Privacy Policy
Zenhoko LLC ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website at zenhoko.com and related services (collectively, the "Service").
Zenhoko LLC is the controller of the personal data described here. You can reach us at:
Zenhoko LLC
2108 N ST
#12321
Sacramento, CA 95816
USA
support@zenhoko.com
1. Information We Collect
Account Information
When you create a Zenhoko account, we collect:
- Email address
- Password
- Date of birth, which you enter once so we can check you meet our minimum age. We do not store your date of birth. Your browser works out your age and sends us only the result; the date itself never leaves your device. We keep the outcome of the check — that it passed, the date it was made, and which age threshold applied at the time — so we can show the check was carried out
Item Information
When you register items, we collect:
- Item name, description, and category
- Photos you upload
- Pet details (species, breed, etc.) if you register a pet
- QR code assignments
Finder Information
When a finder scans a QR code and contacts an owner, we collect:
- The message content they send
- A one-way hash of their IP address, used only for rate limiting and abuse prevention. We do not retain the raw address
- Geographic coordinates of the item location, if the finder chooses to include them (optional)
- Photos they upload (optional)
Finders are not required to create an account or provide personal information to contact an owner.
Usage and Technical Data
- QR scan events — see section 6 for exactly what each record contains
- A broad device category (for example “ios” or “android”). We do not store the full browser user-agent string against your browsing of the site. There are two places we do keep it, because it is what makes the feature work: a bug report or message you send us through the contact form (the exact browser and version is usually what lets us reproduce the problem you are reporting), and a device you register for push notifications (so you can tell your devices apart when managing them). Both are described in section 6
- Product analytics events recording that an action happened — for example that an item was registered
- Page counts. When a page loads, we add 1 to a running total for that page for that day — for example “the pricing page was viewed 412 times on 6 August”. That total is all we keep. We do not record who viewed it, we assign you no visitor or session identifier of any kind, and we cannot tell how many different people are behind a number or reconstruct any individual’s path through the site. Pages that show a specific item, conversation or discovery are counted as one page each, never per item, so these totals never reveal that a particular item was looked at
- IP addresses, for security and rate limiting. Wherever we store an IP address alongside your activity — a scan event, a message, an abuse report, a contact-form submission — we store a one-way hash of it, never the address itself. Two operational logs are the exception and do record the raw address for a limited period: our API request log and our firewall’s record of blocked requests. Section 6 says exactly what each one holds, why, and for how long
Payment Information
Payment processing is handled entirely by a PCI DSS Level 1 certified payment provider (Stripe). We do not store credit card numbers or bank account details. We receive only a customer reference, subscription status, and plan tier.
2. How We Use Your Information
We use collected information to:
- Provide the Service — enable item registration, QR scanning, anonymous messaging, and item recovery
- Protect users — detect abuse, enforce rate limits, review flagged content, and prevent fraud
- Manage accounts — process subscriptions, enforce tier limits, and handle billing
- Communicate — send transactional emails (new messages, scan alerts, ownership transfers, account changes)
- Improve the Service — analyze aggregate usage patterns to improve features and performance
Our Legal Basis for Processing
Where data-protection law requires us to identify a lawful basis, we rely on:
- Performance of a contract — running your account, registering items, resolving QR scans, and carrying messages between finders and owners. Without this data the Service cannot function.
- Legitimate interests — keeping the Service secure and available: rate limiting, abuse detection and content moderation, and understanding aggregate usage so we can improve it. We balance these against your rights, which is why finder IP addresses are hashed rather than stored, why browser user-agents are reduced to a broad device category everywhere except the two places named in section 1, and why the logs that do hold a raw address are kept for a limited period and used only for security and fault diagnosis.
- Legal obligation — retaining billing records for tax and accounting purposes, and responding to lawful requests.
- Consent — only where you actively opt in, such as attaching your location or a photo to a message as a finder. You can decline; the message still sends.
3. Information Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We share information only in these cases:
- With finders — only the item category, name, description, and photo, when provided.
- With linked accounts — if you invite someone as a linked account, they can access items and permissions you explicitly share.
- Service providers (sub-processors) — trusted providers acting on our instructions and contractually obligated to protect your data: Amazon Web Services (cloud hosting, storage, email delivery, and authentication, in the United States), Cloudflare (bot and abuse prevention via the Turnstile CAPTCHA), and Amazon Bedrock (AI-assisted content moderation, described below).
