ZipQuarry finds local businesses inside a radius you choose, enriches each one with public context, and drafts a cold email you can edit and send from your own inbox. Doing that involves two sensitive things: connecting to your Gmail account, and holding contact details for businesses that never signed up for anything. This policy is specific about both.
The short version
We ask for access to your Google account so ZipQuarry can create drafts in, and send from, your Gmail. We never read your mailbox, we never sell anything, and we do not use Google user data to train AI models. Prospect contact details come from Google Maps listings and the businesses’ own public websites, and we record where each address was published so that outreach can be shown to be lawful. You can disconnect Google, export your data, or delete your account at any time.
1. Who we are
ZipQuarry (“ZipQuarry,” “the Service”) is a product of Northbound Software Studio (“Northbound,” “we,” “us,” “our”), a software studio based in Toronto, Ontario, Canada. Northbound is the data controller for the personal information described in this policy.
This policy covers the ZipQuarry marketing site at zipquarry.com and the ZipQuarry application at app.zipquarry.com. Northbound’s studio site has its own privacy policy covering the studio’s consulting work; where the two differ for ZipQuarry, this one governs.
Questions, requests and complaints: hello@northboundsoftwarestudio.com.
2. Two kinds of people appear in this policy
Most privacy policies describe one relationship. ZipQuarry has two, and conflating them is how prospecting tools end up doing something indefensible:
- You — the user. You created a ZipQuarry account, connected your Google account, and are sending outreach. You have a direct relationship with us and consented to it.
- The prospect — a business, and sometimes a person at it. They did not sign up. We hold information about them because you are considering contacting them. They still have rights, and Section 5 is about how those are honoured.
Where this policy says “your data” it means the first. Section 5 is entirely about the second.
3. What we collect about you
3.1 Account and identity
ZipQuarry has no password of its own. You sign in with Google, and we receive and store your name, email address, Google profile picture URL, and your Google account identifier. Section 4 covers this in full.
3.2 Your business profile
To draft an email that sounds like you rather than like software, ZipQuarry asks what you sell, who you sell it to, your typical deal size, your service area and postal code, your tone preferences, your email signature, and the postal mailing address that anti-spam law requires in every commercial message. You provide this during onboarding and in Settings, and you can change or clear it at any time.
3.3 Billing
Payments are processed by Stripe. Card numbers never reach ZipQuarry’s servers — they go directly to Stripe. We store your subscription status, plan, and Stripe customer identifier so we know what you are entitled to.
3.4 Usage and technical data
We record which features you use and how much — searches run, prospects scored, drafts generated, emails sent — to enforce plan limits, bill accurately, and find what is broken. Our hosting provider logs standard request data: IP address, user agent, timestamp, path.
3.5 If you join the mailing list
If you enter your email address into the field-notes form on our website, we store that address, the date and time you submitted it, the exact wording of the consent you agreed to, which page you submitted it from, any campaign parameters in the link you arrived by, and the IP address you submitted it from. The IP address is kept for one reason — to evidence that the consent was genuinely given, as Canada’s anti-spam law requires of us — and it is deleted the moment you unsubscribe.
This list is separate from your ZipQuarry account. Joining it does not create an account, and creating an account does not add you to it: we do not send marketing to people on the strength of having signed up for the product. Every message we send from this list carries an unsubscribe link, and unsubscribing is honoured permanently.
3.6 Website analytics
Our public website at zipquarry.com uses Google Analytics to count visits and see which pages people read. We have turned off Google Signals and ad personalisation, so this data is not used to build an advertising profile of you or to follow you to other websites.
The signed-in application at app.zipquarry.com does not use Google Analytics or any other third-party analytics. It records what you do in the product using our own database, on our own servers, with an allowlist that stores only counts, durations and short status codes — never the content of your searches, drafts or prospect lists. That record is deleted with your account.
3.7 What we do not collect
- We do not run advertising trackers or third-party ad pixels.
- We do not buy personal data about you from data brokers.
- We do not track you across other websites.
- We do not sell personal information, and we have not in the preceding twelve months.
4. Google user data
This section exists because it is the part that matters most and the part most often left vague. ZipQuarry’s use of Google APIs is narrow, and it is described here exactly.
4.1 What we ask for, and why
| Scope | Why ZipQuarry needs it | What it does not allow |
|---|---|---|
| openid, email, profile | To sign you in and to know which account is yours. Your name and picture appear in the app so you can tell which Google account is connected. | No access to any Google service beyond your basic profile. |
gmail.compose.../auth/gmail.compose |
To create outreach emails as drafts in your own Gmail, so you can open, edit and send them yourself before anything leaves. | Does not permit reading messages you did not create through ZipQuarry. |
gmail.send.../auth/gmail.send |
To send an approved message from your address when you choose to send it from inside ZipQuarry, and to deliver sends you have scheduled. | Send-only. It confers no ability to read, search, or list your mailbox. |
These are the only Google scopes ZipQuarry requests. We deliberately do not
request read access to your mailbox. If we ever add reply detection — which
would require the gmail.readonly scope — Google will ask for
your consent again on a new screen, and this policy will be updated before that
screen exists. Consent you have already given cannot be silently widened.
