Privacy Policy
Last updated: August 20, 2026
Zeeo Technologies, Inc. ("Zeeo", "we", "us", "our"), a Delaware corporation with a registered agent at 251 Little Falls Drive, Wilmington, DE 19808, United States, operates the Zeeo mobile application and the website at getzeeo.com (together, the "App").
This Privacy Policy explains what personal data we collect, why, who we share it with, how long we keep it, and what rights you have. It applies to everyone who uses the App, in the United States and the European Union.
Questions, requests or complaints: support@getzeeo.com.
1. Our Role
Zeeo is a software interface. We do not custody funds or private keys, and we do not perform the regulated parts of a transaction. Those are performed by Bridge (virtual accounts, conversion, payouts, KYC, AML and sanctions screening) and Privy (wallet infrastructure and authentication).
Different parties are responsible for different processing:
| Activity | Zeeo's role |
|---|---|
| Your Zeeo account, profile, in-app activity, referrals, support, marketing | Controller |
| Passing your details to Bridge so Bridge can verify you and execute transactions | Controller for the transmission; Bridge is an independent controller for its own verification, AML and monitoring |
| Wallet creation and authentication via Privy | Controller for our use of the resulting identifiers; Privy is an independent controller for its own processing |
| Hosting, storage, error monitoring | Controller, using processors (Convex, Sentry) |
Bridge and Privy process your personal data under their own privacy policies, for their own legal and compliance purposes. We do not control that processing. Links are in Section 6.
2. Personal Data We Hold
This is a complete description of the categories of personal data stored in our systems.
2.1 Profile
First name, last name, username, email address, phone number, country, and state or region. Whether you have completed security setup. Account creation and update timestamps.
2.2 Wallet identifiers
Your Privy user identifier (privyDid), your Privy wallet ID, and your wallet address on the Base network.
2.3 Verification status
Your Bridge customer identifier, your verification status and the time it last changed, whether you have accepted Bridge's terms, and whether identity verification has been completed. During onboarding we also store the name and email address you supply to start verification, and the verification link issued to you.
We do not receive or store copies of your identity documents. You submit those directly to Bridge through its own verification flow. We receive the outcome, not the documents.
2.4 Virtual account details
The bank details of the virtual account issued to you for receiving money: bank name and address, IBAN and BIC, or routing and account number, beneficiary name and address, currency and payment rail.
2.5 External bank accounts you add
Account holder name, first and last name, bank name, bank country, the last four digits of the account, a label or display name you choose, whether the account is your own or belongs to someone else, and whether the holder is an individual or a business.
For accounts added under our current system we store only the last four digits, not the full account number or IBAN. Records created under an earlier version of the App may contain full bank details; these are being retired.
2.6 Transactions
For every transaction: type, status, network, asset, amount and display values, sender and recipient wallet addresses, sender and recipient Zeeo identifiers where both parties are Zeeo users, the blockchain transaction hash, the channel used, any optional note you attach, fees and exchange rates applied, and timestamps.
For payouts and incoming payments we additionally store the transfer or deposit identifier, its state history, the counterparty's bank name, the last four digits of the counterparty's account, the counterparty's name, the payment reference, receipt details, and — where a payment is returned — the refund reason and reference.
2.7 Referrals and invitations
Your referral code, the identifier of the user who invited you, and counts of invitations you have sent and users you have referred.
2.8 Card waitlist
If you reserve a place for a future card product, we store your identifier and your place in the queue.
2.9 Technical and diagnostic data
Device and app usage information, IP address, app version and operating system, basic log data, webhook event data received from Privy and Bridge, crash reports and error diagnostics collected through Sentry, and product analytics events collected through PostHog (for example, app opens and custom events such as completing onboarding or ordering a card), used to measure active users and understand how the App is used.
2.10 Communications
Emails, support messages, onboarding notes, and feedback you send us.
2.11 Deletion records
If you delete your account, the time of the request and any reasons you choose to give.
3. Finding Other Users
You can send money to another Zeeo user using their Zeeo @username handle. To make this work, your username is visible to other users of the App.
You may also allow other users to find you by your phone number. This is a setting you control, and you can turn it off at any time in the App. When it is off, your phone number is not used for discovery.
4. Personal Data About Other People
When you add an external bank account belonging to someone else, or send money to another person, you provide us with their personal data — typically their name and partial bank details. When someone sends money to you, we receive their name and partial bank details from Bridge.
