Cookie Preferences

    We use cookies and similar technologies to enhance your experience, analyze site usage, and assist in our marketing efforts. By clicking "Accept All", you consent to the use of all cookies. You can manage your preferences or reject non-essential cookies.

    For more information, please read our Privacy Policy and Cookie Policy.

    STAGING

    Privacy Policy

    Last updated: September 14, 2026

    1. Introduction

    Zentry ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our digital key platform and related services. This policy applies to all users worldwide and addresses requirements under the California Consumer Privacy Act (CCPA), the General Data Protection Regulation (GDPR), the Telephone Consumer Protection Act (TCPA), and other applicable privacy laws.

    2. Information We Collect (Web Platform)

    Scope: This section applies to our web platform - the Zentry website (zentrydigitalsolutions.com) and the admin/property management portal used by property staff and account owners. For data practices specific to the Zentry Guest iOS app, see Section 2a below.

    Personal Information

    On the web platform, we may collect the following categories of personal information:

    • Identifiers: Name, email address, phone number, IP address
    • Commercial Information: Reservation details (check-in/check-out dates, room assignments)
    • Geolocation Data: Location data (when using proximity-based unlock features)
    • Electronic Activity: Access logs (times and locations of key usage), device information
    • Inferences: Usage patterns derived from the above information

    Billing Information (Property Accounts)

    Paid subscriptions are processed by Stripe. Card details and billing address are entered directly with Stripe and are never received or stored by Zentry. We keep only a customer reference, the selected plan, and the subscription status so we can manage your account.

    Identity Verification (Guests)

    Where a property requires it before access is issued, you may be asked to photograph a government-issued ID and, if that property also requires it, to take a selfie that is compared with the photo on the ID. This is captured and processed directly by Stripe Identity. Zentry never sees, downloads or stores the ID image or the selfie, and keeps no biometric data. The property receives only the outcome, never the document itself.

    Automatically Collected Information (Web Platform)

    • IP address and browser type
    • Usage data and analytics
    • Cookies and similar tracking technologies (see our Cookie Policy)

    2a. Mobile App (iOS Guest App)

    This section describes the data practices specific to the Zentry Guest iOS app available on the Apple App Store. The mobile app is a tightly scoped guest experience and collects only the minimum information required to deliver your digital room key.

    What the iOS app collects

    • Phone number - used to send a one-time passcode (OTP) for authentication.
    • Reservation details - your room assignment and check-in/check-out dates, retrieved from the property's reservation system after authentication.
    • Unlock activity - timestamps of digital key usage, recorded for security and for the property's access logs.
    • Authentication identifier - an internal user ID associated with your authenticated session.

    What the iOS app does NOT collect

    • Your name or email address (these are not requested in the guest flow).
    • Precise or approximate device location (the app does not request location permission).
    • Contacts, photos, microphone, camera, or health data.
    • Advertising identifiers (IDFA) or any data used for advertising or cross-app tracking.
    • Crash, diagnostic, or analytics data - the iOS app contains no third-party analytics or crash-reporting SDKs.

    No tracking

    The iOS app does not track you across other companies' apps or websites and does not share data with advertising networks.

    Where the rest of this policy applies

    Sections 3-13 below (use, SMS, sharing, security, retention, your rights, transfers, children, and contact) apply equally to information collected through the iOS app. The broader categories listed in Section 2 apply to our web platform (admin and property users); the iOS guest app's scope is limited to the items listed in this section.

    3. How We Use Your Information

    We use collected information for the following business purposes:

    • Provide and maintain our digital key services
    • Send you important notifications about your stay
    • Process and manage your reservations
    • Improve our services and user experience
    • Ensure security and prevent fraud
    • Comply with legal obligations

    Legal Basis (GDPR): We process your data based on: (a) performance of a contract, (b) your consent, (c) our legitimate business interests, and (d) compliance with legal obligations.

    4. SMS Communications (TCPA Compliance)

    Zentry sends only transactional SMS messages related to your stay. We do not send marketing or promotional SMS messages.