4.2 How we use it
Google user data is used only to provide features you initiated:
- Signing you in and keeping you signed in.
- Writing a draft into your Gmail when you generate outreach.
- Sending a message from your address when you press send, or when a send you scheduled comes due.
- Recording the Gmail message and thread identifiers of what we sent, so the app can show you what went out and stop a follow-up when a thread is already handled.
4.3 What we store
We store your Google OAuth access token and refresh token, their expiry, and the list of scopes you granted, in our encrypted database. The refresh token is what allows a send you scheduled for Tuesday to actually go out on Tuesday. We also store the content of drafts ZipQuarry generated for you and the Gmail message identifiers of sends we performed.
We do not download, index, cache or store the contents of your mailbox, because we never had access to it.
4.4 Limited Use
Required disclosure
ZipQuarry’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, and without qualification:
- We do not transfer Google user data to any third party except as necessary to provide the Service you asked for, to comply with applicable law, or as part of a merger or acquisition — and in the last case only after notifying you.
- We do not use Google user data for advertising, and we do not serve advertising at all.
- We do not sell Google user data. Ever, to anyone, for any price.
- We do not use Google user data to develop, improve or train generalised artificial intelligence or machine learning models. The AI described in Section 6 drafts emails from prospect research and the business profile you wrote; it is not fed your mailbox, and it could not be, because we cannot read it.
- Humans do not read your Google user data, except with your explicit consent for a support issue you have raised, where required by law, or on aggregated anonymised data for security and abuse investigation.
4.5 Taking it back
You can revoke ZipQuarry’s access to your Google account at any moment, from either end:
- In ZipQuarry, under Settings → Connected accounts → Disconnect. We delete the stored tokens immediately.
- At Google, via myaccount.google.com/permissions. This revokes the tokens at the source.
Either way, ZipQuarry loses the ability to create drafts or send on your behalf, and any scheduled sends stop. Deleting your ZipQuarry account deletes the tokens along with everything else, as described in Section 8.
5. Prospect data — information about people who did not sign up
ZipQuarry’s whole job is to build a list of businesses to contact, so it holds information about businesses and, sometimes, identifiable people at them. That is a real responsibility and it is treated as one.
5.1 What we hold
For each prospect: business name, address, geographic coordinates, phone number, website, business category, and — where one is publicly published — a contact email address. Alongside that we store our own derived material: fit and urgency scores, the reasoning behind them, notes drawn from the business’s public website, and any drafts you generated for them.
5.2 Where it comes from
- Google Maps / Places data, for the business listing itself — name, address, category, phone, website.
- The business’s own public website, fetched the way any visitor’s browser would fetch it. We read publicly served pages. We do not attempt to bypass logins, paywalls, rate limits or access controls, and requests are made through a guard that refuses to fetch private network addresses.
We do not buy contact lists, and we do not use data brokers, scraped social profiles, or email-guessing services that invent an address from a name and a domain.
5.3 Provenance, because the law turns on it
When ZipQuarry finds a contact address, it records the URL of the page it was published on alongside the address itself. This is not housekeeping. Canada’s Anti-Spam Legislation permits certain messages to an address a business has conspicuously published without a statement refusing unsolicited commercial email — and if you are ever asked to demonstrate that, the evidence has to already exist. ZipQuarry’s send path checks that provenance before a commercial message leaves, and refuses the send if it cannot establish it.
5.4 Compliance is enforced by the software, not by the sender’s memory
Every commercial message ZipQuarry sends carries a working unsubscribe mechanism and the sender’s physical mailing address, applied server-side on the send path. This is required by CASL in Canada and CAN-SPAM in the United States, and it is not optional in ZipQuarry: a message that cannot be made compliant is not sent. Unsubscribe requests are recorded in a suppression list and honoured across all future sends by that account.
5.5 The user is the sender
You decide who to contact and what to say. You are the sender of your outreach and are responsible for it, including for having a lawful basis to contact each recipient in their jurisdiction. Northbound processes prospect data on your behalf when you use the Service. Our Terms of Service set out what you agree to when you send.
5.6 If you are a prospect reading this
You may have received an email that was drafted with ZipQuarry, or found this page while checking who holds data about your business. You can:
- Use the unsubscribe link in the message you received. It works, it is one click, and it suppresses further contact from that sender immediately.
- Email hello@northboundsoftwarestudio.com and ask us to delete the information ZipQuarry holds about your business, or to tell you what it holds. We will do it, and we do not require you to prove a prior relationship first.
Because ZipQuarry processes prospect data on behalf of the individual sender, a deletion request may also need to reach that sender. Tell us and we will identify them for you and pass the request along.
6. AI processing
ZipQuarry uses large language models from OpenAI and Anthropic to score prospects and draft emails. What is sent to them is the prospect research described in Section 5 and the business profile you wrote in Section 3.2 — enough for the model to write something specific rather than generic.