- Payment processing — Stripe processes payments for paid plans. Stripe collects your billing details directly and we never see your card number. Stripe also uses payment data for its own fraud prevention, anti-money-laundering, and regulatory reporting purposes, for which it is independently responsible rather than acting on our instructions. See Stripe’s privacy policy.
- Legal requirements — if required by law, court order, or governmental regulation.
- Safety — to protect the rights, safety, or property of Zenhoko, our users, or the public.
Automated Content Moderation
To detect scams, abuse, and harmful content, messages and other user-submitted text may be analyzed by an AI moderation service (Amazon Bedrock, operated by Amazon Web Services in the United States). Bedrock processes this content solely on Zenhoko’s instructions, as a tool we use to screen messages carried on our own platform — it makes no independent use of it. The content is processed only to generate a real-time safety assessment. It is not used to train AI models, and Zenhoko does not enable provider-side logging or retention of this content.
We tell you about this screening at the point you write a message, not only here, so that you know before you type rather than afterwards.
This screening is automated: a message assessed as abusive, fraudulent, or containing sensitive financial or identity numbers may be blocked before delivery, without a person reviewing it first. It affects the delivery of that message only — it cannot close your account or change your plan on its own. If you believe a message was blocked in error you can ask us to review the decision by hand, and to contest the outcome, by emailing support@zenhoko.com.
4. Progressive Visibility
Zenhoko uses a "progressive visibility" system for item pages. When a finder scans your QR code, they see only the item name, description, category, and photo by default.
No personal information is shared between finders and owners by default. Registering an item does not require your name, phone number, or address, and we never collect those in order to register an item or to put a finder in touch with you. If you subscribe to a paid plan, our payment processor collects billing details on its own behalf — see section 1.
Owners and finders may choose to share personal details through the messaging platform, at their own risk, for the purpose of facilitating a return. Each party controls what the other can see.
5. Data Storage and Security
- All data is stored on infrastructure hosted in the United States
- Data is encrypted in transit (TLS/HTTPS) and at rest
- Authentication is managed by an industry-standard identity provider
- Finder access is temporary and automatically expires
- Photos are stored securely and accessed through restricted, expiring links
- Photo metadata is removed before upload. Photos taken on a phone often embed the exact place they were taken. Every photo you or a finder attaches is re-encoded by your browser before it is sent, which discards the embedded metadata — GPS coordinates, camera details, and timestamps — so it never reaches us. This matters in both directions: an item photo is usually taken at home, and a finder’s photo is taken wherever the finder is
- API endpoints are rate-limited to prevent abuse
6. Data Retention
Each category below states how long we keep it and what happens when you delete. Where a period is given, records carry an expiry timestamp and are removed automatically once it passes — we do not rely on manual clean-up.
- Account data — retained while your account is active. Deleted when you delete your account.
- Item data — retained while the item is registered. When you delete an item we remove its name, description and photo. We keep the QR code’s identifier and a record of whether it is currently registered, so that a printed or engraved code cannot be claimed by someone else. When you delete your account, the link between the QR code and your account is severed: the code is deactivated, and the record that remains does not identify you.
- Conversations and messages — deleted when the associated item is deleted or your account is closed. They also expire on their own: a conversation is archived 7 days after its last message and permanently deleted 30 days after that (37 days in total), including any photo a finder sent.
- QR scan events — kept for up to 365 days, then deleted automatically. Deleting the item, or closing your account, deletes its scan events at that point rather than waiting for the year to elapse. Each record contains: the QR code’s identifier, the item URL it resolved to, the date and time, the account identifier of the item’s owner, the country the scan came from, a broad device category (for example “ios” or “android”), and a one-way cryptographic hash of the scanner’s IP address. We do not store the raw IP address — it is hashed with a secret key before it leaves the server that receives the scan, and we never store the full browser user-agent string. We treat the hashed IP as pseudonymous rather than anonymous data, and it is covered by your rights in section 7.
- Product analytics events — kept for up to 400 days, then deleted automatically. Deleting your account deletes your analytics events at that point rather than waiting for the period to elapse. These record that an action happened (for example “an item was registered”) along with the account identifier of the person who did it, the identifier of the item or conversation involved, and the time. They contain no message content, names, photos or contact details.
- Page counts — kept for up to 400 days, then deleted automatically. Each record is a page, a date, and a number. There is no field for a person, so there is nothing in these records to link to you, and nothing to delete when you close your account.
