Privacy Policy
Introduction
At Zena, we take your privacy seriously. Please read this Privacy Policy to learn how we handle personal data that we collect via our Services, how we use and disclose your personal data, how long we retain it, and what choices you have.
Remember that your use of Zena's Services is at all times subject to our Terms of Use, which incorporates this Privacy Policy. Any terms we use in this Privacy Policy without defining them have the definitions given to them in the Terms of Use.
If you have a disability, you may access this Privacy Policy in an alternative format by contacting help@zena.com.
Privacy Policy Applicability
This Privacy Policy covers how we treat personal data that we gather when you access or use our Services. Zena’s Services are generally intended for use by business customers and their employees and other authorized users, which we refer to as an “Authorized User”. If you are using Zena’s Services as an Authorized User of one of our business customers and you have any questions about our privacy practices or would like to exercise any rights with respect to your personal data that we process on behalf of our customers, please contact the corresponding customer as we only process your personal data in our capacity as a service provider to our customer.
Please see our Privacy Snapshot below for a high-level overview of our privacy practices.
Personal Data We Collect
We collect the following categories of personal data about you:
- Contact information, such as your first and last name, email and mailing addresses, and phone number.
- Account information, such as the username and password you use to access our Services.
- Transaction Data, including information associated with your bill payments, reimbursements and card transactions made through the Services, such as the purchase details, payment mechanism, amount, location, and any annotations or coding you provide. Transactions can be made through a variety of domestic and international payment mechanisms, such as sending or receiving funds via ACH, wire, or check, or making charges through a payment card.
- Payment information needed to complete your transactions with us, including name, payment card information, and billing information. This information is processed by our payment service provider, Stripe, Inc., which may handle your payment information in accordance with its own privacy policy (https://stripe.com/privacy). We do not have access to your full payment card information.
- Communications that we exchange with you, including when you contact us with questions, feedback, or otherwise.
- Demographic information, such as information about your employment setting and other data you voluntarily provide through user surveys.
- User generated content, such as photos, videos, PDFs, invoices or other user-generated content that you upload or otherwise provide through the Services.
- Marketing information such as your preferences for receiving our marketing communications and details about your engagement with them.
Other information not specifically listed here, which we will use as described in this Privacy Policy or as otherwise disclosed at the time of collection.
Sources of Personal Data
We collect personal data about you from the following sources:
You
When you provide such information directly to us.
- When you create an account or use our interactive tools and Services.
- When you voluntarily provide information in free-form text boxes through the Services or through responses to surveys or questionnaires.
- When you send us an email or otherwise contact us.
Automatic data collection
We and our service providers may automatically log and combine information about you, your computer or mobile device, and your interactions over time with the Services, online resources, and our communications.
- Through Cookies (defined in the “Tracking Tools and Opt-Out” section below).
- If you download a mobile application from us or use a location-enabled browser, we may receive information about your approximate location and mobile device, as applicable.
- If you download and install certain applications and software we make available, we may receive and collect information transmitted from your computing device for the purpose of providing you the relevant Services, such as information regarding when you are logged on, usage patterns and frequency, and availability to receive updates or alert notices.
Third Parties
Public Records
- We may collect information from the government, from public social media sources or other public sources of information.
Vendors
- We rely on receive personal data from financial institution partners, including card networks, payment processors, money transmitters, or other entities that provide or support delivery of financial services.
- We may use analytics providers to analyze how you interact and engage with the Services, or third parties may help us provide you with customer support.
- We may use vendors to obtain information to generate leads, create user profiles, assist with identity verification and fraud response, and assist with compliance and security.
Advertising Partners
- We receive information about you from some of our vendors who assist us with marketing or promotional services related to how you interact with our websites, applications, products, Services, advertisements or communications.
Social Networks
- If you provide your social network account credentials to us or otherwise sign in to the Services through a third-party site or service, some content and/or information in those accounts may be transmitted into your account with us.
Banks and Payment Processors
- We may request and receive information about your banking history and payment information through Stripe when you sign-up to our Services.
