Skip to content

Legal

Privacy Policy

What we collect, why, and what you can do about it.

Last updated: 2026-07-02

Draft.This document is a starting point and has not been reviewed by counsel. We’ll replace it before public launch.

The headline

We don’t sell your data. Verification reports are private by default. You decide if and when to publish a badge.

What we collect

  • Account information. Your name, email, optional avatar, and (for verifiers) your role, company, LinkedIn URL, rates, and bio.
  • Session content. Pre-session materials you choose to share, prep briefs, in-app messages, and recorded video sessions.
  • Booking + payment metadata.Booking times, counterparty, service details, Stripe payment references. We don’t store full card numbers.
  • Usage telemetry. Pages viewed, basic session analytics. We use PostHog for this.

Why we collect it

  • To run the marketplace: match pros with verifiers, deliver sessions, generate reports.
  • To process payments and pay verifiers.
  • To improve the product and detect abuse.
  • To send transactional emails (booking confirmations, prep briefs, message notifications).

Who we share it with

  • Supabase - our database and authentication provider.
  • Stripe - payments and verifier payouts.
  • Cal.com - scheduling.
  • Daily.co - video infrastructure.
  • Resend - transactional email delivery.
  • PostHog - product analytics.
We don’t sell your data. We only share what each provider needs to do their job.

Google Calendar

Connecting Google Calendar is optional. If you connect it, Zealoq requests access to your calendar so it can keep your availability accurate and manage session events. You can disconnect at any time.

  • What we access. With your permission we use the Google Calendar events and free/busyscopes to (1) read your busy time windows so we never offer a slot when you’re already booked, and (2) create, update, and cancel calendar events for sessions you book or host.
  • What we do not access. We do not read the titles, descriptions, attendees, or contents of your other calendar events - only your free/busy windows and the events Zealoq itself creates.
  • Storage. We store the OAuth tokens needed to keep the connection working. You can revoke access at any time from Settings, which deletes the connection and stops all access.
  • Sharing. We do not sell this data, use it for advertising, or transfer it to third parties, and we do not use it to develop, improve, or train generalized AI or machine-learning models.

Limited Use

Zealoq’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Verification reports + badges

A verification report is private to you by default. You control whether and how to share it. A badge derived from a passing report is designed to be public when you choose to publish it.

Your rights (GDPR)

  • Access - request a copy of your data.
  • Rectification - correct errors via your settings or by emailing us.
  • Erasure - delete your account at any time from settings, or email us.
  • Portability - request an export of your data.
  • Objection - opt out of analytics from your settings.

Retention

We keep your account data while your account is active. After deletion we retain anonymized booking and report records for legal and accounting purposes (typically 7 years). Recordings are deleted within 90 days unless either party objects.

Cookies

We use cookies for sign-in (essential) and product analytics (optional). You can opt out of analytics from your settings.

Contact

Questions about your data? Contact us.