- Server access logs — kept for 90 days, then deleted automatically. These are operational records of requests reaching our content delivery network, used to diagnose outages and errors. Each line records the page requested, the response status, how long it took, whether it was served from cache, and a request identifier. It does not contain your IP address or your browser user-agent string.
- API request logs — kept for 90 days, then deleted automatically. Separately from the above, every request to our application programming interface — the endpoints the site calls to register an item, send a message, sign in and so on — is logged with the originating IP address, the time, which endpoint was called, the response status and size, and a request identifier. Why we keep the address: it is the only record that lets us tell whether a burst of failed sign-ins, claim-code guesses or spam submissions is one actor or many. Our firewall (below) only records requests it blocks, so abuse that stays under a blocking threshold — slow credential-stuffing, distributed probing — is visible nowhere else. We cannot hash it here: the log is written by the gateway before our own code runs, which is exactly what makes it useful for requests that never reach our code. It is used only for security, abuse investigation and diagnosing faults — never for analytics, profiling or advertising — and it is not joined to your account activity.
- Firewall block records — when our web firewall blocks a request as an attack or abuse, that request is logged with its originating IP address, for up to 90 days. Requests that are allowed through are not logged this way. It exists solely to investigate and defend against attacks, and it is never used for analytics or advertising.
- Abuse reports — kept for 90 days, then deleted automatically.
- Support emails and contact-form messages — kept for up to 365 days, then deleted automatically. This includes the message you sent, your email address, any attachment, a one-way hash of your IP address (never the address itself), and your browser’s user-agent string — the line naming your browser, its version and your operating system. We keep that last one because most of these messages are bug reports, and knowing the exact browser is usually what makes a reported problem reproducible. It is deleted with the rest of the message.
- Push-notification devices — if you turn on push notifications, we store what your browser gives us to deliver them (a push-service address and the two keys that encrypt the message), together with your browser’s user-agent string so that you can tell one registered device from another when managing them. Retained until you turn notifications off for that device or remove it, and deleted when you delete your account.
- Rate-limit and anti-abuse records — short-lived counters that expire automatically. Each is a count against a scope and a one-way hash of the IP address (or your account identifier when you are signed in) — never the address itself — and typically expires within an hour.
- Agreement records — when you accept the Terms of Service and this Privacy Policy at signup, we record that you did: your account identifier, the time, and which version of each document you accepted. This is kept with your account data and removed when you delete your account.
- Automatic-renewal consent records — when you subscribe to a paid plan, we separately record your agreement to the renewal terms: your account identifier, the time, the plan, price and renewal interval you were shown, the version of the Terms then in force, and a one-way hash of your IP address (never the address itself). California’s automatic-renewal law requires this proof to be kept for at least three years, or one year after the subscription ends, whichever is longer. Because that end date is not knowable when the record is written, and because it is the record of a commercial agreement rather than of your use of the Service, these are kept on a legal-obligation basis and are not removed when you delete your account — the same footing as the billing records our payment processor holds.
- Billing records — payment history is held by our payment processor (Stripe) and retained as long as tax and accounting law requires, which is generally longer than the periods above. We never store your card details.
Backups are a separate copy of the above and are kept for up to 120 days. Data you delete may persist in a backup until it ages out; it is not restored to the live service except in a disaster-recovery event.
7. Your Rights
Wherever you live, you can exercise all of the following. Several are self-service; for the rest, email support@zenhoko.com and we will respond within 30 days (or 45 days for requests under California law, which we may extend once by a further 45 days if the request is complex — we will tell you if that happens).
- Access — see the personal data we hold about you, through your dashboard and account settings, or by asking us for a copy.
- Correct — fix inaccurate information by editing your items and account details.
- Delete — remove your account and its associated data from the account settings page. Note the limits described in section 6: the QR identifier and its status are kept so a printed code cannot be claimed by someone else, though the link to your account is severed; and backups age out over up to 120 days.
- Export (portability) — receive your data in a portable, machine-readable format (JSON). This is currently a support-mediated request rather than a self-service button: email us and we will prepare it. We verify that the request comes from the account holder before sending anything, so please write from the address on the account.
- Restrict processing — ask us to pause processing while a dispute about accuracy or our legitimate interests is resolved.
- Object — object to processing we carry out on the basis of legitimate interests. Note that security and abuse prevention are essential to running the Service, so we may not be able to continue providing it if you object to those.
- Withdraw consent — where you gave it (for example a location or photo attached to a message), at any time, without affecting processing already carried out.
- Human review of automated decisions — ask a person to review a message our automated moderation blocked, and contest the outcome.
