Trust

Security and data handling

You capture your customers' personal data. Here is exactly what we do with it — and what we don't.

Encrypted in transit

Everything travels over HTTPS. Webhooks only accept https destinations: over http your participants' data would go unencrypted.

The data belongs to the brand

You are the data controller and we are the processor. We never sell or share participant data with third parties.

Explicit consent

The participant form requires actively accepting the terms, and links to your legal terms before anything is submitted.

Deletion and export

Export a campaign's participants as CSV whenever you want, and deleting from the dashboard really removes them from the database — it does not just hide them.

Role-based access

Owner, admin, operator and member: each one sees only what their role allows. Whoever validates prizes in a store does not see the brand's billing.

Prize anti-fraud

Attempts are capped per person and per game, with the window computed in your brand's time zone. Each prize generates a code that can only be validated once.

Secrets that cannot be recovered

API keys are stored hashed and signing secrets encrypted. They are shown once, when you create them.

The server decides the outcome

The game only animates. No prize is awarded because the browser says so, so you cannot win by touching the code.

Isolation between brands

Every query is scoped to the company of whoever makes it. One brand cannot read another brand's participants.

Where the data lives, and for how long

The two answers your legal team will ask for first — with provider, region and retention period.

Where the data runs

In the United States. The web app, the API and the database run on Railway, in its US East (Virginia) region. There is no replica in the European Union.

If your brand needs your audience's data never to leave the EU, Zest does not meet that requirement today. We'd rather you knew now than after you have already sent us your list.

Besides Railway, two providers see data: Stripe processes payments — yours, not your participants': the card is entered in their form — and Resend delivers email, including the redemption code that reaches whoever wins a prize. Nobody else receives the participant list.

How long it is kept

A campaign that has ended does not justify keeping the people who played identified. After a set period from the closing date, the system wipes each participant's first name, last name, email, phone, age, gender, city and country from the database, and records the day it did so.

The row is deliberately not deleted outright: the plays and the prizes remain, with nobody behind them. That way you don't lose your campaign report — how many played, how many prizes went out — which is yours and identifies no one.

The exact period is not set yet, so we are not going to announce a number we don't apply: until it is set, nothing is deleted automatically. Deletion on request does exist, is immediate, and you do it yourself from the dashboard.

What you can do with your participants' data

The European regulation names these rights. This is what the product does about each one, today.

Access

From the dashboard you see any participant's full record: their data, their plays and their prizes, with dates. If someone asks what you hold about them, you have it on screen.

Portability

Export the participants you are looking at as CSV, with the filters applied. The file is exactly the same set as the screen, and opens in Excel with accents intact.

Erasure

Select participants and delete them: it is a DELETE against the database, not a hidden flag. What is deleted does not come back, for you or for us.

Consent

Nobody leaves a single field without ticking a box that starts empty: without it the submit button is disabled. Before the form, a notice explains why the data is being asked for and links to how it is handled.

Minimisation

Each campaign defines which fields it asks for, and the form only draws those. A brand campaign can ask for nothing at all: Zest's public demo works that way.

Purpose limitation

Your participants' data is used to provide you the service and nothing else. We don't sell it, don't share it and don't cross it between brands: every query is scoped to the company of whoever makes it.

The questions we always get

Does the data leave my country?

Yes. It runs in Virginia, United States, whatever the country of your brand or your participants. It is explained above, with provider and region.

Are you GDPR compliant?

We are not going to claim that: compliance is a legal determination, not a product feature, and we have not yet signed a standard data processing agreement. What we can state is what the product lets you do, which is the list above. If your team needs the signed agreement, write to us and we'll work it out with them.

What happens to the data if I stop being a customer?

You can export everything as CSV at any time, including before you cancel, and you can delete whatever you want from the dashboard. The retention period after cancellation is agreed by contract: there is no single number that applies to everyone yet, and we are not going to invent one.

About payments

We neither store nor see card details. Payments are processed by Stripe, and payment details are entered in their form, not ours.

That is why adding or changing a card takes you to a Stripe screen instead of a form of ours.

What we don't have yet

We do not yet have SOC 2 or ISO 27001 certification, nor a formal vulnerability disclosure program, nor a signed standard data processing agreement, nor hosting in the European Union.

If you found something, write to us and we'll look at it the same day. We'd rather hear it from you than from an incident.

Does your legal team need more detail?

The above is what exists today. If you are missing a document, a period in writing, or an answer to a vendor questionnaire, write to us.