Privacy Policy
Last updated: August 2026
This Privacy Policy explains how Zenvy ("we", "us", "our") collects, uses, shares, and protects personal data in connection with:
- The Zenvy Advertiser Portal at myzenvy.app — used by businesses to manage campaigns and creatives.
- The Zenvy mobile app — used by consumers to discover beauty and lifestyle content and sponsored listings.
We are the data controller for the purposes of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, for users in India, the Information Technology Act 2000 and applicable rules thereunder.
1. Who We Are
Zenvy is a trading name of J Mani, a sole trader based in the United Kingdom. For all data protection enquiries, contact us at privacy@myzenvy.app.
2. What Data We Collect
2A. Advertiser Portal (myzenvy.app)
When you register and use the advertiser portal:
- Name and email address
- Business name, location, and contact details
- Password (stored as a one-way bcrypt hash — we never store plaintext passwords)
- OAuth tokens if you sign in via Google, Microsoft, or Facebook (we do not store access tokens; only a provider ID is retained)
- Payment information — processed by Stripe (UK/international) or Razorpay (India); we do not store card numbers or bank account details
- Creative content you upload (images, videos, audio files)
- Campaign and credit activity logs
- IP address and general browser/device information for security and fraud prevention
- Support communications you send us
2B. Zenvy Mobile App (consumer)
The Zenvy app does not require you to create an account or log in. The following data is collected or processed when you use the app:
| Data type | How it is used | Sent to Zenvy? | Linked to device? |
|---|---|---|---|
| App-scoped pseudonymous device ID (a random UUID stored in encrypted device storage — not IDFA or GAID) | Sent with every analytics event for deduplication and session continuity. Not linked to your name, email, or any real-world identity. | Yes | Yes — linked to device, not to person |
| In-app interaction events (card viewed, sponsored ad tapped, search performed, save/unsave) | Measures content performance and helps advertisers understand reach. Sent with the device ID and app version. | Yes | Yes (via device ID) |
| Device type, OS, app version, platform (iOS / Android) | Included in analytics events for compatibility and crash diagnostics. | Yes | Yes (via device ID) |
| Precise GPS location (latitude / longitude) | Used on-device to find nearby businesses in the Discover tab. The app never sends coordinates to Zenvy's servers. The device may use its operating-system geocoding service (Google on Android, Apple on iOS) to derive approximate address information such as city, postcode, or country. | No — on-device / OS geocoding only | N/A |
| UK postcode (if you choose to enter one manually) | Sent to api.postcodes.io (a public UK geocoding service) to convert your postcode to coordinates for Discover. Zenvy does not receive the postcode. | No — goes to postcodes.io only | N/A |
| Location method and permission status (granted / denied / remembered) | Logged as an analytics event so we can understand how users engage with the Discover feature. | Yes | Yes (via device ID) |
| Onboarding interests, saves, collections, reminder settings, remembered location | Stored locally on your device only in app storage. Never transmitted to Zenvy. | No — on-device only | N/A |
The device ID is pseudonymous— it identifies your device installation but cannot be traced back to you as a person. It is not Apple's IDFA, not Google's GAID, and is not shared with any advertising network. We do not collect: your name, email, phone number, photos, contacts, microphone input, or payment information.
3. How We Use Your Data
3A. Advertiser Portal
| Purpose | Legal basis (UK GDPR) |
|---|---|
| Providing and managing your advertiser account | Contract (Art. 6(1)(b)) |
| Processing payments | Contract (Art. 6(1)(b)) |
| Moderating and publishing your creatives | Contract (Art. 6(1)(b)) |
| Sending transactional emails (credit expiry, creative approval / rejection) | Contract (Art. 6(1)(b)) |
| Detecting fraud and preventing abuse | Legitimate interests (Art. 6(1)(f)) |
| Improving the platform and diagnosing technical issues | Legitimate interests (Art. 6(1)(f)) |
| Complying with legal obligations (e.g. financial record-keeping) | Legal obligation (Art. 6(1)(c)) |
| Sending feature updates (you may opt out at any time) | Legitimate interests (Art. 6(1)(f)) |
3B. Zenvy Mobile App
Pseudonymous analytics events (identified by the app-scoped device ID) are used solely to measure content popularity and advertiser reach. They are never used to build personal profiles, serve behavioural advertising, or share data with ad networks or data brokers.
