zplCloud.com
Privacy Policy
This privacy policy informs you, in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR), about the personal data we process when you use the website zplcloud.com, the zplCloud platform, the REST API, the Weblink service, the agent and the CLI tools (together the "Service"), on which legal basis we do so and which rights you have.
Last updated: 14 September 2026
1. Controller
The controller within the meaning of the GDPR is:
iqmeta GmbH
Am Sonnenhang 24
71111 Waldenbuch, Germany
Represented by: Managing Director Otto Neff
Email: support@zplcloud.com · Phone: +49 7157 563 111
For all questions regarding data protection you can reach us at support@zplcloud.com. Further details about the provider can be found in the Imprint.
2. Principles and legal bases
We process personal data only to the extent necessary to provide the Service, to perform contracts, to pursue legitimate interests or to comply with legal obligations, or where you have given your consent. The applicable legal basis is stated for each processing activity: Art. 6 (1) (a) GDPR (consent), (b) (contract and pre-contractual measures), (c) (legal obligation) and (f) (legitimate interest).
We do not sell personal data and do not use advertising services. Web analytics (Google Analytics) only runs with your consent (section 4). We disclose data only to the recipients named in this policy.
3. Hosting and server log files
The servers on which zplcloud.com and its subdomains run are located exclusively in Germany: we operate them ourselves on a dedicated server of Hetzner Online GmbH (data centre in Falkenstein); emergency recovery takes place at netcup GmbH, also in Germany. Both providers are bound by data processing agreements (Art. 28 GDPR). The third-party providers named in this policy (such as payment, sign-in or messaging providers) operate their systems at the locations stated in their own privacy notices, possibly also outside the European Union; see the respective sections and section 16 for details. When you access the Service, the server automatically records the following data in log files: IP address, date and time of access, requested URL, HTTP status code, amount of data transferred, referrer URL, and browser type and operating system (user agent). An upstream reverse proxy forwards the real client IP address to the application so that abuse protection and security logs work correctly.
The purpose is the technically sound and secure operation of the Service, defence against attacks and error analysis. The legal basis is Art. 6 (1) (f) GDPR. Log files have a limited storage size and are overwritten continuously; we keep individual entries longer only where this is required to investigate a specific security incident or by law.
To protect against abuse we limit the number of requests to individual functions (rate limiting). The assignment to an IP address or account required for this takes place in memory only and is not stored permanently.
Operating telemetry: To monitor the stability and performance of the Service, our servers and the platform web app record technical telemetry (metrics and traces) using OpenTelemetry, for example the requested path, HTTP method, status code, duration, error messages including technical error details (stack traces), browser identifier (user agent) and, for persistent WebSocket and SignalR connections (e.g. printer or live status connections), the IP address. Label, design and form contents are not part of this telemetry. The legal basis is Art. 6 (1) (f) GDPR (secure and stable operation).
4. Cookies, consent and Google Analytics
We use technically necessary cookies and comparable storage techniques that are required to provide the service you have expressly requested (Section 25 (2) no. 2 of the German Telecommunications Digital Services Data Protection Act, TDDDG); no consent is required for these. Cookies for web analytics (Google Analytics) are only set, and the associated script is only loaded, after you have given your consent in the cookie banner (Section 25 (1) TDDDG, Art. 6 (1) (a) GDPR). We do not use marketing or advertising cookies.
Technically necessary are: a login cookie ("zplcloud.identity", lifetime up to one month, extended on activity) that authenticates you after signing in; a cookie storing your chosen colour scheme ("zplcloud-theme", domain-wide for zplcloud.com, long-term); a security token protecting against cross-site request forgery; short-lived correlation cookies that are set only during a sign-in via an external provider (section 6); and the cookie "zplcloud_consent" (domain-wide for zplcloud.com, lifetime 12 months), which stores your decision in the cookie banner so that we do not ask again on every page. The platform additionally stores your language choice and the label designer's editor settings locally in your browser (local storage); this data does not leave your device.
