Privacy Policy
Last updated: 2026-05-08 · v1.1
1. Who we are
[LEGAL_ENTITY_NAME] ("Zendinit", "we") operates the Zendinit platform, which connects people who need products brought from abroad (senders) with travelers willing to deliver them. This policy describes what data we collect, how we use it, and your rights.
For privacy questions: [CONTACT_EMAIL]. Where applicable under GDPR (EU/EEA), our data protection officer is: [DPO_EMAIL].
2. Information we collect
- Account data: name, email, phone number, profile photo, preferred language, hashed password, OAuth provider (Google, Apple) when applicable.
- Transactional data: routes published, offers made or received, requested products, receipt and delivery photos, ratings and reviews, messages with other users.
- Payment data: full card details are processed by our payment providers (Stripe / PayPal). We store transaction identifiers and the last 4 digits for reference.
- Device and usage data: IP address, user agent, device type, operating system, usage events, errors. Collected automatically when you use the service.
- Cookies and similar technologies: see section 7.
3. How we use your information
- Operating the service: matching senders with travelers, processing payments held in escrow, releasing funds when delivery is confirmed.
- Operational communications: confirmations, reminders, status-change notifications.
- Support and dispute resolution.
- Fraud and abuse prevention.
- Legal and tax compliance.
- Improving the service and developing new features (using aggregated / anonymized data).
We do not sell your personal data.
4. Who we share your data with
- Payment providers: Stripe, PayPal — to process transactions.
- Infrastructure providers: hosting, file storage, transactional email, push notifications (only the minimum data needed).
- Other users: your name, photo, ratings, and reviews are visible to users you interact with.
- Authorities: when a valid legal order requires it, or to protect rights, property, or safety.
5. Your rights
Depending on your jurisdiction, you may have the right to:
- Access the data we hold about you.
- Correct inaccurate data.
- Request deletion of your account and associated data.
- Data portability.
- Object to certain processing.
- Withdraw consent (where applicable).
If you are in the EU/EEA, GDPR grants you these rights. If you are in California, CCPA grants similar rights. To exercise any of them, contact [CONTACT_EMAIL].
6. Retention
- Active accounts: for as long as the account exists.
- Transactional data: up to 7 years after the last transaction, due to legal and accounting obligations.
- Messages: up to 2 years after account closure.
- Technical logs: 90 days.
7. Cookies
We only use cookies strictly necessary for the service to work:
- Session (NextAuth): keep you signed in after logging in. Without these cookies you cannot use your account.
- Language preference: remember the language you selected (es / en).
We do not use marketing, advertising, or cross-site tracking cookies.
Analytics: we measure aggregated usage with Umami, a privacy-first tool that does NOT use cookies and does NOT track individual visitors. We do not share analytics data with third parties.
Your browser lets you clear all cookies at any time from its settings. If you clear the session cookies, you will have to log in again.
8. Minors
The service is intended for people over [MINIMUM_AGE]. We do not knowingly collect data from minors. If you believe a minor has provided us with data, please contact us so we can delete it.
9. Changes to this policy
We may update this policy. When there are substantial changes, we will notify you by email or in-app before they take effect. The "last updated" date at the top indicates the current version.
10. Contact
For any question about this policy or your data: [CONTACT_EMAIL].
[LEGAL_ENTITY_NAME] [LEGAL_ENTITY_ADDRESS]
This document is an MVP draft and must be reviewed by legal counsel before final publication.