Many fields can be updated directly in your account. For records we hold outside the platform, contact us.
Deletion Request deletion of your personal information, subject to legal and contractual obligations that require us to retain certain records. Contact us at [email protected]. Note that deletion of account data may affect your ability to use the service.
Portability Request a structured, machine-readable export of your personal data and your franchise operational data held in ZRM. Data export is available within the platform for operational records. Contact us for personal data portability requests.
Objection Object to processing of your personal information for certain purposes, including direct marketing. Unsubscribe from marketing communications at any time via the link in any email, or contact us directly.
Restriction Request that we limit processing of your personal information in certain circumstances while a dispute or review is in progress. Contact us at [email protected] with details of your request.
Withdrawal of consent Where processing is based on your consent, withdraw that consent at any time without affecting the lawfulness of prior processing. Contact us or use the unsubscribe mechanism in marketing communications.

If you are located in the European Economic Area, United Kingdom, or California, additional rights and specific response timeframes may apply under GDPR, UK GDPR, or the CCPA/CPRA respectively. We will identify and honour the applicable framework in responding to your request.

06

Data retention

We retain personal information and franchise operational data for as long as necessary to fulfil the purposes for which it was collected, to provide the service, and to meet our legal and contractual obligations.

Active accounts: data is retained for the duration of your ZRM subscription and as necessary to support ongoing service delivery. You can request an export of your data at any time.

Royalty and financial records: audit records associated with royalty calculations — including the revenue source, agreement, fee schedule, and calculated output — may be subject to statutory retention obligations. The applicable retention period depends on the jurisdiction in which you operate and will be discussed during onboarding.

After contract termination: we will retain data for a reasonable period following contract end to allow for export requests and to meet any applicable legal obligations. After that period, data is deleted or de-identified according to our internal retention procedures. Specific timelines are confirmed in your service agreement.

Marketing and communication data: if you have not entered into a contract with us (for example, if you submitted a demo request but did not proceed), we retain your contact details for a reasonable period for follow-up purposes and delete them if you have not engaged further or have requested deletion.

📤
Exporting your data before termination. If your ZRM subscription ends, you may request a full export of your franchise operational data — including franchise tree records, agreement data, royalty history, and CRM records — before deletion. Contact your account manager or email [email protected] to arrange an export.
07

Cookies and tracking

We use cookies and similar tracking technologies on the FranchiseZRM website and platform. Cookies are small text files placed on your device that help us operate the site, understand how it is used, and improve the experience.

You can manage cookie preferences through your browser settings or via our cookie management tool. Note that disabling certain cookies may affect the functionality of the ZRM platform.

08

Third-party services

ZRM integrates with third-party platforms to retrieve revenue data for royalty calculation. These integrations are separate from ZRM's own data handling and are governed by the privacy policies of the respective platforms.

Revenue integration partners — including but not limited to Square, Toast, Lightspeed, Clover, QuickBooks, Xero, Stripe, and Mindbody — operate under their own privacy policies. When ZRM connects to these systems via read-only API access, the data retrieved (revenue totals, period identifiers, location references) is handled by ZRM as described in this policy. ZRM does not control or take responsibility for the privacy practices of these third-party platforms.

We recommend reviewing the privacy policies of any system your franchisees use that is connected to ZRM. If you have concerns about a specific integration's data handling, contact us at [email protected].

Analytics and monitoring: we use third-party analytics tools to understand platform usage. These tools process aggregated, de-identified data only — individual franchise operational records are not shared with analytics providers.

Payment processing: billing for ZRM subscriptions is handled by a third-party payment processor. We do not store full payment card details. The payment processor's own privacy policy governs how it handles billing information.

09

International data transfers

FranchiseZRM is primarily operated from the United States. If you access ZRM from outside the United States, your information will be transferred to and processed in the United States and potentially in other countries where our service providers operate.

Where we transfer personal information of individuals located in the European Economic Area or United Kingdom to countries that are not considered to provide an adequate level of data protection under applicable law, we implement appropriate safeguards — such as Standard Contractual Clauses — to protect that information in transit and at the destination.

If you have questions about the safeguards we apply to international transfers of your data, contact us at [email protected].

10

Children's privacy

ZRM is a B2B SaaS platform intended exclusively for use by business professionals at franchise headquarters organisations and their franchisees. We do not knowingly collect personal information from individuals under the age of 18.

If you believe that personal information of a minor has been inadvertently collected, please contact us at [email protected] and we will take steps to delete it promptly.

11

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the platform, or applicable law. When we make changes, we will update the "Last updated" date at the top of this page.

For material changes — those that meaningfully affect how we handle your personal information or your rights — we will provide notice by email to the primary account contact at least 30 days before the change takes effect, or as required by applicable law. We may also display a notice within the ZRM platform.

For non-material changes — such as corrections, clarifications, or changes to contact details — we will update the policy without advance notice beyond the updated date.

We encourage you to review this policy periodically. Continued use of ZRM after the effective date of any change constitutes your acceptance of the updated policy. If you do not agree with a material change, you may request to terminate your account in accordance with your service agreement.

12

Contact us for privacy questions

If you have questions about this Privacy Policy, how we handle your data, or to exercise any of your rights, reach us through the following channels. We will respond within the timeframe required by applicable law — and typically much sooner.

Privacy questions and requests

Our privacy team handles all data rights requests, security concerns, and questions about this policy. All enquiries are treated seriously and responded to promptly.

Post
FranchiseZRM, Inc.
Privacy Officer
30 N. Gould Ste R
Sheridan, WY 82801
Response
Within 30 days (sooner for urgent matters)