Privacy Policy

Last updated: August 2026

1. Who We Are (Data Controller)

LIZZA TECH, S.A.P.I. de C.V. ("Lizza", "we", "us", or "our") is the data controller responsible for the personal information described in this Privacy Notice.

Legal name: LIZZA TECH, S.A.P.I. de C.V.

Tax ID (RFC): FME200403CF3

Registered address: Av. José Vasconcelos 210, Residencial San Agustín 1er Sector, 66260 San Pedro Garza García, Nuevo León, Mexico

Privacy contact: privacy@lizza.ai

This Privacy Notice describes how we collect, use, share, and protect personal information when you use our platform, website, applications, and related services (collectively, the "Service"). It is issued in compliance with the Mexican Federal Law on the Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares) and its regulations, and applies alongside any additional rights you may have under the law of your own jurisdiction.

By using the Service, you acknowledge the practices described in this notice.

2. Information We Collect

We collect information that you provide directly to us (such as account registration data, profile information, and communications), information generated through your use of the Service (such as usage data, interaction logs, and device information), and information from third-party sources (such as social media platforms you connect to the Service). The specific data collected depends on how you use the Service and which features you access.

3. How We Use Your Information

We use your information to: (a) provide, operate, maintain, and improve the Service; (b) process transactions and facilitate collaborations; (c) communicate with you about the Service; (d) personalize your experience; (e) ensure platform security and prevent fraud; (f) comply with legal obligations; (g) enforce our Terms and Conditions; and (h) for any other purpose with your consent.

4. Information Sharing and Disclosure

We may share your information with: (a) other platform users as necessary to facilitate collaborations and the functioning of the Service; (b) third-party service providers who assist in operating the Service (payment processors, hosting providers, analytics services); (c) professional advisors (lawyers, accountants, auditors); (d) law enforcement or government authorities when required by law or to protect our rights; and (e) in connection with a merger, acquisition, or sale of assets. We do not sell your personal information to third parties.

5. Service Providers and Subprocessors

We rely on third-party providers to operate the Service. They process personal information on our behalf, under contractual confidentiality and security obligations, and are not authorized to use it for their own purposes. They fall into the following categories: cloud infrastructure, database and file storage; payment processing; connections to brands' online stores; transactional email and messaging; electronic signature; tax document validation; error monitoring and analytics; and artificial intelligence providers that power automated features of the Service. A current list of these providers is available on request at privacy@lizza.ai.

6. Public Profiles

Certain profile information may be publicly accessible, including creator media kits and brand profiles. Users control what information appears on their public-facing profiles. By making information public, you acknowledge that it may be accessed, indexed, and used by third parties.

7. Connected Store Data

When a brand connects its online store (for example Shopify or Tienda Nube) to the Service, we access a limited set of data from that store in order to create and track product shipments to creators. This is limited to the recipient's name, email address, phone number and shipping address for the specific orders we create, together with the resulting order and fulfillment status.

For this data we act on the brand's instructions as a processor; the brand remains the controller and is responsible for it. We process only the minimum required to create the order and follow its delivery, and we do not use it for marketing, advertising, profiling or analytics. We delete it once it is no longer needed for that purpose — currently 180 days after a shipment reaches its final state — and we honor deletion requests submitted by the brand or forwarded by their e-commerce platform.

This is separate from a shipping address that a creator provides to us directly in order to receive a product, which we hold in our own right under this policy.

8. Data Security

We implement commercially reasonable technical and organizational measures to protect your personal information. However, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security of your data, and you use the Service at your own risk.

9. Security Incident Notification

If a security incident affects your personal information in a way that could materially affect your rights, we will notify you without undue delay and in any case within 72 hours of becoming aware of it. That notice will describe what happened, the categories of information involved, the measures we have taken, and the steps you can take to protect yourself, and will include a contact point for questions. Where applicable law requires it, we will also notify the competent supervisory authority.

10. Data Retention

We retain your personal information for as long as your account is active, as needed to provide the Service, or as required by law. When retention is no longer necessary, we will delete or anonymize your data in accordance with our internal data management procedures.

11. Cookies and Tracking Technologies

We use cookies and similar tracking technologies for authentication, functionality, analytics, and performance purposes. You can manage your cookie preferences through your browser settings, though disabling certain cookies may affect the functionality of the Service.

12. Limiting the Use or Disclosure of Your Information

In addition to the rights described in the next section, you may at any time limit how we use or disclose your personal information. Specifically, you may:

(a) unsubscribe from marketing and non-essential communications, using the unsubscribe link in any such message or by writing to privacy@lizza.ai; (b) disable or restrict optional integrations, such as connected social accounts, from your account settings; (c) manage cookies and similar technologies through your browser settings; (d) ask us to stop using your information for a specific purpose that is not necessary to provide the Service, by writing to privacy@lizza.ai.

We will confirm receipt of any such request and act on it within the period stated in the next section. Limiting certain uses may reduce the functionality available to you, and we will tell you when that is the case.

13. Your Rights (ARCO Rights)

You have the right to Access, Rectify, Cancel (delete) and Object to the processing of your personal information — known collectively under Mexican law as your ARCO rights. You may also withdraw consent you previously gave, and request portability of your data where applicable law provides for it.

To exercise any of these rights, write to privacy@lizza.ai with: (a) your name and a contact address for our reply; (b) a document proving your identity, or that of your legal representative; (c) a clear description of the personal data concerned and the right you wish to exercise; and (d) any element that helps us locate the data.

We will respond to your request within 20 business days of receiving it. If the request is granted, we will give effect to it within 15 business days of communicating our response. If we need further information to process your request, we will tell you within 5 business days.

There is no charge for exercising these rights, other than justified shipping or certification costs where you request copies in a particular format. Where we cannot grant a request in full — for example where we are required by law to retain fiscal records — we will explain why.

If you are dissatisfied with our response, you may bring the matter before the competent data protection authority in Mexico.

14. International Data Transfers

Lizza stores and processes personal information in the United States, where our cloud infrastructure provider operates. Additional service providers may process limited personal information in Mexico, the United States, Latin America and the European Union; the categories of these providers are described in Section 5 and a current named list is available on request at privacy@lizza.ai.

These transfers are made so that we can provide the Service to you, and are covered by contracts that impose confidentiality and security obligations on each provider equivalent to those in this notice. We do not sell your personal information, and we do not transfer it to third parties for their own independent purposes.

If you do not wish your personal information to be transferred as described in this section, you may object by writing to privacy@lizza.ai. Because our infrastructure is located outside Mexico, objecting to these transfers may mean we can no longer provide the Service to you, and we will explain the consequences before acting on your objection.

15. Children's Privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete such information promptly.

16. Changes to This Notice

We may update this Privacy Notice from time to time. We will notify you of material changes by posting the updated notice at this address with a revised "last updated" date, and, where the change is significant, by notifying you through the Service or by email to the address associated with your account. Your continued use of the Service after a change takes effect constitutes acceptance of the updated notice. Previous versions are available on request at privacy@lizza.ai.

17. Contact

For privacy-related inquiries, to exercise your ARCO rights, or to request our current list of service providers, contact our privacy officer at privacy@lizza.ai.