    Transactional Messages We Send

    When you use our Service, you may receive the following stay-related transactional SMS messages:

    • One-time passcodes (OTP) for authentication
    • Digital key activation notifications
    • Check-in and check-out reminders
    • Reservation confirmations and updates
    • Security alerts and urgent notifications

    Your SMS Choices

    During guest login, you may opt in to receive SMS notifications about your stay (such as check-in reminders and key activations). This consent is optional and does not affect your ability to use your digital key.

    Opt-Out: You can opt out of SMS notifications at any time by replying STOP to any message. Note that one-time passcodes for authentication cannot be disabled while using our Service.

    Message frequency varies. Message and data rates may apply.

    Consent Records: We maintain records of your SMS consent including the date, time, and method of consent for compliance purposes.

    5. Information Sharing and Disclosure

    We may share your information with:

    • Property Partners: The properties where you have reservations (for service delivery)
    • Service Providers: Third parties who assist in operating our services (SMS providers, cloud hosting, analytics)
    • Stripe, Inc.: Our sub-processor for subscription payment processing and, where a property enables it, identity verification. Stripe handles this information under its own privacy policy, available at stripe.com/privacy.
    • Legal Requirements: When required by law, court order, or to protect our rights

    We do not sell your personal information to third parties.

    For California residents: In the preceding 12 months, we have not sold personal information and do not have actual knowledge of selling personal information of minors under 16 years of age.

    6. Data Security

    We implement industry-standard security measures to protect your information, including encryption in transit and at rest, secure data transmission (TLS/SSL), access controls, and regular security assessments. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

    7. Data Retention

    We retain your personal information for as long as necessary to provide our services and fulfill the purposes described in this policy. Access logs are retained for security and compliance purposes for up to 2 years. SMS consent records are retained for the duration required by TCPA regulations (typically 4 years). After the retention period, data is securely deleted or anonymized.

    Identity verification: From a verification we keep only the result (verified, another attempt needed, or referred to the property for review), the time it happened, and a short reason code. We keep no ID images, no selfies and no biometric data. Those images are held by Stripe under Stripe's own retention policy, not ours.

    8. Your Privacy Rights

    California Residents (CCPA/CPRA)

    If you are a California resident, you have the following rights:

    • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected
    • Right to Delete: Request deletion of your personal information, subject to certain exceptions
    • Right to Correct: Request correction of inaccurate personal information
    • Right to Opt-Out: Opt out of the sale or sharing of your personal information
    • Right to Non-Discrimination: We will not discriminate against you for exercising your rights

    To exercise these rights, visit our Privacy Rights Request page or contact us at contact@zentrydigitalsolutions.com. We will respond within 45 days.

    EU/UK Residents (GDPR)

    If you are in the European Union or United Kingdom, you have the following rights:

    • Right of Access: Obtain confirmation of whether we process your data and access to that data
    • Right to Rectification: Request correction of inaccurate personal data
    • Right to Erasure: Request deletion of your personal data ("right to be forgotten")
    • Right to Restrict Processing: Request restriction of processing in certain circumstances
    • Right to Data Portability: Receive your data in a structured, machine-readable format
    • Right to Object: Object to processing based on legitimate interests or for direct marketing
    • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent

    To exercise these rights, visit our Privacy Rights Request page. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority.

    9. International Data Transfers

    Your information may be transferred to and processed in countries other than your country of residence. When we transfer data internationally, we use appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection of your personal data.

    10. Children's Privacy

    Our Service is not intended for children under 16 (or under 13 in the United States). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at contact@zentrydigitalsolutions.com.

    11. Do Not Track Signals

    Some browsers have a "Do Not Track" feature. We currently do not respond to Do Not Track signals. You can manage your cookie preferences through our cookie consent banner or by adjusting your browser settings.

    12. Changes to This Policy

    We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. For significant changes, we will provide additional notice (such as by email or prominent notice on our website).

    13. Contact Us

    If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us:

    For GDPR inquiries, you may also contact our Data Protection Officer at contact@zentrydigitalsolutions.com.