Privacy Policy
Effective date: March 1, 2026 · Zenny Books Inc. · Vancouver, BC, Canada
1. Introduction
Zenny Books Inc. ("Zenny", "we", "us", or "our") operates the Zenny financial management platform accessible at zennybooks.com. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our services.
We are incorporated in British Columbia, Canada, and serve users across Canada and the United States. Because we transfer personal information to third-party processors located in the United States in the course of providing our services, Canada's federal Personal Information Protection and Electronic Documents Act (PIPEDA) applies to our data handling practices. We also comply with the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA) for California residents.
By using Zenny, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use our services.
2. Information We Collect
2.1 Account Information
When you create an account we collect your name, email address, password (hashed), country, province or state, and usage preferences (personal, business, or both).
2.2 Financial Data (via Plaid)
When you connect a bank account through our Plaid integration, we retrieve account balances, transaction history, account numbers (masked), and institution details. We do not store your banking credentials. Plaid uses access tokens to retrieve data on your behalf. See Section 7 (Third-Party Processors) for Plaid's privacy policy link.
2.3 Payment Information (via Stripe)
Payment card details, billing address, and subscription status are processed by Stripe. We do not store full card numbers on our servers. We retain subscription identifiers and billing history to manage your account.
2.4 Uploaded Files
Receipts, invoices, and other documents you upload are stored securely through UploadThing and associated with your account for processing and retrieval.
2.5 AI-Processed Data
Transaction descriptions, receipt text, and financial data may be processed by Google (Gemini) and OpenAI (GPT) to generate categorizations, insights, and automated analysis. These processors act as service providers under contractual restrictions and may not use your data to train their models without your separate consent.
2.6 Usage and Technical Data
We collect IP addresses, browser type, device identifiers, pages visited, features used, and error logs through Vercel (our hosting provider), Sentry (error tracking), and Vercel Analytics. This data helps us improve the service and diagnose issues.
3. How We Use Your Information
We use your personal information only for the following purposes:
- Providing, maintaining, and improving the Zenny platform
- Processing your subscription and payments through Stripe
- Connecting your bank accounts and retrieving financial data through Plaid
- Generating AI-powered financial insights, categorizations, and analytics
- Communicating with you about your account, service updates, and support requests
- Detecting and preventing fraud, abuse, and security incidents
- Complying with legal obligations
- Generating de-identified, aggregated analytics about how the service is used (we never sell or share individually identifiable data)
We will not use your personal information for any purpose not listed above without obtaining your prior consent.
4. Legal Basis for Processing
Under PIPEDA, we process personal information on the basis of your informed consent (which you provide when you create an account and agree to these terms), and where processing is necessary to perform our contractual obligations to you. Some processing is required to comply with legal obligations such as tax and financial recordkeeping requirements.
For California residents, the CCPA categories of personal information we collect include: identifiers, financial information, commercial information, internet/network activity information, geolocation data (limited, from IP), and inferences drawn from the above to create a profile about your financial preferences and habits.
5. How We Share Your Information
We do not sell or rent your personal information. We share your information only as follows:
- Service providers: We share information with the third-party processors listed in Section 7 solely to provide our services. Each processor is bound by a Data Processing Agreement restricting their use of your data.
- Legal requirements: We may disclose your information if required by law, court order, or regulation, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business transfers: If Zenny is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your personal information becomes subject to a different privacy policy.
- With your consent: We may share your information for any other purpose with your prior consent.
California residents: We do not "sell" or "share" your personal information as defined under the CCPA/CPRA, including for cross-contextual behavioral advertising. You may submit a request to confirm this or to exercise your rights at support@zennybooks.com.
6. Data Retention
We retain your personal information for as long as your account is active or as necessary to provide our services. Upon account deletion:
- Account and financial data are deleted within 30 days, subject to legally required retention periods
- Payment records may be retained for up to 7 years for tax and accounting purposes
- Security incident and breach logs are retained for 24 months as required under PIPEDA
- Anonymized, aggregated analytics data may be retained indefinitely as it cannot be used to identify you
7. Third-Party Processors
The following service providers process personal information on our behalf. Each is bound by contractual data protection obligations consistent with PIPEDA and, where applicable, CCPA.
| Processor | Purpose | Data Shared | Location |
|---|---|---|---|
| Clerk | Authentication & identity | Email, password hash, auth tokens | US |
| Plaid | Bank account connectivity | Banking tokens, transaction & balance data | US |
| Stripe | Subscription payments | Payment card info, billing address | US |
| Vercel | Application hosting | HTTP request logs, IP addresses | US |
| Neon | Database storage | All application data | US |
| UploadThing | File storage | Uploaded receipts and documents | US |
| Sentry | Error & performance monitoring | Error logs (may contain limited session data) | US |
| Google (Gemini) | AI processing for insights & categorization | Transaction descriptions, receipt text | US |
| OpenAI | AI processing for insights & categorization | Transaction descriptions, receipt text | US |
| Inngest | Background job processing | Job metadata and payloads | US |
All processors are located in the United States. Transfers of personal information outside Canada are made subject to contractual protections as required by PIPEDA Principle 4.1.3.
8. Security
We use industry-standard security measures including TLS encryption in transit, encryption at rest for sensitive data, access controls, and regular security reviews. However, no system is completely secure. If you become aware of any security issue, please notify us immediately at support@zennybooks.com.
9. Security Breach Notification
In the event of a security breach that creates a real risk of significant harm to you, we will notify you and, where required, the Privacy Commissioner of Canada "as soon as feasible" as required under PIPEDA. For California residents, we will notify you within 30 days of discovering a breach involving your personal information. If more than 500 California residents are affected by a single breach, we will also notify the California Attorney General within 15 days.
10. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate information
- Deletion: Request deletion of your personal information (subject to legal retention requirements)
- Portability: Export your data in a machine-readable format through Settings → Account
- Opt-out of secondary processing: Object to your data being used for analytics or product improvement beyond service delivery
- California residents (CCPA/CPRA): Right to know, right to delete, right to correct, right to opt out of sale/sharing, right to limit use of sensitive personal information, and right to non-discrimination
To exercise any of these rights, contact us at support@zennybooks.com. We will respond within 30 days. We may need to verify your identity before processing your request.
11. Cookies and Tracking
We use session cookies required for authentication and security. Vercel Analytics collects anonymized usage data to help us improve the service. We do not use cookies for targeted advertising. You can control cookies through your browser settings; disabling session cookies may prevent you from logging in.
12. Children's Privacy
Zenny is not directed at children under 13 years of age. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately at support@zennybooks.com.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a prominent notice in the application. Continued use of Zenny after the effective date of the updated policy constitutes your acceptance of the changes.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Zenny Books Inc.
Vancouver, British Columbia, Canada
Email: support@zennybooks.com
You also have the right to lodge a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, for California residents, the California Privacy Protection Agency (cppa.ca.gov).