Compliance
Zenhoko is committed to responsible data handling and security. This page outlines our security practices and approach to regulatory compliance.
1. Infrastructure and Hosting
Zenhoko is hosted on industry-leading cloud infrastructure that maintains SOC 1/2/3, ISO 27001, and PCI DSS compliance certifications. All data is stored in the United States. Our infrastructure providers are contractually obligated to protect your data.
To be unambiguous about what that means: these certifications are held by our infrastructure providers and cover the platforms we build on. Zenhoko has not itself undergone a SOC 2, ISO 27001, or equivalent independent audit. The sections below describe our own practices, and we are happy to answer specific questions at support@zenhoko.com.
2. Data Encryption
- All connections are encrypted in transit using TLS (HTTPS enforced)
- All stored data is encrypted at rest using industry-standard encryption
- Passwords are never stored by Zenhoko — authentication is managed by a dedicated, industry-standard identity provider
3. Authentication and Access Control
- User authentication uses a trusted, industry-standard identity provider with email verification required
- Passwords are securely hashed and never accessible to Zenhoko staff
- All authenticated API access requires valid, time-limited credentials
- Finder access tokens are cryptographically signed and short-lived
- Administrative access to infrastructure requires multi-factor authentication
4. Application Security
- Rate limiting: All public endpoints are rate-limited to prevent abuse
- Input validation: All user input is validated and sanitized on the server side
- XSS prevention: User-generated content is sanitized before display
- Upload restrictions: File uploads are restricted to approved image types
- Bot protection: Public forms include automated abuse deterrents
- Security headers: Industry-standard HTTP security headers are applied to all responses, including protections against clickjacking, MIME sniffing, and cross-site scripting
5. Data Minimization
Zenhoko follows a data minimization principle:
- Finders are never required to create an account or provide personal information
- Progressive visibility ensures owner contact details are hidden by default and only shared when you explicitly enable them
- Temporary records such as abuse reports and rate limit data expire and are automatically removed
- Account deletion removes your account, your items’ details, conversations, photos, linked accounts, product analytics events, and the scan history of your QR codes. Two things are retained and one link is severed — see section 6 of the Privacy Policy for the retention exceptions and the backup window, which is the single authoritative description
6. Incident Response
In the event of a security incident:
- Investigating and containing the incident is our first priority
- We notify affected users by email without unreasonable delay, and as applicable law requires. Our internal target is within 72 hours of confirming that user data was affected — though we may need longer where that is necessary to determine the scope of the incident, restore the integrity of the system, or comply with a law enforcement request
- Notices describe what happened, what information was involved, what we have done, and what you can do
- We notify applicable regulatory authorities as required by law
- We publish a post-incident summary where doing so does not create further risk
- We take corrective action to prevent recurrence
7. International Users
Zenhoko currently operates in the United States only, and all data is stored and processed in the United States. We do not target, market to, or offer the Service in the European Union, the United Kingdom, or other jurisdictions outside the United States.
That does not narrow what we offer you. We extend the same access, correction, deletion, portability, restriction, and objection rights to every user regardless of where they live — including the right to ask a person to review a message our automated moderation blocked. They are set out in full in section 7 of the Privacy Policy, along with the lawful bases we rely on.
If we expand to other regions, we will update this page and notify registered users before doing so.
8. California Privacy
Our California disclosures — the Notice at Collection, the categories of information we collect and why, retention periods, and how to exercise your rights — are set out in full in our Privacy Policy, sections 6, 7, and 7a. That is the authoritative version; this page does not maintain a second one.
In summary: we do not sell or share personal information, we do not use third-party advertising trackers, and we honour access, deletion, correction, portability, and non-discrimination rights for all users.
9. COPPA Compliance
Accounts require a minimum age of 13, which is the threshold COPPA applies to. Zenhoko is not directed at children under 13, and we do not knowingly collect personal information from anyone under 13 or knowingly permit them to register. If we become aware that an underage account exists, we delete the account and all associated data promptly. Finders need no account, and we collect no identifying information from them.
10. Payment Compliance
All payment processing is handled by Stripe, which is PCI DSS Level 1 certified. Zenhoko does not store, process, or transmit cardholder data. Credit card information is entered directly into Stripe's secure checkout and never touches our servers.
11. Third-Party Services
Zenhoko uses a small number of trusted third-party services for infrastructure and payment processing. All providers maintain industry-recognized security certifications and are contractually obligated to protect user data. We do not use third-party analytics, advertising networks, or social media tracking pixels.
12. Contact
For compliance inquiries, data requests, or to report a security concern, contact us at support@zenhoko.com.
Last updated: August 8, 2026 · Version v2026-08-08