The legal basis for the processing associated with these necessary cookies is Art. 6 (1) (b) GDPR (provision of the Service) and Art. 6 (1) (f) GDPR (security). You can delete or block cookies at any time in your browser settings; login and some convenience functions will then be unavailable.
Cookie banner: When you first visit zplcloud.com or one of its subdomains (including the platform, the API documentation at api.zplcloud.com and print views), we ask for your consent to web analytics. "Reject" and "Accept analytics" are offered as equal choices; until you decide, no analytics script is loaded and no analytics cookie is set. You can change or withdraw your decision at any time with effect for the future via the Cookie settings link at the bottom of every page; if you withdraw your consent, the analytics cookies set in your browser are deleted.
Google Analytics: With your consent we use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). It helps us understand how visitors use our website and platform (e.g. pages viewed, time spent, referring website, device and browser type, approximate location at country or region level) so that we can improve content and usability. For this purpose Google sets the cookies "_ga" and "_ga_CN5XTC62RK" (pseudonymous user and session identifiers, lifetime up to 13 months). Google Analytics 4 does not store IP addresses; they are only used briefly to derive the approximate location and are then discarded. We have disabled Google signals and advertising personalisation; the data is not used to build advertising profiles.
The legal basis is your consent (Section 25 (1) TDDDG, Art. 6 (1) (a) GDPR), which you can withdraw at any time via "Cookie settings". Google processes the data on our behalf as a processor under the Google Ads Data Processing Terms. A transfer of data to Google LLC in the USA cannot be ruled out; Google LLC is certified under the EU-US Data Privacy Framework, so the transfer is based on the European Commission's adequacy decision, supplemented by standard contractual clauses. Analytics data is retained in Google Analytics for 14 months and then deleted automatically. Further information: Google privacy policy and Google Ads Data Processing Terms.
5. Registration, user account and sign-in security
A user account is required to use the platform. During registration we process your email address, a password of your choice (stored exclusively as a cryptographic hash), optionally your name and company, and the time of registration. To confirm your address we send you an email with a confirmation link (double opt-in).
To protect your account we log sign-in events with date, time, IP address and browser identifier and show you your active sessions. To display an approximate location (city, country) in this overview, we match the IP address against a geolocation database stored locally on our server. The IP address is not transmitted to any third party for this; only the location at city level is stored. The database is provided by DB-IP (IP Geolocation by DB-IP, licence CC BY 4.0) and is updated monthly. You can optionally enable two-factor authentication; we store the secrets required for this in our access-protected database and use them only to verify your codes.
The legal basis is Art. 6 (1) (b) GDPR (performance of the contract) and, for the security logs, Art. 6 (1) (f) GDPR (protection against unauthorised access). Session and sign-in logs are kept for as long as your account exists; you can end individual sessions at any time. You can delete your account yourself at any time in the account settings; your account data and session logs are then deleted and your content is separated from your person (anonymised). On request we also delete the content completely, unless statutory retention obligations apply (section 15).
6. Sign-in with Google, Microsoft or Apple
You may optionally register and sign in with an existing Google, Microsoft or Apple account. If you use this option you are redirected to the respective provider and sign in there. We then receive from the provider a unique user identifier, your email address and, where released, your name. We do not retrieve any further data from your account with the provider. Which data the provider itself collects is governed by its own privacy policy.
Providers: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (privacy policy); Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (privacy statement); Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland (privacy policy). Data may be transferred to the USA; the companies named are certified under the EU-US Data Privacy Framework (adequacy decision of the European Commission, Art. 45 GDPR).
The legal basis is Art. 6 (1) (b) GDPR; external sign-in is used only at your express request. You can unlink the connection at any time in your account settings and set a password instead.
7. Use of the platform: content, printers, data sources
While you use the Service we store the content and configurations you create: label designs, templates, ZPL code, graphics and fonts, print views, print jobs and their logs, connected printers (serial number, model, firmware, network address, certificates), Weblink and agent connections, API keys, webhook targets, data sources (e.g. connection details of your SQL Server), stream subscriptions (Kafka, Azure Service Bus, MQTT, AMQP 1.0, RabbitMQ, Amazon SQS, Google Pub/Sub), connected object storage (Amazon S3, Azure Blob Storage) and CLI start configurations. Credentials for data sources, streams, object storage and push channels are stored in encrypted form, API keys only as a cryptographic hash (the full key is shown once when it is created). We use all credentials solely to execute the function you configured.
