Privacy Policy
Draft for professional legal review before commercial launch.
Who this covers
This page describes data handled by the Zenentre application when a passenger scans a vehicle QR, views an advertiser page, uses a coupon, contacts us, or when an administrator manages the service. Zenentre is currently a local MVP. A responsible legal operator and contact details must be confirmed before commercial launch.
QR scans and fraud controls
A valid QR request creates a scan record with the server time, rickshaw and campaign actually displayed, a random anonymous browser identifier, broad device category derived from the browser user-agent, qualification and risk results, reasons, and a keyed HMAC of the request IP address. The browser identifier recognizes a browser profile and is not a verified person or physical device. It remains the same when that browser changes networks. Zenentre treats IP activity only as a secondary risk signal because one public IP may represent many people, including through mobile carrier CGNAT. The application database does not store the raw IP address, but network infrastructure and server logs may receive connection and request information.
Coupons and interactions
For enabled campaigns, Zenentre stores coupon code, campaign, originating rickshaw, anonymous visitor identifier, claim scan, issue time, expiry and redemption time. It records CTA taps such as call, WhatsApp, directions, menu, booking and website actions against the scan. Public coupon verification uses a keyed IP hash to limit attempts. Restaurant staff see coupon status, business, offer and expiry; they do not see visitor or rickshaw data.
Enquiries and administration
Advertiser enquiries contain the business and contact details submitted, category, city, message, time and a keyed IP hash for abuse prevention. Contact messages contain name, email, optional phone, message, time and a keyed IP hash. Administrators can see these submissions. Admin data also includes driver names and phone numbers, vehicle details, scan earnings and recorded payment transactions.
Cookies and browser storage
Zenentre sets a first-party HttpOnly zenetre_visitor cookie for up to 90 days to recognize repeat visits and reuse an eligible coupon. Admin sign-in sets a signed HttpOnly zenetre_admin cookie for up to 7 days. Both use SameSite=Lax. Zenentre does not currently use localStorage, sessionStorage, advertising cookies or third-party analytics scripts. Clearing the visitor cookie makes the browser appear new, subject to scan qualification controls. See the Cookie Policy for details.
Storage, recipients and links
The local MVP keeps structured records in PostgreSQL and new advertiser-supplied images and PDFs in a private Supabase Storage bucket; the website serves approved media publicly. Any older locally uploaded images remain on the application server until moved or removed. Older campaigns may also use external image URLs, so those hosts may receive browser connection information when the page loads. Operators with database or server access can access records. Opening Maps, WhatsApp, an advertiser website, social page, telephone app or booking site passes you to that third party, which handles information under its own terms and privacy practices. Zenentre does not control what the advertiser later collects directly from you.
Retention, requests and security
Visitor and admin cookies have the lifetimes above. Scan and risk review records, including keyed IP HMAC values, currently have no automatic deletion job and remain until an authorized retention process removes them. Coupon, enquiry, contact, payment and campaign records likewise remain until that process is configured. Server-log retention depends on the hosting environment and is not fixed here. Use the Contact page to ask about access, correction or deletion. Zenentre uses restricted database roles, server-side checks and a private media bucket, but no system can guarantee absolute security.
For questions, use the Contact page.