KRZY|MediaLab+Management

Legal

Privacy Policy

Effective 20 August 2026. This version replaces the 15 August 2026 policy, correcting who approves posts before they are published.

1. Who we are

KRZY Media Lab is operated by KRZY Equity LLC, a limited liability company organized in New Mexico, United States. In this policy "we", "us" and "KRZY" mean KRZY Equity LLC.

We can be reached at admin@krzymedialab.com for any question, request or complaint about this policy.

2. What this policy covers

This policy covers www.krzymedialab.com, the signed-in client portal, and every KRZY product delivered through them: Media Lab (social content), +Management (the operations assistant), Loyalty, Marketing Tools, and any free tools or demos we publish.

It does not cover Facebook, Instagram, or any other company's platform. Once a post is published to a social network, that network's own policy governs it.

3. The three groups of people in this policy

Read this section first, because the rest of the document depends on it. KRZY holds information about three different groups, and our responsibilities differ for each.

  • Business clients. The owner or manager who buys a KRZY plan. We decide how their account data is handled, so for them we are the controller of that data and this policy is our direct promise to them.
  • Loyalty members. A client's own customers, who join that client's rewards program. We hold their details on the client's behalf and act on the client's instructions. The client decides what their program does; we process it.
  • Employees. A client's staff, who receive messages from the +Management assistant. We hold their details on the employer's behalf and act on the employer's instructions.

If you are a loyalty member or an employee and want your information changed or deleted, you can contact us directly at admin@krzymedialab.com and we will act on it, but the business you deal with is the party that decides what is collected in the first place. We will tell you who that is if you ask.

4. What we collect

From business clients

  • Name, business name, email address, phone number, business address, website and social handles.
  • Account credentials. Passwords are stored only as a one-way hash; we cannot read them.
  • Photographs, videos, logos and brand assets you upload, and the menu items, prices and descriptions you give us or that we read from your own public website.
  • Captions, scheduling data and the posts we produce for you.
  • Access tokens for the accounts you connect — Facebook Pages, Instagram Business accounts, and for +Management clients, point-of-sale, scheduling and accounting providers.
  • Support messages, service requests and any documents you send us, including sales reports, invoices and schedules you upload to +Management.
  • Billing records. See section 9 — we never see or store your card number.

From loyalty members

  • Name, mobile number, and email address if given, submitted on the client's public join page.
  • Check-in history, points balance and rewards earned at that business.

From employees

  • Name, mobile number, role, skill level and shift availability.
  • Pay rate, where the employer chooses to provide it.
  • Messages exchanged with the assistant, and records of coaching notes, corrective-action drafts and shift events. Please read section 8 before using +Management, whether you are an employer or an employee.

Automatically, from anyone who visits

  • Pages viewed, time on page, referring page, approximate location derived from IP address, and general device and browser type.
  • A session identifier stored in your browser so that repeat page views in one visit are counted as one visit rather than several.

5. Why we use it

  • To create, review, schedule and publish content for a client.
  • To build a brand profile from a client's own logo, website and photographs, so that what we produce matches their business rather than a generic template.
  • To run the +Management assistant, including staff messaging and coverage.
  • To operate a client's loyalty program and send messages they authorize.
  • To take payment, prevent duplicate charges and handle failed payments.
  • To provide support and answer requests.
  • To keep the service secure — rate limiting, abuse prevention and fraud checks.
  • To understand how the website is used in aggregate, so we can improve it. Traffic from our own staff and devices is excluded from those figures.
  • To meet our legal and tax obligations.

We do not sell personal information, and we never have. We do not share it with advertising networks or data brokers, and we do not use a client's photographs, menu or business data to build products for anyone else.

6. Who we send data to

We use other companies to run the service. Each receives only what it needs to do its job, and each is bound by its own agreement with us. This is the complete list of the categories of provider we send personal information to:

  • Hosting and database — our website host and our database, authentication and file-storage provider. Effectively all data described above rests here.
  • Artificial intelligence providers — this one matters and was not disclosed before. Photographs you upload, together with the menu item they show and your brand profile, are sent to a third-party AI provider so the image can be retouched and a caption drafted. Documents you give +Management are converted into a searchable form using the same kind of provider. We use these providers on their business terms, under which content sent through their interface is not used to train their models.
  • Meta — Facebook and Instagram, to publish to the Page and Instagram account you connect. See section 7.
  • Payment processing — to take payment and, for affiliates, to make payouts.
  • Email delivery — to send account email, trial reminders, support replies and loyalty messages a client authorizes.
  • Text-message delivery — to carry +Management messages to and from staff.
  • Web scraping — to read a client's own public website when building their brand profile or importing their menu.
  • Abuse prevention — to tell a real person from an automated script on our public forms.
  • Digital wallet providers — to issue loyalty cards to Apple Wallet and Google Wallet.
  • Providers a client connects themselves — point-of-sale, scheduling and accounting systems. These receive nothing until a client links them and can be disconnected at any time.

