Privacy Policy
What personal data Zenify Homes collects, why, and what you can ask us to do about it.
1. What this policy covers
This policy explains how Zenify Homes handles personal data on the Zenify website and marketplace, in the customer portal, and in the course of managing a property or a tenancy.
It is written to be read, not to be survived. Where we do not yet do something, it says so rather than implying we do.
2. What we collect
Information you give us directly:
- Contact details — your name, mobile number and email address, and the city you are interested in.
- What you are looking for — your enquiry or message, budget range, preferred localities, home size, furnishing, parking, move-in dates, and whether pets or other household members will live there.
- Property information, if you are an owner — the property's address, type, size, expected rent or sale price, photographs, and notes about access.
- Account details — the name, mobile number and email on your Zenify account, and your profile photo if you add one.
- Identity documents, where verification is required — a PAN, Aadhaar, passport, driving licence, voter ID, address proof or photograph. We store the document file itself in private storage and keep only the last four characters of the reference number in our database.
- Bank and payment destination details, where you are an owner receiving payouts or a vendor being paid.
- Job applications — your CV, LinkedIn URL and the details on the careers form.
- Vendor onboarding details, if you apply to work with us — business details, PAN, GSTIN, bank details and supporting documents.
Information created by using the service:
- Enquiries, visit requests, shortlists and saved searches.
- Tenancy and management records — agreements, contract parties, occupancy details, rent and payment records, and payment references.
- Maintenance tickets, the access instructions you give with them, and the photographs and evidence attached to the work.
- Inspection records, including photographs and the location at which evidence was captured.
- Support cases and your correspondence with our team, including calls and messages handled through our CRM.
- Your communication preferences and notification settings.
Information collected automatically:
- The page you arrived on and the referring site, recorded only when you submit a form.
- Campaign and advertising identifiers present in the link you arrived through — utm_source, utm_medium, utm_campaign, utm_content, utm_term, and click identifiers such as gclid, gbraid, wbraid, fbclid and msclkid. See section 8.
- Standard security and operational logs kept by the platforms we run on.
3. Why we use it
- To answer your enquiry and arrange visits.
- To provide the service — managing a property, running a tenancy, coordinating maintenance, carrying out inspections and handling move-in and move-out.
- To administer your account and give you access to the right workspace.
- To handle rent, deposits, payouts and settlements, and to keep the financial records that go with them.
- To prepare, execute and keep the agreements and documentation a tenancy or a management relationship requires.
- To verify identity where a tenancy, an ownership relationship or a vendor onboarding requires it.
- To provide customer support and to resolve complaints.
- To send you service messages about your account, your property, your tenancy or a request you have made.
- To send you promotional messages, only where you have separately opted in.
- To keep the service secure, to detect and prevent fraud and misuse, and to investigate incidents.
- To meet legal, tax and regulatory obligations, and to establish or defend legal claims.
- To understand which campaigns bring people to Zenify, using the identifiers described in section 8.
Where we rely on consent you can withdraw it. Refusing or withdrawing an optional consent — promotional messages above all — never affects your account, and never stops the service messages we must send you about it.
India’s data protection law does not recognise “contractual necessity” as a ground, so we do not rely on one. Most of what is listed above rests on the consent you give when you hand us information for a stated purpose — an enquiry form, creating an account, a KYC submission — together with the specific consents described in the Data & Consent Policy. The rest rests on the limited legitimate uses the law allows, chiefly complying with a legal obligation and establishing or defending a legal claim.
5. Where it is stored
Our production database and file storage are hosted in the Mumbai (ap-south-1) region in India.
Some of the service providers named above operate globally, so a limited amount of data is processed outside India: address text sent to Google for autocomplete and maps, assistant conversations sent to OpenAI, and application platform and error-reporting data. We do not transfer your records in bulk outside India.
6. How we protect it
- Traffic to and from the site is encrypted in transit.
- Access to data is enforced in the database itself by row-level security, so a signed-in account can reach only the records it is entitled to.
- Every file store holding documents, identity evidence, inspection photographs and agreements is private. Only public marketing images are in a public store.
- Staff access is role-based and scoped, and changes to access are recorded in an audit log.
- Where we verify your identity, the document’s reference number is not stored in full — we keep only its last four characters alongside the document itself. This does not apply to the tax and bank details a vendor or an owner gives us for payment, which we must hold in full to pay them.
8. Campaign and advertising identifiers
If you arrive from a campaign link, that link may carry campaign parameters and an advertising click identifier. We hold these in the page's memory only — they are not written to your device, and there is no cookie or fingerprint behind them.
They are stored only if you submit a form, and then only attached to the enquiry you submitted, so we can tell which campaign produced it. If you never submit anything, nothing is stored.
9. How long we keep it
We keep personal data for as long as it is needed for the purpose it was collected for, and after that for as long as we are legally required to.
- Enquiries that do not become a relationship are kept while they are still commercially relevant.
- Tenancy, management, agreement and financial records are kept for the life of the relationship and then for the period tax and limitation law requires.
- Some records are deliberately immutable: your acceptance of a legal document, security audit entries, settlement lines and verification events are never edited or deleted, which is what makes them evidence. Other consent records are kept as an append-only history that authorised staff can correct if something was recorded wrongly.
- Identity documents are kept for as long as the relationship they support requires.
10. Your rights
You can ask us to:
- Tell you what personal data of yours we hold and what we do with it.
- Correct anything inaccurate, or complete anything incomplete.
- Delete data where we no longer have a lawful reason to keep it.
- Withdraw a consent you have given, including consent to promotional messages.
- Nominate someone to exercise these rights on your behalf if you are unable to.
Some details you can change yourself in your Zenify account. For anything else, write to hello@zenifyhomes.com from the email address on your account and tell us what you want. We may need to verify who you are before we act, which protects you from someone else making a request in your name.
Deletion is not always possible. Where a record is legally required, or is evidence in a tenancy, financial or security matter, we will keep it and tell you why.
11. If something goes wrong
If personal data we hold is lost, exposed, or accessed without authorisation, we will investigate and contain it, and tell the people affected. Where the law in force at the time requires us to notify a regulator — including the Data Protection Board once the Digital Personal Data Protection Act, 2023 is brought into effect — we will do that too, in the form and within the time it specifies.
12. Children
Zenify's services are for adults. We do not offer accounts to anyone under 18 and we do not knowingly collect children's personal data. A tenancy record may name a child living in a household because the tenancy requires it; that information comes from the adult tenant, is not used to profile anyone, and is never used for advertising. If you believe a child has given us data directly, write to us and we will remove it.
13. Changes, and how to reach us
Each version of this policy carries a version number and an effective date. Where a change is material we will ask you to review it the next time you sign in, and we record which version your account accepted.
To ask a question, make a request, or raise a grievance about how your personal data has been handled, write to hello@zenifyhomes.com with "Privacy" in the subject line, or to Zenify Homes, 314 The Crescent Business Park, MTNL Road, Saki Naka, Andheri East, Mumbai 400072. We will acknowledge your grievance and tell you who is handling it.
India’s Digital Personal Data Protection Act, 2023 provides for a Data Protection Board. As and when the Board is constituted and its complaint procedure is notified, you will be able to escalate an unresolved complaint to it in the manner it prescribes. Our consent and acceptance records are built to be ready for that.
The version shown above is the version that applies while it is current. If Zenify publishes a newer version, it applies from that point onward and, where the change is material, you will be asked to review it the next time you sign in.