- Control visibility — decide which of your item’s details a finder can see.
- Non-discrimination — we will not deny you service, charge you a different price, or give you a lesser experience for exercising any of these rights.
We do not sell or share your personal information, and we have not done so in the preceding 12 months. We do not use it for cross-context behavioural advertising, and we do not knowingly sell or share the personal information of anyone under 13. There is therefore nothing for a “Do Not Sell or Share My Personal Information” request to opt out of.
You may use an authorised agent to make a request on your behalf; we will ask for proof of their authority. If we deny a request we will tell you why, and you may ask us to reconsider. California residents may also raise a concern with the California Privacy Protection Agency or the California Attorney General’s office. We would appreciate the chance to address it first.
7a. Notice at Collection (California)
At or before the point we collect it, this is what we collect and why:
- Identifiers (email address, account identifier, hashed IP address) — to create and secure your account, and to prevent abuse.
- Commercial information (plan tier, subscription status, a customer reference held by our payment processor) — to bill you and enforce plan limits.
- Internet and device activity (QR scan events, broad device category, product analytics events) — to operate QR resolution, show you your own item’s scan history, and improve the Service.
- Geolocation (only if a finder chooses to attach it to a message) — to help you recover the item.
- User content (item names, descriptions, photos, messages) — to operate the Service and to moderate for safety.
Retention periods for each are set out in section 6.
We do not collect biometric data, and we do not track your location in the background or at any moment you have not chosen. The one piece of location data we hold is a coordinate a finder may choose to attach to a message about an item they have found. That coordinate can be precise, which under California law makes it sensitive personal information — so, to be exact about it: it is entirely optional, the finder can edit or remove it before sending, it is used only to help you recover the item, and it is deleted with the conversation (37 days after the last message, or immediately if the item or account is deleted). We do not sell or share any of the above, and we do not use sensitive personal information to infer characteristics about anyone.
8. Children's Privacy
You must be at least 13 years old to hold a Zenhoko account. That is the threshold the US Children’s Online Privacy Protection Act (COPPA) sets, and Zenhoko is offered in the United States.
Zenhoko is not directed at children under 13. We do not knowingly collect personal information from anyone under 13, and we do not knowingly permit anyone under 13 to register an account. If you believe someone under 13 has created an account or provided us with personal information, contact us at support@zenhoko.com and we will delete it promptly.
Finders are a separate case: scanning a tag and messaging an owner requires no account, and we collect no identifying information from a finder. We do not ask a finder’s age.
9. Cookies and Tracking
Zenhoko uses only essential cookies and local storage for authentication (session tokens). We do not use third-party tracking cookies, advertising pixels, or analytics services that track individual users across websites.
Our page counts (section 1) do not use cookies, local storage, device fingerprinting, or any other technique that stores or reads information on your device. Nothing is placed on your device to make them work, which is why they require no consent and appear on no consent banner.
Global Privacy Control
Global Privacy Control (GPC) is a browser or extension setting that tells websites you want to opt out of the sale or sharing of your personal information. Unlike Do Not Track, several US state laws require businesses to honour it.
We honour GPC signals. In practice it changes nothing about how we treat your data, because we do not sell or share personal information with anyone and we do not use it for cross-context behavioural advertising — there is nothing for the signal to switch off. We record no preference and place nothing on your device in response to it. If that ever changes, we will honour GPC as an opt-out and will say so here before the change takes effect.
Do Not Track signals
Some browsers can send a “Do Not Track” (DNT) signal. There is no industry-standard agreement on how services should respond to it.
Zenhoko does not perform the kind of tracking DNT was designed to prevent: we do not follow you across third-party websites, we do not build advertising or behavioural profiles, and we run no third-party analytics. Our own page counts are totals per page per day with no visitor identifier attached, so they cannot follow you anywhere — there is no “you” in the data to follow. Because there is no such tracking to switch off, a DNT signal makes no difference to how we handle your data — you already receive the outcome DNT asks for. We do not change our behaviour when we receive one, and we do not log whether you sent one.
We also do not permit any third party to collect personally identifiable information about your online activities over time and across different websites through the Service.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we revise the "Last updated" date at the bottom of this page, and we may additionally notify registered users by email where a change is significant. We encourage you to review this page periodically.
11. Contact Us
If you have questions about this Privacy Policy or your personal data, contact us at support@zenhoko.com.
Last updated: August 12, 2026 · Version v2026-08-12