ZZigStream

Legal

Privacy policy

Last updated: 2 September 2026

This Privacy Policy explains how ZigStream (“ZigStream”, “we”, “us”, or “our”) processes personal data when you visit our website, create or use a ZigStream account, contact us, or use the ZigStream service.

ZigStream provides telemetry ingestion, live device visibility, historical device data, dashboards, and related services for Zigbee2MQTT installations.

1. Who is responsible for your data?

The controller responsible for your personal data is ZigStream. Until a legal entity is formally registered, this policy applies to the ZigStream service operated by its founder(s). Once a company is registered, the legal entity name and details will be updated here.

If you have questions about this policy or wish to exercise your data-protection rights, contact us at privacy@zigstream.app.

2. Data we collect

Account and identity data

When you create or use an account, we may process your email address, account identifier, authentication information, subscription status, and communications with us.

Service and telemetry data

When you connect a Zigbee2MQTT installation, ZigStream may process the telemetry that you configure it to forward. This may include bridge identifiers, device identifiers, message timestamps, reported values, availability information, battery levels, link-quality information, raw payloads, and related metadata.

Telemetry can reveal information about a household’s environment, routines, occupancy, or energy use. Do not forward data that you do not want to store or process through the service.

Technical and usage data

We may process technical information needed to operate and secure the service, such as IP address, browser and device information, request timestamps, authentication events, error logs, and service-usage information.

Support and communication data

If you contact us, we process the information you provide, including your email address, message content, attachments, and information needed to respond to your request.

3. Why we use your data

We use personal data for the following purposes:

  • To create and administer your account.
  • To authenticate requests and protect the service.
  • To ingest, associate, display, and retain the telemetry you send.
  • To provide live views, historical views, APIs, and other requested functionality.
  • To measure usage where needed to apply plan limits or calculate charges.
  • To diagnose errors, prevent abuse, and maintain service security.
  • To respond to support requests and service communications.
  • To comply with legal obligations and establish or defend legal claims.

4. Legal bases

Depending on the context, we rely on one or more of the following legal bases under the GDPR:

  • Contract: processing needed to provide the service you requested, manage your account, and perform our agreement with you.
  • Legitimate interests: operating, securing, improving, and supporting the service, provided those interests are not overridden by your rights.
  • Legal obligation: processing required by applicable law.
  • Consent: where we ask for consent, such as for optional cookies or certain communications. You may withdraw consent at any time.

If we rely on a legitimate interest, the relevant interest is identified in the applicable context, such as service security, abuse prevention, operational support, or product improvement.

5. Telemetry responsibility

You decide which Zigbee2MQTT data is sent to ZigStream and are responsible for configuring your local installation appropriately. Do not send personal data belonging to other people unless you have a lawful basis and any required permissions to do so.

ZigStream uses telemetry to provide the service requested by the account holder. We do not use customer telemetry to train general-purpose AI models unless we clearly state this and obtain any consent or authorization required by law.

6. Sharing and service providers

We may share personal data with service providers that process it on our behalf, such as hosting, storage, authentication, email, monitoring, analytics, customer-support, and payment providers.

Our current providers are:

  • Cloud infrastructure: Cloudflare (hosting, storage, edge compute, and related services).
  • Payments: Stripe (when paid plans are enabled).

We may also disclose data where required by law, to protect the rights and safety of ZigStream or others, or as part of a merger, acquisition, financing, or sale of assets.

7. International transfers

Some service providers may process data outside the European Economic Area. Where data is transferred internationally, we use an applicable legal transfer mechanism, such as an adequacy decision or standard contractual clauses, together with any supplementary measures required by law.

Cloudflare and Stripe operate global infrastructure. Their privacy policies and data transfer mechanisms (including standard contractual clauses where applicable) describe how they handle international transfers. We rely on these mechanisms for transfers to providers outside the EEA.

8. Retention

We retain data only for as long as necessary for the purposes described in this policy, unless a longer period is required by law.

  • Account data: retained while your account is active and for a reasonable period thereafter to support account recovery, legal obligations, and dispute resolution.
  • Telemetry: retained according to the retention policy associated with your plan and configuration. You can delete devices or your account to remove associated data.
  • Security and access logs: retained for a limited period needed for security monitoring and incident response.
  • Backups: retained for a limited period to support recovery from accidental loss or corruption.
  • Deleted accounts: personal data is removed from active systems within a reasonable timeframe after account deletion, subject to backup cycles and legal retention requirements.
  • Billing and legal records: retained as required by applicable accounting and tax laws.

9. Security

We use technical and organisational measures designed to protect data against unauthorized access, loss, misuse, alteration, or disclosure. These measures may include access controls, authentication, encryption in transit, environment separation, monitoring, and backup procedures.

No internet service can guarantee absolute security. Keep your API tokens confidential and revoke or rotate them if you believe they have been exposed.

10. Your rights

Subject to applicable conditions and exemptions, you may have the right to request access to, correction of, deletion of, or restriction of processing of your personal data. You may also have the right to object to certain processing and to receive data in a portable format.

Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect processing that took place before withdrawal.

To exercise a right, contact privacy@zigstream.app. We may need to verify your identity before completing a request.

11. Complaints

You may contact us first so that we can try to resolve your concern. You also have the right to lodge a complaint with the data-protection supervisory authority in the country where you live, work, or believe an infringement occurred.

For Belgium, the supervisory authority is the Belgian Data Protection Authority.

12. Cookies and similar technologies

We use only the cookies needed for authentication and session management. Specifically, we set a session cookie to keep you logged in while using the dashboard. This cookie is essential for the service to function and is not used for tracking or advertising.

13. Changes to this policy

We may update this policy when our service, data processing, or legal obligations change. We will publish the updated version on this page and change the “Last updated” date.

14. Contact

For privacy questions or requests, contact privacy@zigstream.app.