← Back to Zenoa Version française
DRAFT — under legal review; not the final version.
Version v1.0-draft · Latest version 2026-09-13 · Zenoa — zenoa.tech

Zenoa — Privacy Policy

DRAFT v1 for counsel review — not final. Items marked [Counsel: …] need checking.

This policy explains what personal data Zenoa (zenoa.tech) collects, why, who it is shared with, how long it is kept, and your rights under the UK GDPR, the Data Protection Act 2018 and the EU GDPR.

1. Who is responsible

The controller is the entity operating Zenoa in your country (see the Legal notice):

Contact for any question or request about your data: info@zenoa.tech. [Counsel: confirm the split of responsibilities between the two entities and that no DPO / UK representative is required.]

The practitioner you book is a separate controller for the data they receive to deliver your session (name, phone, email, message).

2. What we collect and why

2.1 Clients (booking, no account)

Data Purpose Legal basis
Name, phone, email, optional message Pass your request to the practitioner, confirm or decline the booking, send you the tracking link and confirmation / cancellation emails Contract (art. 6(1)(b))
Stripe payment identifiers (session, payment and refund ids), amount, currency Collect payment on the practitioner's behalf, handle cancellations and refunds Contract; legal obligation (accounting)
Accepted terms version and timestamp Prove which terms applied to your booking Legal obligation / legitimate interest (evidence)
Review (rating, comment, first name) after an attended session Display the review publicly on the practitioner's profile Consent (art. 6(1)(a))

Zenoa never sees or stores your card number: payment details are entered on Stripe's secure page.

2.2 Practitioners (account)

Data Purpose Legal basis
Name, email, password (hashed by Supabase), city Create and secure your account Contract
Public profile: name, specialties, bio, phone, profile link Present you to clients on the map and your page Contract
Location: the address you enter and its coordinates; if you enable "hide exact location", only rounded coordinates and the neighbourhood are public — the exact address is disclosed to the client at confirmation only Place you on the map, tell the client where to go Contract
Published slots, prices, discounts, bookings received Provide the booking service Contract
Stripe Connect account id and activation status Pay you out (Stripe itself collects your identity documents and bank details as an independent controller for its regulatory duties: stripe.com/gb/privacy) Contract; legal obligation
Terms acceptance: document, version, timestamp, IP address Prove your acceptance of the terms (the electronic equivalent of a signature) Legal obligation / legitimate interest (evidence)
Invitation code used, introducer (referral) code, activation date Control registrations and attribute introductions Legitimate interest

2.3 Push notifications (installed app)

If you turn alerts on, we store your browser's technical push subscription (endpoint and encryption keys), the city and optional discipline you chose, and the date of the last send. No name or email is attached. You can revoke permission at any time in your browser settings; the subscription is then removed. Legal basis: consent.

2.4 Technical data

Like any website, our hosts keep technical logs (IP address, browser, pages requested) for security and operations. Legal basis: legitimate interest. Zenoa uses no analytics or advertising tools.

3. Cookies and local storage

Zenoa sets no advertising or analytics cookies. The site only uses strictly necessary local storage: the practitioner login session (Supabase), app display preferences (install banner, visit count) and a pending referral code. These do not require consent under PECR. Stripe sets its own cookies on its payment page (stripe.com/gb/privacy).

4. Recipients and processors

Your data is processed by the following providers, bound by contract:

Provider Role Data Location
Supabase Inc. Database, authentication, booking emails All account and booking data European Union — AWS region eu-central-1 (Frankfurt, Germany)
Vercel Inc. Website and serverless hosting Technical logs, data passing through the site USA / global network
Stripe Payments UK Ltd / Stripe Inc. Payments, refunds, practitioner payouts Payment data, practitioner identity (Stripe Connect) UK / Ireland / USA
Resend Inc. Transactional emails Email address, email content USA
Mapbox Inc. Map tiles IP address (tile loading) USA
OpenStreetMap (Nominatim) Address search when a practitioner types their address The address searched Europe

Transfers outside the UK / EU rely on the UK International Data Transfer Agreement or Addendum, the EU Standard Contractual Clauses, or the Data Privacy Framework where the provider is certified. [Counsel: verify the transfer mechanism per provider.]

Practitioners receive their clients' booking data. No data is sold or used for advertising.

5. How long we keep it

Data Retention
Bookings (name, contact, message) Up to 3 years after the session or last interaction, then deleted; payment records are kept 6 years (accounting) [Counsel: confirm]
Practitioner account Life of the account; deleted on request except data under legal retention
Terms acceptance evidence (version, timestamp, IP) Term of the contract + 6 years (limitation) [Counsel: confirm]
Push subscriptions Until permission is revoked or the subscription expires technically
Reviews While the practitioner's profile is published
Technical logs 12 months maximum

6. Your rights

You have the right to access, rectify, erase, restrict, port and object to the processing of your data, and to withdraw consent at any time (without affecting earlier processing).

To exercise them: info@zenoa.tech. We respond within one month. We may ask for proof of identity where there is reasonable doubt.

You can complain to the ICO (ico.org.uk) or, in the EU, to the CNIL (cnil.fr) or your local authority.

7. Security

Database-level access rules (each practitioner can only reach their own data; the exact address is never public), encryption in transit (HTTPS), payments delegated to Stripe (PCI-DSS certified), no card data stored by Zenoa.

8. Children

Zenoa is intended for adults. [Counsel: confirm the wording and the handling of a booking made by a minor.]

9. Changes

This policy may be updated; the current version and date appear at the top of the page. Material changes are announced on the site or by email to practitioners.

Version française : Politique de confidentialité.