Both providers are used through their commercial APIs, under terms that do not permit them to train their models on data submitted through those APIs. Your Gmail contents are never sent to a model, because ZipQuarry cannot read them.
Drafts are generated, not sent. Every message is yours to read, edit, or discard before anything is delivered.
7. Who else sees your data
We use a small number of service providers to run ZipQuarry. Each receives only what it needs, is bound by contract to protect it, and may not use it for its own purposes.
| Provider | What it does | What it receives |
|---|---|---|
| Sign-in, Gmail sending, Maps and Places lookups | Your identity and OAuth tokens; the search location and radius | |
| Vercel | Application hosting | Request logs; all traffic transits it |
| Neon | Managed Postgres database | Everything the app stores |
| OpenAI | Scoring and email drafting | Prospect research and your business profile |
| Anthropic | Scoring and email drafting | Prospect research and your business profile |
| Stripe | Payments and subscriptions | Your email, billing details and payment method |
| Google Analytics | Visit counts for the public website only — not the signed-in app | Page views from zipquarry.com, with ad features disabled |
| Resend | Transactional email from ZipQuarry itself — receipts, briefings, account notices | Your email address and the message |
Beyond these, we disclose personal information only when required by law, court order or a lawful request from a public authority; when necessary to establish or defend a legal claim; when necessary to protect someone’s safety or to investigate fraud or abuse; or as part of a merger, acquisition or asset sale, in which case we will notify you before your information becomes subject to a materially different policy.
8. How long we keep it
- Account and profile data — while your account is open.
- Google OAuth tokens — until you disconnect Google, revoke access, or delete your account. Deleted immediately in all three cases.
- Prospects, drafts and outreach history — while your account is open, or until you delete them individually.
- Unsubscribe and suppression records — kept indefinitely, deliberately. Deleting the record that someone opted out is how you email them again by accident. These are minimal and exist only to prevent contact.
- Billing records — seven years, as tax and accounting law requires.
- Server logs — thirty days.
When you delete your ZipQuarry account we delete your profile, your Google tokens, your prospects, your drafts and your outreach history within 30 days, retaining only the suppression and billing records above. Backups are purged on their own rolling cycle, which completes within 90 days.
9. Security
Everything travels over HTTPS. The database is encrypted at rest and reachable only over TLS. OAuth tokens are stored in that database and are never exposed to the browser. Access is scoped per user in the application layer: a request can only reach rows belonging to the signed-in account, and the account identity comes from the session, never from anything the request itself claims. Access to production systems is limited to personnel who need it.
No system is perfectly secure, and anyone who tells you otherwise is selling something. If we become aware of a breach affecting your personal information we will notify you and the relevant regulators as applicable law requires. To report a vulnerability, email hello@northboundsoftwarestudio.com — we will not pursue good-faith security research.
10. Where your data lives
Northbound is in Canada. Our infrastructure and service providers operate primarily in Canada, the United States and the European Union, so your information is transferred to and processed in those jurisdictions and may be subject to lawful access requests there. Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on the European Commission’s Standard Contractual Clauses or an equivalent safeguard.
11. Your rights
Whatever jurisdiction you are in, you can ask us to:
- Access — tell you what personal information we hold about you and provide a copy.
- Correct — fix anything inaccurate or incomplete.
- Delete — erase your personal information, subject to the retention exceptions in Section 8.
- Export — provide your data in a portable, machine-readable format.
- Withdraw consent — disconnect Google, or close your account entirely.
- Object or restrict — object to a particular processing activity, or ask us to pause it while a dispute is resolved.
Email hello@northboundsoftwarestudio.com. We respond within 30 days and we do not charge for this.
Canada (PIPEDA). If you are not satisfied with our response you may complain to the Office of the Privacy Commissioner of Canada.
EEA and UK (GDPR). Our lawful bases are: performance of a contract, for running your account and providing the Service; legitimate interests, for security, abuse prevention and product improvement; consent, for the Google account connection; and legal obligation, for billing records. You may lodge a complaint with your local supervisory authority.
California (CCPA/CPRA). We do not sell or share personal information as those terms are defined, and we have not in the preceding twelve months. We do not use or disclose sensitive personal information beyond the purposes permitted without a right to limit. You will not be discriminated against for exercising any right.
12. Children
ZipQuarry is a business tool sold to businesses. It is not directed at anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
13. Changes to this policy
When we change this policy we update the date at the top. If a change materially affects how we handle your personal information — a new scope, a new category of data, a new purpose — we will notify account holders by email before it takes effect, and where consent is required we will ask for it again rather than assume it.
14. Contact us
Northbound Software Studio
Toronto, Ontario, Canada
hello@northboundsoftwarestudio.com
For privacy requests, put “Privacy request” in the subject line and it will be routed accordingly.
See also the ZipQuarry Terms of Service, which cover acceptable use and your obligations as a sender.