We process this data exclusively to provide the Service to you (Art. 6 (1) (b) GDPR). For billing and capacity planning we record usage metrics such as the number of rendered labels and API calls per account (Art. 6 (1) (b) and (f) GDPR).
If your content contains personal data of third parties – for example recipient addresses on shipping labels or data from connected databases – you are the controller for that data and we act as a processor pursuant to Art. 28 GDPR. We will provide you with a data processing agreement including the required technical and organisational measures on request at support@zplcloud.com.
Marketplace and shipping integrations: If you connect an integration such as Shopify, ShipStation or Veeqo in the platform, we use the credentials or authorisation you provide to retrieve open orders with shipping address and line items from your account with that provider in order to create labels. Data is exchanged with these providers only once you have connected the respective integration. The provider's own terms and privacy policy apply to processing on its side; data may be transferred to third countries. For these data we act as a processor on your behalf (see above); the legal basis is Art. 6 (1) (b) GDPR.
8. Converters and online tools
Our freely usable tools (e.g. PDF, HTML, image and SVG to ZPL converters, barcode generator, ZPL preview) process uploaded files and entered content in memory only for the duration of the respective conversion. The content is not stored permanently; the data is discarded immediately after the result has been delivered. The legal basis is Art. 6 (1) (b) GDPR. The rate limiting described in section 3 applies to protect against abuse.
9. Payment processing via Stripe
Paid plans and add-ons are billed through the payment service provider Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland ("Stripe"). You enter payment details such as card numbers or bank details, your billing address and, as a business, optionally your VAT identification number directly on pages provided by Stripe; we never receive card data. Stripe determines the VAT portion included from the billing address and, where provided, the VAT identification number and validates the VAT identification number via the European Commission's VAT Information Exchange System (VIES); the validation result is stored as evidence for the reverse-charge treatment. We transmit to Stripe your email address, the selected plan, amount and currency, and a customer identifier; from Stripe we receive the status of payments and subscriptions, invoice information, billing address and VAT identification number. Stripe issues and emails invoices on our behalf. When you complete an order we log your confirmations given during checkout (acceptance of the Terms, request to begin performance before the end of any withdrawal period) together with time, plan, IP address and browser identifier in order to evidence the conclusion of the contract (Art. 6 (1) (b) and (f) GDPR).
The legal basis is Art. 6 (1) (b) GDPR (performance of the contract) and Art. 6 (1) (c) GDPR for retention under commercial and tax law. Stripe may transfer data to affiliated companies in the USA; Stripe, Inc. is certified under the EU-US Data Privacy Framework and standard contractual clauses apply in addition. Details: Stripe privacy policy. We log subscription events (creation, change, cancellation) to manage your entitlements correctly and to keep bookings traceable.
10. Deutsche Post INTERNETMARKE (DHL integration)
If you enable the Deutsche Post INTERNETMARKE integration, you link your own Portokasse account with zplCloud. We store the required credentials in our access-protected database and use them only for the purchases you trigger. When you buy a stamp we transmit the data you entered (sender and recipient address, product, format, amount) to Deutsche Post AG, Charles-de-Gaulle-Straße 20, 53113 Bonn, Germany, which concludes the purchase contract for the stamp with you. For each transaction we store a log with voucher ID, amount, balance and the generated stamp (PDF/ZPL) so that you can reprint stamps and trace costs.
The legal basis is Art. 6 (1) (b) GDPR. We keep the transaction log for as long as you use the integration and thereafter to the extent statutory retention obligations apply. Deutsche Post's privacy information is available at deutschepost.de.
