Privacy notice
Last updated: 11 October 2026
This notice explains what personal information Zolution collects, why, who can see it, how long we keep it, and what you can ask us to do. It covers zolution.io, the member workspace, the emails we send and our support mailbox.
1. Who is responsible
Zolution is operated by MedA LLC, 30 N Gould St Ste N, Sheridan, Wyoming 82801, USA. MedA LLC decides why and how personal information is used on Zolution, so it is responsible for that information (the "controller").
Contact: support@zolution.io.
2. The short version
- We collect what you give us to run your requests, offers and applications, and a little technical information to keep Zolution secure.
- We do not collect payment card details. Zolution takes no payments.
- Your documents stay in your own storage. We store the links you add, encrypted, and a history of each release, withdrawal and display of them in Zolution.
- Other members see your information only as the service needs. For example, providers whose coverage matches your request see seven facts about it.
- Much of Zolution's history cannot be edited or deleted once saved. There is no automatic deletion schedule: a person reviews each deletion request and carries it out by hand.
- We do not sell personal information, and we do not use it for advertising.
3. What we collect and why
Your account. Your confirmed email address, when you joined and when you last signed in. We do not ask for your name to create an account. When you sign up, we also record which version of our terms you agreed to, and when. We use this to sign you in, to email you about your requests, offers, applications and help requests, and to keep the service secure.
Sign-in and security records
- When you ask for a sign-in code, we store the email address you entered, what the code was for and when it expires. The code itself is stored only as a one-way keyed hash. We keep this record even if you never finish signing in.
- When you sign in, your browser receives a random session token. We store only a one-way hash of it, with when the session started, when it was last used, and when it ends or was ended.
- We record security events, such as a sign-in, a sign-out or a wrong code, with your account's internal identifier and the time. These records never contain your email address, a code, a token or an IP address.
- To stop guessing and abuse, we count requests per email address and per network. The counters hold one-way keyed hashes, not the addresses themselves.
Your IP address. When you ask for a code, enter one, send a recovery request or use the contact form, we use your IP address to apply limits per network. We store only a one-way keyed hash of it (for an IPv6 address, of its network part). On forms with a bot check, we also send your IP address to our bot-protection provider with the check's token, so that the provider can confirm the check (section 9).
Your business, if you are a merchant. Business name, website, legal name, year of incorporation, industry, the country where the company is registered, where your customers are, total monthly revenue and whether it is actual or projected, the year you started trading, the country where the person who will sign lives, and whether a US-based signer with a Social Security number is available (yes or no only; we never ask for the number); and, in an application, the platform your store runs on. We use these to build your requests and applications.
Your business, if you are a provider. Company name, website, legal name, service type, registered country, the years you were incorporated and started operating, description, coverage (industries, merchant countries, customer markets and volume limits), conditions for research-use-only peptide merchants if you serve them, acceptance and setup notes, gateways and connection methods. We use these to match you with requests and to show your offers.
Requests, offers and links. Drafts you save before publishing; the facts in each version of a request; the terms in each version of an offer (fees, reserves, payout terms, the contracting company and its country, conditions and how long the terms are valid); and the settings of your proposal link.
Invitations. The email address a provider invites, the optional business name and note the provider adds, the industry, and the invitation's history. If a provider invited you, this is how we have your email address.
Applications. The application details a merchant enters; any note about missing documents; the conversation; decisions, setup records, test results, live reports, website reviews, terms references and acknowledgements; and the names people type when they record them.
Document links. The address (encrypted), label, document type, note, and the date you say the documents were last updated; each release and withdrawal; each time Zolution displayed the address; and providers' review records. We do not open or store what a link points to.
Help and recovery requests. Your message and any reference you add; for a public recovery request, the contact email you give; and the full history of the request, including each support action and its reason.
Emails we send. For each email: the recipient's address, the type of email, its delivery status and times. The content is stored encrypted until the email is delivered or expires, and is then erased. Our emails about offers, applications and help requests do not contain your messages, document addresses or the terms of an offer. They link to the page in your account.
Your email choices. Whether you want lead alerts (providers) or product news. Both stay off until you turn them on.
Contact form and emails to support. Your name, email address, the role and topic you choose, and your message; and any email you send to support@zolution.io. We use them to answer you.
Visits to our public pages. See section 9.
What we do not collect. Payment card or bank account details. The documents behind your links. Billing details: nothing in Zolution asks for them today.
Please do not put passwords, verification codes, identity documents, card or bank details, or private links in any message, note or form.
Where EU or UK data protection law applies to you, we use your information to perform our agreement with you, for our legitimate interests in running a secure service and counting visits to our public pages, and to meet legal obligations.
4. Information we protect with extra measures
- Encrypted field by field, with a separate key for each purpose: document link addresses; private invitation and proposal links (kept so that their owner can see the link again); the setup records shared in an application; and the content of emails waiting to be sent.
- Kept only as one-way hashes: sign-in codes, the tokens in our cookies, the lookup copies of invitation and proposal links, and the keys of our request counters.
- The database is encrypted at rest by our hosting provider. Connections to it are encrypted, and it accepts connections only from our application.