We process this data to execute the transaction, to display it accurately in your activity, and to meet recordkeeping obligations. If you provide us with another person's data, you confirm that you are entitled to do so.
5. How We Use Personal Data
- To create, verify and manage your account
- To operate the App and display your balance, activity and transaction history
- To pass your details to Bridge for verification and to execute transactions you instruct
- To issue and display your virtual account details
- To let you send money to other Zeeo users and to external bank accounts
- To calculate and display fees and exchange rates
- To operate the referral programme
- To meet legal and regulatory obligations, and to support our partners' AML, sanctions-screening and monitoring obligations
- To detect, investigate and prevent fraud, abuse, unauthorised access and other security issues
- To provide support, respond to your questions, and resolve disputes
- To debug errors, monitor stability and improve the App
- To communicate with you about service changes and security matters, and — where you have opted in — product updates
- To establish, exercise or defend legal claims and enforce our Terms of Service
We do not sell your personal data, and we do not share it for cross-context behavioural advertising. We do not use your data for automated decision-making that produces legal or similarly significant effects. Verification and compliance decisions are made by Bridge under its own policies; if such a decision affects you, contact us and we will direct you to Bridge's process.
6. Who We Share Personal Data With
Financial and wallet partners (independent controllers)
| Partner | Purpose | Policies |
|---|---|---|
| Bridge Building Inc (US) | Virtual accounts, conversion, ACH and SEPA payouts, KYC, AML, sanctions screening, monitoring | Terms · Privacy Policy |
| Bridge Building S.A. (EEA) | As above, for EEA users | Terms · Privacy Policy |
| Bridge Building Limited (rest of world) | As above | Terms · Privacy Policy |
| Privy (Horkos, Inc.) | Authentication and wallet infrastructure | User Terms · Privacy Policy |
Service providers (processors acting on our instructions)
| Provider | Purpose | Location | Policies |
|---|---|---|---|
| Convex | Backend infrastructure and application data storage | US East (N. Virginia) | Privacy Policy · DPA |
| Sentry (Functional Software, Inc.) | Error monitoring, crash reporting, diagnostics | United States | Terms · Privacy Policy |
| PostHog (PostHog, Inc.) | Product analytics — monitoring monthly and daily active users, and tracking custom in-app events (e.g. onboarding completion, card orders) | United States (PostHog Cloud) | Privacy Policy · DPA |
To display currency conversions, the App also retrieves current exchange rates from ExchangeRate-API (open.er-api.com). This is a simple, unauthenticated lookup of public exchange rate data — no personal data about you is sent or received as part of this call.
Others
- Professional advisers — lawyers, accountants and auditors, where necessary and under confidentiality obligations.
- Regulators, law enforcement and courts — where required by law, court order or lawful request, or to protect our rights or the safety of others. We and our partners may be legally prohibited from telling you that such a disclosure or report has been made.
- Acquirers — in connection with a merger, acquisition, financing or sale of assets, subject to appropriate safeguards.
- With your consent or at your direction.
7. Transaction Data on Public Networks
Transactions in the App settle on the Base blockchain, a public network. Transaction data — including wallet addresses, amounts and timestamps — is public, permanent, and outside the control of Zeeo, Privy and Bridge.
We cannot delete, alter or restrict these records, and no data subject right can be exercised against a public network. A wallet address may, in combination with other information, be linked back to you by third parties. Please take this into account when deciding what to transact and with whom.
8. Legal Bases (EEA and UK)
| Purpose | Legal basis |
|---|---|
| Creating your account, operating the App, executing transactions you instruct | Performance of a contract (Art. 6(1)(b)) |
| Passing verification data to Bridge; retaining transaction records | Legal obligation (Art. 6(1)(c)) and legitimate interests |
| Fraud prevention, security, abuse detection | Legitimate interests (Art. 6(1)(f)) |
| Debugging, diagnostics, product improvement | Legitimate interests (Art. 6(1)(f)) |
| Product analytics (PostHog) | Legitimate interests (Art. 6(1)(f)) |
| Referral programme | Performance of a contract and legitimate interests |
| Phone number discovery | Consent (Art. 6(1)(a)) — you control this setting |
| Establishing, exercising or defending legal claims | Legitimate interests (Art. 6(1)(f)) |
| Marketing communications and non-essential cookies | Consent (Art. 6(1)(a)) |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. Where we rely on consent, you may withdraw it at any time; withdrawal does not affect processing carried out beforehand.
