Your data, clearly explained

Privacy Policy

This policy describes how Zinc collects, uses, and protects personal information when you use the app.

Zinc: Events for Friends · Last updated July 16, 2026

1. Introduction

This Privacy Policy describes how we ("we," "us," or "our") collect, use, and protect your personal information when you use the Zinc: Events for Friends mobile application ("the App"). By using the App, you agree to the collection and use of information as described in this policy.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Phone number — used for authentication via SMS one-time password (OTP) verification
  • Name — your display name within the App
  • Date of birth — used for profile personalization

2.2 Profile Information

  • Profile photo — uploaded from your device's photo library

2.3 Contact Information (Optional)

If you choose contact discovery and grant the App access to your device contacts, we process:

  • Phone numbers from the contacts shared with the App — normalized to E.164 format, transmitted securely to our server, and immediately transformed into keyed lookup hashes. Raw contact phone numbers are not stored in the contact-import database.
  • Contact display names — stored locally on your device only (never transmitted to our servers), used solely to show you a recognizable label for each imported contact

Contact discovery is entirely opt-in. After access is granted, the App re-syncs the contacts currently shared by your operating system when the contact list changes and when the App starts or returns to the foreground. You can review the current device list in the App, dismiss individual account suggestions, or change contact access in your device settings.

2.4 Event Information

  • Event title, description, date, and time
  • Event type (open or closed)
  • Event images uploaded from your device's photo library
  • RSVP status (invited, attending, or declined)

2.5 Social Connection Data

  • Relationships between users (pending or confirmed connections)
  • Connection method (QR code scan or in-app request)

2.6 Automatically Collected Information

  • Authentication tokens — session tokens stored locally on your device for maintaining your login state. These are managed by our backend service provider (Supabase) and are not used for tracking purposes.
  • Random installation identifier — an App-generated value used to keep contact permission and import snapshots separate across your devices. It is not a hardware identifier and is not used for advertising or cross-app tracking.

3. Information We Do NOT Collect

  • We do not collect your geographic location
  • We do not collect hardware advertising identifiers or use the random App installation identifier for tracking
  • We do not use analytics, crash reporting, or advertising SDKs
  • We do not access your device contacts without your explicit action — contact data is only read and transmitted if you choose to import contacts via the Imported Contacts feature
  • We do not track your activity across other apps or websites

4. How We Use Your Information

  • Authenticate your identity and maintain your account
  • Display your profile to other users within the App
  • Enable you to create, manage, and participate in events
  • Facilitate social connections between users
  • Display a social graph visualization of your connections
  • Suggest potential connections by identifying which of your imported contacts already use the App (phone numbers only; contact names are never sent to our servers)

5. Data Storage and Security

Your data is stored securely using Supabase, a cloud infrastructure platform.

  • Account and profile data is stored in a PostgreSQL database hosted by Supabase
  • Photos (profile and event images) are stored in Supabase Storage
  • All data transmission between the App and our servers is encrypted using HTTPS/TLS
  • Authentication is handled via Supabase Auth with SMS OTP verification through Twilio
  • Imported contact numbers are stored only as server-keyed lookup hashes; contact display names remain on your device

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.

6. Data Sharing

We do not sell, trade, or rent your personal information to third parties.

Your data may be shared in the following limited circumstances:

  • With other App users: Your name, profile photo, and connection status are visible to users you connect with. Event information is visible to invited or attending participants.
  • Service providers: We use Supabase (database, storage, authentication) and Twilio (SMS delivery) to operate the App. These providers process data on our behalf.

7. Data Retention

We retain your personal data for as long as your account is active. Contact-import snapshots expire 30 days after their last successful synchronization and are renewed only while an authorized device continues to use contact discovery. Revoking contact access deletes that device's imported hashes the next time the App can contact our server; the 30-day expiry provides deletion even if the App never returns. When you delete your account, its contact snapshots and other associated user data are removed from our systems.

8. Your Rights

  • Access your personal data through the App
  • Update your profile information at any time
  • Delete your account and associated data using the account deletion option in the App
  • Withdraw consent for data processing by deleting your account

If you are located in the European Economic Area (EEA), you may also have additional rights under the General Data Protection Regulation (GDPR), including the right to data portability and the right to lodge a complaint with a supervisory authority.

9. Children's Privacy

The App is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will take steps to delete that information.

10. Camera, Photo Library, and Contacts Access

  • Camera: Used solely for scanning QR codes to connect with other users. No photos or videos are captured or stored.
  • Photo Library: Used to allow you to select images for your profile photo and event images. Only images you explicitly select are uploaded.
  • Contacts: The App requests contacts access only if you choose contact discovery. If granted, contacts currently shared with the App are read and their normalized phone numbers are transmitted securely for matching, then stored only as keyed lookup hashes. Contact names stay on your device. The App reconciles additions, removals, limited-access selections, and permission changes when it starts or returns to the foreground. Revoking access removes that device's server snapshot as soon as the App is next online; snapshots also expire automatically after 30 days without a successful sync.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the updated policy within the App. Continued use of the App after changes are posted constitutes acceptance of the revised policy.

12. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, email [email protected].