Legal

Privacy Policy

Last updated: January 1, 2026

1. Introduction

Zenith Connect ("we," "us," or "our") is committed to protecting the privacy of the individuals and organizations that use our platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Zenith Connect service ("Service").

By using the Service, you consent to the data practices described in this policy. If you do not agree, please discontinue use of the Service.

2. Information We Collect

Account information: Name, email address, and hashed password when you create an account.

Organization data: Member records, attendance logs, contribution histories, reports, and transfer records that you or your organization enters into the platform.

Usage data: Log data including IP address, browser type, pages visited, time spent, and actions taken within the platform.

Device information: Hardware model, operating system, browser version, and unique device identifiers.

Payment information: Billing data is processed by our payment processor (Stripe) and we do not store full card details on our servers.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Process transactions and send related information
  • Send administrative notifications (account changes, security alerts)
  • Respond to support requests and inquiries
  • Analyze usage patterns to improve the Service
  • Detect and prevent fraudulent or unauthorized activity
  • Comply with legal obligations

We do not sell your personal data to third parties. We do not use your data for advertising purposes.

4. Data Sharing and Disclosure

We may share your information with:

Service providers: Third-party vendors who assist in operating the Service, including cloud infrastructure (Supabase, Vercel), payment processing (Stripe), and email delivery. These providers are contractually bound to protect your data.

Legal requirements: We may disclose information if required by law, court order, or governmental authority, or to protect the rights, property, or safety of Zenith Connect or others.

Business transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred. We will provide notice before your data becomes subject to a different privacy policy.

5. Data Security

We implement industry-standard security measures to protect your data, including:

  • Row Level Security (RLS) enforced at the database layer
  • Encryption of data in transit (TLS 1.2+) and at rest
  • Environment variable isolation for sensitive credentials
  • Rate limiting on authentication endpoints
  • Regular security reviews and dependency audits

No method of transmission over the internet is 100% secure. While we take commercially reasonable steps to protect your data, we cannot guarantee absolute security.

6. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. Upon account termination, data is retained for 30 days to allow recovery, then permanently deleted.

Certain data may be retained longer where required by law, for legitimate business purposes (e.g., billing records), or to resolve disputes.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the data we hold about you
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your personal data
  • Portability: Request a machine-readable export of your data
  • Objection: Object to processing of your data in certain circumstances

To exercise these rights, contact us at privacy@zenithconnect.org. We will respond within 30 days.

8. Cookies and Tracking

We use cookies and similar technologies to maintain session state, remember preferences, and analyze usage patterns. The following types of cookies are used:

  • Essential: Required for the Service to function (authentication sessions)
  • Analytics: Anonymous usage data to improve the Service

You can disable cookies in your browser settings, but this may affect functionality of the Service.

9. Children's Privacy

The Service is not intended for use by individuals under the age of 13. We do not knowingly collect personal data from children under 13. If we become aware that we have collected such data, we will delete it promptly.

Organizations using the Service to manage minors (e.g., schools) are responsible for obtaining appropriate parental consent in accordance with applicable law.

10. New York State Privacy

For residents of New York State, we comply with applicable New York privacy laws. You have the right to know what personal information we collect, to access that information, and to request deletion. We do not discriminate against users who exercise these rights.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a prominent notice within the Service at least 14 days before the changes take effect.

Your continued use of the Service after the effective date constitutes acceptance of the revised policy.

12. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy, please contact us:

Zenith Connect — Privacy
Email: privacy@zenithconnect.org
Website: zenithconnect.org

Terms of Service →← Back to home