9. International Transfers
Zeeo is established in the United States, and our application data is stored by Convex in the US East (Northern Virginia) region. Sentry processes diagnostic data, and PostHog processes analytics data, in the United States.
If you are in the EEA or the UK, your personal data is transferred to the United States. Where required, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), supplemented by technical and organisational measures. You may request a copy of the relevant safeguards by emailing support@getzeeo.com.
Bridge and Privy apply their own transfer mechanisms for the processing they carry out as independent controllers.
10. Retention
| Category | Retention |
|---|---|
| Profile and account data | For the life of your account, then up to 12 months after deletion, subject to the record below |
| Transaction records, virtual account records, payout records, receipts | At least 5 years after the transaction, and up to 7 years where required by financial recordkeeping rules |
| Verification status and identifiers | For the life of your account plus the period required by law; verification records themselves are retained by Bridge under its own schedule |
| Support and communications | Up to 3 years after the matter is closed |
| Technical logs, webhook events, crash reports | Typically up to 90 days |
| Deletion records | Retained as evidence that your request was actioned |
| Marketing preferences | Until you withdraw consent, plus a suppression record kept so we can honour your opt-out |
How deletion works. When you delete your account, we first mark it as deleted, which immediately removes your access to the App and stops it being used. We then remove or anonymise personal data that we are not required to keep, and retain the remainder for the periods above. Transaction and compliance records cannot be deleted on request, because we and our partners are legally required to keep them.
Bridge and Privy apply their own retention periods to data they hold as controllers, which may exceed ours and which we cannot shorten. Records on the Base network cannot be deleted at all (Section 7).
11. Your Rights
Depending on where you are located, you may have the right to:
- Access the personal data we hold about you and receive a copy
- Rectify inaccurate or incomplete data
- Erase your data, subject to legal and regulatory retention requirements
- Restrict or object to certain processing, including direct marketing
- Withdraw consent where processing is based on consent
- Port certain data to another provider in a structured, machine-readable format
- Lodge a complaint with your supervisory authority
How to exercise them. Email support@getzeeo.com with "Privacy Request" in the subject line. We will respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. We may need to verify your identity first.
Limits. We cannot delete data we are required to retain by law, and we cannot alter or delete records on a public network. Where Bridge or Privy holds your data as an independent controller, direct your request to them as well; we will help you identify the right contact.
EEA and UK. You may complain to your national data protection authority; in the UK, the Information Commissioner's Office.
California and other US states. You may have the right to know, delete, correct, and opt out of the "sale" or "sharing" of personal information and of targeted advertising, and to limit the use of sensitive personal information. We do not sell or share personal information for cross-context behavioural advertising. We will not discriminate against you for exercising your rights. You may appeal a denied request by replying to our response.
12. Cookies
Our website uses cookies to keep the site working, remember preferences, and understand usage. Strictly necessary cookies cannot be disabled without affecting functionality. Where required by law we ask for consent before setting non-essential cookies, and you may withdraw it at any time through the cookie preference control or your browser settings.
Our mobile app does not use browser cookies. It uses SDKs and local storage for authentication, session persistence, diagnostics, and analytics (PostHog).
13. EU / UK Representative
[To be appointed. As a US-established controller offering services to individuals in the EU, Zeeo is likely required to designate a representative in the Union under Article 27 GDPR, and a UK representative under Article 27 UK GDPR if it offers services to UK individuals. Insert the representative's name, address and contact email here once appointed, or remove this section if counsel confirms an exemption applies.]
14. Security
We use technical and organisational measures designed to protect personal data, including encryption in transit and at rest, access controls on a least-privilege basis, authentication for administrative access, logging and monitoring, and vendor due diligence.
No system is completely secure. We cannot guarantee absolute security. You are responsible for protecting your device and your login credentials. Because your wallet is self-custodial, Zeeo cannot recover it or restore access on your behalf.
If we become aware of a personal data breach affecting you, we will notify you and the relevant authorities where required by applicable law.
15. Children
The App is not intended for anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact support@getzeeo.com and we will delete it.
16. Third-Party Links
The App and our website may link to third-party sites and services that operate independently of us. Their privacy practices are governed by their own policies. We encourage you to review them.
17. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will post the updated version, update the "Last updated" date, and notify you by email or in-app notice where required.
18. Contact
Zeeo Technologies, Inc. Registered agent: 251 Little Falls Drive, Wilmington, DE 19808, United States Email: support@getzeeo.com
Privacy requests: email support@getzeeo.com with "Privacy Request" in the subject line.