4. Third Parties We Share Data With
We do not sell your personal data. We share data only where necessary to operate the platform:
| Provider | Purpose | Applies to |
|---|---|---|
| Stripe | Payment processing (UK / international) | Portal advertisers |
| Razorpay | Payment processing (India) | Portal advertisers in India |
| Vercel | Hosting and edge delivery | Portal & app API |
| Cloudflare R2 | Media file storage (images, videos, audio) | Portal advertisers |
| Neon / PostgreSQL | Database hosting | Portal & app |
| Resend | Transactional email delivery | Portal advertisers |
| Upstash Redis | Rate limiting and session cache | Portal & app API |
| api.postcodes.io | UK postcode geocoding — your postcode is sent to this service to find coordinates for the Discover tab. No account or personal data is required. See postcodes.io for their privacy terms. | Mobile app (UK users who enter a postcode) |
| Google (Android) / Apple (iOS) — OS geocoding service | When GPS is used, the device operating system may send coordinates to the platform geocoding service to derive an approximate address (city, postcode, country). This is handled by the OS, not Zenvy. Subject to the Google Privacy Policy or Apple Privacy Policy respectively. | Mobile app (users who grant location permission) |
All providers are contractually bound to handle your data in accordance with applicable data protection law. Where providers process data outside the UK or India, we rely on Standard Contractual Clauses or equivalent adequacy safeguards.
5. App Tracking and Cross-App Data Use
The Zenvy mobile app uses a pseudonymous app-scoped device ID (a random UUID generated on first launch and stored in encrypted device storage). This ID is used only within Zenvy to deduplicate analytics events and is never shared with advertising networks, data brokers, or any third party.
The app does notuse Apple's Advertising Identifier (IDFA), Google's Advertising ID (GAID), or any fingerprinting technique. We do not track you across third-party apps or websites. No App Tracking Transparency (ATT) prompt is shown because Zenvy does not engage in cross-app or cross-site tracking as defined by Apple.
All analytics events go directly to our own servers. We do not use Firebase, Amplitude, Mixpanel, or any third-party analytics or crash-reporting SDK.
6. Data Retention
Advertiser Portal
- Account data is retained while your account is active and for up to 7 years afterwards to meet UK financial record-keeping requirements.
- Creative media files are deleted from our CDN within 30 days of the creative expiring or being removed.
- Payment records are retained for the period required by applicable tax law (7 years in the UK; 8 years in India).
Mobile App
- Analytics events (including the pseudonymous device ID) are retained on our servers for up to 24 months, then deleted.
- To delete all server-side records associated with your device, email privacy@myzenvy.app with the subject "Mobile Data Deletion" and include your device ID (found in the app under Profile → Your device ID). We will delete all matching records within 30 days.
- Data stored only on your device (saves, collections, reminders, location) is removed when you uninstall the app or clear app data in your device settings.
7. Data Deletion Requests
To delete your advertiser account and all associated personal data, email privacy@myzenvy.app with the subject line "Data Deletion Request" and the email address on your account. We will complete deletion within 30 days, subject to any legal retention obligations (e.g. financial records).
We do not maintain an account identity for Zenvy app users. You can uninstall the app to remove all locally stored data (saves, collections, reminders, remembered location). To also remove matching server-side analytics records, use the device-ID deletion route described in Section 6 above — email privacy@myzenvy.app with subject "Mobile Data Deletion" and include your device ID (found in the app under Profile → Your device ID).
8. Your Rights
UK users (UK GDPR)
You have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — request deletion of your data
- Restriction — ask us to restrict how we process your data
- Portability — receive your data in a machine-readable format
- Object — object to processing based on legitimate interests, including direct marketing
To exercise any right, email privacy@myzenvy.app. We will respond within one calendar month. You may also lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Indian users (IT Act 2000)
Users in India may contact us at privacy@myzenvy.app to request access to, correction of, or deletion of any personal data we hold. We will respond within 30 days. Indian payment data is processed by Razorpay in accordance with applicable RBI guidelines.
9. Cookies and Local Storage
The advertiser portal uses only essential cookies: an authentication session cookie to keep you logged in and a market-preference cookie to serve localised content. No tracking or advertising cookies are used. No cookie consent banner is required for essential cookies under UK law.
The Zenvy mobile app does not use browser cookies. The app may store minimal preferences (such as your market selection) in local device storage. This data never leaves your device.
10. Security
We use HTTPS/TLS for all data in transit, bcrypt hashing for passwords, and restrict database access to application services only. Our infrastructure providers (Vercel, Neon, Cloudflare) maintain SOC 2 compliance. In the event of a data breach that affects your rights and freedoms, we will notify affected users and the ICO (and CERT-In for Indian users) within the legally required timeframes.
11. Children
The Zenvy advertiser portal is intended for business use by individuals aged 18 and over. The Zenvy consumer app is intended for users aged 13 and over. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with data, contact privacy@myzenvy.app and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered advertisers of material changes by email at least 14 days before they take effect. For app users, the updated policy will be linked from the app and from this page. Continued use of our services after changes take effect constitutes acceptance.
13. Contact Us
For any privacy-related questions, access requests, or deletion requests:
- Email: privacy@myzenvy.app
- Subject line for deletion requests: "Data Deletion Request"
- We aim to respond to all enquiries within 30 days.