How we use Personal Data
We use personal data for business and commercial purposes in accordance with the practices described in this Privacy Policy.
Providing, customizing, and improving the Services
- Providing you with the products, Services or information you request.
- Meeting or fulfilling the reason users provided the information to the Company.
- Providing support and assistance for the Services.
- Improving the Services, including testing, research, internal analytics and product development.
- Personalizing the Services, website content and communications based on your preferences.
- Doing fraud protection, security and debugging.
- Creating and managing user account or other user profiles.
- Processing orders or other transactions; billing.
Marketing the Services
- Marketing and selling the Services.
Corresponding with You
- Responding to correspondence that we receive from you, contacting you when necessary or requested, and sending you information about Zena or the Services.
- Sending emails and other communications according to your preferences or that display content that we think will interest you.
AI Technology and AI Powered Services
We use AI (artificial intelligence) and ML (machine learning) technologies to develop, improve, and provide our Service for all our users.
Such AI and ML technologies are trained on real-world data, including personal data that we collect from you in the course of providing our Service. We may use your personal data to develop, improve, train, and provide our proprietary AI and ML technologies. We do not use your data to develop, improve, train, and provide any generalized (non-personalized) AI and ML models. We may disclose your personal data to third-party providers of AI and ML technologies, who will use your personal data strictly to support our Service. We do not permit such third-party providers of AI and ML technologies to use your personal data to develop, improve, train, or provide their AI and ML technologies for the benefit of their other customers.
You can opt out of having your personal data retained and used for the purposes of developing, improving, training and providing our AI and ML technologies by contacting us at help@zena.com, in which case we will not use any personal data you provide after you opt-out for such purposes.
Meeting Legal Requirements and Enforcing Legal Terms
- Fulfilling our legal obligations under applicable law, regulation, court order or other legal process, such as preventing, detecting and investigating security incidents and potentially illegal or prohibited activities.
- Protecting the rights, property or safety of you, Zena or another party.
- Enforcing any agreements with you.
- Responding to claims that any posting or other content violates third-party rights.
- Resolving disputes.
How We Share Your Personal Data
We disclose your personal data to the categories of service providers and other parties listed in this section. Depending on state laws that may be applicable to you, some of these disclosures may constitute a “sale” of your personal data. For more information, please refer to the “Additional Disclosures” section below.
Service Providers. These parties help us provide the Services or perform business functions on our behalf. They include:
- Hosting, technology and communication providers.
- Security and fraud prevention consultants.
- Analytics providers.
- Support and customer service vendors.
- Payment processors and banking services providers.
- Our banking services providers Stripe, Inc. (“Stripe”) and Celtic Bank (“Celtic”) collect your voluntarily-provided information necessary to issue payment credentials, process payments, and provide other related services.
- Please see Stripe’s terms of service and privacy policy and Celtic’s terms of service and privacy policy for information on its use and storage of your personal data.
Advertising Partners. These parties help us market our services and provide you with other offers that may be of interest to you. They include:
- Marketing providers.
- Referral network platforms.
Analytics Partners. These parties provide analytics on web traffic or usage of the Services. They include:
- Companies that track how users found or were referred to the Services.
- Companies that track how users interact with the Services.
Business Partners. These parties partner with us in offering various services. They include:
- Businesses that you have a relationship with.
- Companies that we partner with to offer the Services, such as banking partners and software providers.
- Companies that you partner with to offer joint promotion offers or opportunities.
Parties You Authorize, Access or Authenticate
- Third parties you access through the services.
- Social media services.
- Other users.
Legal Obligations
We may share any personal data that we collect with third parties in conjunction with any of the activities set forth under “Meeting Legal Requirements and Enforcing Legal Terms” in the “Our Commercial or Business Purposes for Collecting personal data” section above.
Business Transfers
Your personal data that we collect may be transferred to a third party if we undergo a merger, acquisition, bankruptcy or other transaction in which that third party assumes control of our business (in whole or in part).
