Legal

Privacy Policy

What we collect, why we collect it, who else sees it, and how to make us stop.

Effective 6 September 2026. We will post any change on this page and update this date.

1. Scope

This policy explains how ZenOrbit handles personal data when you visit zenorbit.app, create an account, use the platform, or book time with someone who uses it. It covers the data we decide the purposes for. Where you use ZenOrbit to run your own business, you decide what to collect from your clients and we process it on your instructions.

2. What we collect

Data you give us

  • Account data — name, email address, password credentials held by our identity provider, and account preferences.
  • Profile and booking configuration — what you offer, your availability, your public profile content.
  • Booking data — the appointments made with you, including the name, email address and any answers the person booking provides.
  • Billing data — your plan, subscription status, invoices and the country used for tax. Card details go to our payment provider, not to us.
  • Support correspondence — what you write to us and our replies.

Data from connected services

  • Calendar data — busy time and the events we create, from the calendar you choose to connect.
  • Conferencing data — meeting identifiers and join links created on your behalf.

Data generated by use

  • Meeting content — where you enable the AI meeting assistant, transcripts and summaries of those meetings.
  • Technical data — request logs, error records and traces containing identifiers, timestamps and IP address, used to operate and secure the Service.

3. This website

zenorbit.app is a static website. It sets no cookies, runs no advertising or analytics scripts, and does not track you across sites. Our hosting provider records standard server request logs for security and operational purposes. The signed-in application at app.zenorbit.app uses cookies and local storage that are strictly necessary to keep you signed in.

4. Why we use it, and on what basis

  • To provide the Service — creating bookings, syncing calendars, generating meeting links, sending reminders. Basis: performance of our contract with you.
  • To take payment — subscriptions, invoices and refunds. Basis: performance of our contract, and legal obligation for tax records.
  • To keep the Service secure and working — logging, monitoring, abuse prevention, debugging. Basis: our legitimate interest in a secure and reliable service.
  • To support you — answering questions and investigating problems. Basis: performance of our contract.
  • To comply with law — retaining financial records, responding to lawful requests. Basis: legal obligation.

We do not sell personal data, and we do not share it for anyone else’s advertising.

5. Who we share it with

We share personal data only with providers who process it for us, and only for the purposes above:

  • Cloud infrastructure — hosting, database, storage and content delivery.
  • Payment provider — to take payments and process refunds. They hold card details under their own terms.
  • Calendar and conferencing providers — those you choose to connect, for the integration you asked for.
  • Communication providers — to deliver email and messaging notifications.
  • AI processing — where you enable the meeting assistant, to produce transcripts and summaries. Content sent for that purpose is not used to train third-party models on our instruction.

We may also disclose data where required by law, or in connection with a merger or acquisition, in which case we will tell you before your data becomes subject to a different policy.

6. International transfers

Our infrastructure is operated in the Asia Pacific (Mumbai) region. Some providers may process data in other countries. Where data leaves the country it was collected in, we rely on the transfer mechanisms permitted by applicable law and require appropriate safeguards from the provider.

7. How long we keep it

  • Account and booking data — while your account is active, and for a limited period after closure to handle disputes.
  • Financial records — for the period tax and accounting law requires.
  • Technical logs — for a short operational retention period, then deleted or archived.
  • Support correspondence — while it is useful to the relationship, then deleted.

When you ask us to delete your data, we delete it except where law requires us to keep it.

8. Security

Data is encrypted in transit and at rest. Access is limited to what a role requires. Secrets and credentials are held in a managed secret store and are never written to logs. Our security page describes this in more detail.

9. Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you;
  • correct it if it is wrong;
  • delete it;
  • receive a copy in a portable format;
  • object to or restrict certain processing;
  • withdraw consent where processing relies on it; and
  • complain to your data protection authority.

To exercise any of these, write to support@zenorbit.app. We will verify your identity and respond within the period the applicable law allows. If you booked time with someone who uses ZenOrbit, ask them first — for that booking, they decide what is collected and we act on their instructions.

10. Children

The Service is not directed at children and we do not knowingly collect their personal data. If you believe a child has provided us data, write to us and we will delete it.

11. Changes

We will post any change to this policy on this page and update the effective date. Material changes will be notified to the email address on your account.

12. Contact

Privacy questions and data requests: support@zenorbit.app. Anything else: contact@zenorbit.app.