11. Notifications and messaging integrations
Web push: On request we send you browser notifications, for example about completed print jobs. Your browser asks for your consent; we then store the push endpoint generated by the browser and the associated keys. Delivery takes place via the push service of your browser vendor (e.g. Google, Mozilla, Apple), which only sees encrypted messages. The legal basis is your consent (Art. 6 (1) (a) GDPR), which you can withdraw at any time in your browser or account settings.
ntfy and Gotify: These push channels become active only if you configure them. For ntfy you can enter the server yourself; if you leave the field empty, the public server ntfy.sh is used, which is operated by a third party, not by us. For Gotify you enter the address of your own server. The topic or token and the message content you define are transmitted to the server you have chosen; the legal basis is Art. 6 (1) (b) GDPR.
Telegram, Signal, WhatsApp, webhooks and email notifications: These channels become active only if you configure them with your own credentials or target addresses. The message content you define is then transmitted to the respective provider (Telegram FZ-LLC, Signal Technology Foundation, WhatsApp Ireland Limited / Meta Platforms Ireland Limited) or to your webhook target. The respective provider's terms apply to processing there; data may be transferred to third countries. The legal basis is Art. 6 (1) (b) GDPR; you alone decide which content you send via which channel.
12. Email
We send transactional emails (registration confirmation, password reset, security notices, subscription and invoice information, notifications you configured) via our mail server. Incoming emails to zplcloud.com addresses (for example our support address) first pass through an email gateway operated by us, which checks them for spam and malware before they reach our mailbox; the mail server and gateway run on our servers in Germany (section 3). We send promotional emails or newsletters only with your express consent (Art. 6 (1) (a) GDPR, Section 7 of the German Act against Unfair Competition, UWG); you can withdraw any consent given at any time via the unsubscribe link or by emailing us.
13. Contact, support and feedback
If you contact us by email, via the contact form, the feedback function or support, we process the information you provide (name, email address, message content, and where applicable screenshots and account information) to handle your request. The same applies to notices of illegal content under Art. 16 of the Digital Services Act submitted via the reporting channel described on the contact page; in that case we additionally process the details of the reported content and inform the affected user of our decision without disclosing your identity unless this is necessary to handle the notice. The legal basis is Art. 6 (1) (b) GDPR where the request relates to a contract, Art. 6 (1) (c) GDPR for handling DSA notices, and otherwise Art. 6 (1) (f) GDPR (responding to enquiries). We keep requests for as long as necessary to handle them and to keep our support traceable; at your request we delete them unless statutory retention obligations apply.
14. External links, fonts and embedded content
We serve all fonts, scripts and stylesheets from our own servers and do not embed third-party content (e.g. Google Fonts, content delivery networks, map or video services). The only exception is the Google Analytics script, which is loaded from Google's servers only after you have given your consent (section 4). Without that consent, your IP address is not transmitted to any third party when you open our pages. Links to external services (e.g. GitHub, vendor documentation) are recognisable as such; data is transferred to the respective provider only once you click such a link.
15. Retention periods
We store personal data only for as long as necessary for the purposes stated. The following criteria apply: we store account data and content for the duration of the contractual relationship; when the account is deleted we delete the account data and separate the content from your person, and on request we also delete the content completely. After a contract ends we provide business customers, on request, with an export of their data within 30 days and delete the data afterwards; free accounts that are permanently unused may be deleted after prior notice by email. Technical logs are kept for as long as required for secure operation. Data subject to statutory retention obligations (in particular invoices and accounting records under Section 147 of the German Fiscal Code (AO) and Section 257 of the German Commercial Code (HGB), and business correspondence) is retained for the duration of those obligations, with processing restricted to fulfilling the obligation during that time. Once the purpose no longer applies and the periods have expired we delete or anonymise the data.
16. Recipients and transfers to third countries
Within our company only those persons who need your data for the stated purposes have access to it. External recipients are the service providers and contractual partners named in this policy: Google for web analytics with your consent (section 4), Google, Microsoft and Apple for external sign-in (section 6), Stripe (section 9), Deutsche Post AG (section 10), the messaging and webhook targets you configure yourself, including the ntfy server you choose (section 11), the providers of the marketplace and shipping integrations you connect (section 7), the hosting providers Hetzner Online GmbH and netcup GmbH as processors with data centres in Germany (section 3) and, with your consent, Zebra Technologies and its authorised sales partners (section 21). Public authorities receive data only where we are legally obliged to disclose it.