We will also disclose information if the law requires it, to enforce our agreements, or to protect the rights and safety of people. If KRZY is ever sold or merged, information may transfer as part of that transaction, and this policy will continue to apply until you are told otherwise.

We are a United States business and our providers are principally in the United States. If you use the service from elsewhere, your information will be handled in the United States.

7. Facebook and Instagram

When you connect your Facebook Page, we request these permissions through Meta's official login flow, and only these:

  • pages_show_list — to list the Pages you manage.
  • pages_read_engagement — to read basic Page information.
  • pages_manage_posts — to publish your restaurant's posts to your Page.
  • instagram_basic — to identify the Instagram Business account linked to your Page.
  • instagram_content_publish — to publish to that Instagram account.

We use this access to publish on your behalf and for nothing else. We do not read your inbox, we do not publish anything outside the content service you signed up for, and we do not use your audience data for advertising. Every post is reviewed and approved by a person at KRZY before it is published.

Tokens are held in our backend and are never exposed to the browser. You can disconnect at any time from your KRZY account or by removing KRZY in your Facebook Business settings; either one stops publishing immediately. To have the data deleted as well, use our data deletion page.

8. +Management, staff messages and consent

+Management communicates with a client's staff by text message. Two things about that are important enough to state plainly.

Staff opt in themselves. An employer adding a phone number does not enrol anyone. The employee starts the conversation by texting the assistant, and that is the consent record. Any employee can stop at any time by replying STOP, and standard message and data rates apply.

Conversations are recorded and are visible to the employer. Coaching notes, corrective-action drafts and message history form a workplace record that the employer can read and that may be disclosable in a legal dispute. Employees should treat these messages as work communications, not private ones.

Messages that raise harassment, safety, injury, wage or similar concerns are passed to the business owner and are not handled by the assistant.

Employers are responsible for using this feature lawfully, including notifying their staff and honouring the employment and labour laws that apply to them.

9. Payments

Payments are processed by our payment provider. Card numbers are entered on their systems, not ours. We never receive, see or store your full card number. We keep a customer reference, the plan you are on, the last payment result and our own invoice records.

10. Analytics and cookies

We use a small amount of first-party storage in your browser to keep you signed in, to remember whether you have already seen our introduction panel, and to group your page views into a single visit. We do not run third-party advertising trackers and we do not build advertising profiles.

Our analytics are our own and are used in aggregate. If your browser sends a Do Not Track or Global Privacy Control signal, we treat it as a request not to be counted.

11. How long we keep it

We keep information for as long as an account is open, and for a reasonable period afterwards so that we can answer questions, resolve disputes, and meet tax and accounting obligations. Financial records are generally kept for seven years because tax law requires it.

Connection tokens are deleted when you disconnect an account. Everything else can be deleted on request — see section 13. Backups are overwritten on their own cycle, so a deleted item may persist briefly in a backup before it is gone for good.

We do not state a fixed number of days for every category here, because that would describe an automatic process we do not currently run. When we build one, this section will say so.

12. How we protect it

Access to client data requires authentication, and the database enforces separation between accounts at the row level rather than relying on the application to remember to filter. Traffic is encrypted in transit and data is encrypted at rest by our infrastructure providers. Uploaded photographs are held in private storage and served only through short-lived signed links. Administrative access is limited to KRZY staff who need it.

No service can promise perfect security, and we do not. If a breach affects your information we will tell you and the relevant authorities as the law requires.

13. Your rights and how to use them

You can ask us to:

  • Tell you what information we hold about you, and give you a copy.
  • Correct anything that is wrong.
  • Delete your information.
  • Stop using it for a particular purpose.
  • Stop sending you marketing email — every marketing email also has an unsubscribe link.

Email admin@krzymedialab.com or use the data deletion page. We will respond within 30 days. We may need to confirm who you are first, which protects you as much as us. Exercising any of these rights costs nothing and we will not treat you differently for it.

California residents. You have the rights above under the California Consumer Privacy Act, including the right to know what we collect and why, the right to delete, the right to correct, and the right not to be discriminated against for asking. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing for you to opt out of on that front. You may use an authorised agent, and we will verify their authority.

14. Children

KRZY is a service for businesses and is not directed at children. We do not knowingly collect information from anyone under 13. If you believe a child has given us information, email admin@krzymedialab.com and we will delete it.

15. Changes to this policy

We may update this policy. The effective date at the top always shows the current version. If a change materially affects how we handle your information, we will tell you by email or in the app before it takes effect rather than quietly changing the page.

16. Contact

Questions, requests, or a complaint about how we have handled your information: admin@krzymedialab.com. A postal address is available on request.

For the commercial side of the relationship, see our Terms & Conditions.