How We Use Personal Data for Service Improvement
Zena’s Services constantly improve based on insights we derive from customer usage. We may use your data to improve our Services, including by creating aggregated, de-identified or anonymized data from the personal data and other data that we collect, including by removing or pseudonymizing information and to support our AI and LLM technologies (as detailed in the section “AI Technology and AI Powered Services”). We may use such data and share it with third parties for our lawful business purposes, including to analyze, build and improve the Services and promote our business.
Our Tracking Tools and Your Choices
The Services use cookies and similar technologies such as pixel tags, web beacons, clear GIFs and JavaScript (collectively, “Cookies”) to enable our servers to recognize your web browser, tell us how and when you visit and use our Services, analyze trends, learn about our user base and operate and improve our Services. Cookies are small pieces of data– usually text files – placed on your computer, tablet, phone or similar device when you use that device to access our Services. We may also supplement the information we collect from you with information received from third parties, including third parties that have placed their own Cookies on your device(s). Please note that because of our use of Cookies, the Services do not support “Do Not Track” requests sent from a browser at this time.
We use the following types of Cookies:
- Essential Cookies. Essential Cookies are required for providing you with features or services that you have requested. For example, certain Cookies enable you to log into secure areas of our Services. Disabling these Cookies may make certain features and services unavailable.
- Functional Cookies. Functional Cookies are used to record your choices and settings regarding our Services, maintain your preferences over time and recognize you when you return to our Services. These Cookies help us to personalize our content for you, greet you by name and remember your preferences (for example, your choice of language or region).
- Performance/Analytical Cookies. Performance/Analytical Cookies allow us to understand how visitors use our Services. They do this by collecting information about the number of visitors to the Services, what pages visitors view on our Services and how long visitors are viewing pages on the Services. Performance/Analytical Cookies also help us measure the performance of our advertising campaigns in order to help us improve our campaigns and the Services’ content for those who engage with our advertising. For example, Google Inc. (“Google”) uses cookies in connection with its Google Analytics services. Google’s ability to use and share information collected by Google Analytics about your visits to the Services is subject to the Google Analytics Terms of Use and the Google Privacy Policy. You have the option to opt-out of Google’s use of Cookies by visiting the Google advertising opt-out page at www.google.com/privacy_ads.html or the Google Analytics Opt-out Browser Add-on at https://tools.google.com/dlpage/gaoptout/.
- Advertising Cookies. Retargeting/Advertising Cookies collect data about your online activity that track the performance of advertising.
You can decide whether or not to accept Cookies through your internet browser’s settings. Most browsers have an option for turning off the Cookie feature, which will prevent your browser from accepting new Cookies, as well as (depending on the sophistication of your browser software) allow you to decide on acceptance of each new Cookie in a variety of ways. You can also delete all Cookies that are already on your device. If you do this, however, you may have to manually adjust some preferences every time you visit our website and some of the Services and functionalities may not work.
To explore what Cookie settings are available to you, look in the “preferences” or “options” section of your browser’s menu. To find out more information about Cookies, including information about how to manage and delete Cookies, please visit https://www.allaboutcookies.org/.
Our Data Security and Retention
We seek to protect your personal data from unauthorized access, use and disclosure using appropriate physical, technical, organizational and administrative security measures based on the type of personal data and how we are processing that data. You should also help protect your data by appropriately selecting and protecting your password and/or other sign-on mechanism; limiting access to your computer or device and browser; and signing off after you have finished accessing your account. Although we work to protect the security of your account and other data that we hold in our records, please be aware that no method of transmitting data over the internet or storing data is completely secure.
We retain your personal data for as long as you have an open account with us or as otherwise necessary to provide you with our Services. In some cases we retain personal data for longer, if doing so is necessary to comply with our legal obligations, comply with our retention policies, resolve disputes or collect fees owed, or is otherwise permitted or required by applicable law, rule or regulation.