Where data is transferred to countries outside the European Economic Area, this is based on an adequacy decision of the European Commission (in particular the EU-US Data Privacy Framework) or on the European Commission's standard contractual clauses (Art. 46 (2) (c) GDPR). A copy of the respective safeguards is available on request.
17. Data security
All connections to the Service are encrypted with TLS. Passwords and API keys are stored exclusively as cryptographic hashes; credentials for data sources, streams, object storage and push channels are stored in encrypted form. Access to production systems is restricted to a small number of authorised persons; access by our support to customer accounts is recorded in the audit trail. We back up the systems in encrypted form every six hours, test recovery regularly and keep the technical and organisational measures under Art. 32 GDPR in line with the state of the art.
18. Your rights
You have the following rights against us: access to the data processed (Art. 15 GDPR), rectification of inaccurate data (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to withdraw any consent given at any time with effect for the future (Art. 7 (3)). Much of your data can be viewed, changed and deleted directly in your account; we provide a complete export of your data on request.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement. The supervisory authority responsible for us is: The State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI), Lautenschlagerstraße 20, 70173 Stuttgart, Germany.
To exercise your rights an informal message to support@zplcloud.com is sufficient.
19. Right to object
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you that is based on Art. 6 (1) (f) GDPR (legitimate interest) (Art. 21 (1) GDPR). We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. Where your data is processed for direct marketing purposes, you may object at any time without giving reasons (Art. 21 (2) GDPR).
20. No automated decision-making, no services for children
We do not make decisions based solely on automated processing that produce legal effects, and we do not carry out profiling. Our Service is aimed at businesses and at persons aged 16 or over; we do not knowingly collect data from children.
21. Hardware recommendations and disclosure to Zebra Technologies
iqmeta GmbH, the operator of zplCloud, is a registered Independent Software Vendor (ISV) in the Zebra PartnerConnect programme of Zebra Technologies. If you request a hardware recommendation via the page Zebra hardware or a corresponding button in the platform, we process the details you provide about your project (description, hardware categories, quantity, timeframe, budget, industry), your company (name, website, country, city and, where applicable, the end customer) and your contact details (name, email address, optionally phone number and job title), together with the origin of the request (page or function), language, IP address and browser identifier, in order to advise you and, where applicable, register the project with Zebra.
With your express consent given in the request form, we disclose these project and contact details to Zebra Technologies Corporation (3 Overlook Point, Lincolnshire, IL 60069, USA) and its European affiliates as well as to Zebra's authorised sales partners (PartnerConnect resellers), so that Zebra or a partner can contact you about demo devices, quotes and local support and can verify the project. Zebra processes this data as an independent controller under its own privacy notice (Zebra Privacy Statement). Transfers to the USA are based on the EU-US Data Privacy Framework and/or the European Commission's standard contractual clauses (see section 16). As part of Zebra's Influence Registration programme, iqmeta GmbH may receive demo equipment, financial rewards or other benefits from Zebra for registered projects; this does not result in any costs for you.
The legal basis is Art. 6 (1) (a) GDPR (consent) for the disclosure to Zebra and its partners and Art. 6 (1) (b) GDPR (pre-contractual measures) for the advice itself. You can withdraw your consent at any time with effect for the future by emailing support@zplcloud.com; data already transmitted to Zebra is then handled under Zebra's own rules. We retain the request for as long as necessary to handle it and to document the registration with Zebra; afterwards it is deleted unless statutory retention obligations apply (section 15).
22. Changes to this privacy policy
We update this privacy policy when the Service, the service providers we use or the legal situation change. The current version is always available at zplcloud.com/en/privacy; the date of the last change is shown at the top of the page. We inform registered users of material changes by email or by a notice in the platform.
Questions about privacy? Write to support@zplcloud.com. Provider details can be found in the Imprint.