Privacy Policy
Last updated: 2026-07-15
Data we collect
- Account data: email, password hash (argon2id), company name, plan, billing info via Stripe (we never see full card numbers).
- Verification inputs: emails you submit for validation. Held for the retention period you configure (default 30 days for cache; jobs + results retained per plan).
- Usage metrics: request rate, credits consumed, endpoint latency, error rate. Aggregated for billing + reliability — never joined with your verification content.
- Server logs: IP + user-agent for security. Rotated at 30 days.
Data we do NOT collect
- No third-party analytics, no ad pixels, no session replay.
- No behavioural tracking across the marketing site (verify.zi2.app has no cookies pre-signup other than the CSRF sameSite=lax anchor).
How we use it
- To run verifications you request.
- To bill you accurately (Stripe as processor).
- To detect abuse (rate limits, credit-ledger integrity checks).
- To send transactional email (signup verification, wise-links, invoices).
We do NOT sell, share, or use your data to train ML models.
Sub-processors
- Stripe — payments (PCI-DSS Level 1).
- Cloudflare — edge CDN + DDoS.
- All other infrastructure runs on Zenith Intelligence Technologies-owned hardware.
Your rights
- Access + export — dashboard → Account → Export data (JSON).
- Deletion — dashboard → Account → Delete. All PII wiped within 30 days.
- Correction — self-serve in the dashboard.
- DPA — see /dpa.
Retention
Account data: while active + 30 days after cancellation. Ledger + audit rows: 7 years (financial + compliance). Verification results: per your configured policy (default 90 days).
Contact
[email protected] or Data Protection Officer at [email protected].