Personal Data of Children
Zena’s Services are intended for businesses. As noted in the Terms of Use, we do not knowingly collect or solicit personal data about children under 13 years of age; if you are a child under the age of 13, please do not attempt to register for or otherwise use the Services or send us any personal data. If we learn we have collected personal data from a child under 13 years of age, we will delete that information as quickly as possible. If you believe that a child under 13 years of age may have provided personal data to us, please contact us at help@zena.com
Additional Disclosures
California Resident Rights
Under California Civil Code Sections 1798.83-1798.84, California residents are entitled to contact us to prevent disclosure of personal data to third parties for such third parties’ direct marketing purposes; in order to submit such a request, please contact us at help@zena.com.
Nevada Resident Rights
If you are a resident of Nevada, you have the right to opt-out of the sale of certain personal data to third parties who intend to license or sell that personal data. You can exercise this right by contacting us at help@zena.com with the subject line “Nevada Do Not Sell Request” and providing us with your name and the email address associated with your account. Please note that we do not currently sell your personal data as sales are defined in Nevada Revised Statutes Chapter 603A.
Changes to this Privacy Policy
We’re constantly trying to improve our Services, and we may update this Privacy Policy from time to time. If we make material changes to this Privacy Policy, we will notify you by updating the date of this Privacy Policy and posting it on our website. We may also provide notification of changes in another way that we believe is reasonably likely to reach you, such as via e-mail (if you have an account where we have your contact information) or another manner through our Services.
Any modifications to this Privacy Policy will be effective upon our posting the new terms and/or upon implementation of the new changes on our Services (or as otherwise indicated at the time of posting). In all cases, your continued use of the Services after the posting of any modified Privacy Policy indicates your acceptance of the terms of the modified Privacy Policy.
Please note that if you’ve opted not to receive legal notice emails from us (or you haven’t provided us with your email address), those legal notices will still govern your use of the Services, and you are still responsible for reading and understanding them.
Contact Information
If you have any questions or comments about this Privacy Policy, the ways in which we collect and use your personal data or your choices and rights regarding such collection and use, please do not hesitate to contact us at:
415-562-8630
help@zena.com
1 Letterman Drive, C-3500
San Francisco, CA, 94129
Privacy Snapshot
Below is a high-level snapshot of how we collect, use, and disclose your personal data when you use the Service, but please read the entire Privacy Policy for complete information.
- First and last name
- Phone number
- Mailing address
- Service Providers
- Advertising Partners
- Analytics Partners
- Business Partners
- Parties You Authorize, Access or Authenticate
- Drivers’ license number
- Passport number
- Service Providers
- Business Partners
- Last 4 digits of payment card
- Billing address, phone number, and email
- Transaction history
- Service Providers, including our bank and payment processing partner(s)
- Business Partners
- Purchase history
- Consumer profiles
- Analytics Partners
- Business Partners
- Parties You Authorize, Access or Authenticate
- Account name and passwords
- Other unique personal or online identifiers
- Service Providers
- Parties You Authorize, Access or Authenticate
- IP address
- Device ID
- Type of device/operating system/browser used to access the Services
- Service Providers
- Analytics Partners
- Business Partners
- Parties You Authorize, Access or Authenticate
- Browsing or search history in the Service
- Web page interactions
- Referring webpage/source through which you accessed the Services
- Statistics associated with the interaction between device or browser and the Services
- Service Providers
- Advertising Partners
- Analytics Partners
- Business Partners
- Parties You Authorize, Access or Authenticate
- Phone number
- Username
- IP address
- Device ID
- Service Providers
- Analytics Partners
- Business Partners
- Parties You Authorize, Access or Authenticate
- Age / date of birth
- Zip code
- Gender
- Service Providers
- Analytics Partners
- Business Partners
- Parties You Authorize, Access or Authenticate
- Job title
- Service Providers
- Analytics Partners
- Business Partners
- Parties You Authorize, Access or Authenticate
- Geolocation Data
- IP address-based location information
- Service Providers
- Analytics Partners
- Business Partners
- Parties You Authorize, Access or Authenticate
- Profiles reflecting user attributes
- Profiles reflecting user behavior
- Service Providers
- Advertising Partners
- Analytics Partners
- Business Partners
- Parties You Authorize, Access or Authenticate