Trust
Security and data handling
You capture your customers' personal data. Here is exactly what we do with it — and what we don't.
Encrypted in transit
Everything travels over HTTPS. Webhooks only accept https destinations: over http your participants' data would go unencrypted.
The data belongs to the brand
You are the data controller and we are the processor. We never sell or share participant data with third parties.
Explicit consent
The participant form requires actively accepting the terms, and links to your legal terms before anything is submitted.
Deletion and export
Export a campaign's participants as CSV whenever you want, and deleting from the dashboard really removes them from the database — it does not just hide them.
Role-based access
Owner, admin, operator and member: each one sees only what their role allows. Whoever validates prizes in a store does not see the brand's billing.
Prize anti-fraud
Attempts are capped per person and per game, with the window computed in your brand's time zone. Each prize generates a code that can only be validated once.
Secrets that cannot be recovered
API keys are stored hashed and signing secrets encrypted. They are shown once, when you create them.
The server decides the outcome
The game only animates. No prize is awarded because the browser says so, so you cannot win by touching the code.
Isolation between brands
Every query is scoped to the company of whoever makes it. One brand cannot read another brand's participants.
Where the data lives, and for how long
The two answers your legal team will ask for first — with provider, region and retention period.
What you can do with your participants' data
The European regulation names these rights. This is what the product does about each one, today.
Access
From the dashboard you see any participant's full record: their data, their plays and their prizes, with dates. If someone asks what you hold about them, you have it on screen.
Portability
Export the participants you are looking at as CSV, with the filters applied. The file is exactly the same set as the screen, and opens in Excel with accents intact.
Erasure
Select participants and delete them: it is a DELETE against the database, not a hidden flag. What is deleted does not come back, for you or for us.
Consent
Nobody leaves a single field without ticking a box that starts empty: without it the submit button is disabled. Before the form, a notice explains why the data is being asked for and links to how it is handled.
Minimisation
Each campaign defines which fields it asks for, and the form only draws those. A brand campaign can ask for nothing at all: Zest's public demo works that way.
Purpose limitation
Your participants' data is used to provide you the service and nothing else. We don't sell it, don't share it and don't cross it between brands: every query is scoped to the company of whoever makes it.
The questions we always get
Does the data leave my country?
Yes. It runs in Virginia, United States, whatever the country of your brand or your participants. It is explained above, with provider and region.
Are you GDPR compliant?
We are not going to claim that: compliance is a legal determination, not a product feature, and we have not yet signed a standard data processing agreement. What we can state is what the product lets you do, which is the list above. If your team needs the signed agreement, write to us and we'll work it out with them.
What happens to the data if I stop being a customer?
You can export everything as CSV at any time, including before you cancel, and you can delete whatever you want from the dashboard. The retention period after cancellation is agreed by contract: there is no single number that applies to everyone yet, and we are not going to invent one.
About payments
What we don't have yet
Does your legal team need more detail?
The above is what exists today. If you are missing a document, a period in writing, or an answer to a vendor questionnaire, write to us.