5. Who can see your information
Other members, as the service needs:
- Providers whose declared coverage matches a published request see its seven facts (business name, website, industry, company country, customer markets, the monthly volume for one provider, and the year trading started). They never see the merchant's email address, total revenue, signer answers or documents.
- Anyone who has a merchant's proposal link sees the business name, website, industry, company country and customer markets. The volume appears only if the merchant chooses.
- Anyone who has a private invitation link sees the provider's name, its note and the invited email address.
- The provider a merchant applies to sees, from submission and while the application is open, the application details (including revenue and signer answers) and the merchant's sign-in email as the contact address, and each document link the merchant releases while that release is active.
- Both sides of an application see its conversation, decisions, setup, test and live records, reviews, and the names recorded with them.
- Merchants see the company named in an offer and its terms, not which person sent it.
Once a provider receives information from a merchant, it handles that information under its own terms and privacy policy. Zolution cannot control what a provider does with information it has received.
Zolution's people:
- Support staff see only the help requests assigned to them. They see your email address partly hidden, your business names and the stage of any request or application you mention, but not its conversation, document links or offers. They cannot sign in as you. Every support action is recorded with its reason, and staff confirm a second factor to use the support console.
- The people who run Zolution's systems can access the database when they need to maintain, secure or repair the service.
Service providers (section 6), and authorities where the law requires it.
6. Service providers
We use these kinds of providers to run Zolution:
| Provider | What it does for Zolution |
|---|---|
| Hosting and database | Runs the Zolution application and stores its database, in the United States (New York region) |
| Email delivery | Sends sign-in codes and notices, from the United States |
| Network and bot protection | Runs our domain's name service, delivers our pages and runs the bot check on forms |
| Analytics | Counts visits to our public pages |
| Support mailbox | Receives emails sent to support@zolution.io and contact-form messages |
Scroll the table to see all columns.
7. Information that leaves your country
Our hosting and database are in the United States. If you use Zolution from another country, your information is transferred to the United States and handled there.
8. How long we keep information
- No automatic deletion schedule. Apart from the things that expire (below), information stays until a deletion request is carried out (section 10).
- History is kept unchanged. Request and offer versions, invitation histories, document releases, withdrawals, displays and reviews, application records and conversations, help-request messages and support actions, plan changes and staff audit records cannot be edited or deleted in Zolution. If a deletion request covers them, the reviewer tells you what can be removed and what must be kept.
- Some things expire. A sign-in code works for 5 minutes. A session ends after 7 days without activity, and after 30 days in any case. An invitation link works for 14 days. An email's content is erased once it is delivered or expires; the record that it was sent stays.
- Removed links. You can remove a document link that was never released. It leaves your library, and we keep its record with the address encrypted. A released link stays, with its history.
- Backups. Our hosting provider backs up the database once a day and keeps each backup for seven days. Information that is changed or removed can stay in those backups for up to seven days.
- Emails to support and contact-form messages stay in our support mailbox; contact-form messages are also kept in our database so we can answer them.
9. Cookies, the bot check and analytics
- Cookies for signing in. Zolution's own cookies are only for signing in: one keeps you signed in, one links a code to the browser that asked for it, and one carries the email address you type on a public page, encrypted, to the first sign-in step for up to 30 minutes.
- Bot check. On the forms that send a sign-in code or a request, a bot check from our network provider runs in your browser. It uses your IP address and technical details of your browser and connection to tell people from bots.
- Analytics on public pages only. Our public pages and Learn articles use Google Analytics to count visits, for every visitor to those pages. It never runs on account, application or support pages, or on invitations, proposal links and document pages. We do not send it your email address or anything you type in Zolution. You can block it (see our cookie notice).
Our cookie notice lists each cookie, what it does and how long it lasts.
10. Your choices and requests
- Emails. Turn lead alerts and product news on or off on your account page. Sign-in codes, and emails about your requests, offers, applications, document links and help requests, are part of the service and cannot be switched off while you have an account.
- Corrections, deletion and other requests. On your account page, choose "Request an account change" or "Request account or data deletion". Your request becomes a help request, and support refers it for review. Nothing changes and nothing is deleted when you send it. A person reviews each request, including who is asking, and carries it out by hand within the time the law requires. Before anything is changed or removed, the reviewer explains what will change and what must be kept.
- Without an account, or if you cannot sign in, use the account recovery form or email support@zolution.io.
Depending on where you are, you may have the right to see, correct, delete or get a copy of your information, to object to or limit how we use it, and to complain to your data protection authority. Ask through your account page or at support@zolution.io.
11. Security
- Sign-in codes expire after 5 minutes, stop working after three wrong entries, and work only in the browser that asked for them.
- We limit requests per email address and per network, and we answer in the same way whether or not an account exists.
- Every request for a business's information is checked on our server against who is asking.
- Staff confirm a second factor before they can use the support console.
- Sensitive fields are encrypted or hashed (section 4).
No system is perfectly secure. If you find a security problem, tell us at support@zolution.io.
12. Children
Zolution is for businesses. It is not meant for children, and we do not knowingly collect children's information.
13. Changes to this notice
We will publish any new version here with its date.
14. Contact
support@zolution.io
MedA LLC, 30 N Gould St Ste N, Sheridan, Wyoming 82801, USA