Zenkai
Privacy Policy
How Zenkai Labs LLC collects, uses, and shares information.
Last updated September 17, 2026
1. Who we are
Zenkai Labs LLC (“Zenkai”, “we”, “us”, or “our”) operates the Zenkai Service at zenkai.cards and related apps, APIs, and smart contracts. We are a Delaware limited liability company. This Privacy Policy explains what personal information we collect, why we collect it, how we share it, and the choices you have.
It should be read with our Terms of Service. If you have a privacy request, contact privacy@zenkai.cards.
2. Scope
This policy covers information we process when you visit the Service, create an account, use the marketplace or auctions, open capsules, vault or redeem items, contact us, or otherwise interact with Zenkai. It does not cover third-party sites or wallets you use outside our Service. Public blockchains are independent networks; transactions you broadcast are visible to anyone, and we do not control those ledgers.
3. Information we collect
We collect the following categories, depending on how you use the Service:
- Account and authentication. Identifiers from sign-in (such as email, social subject IDs, or wallet addresses), username, avatar, preferences, and session data. Our authentication and embedded-wallet partner (currently Privy) processes login and wallet-provisioning data on our behalf.
- Transaction and marketplace data. Listings, bids, buys, offers, auctions, collector trades, capsule opens, sell-backs, deposits, withdrawals, credits, referral attribution, and on-chain transaction references.
- Shipping and fulfillment. Name, address, phone number, and related details when you redeem an item for shipment, plus carrier and tracking information.
- Device and usage. IP address (including for geo and sanctions controls), browser and device metadata, approximate location derived from IP, logs, diagnostics, and crash reports.
- Communications. Support messages, emails you send us, and optional marketing messages if you opt in or as otherwise permitted by law.
- Public activity. Username, avatar, listings, auction activity, and items you pull or trade may appear in public feeds, profiles, and search on the Service.
We aim to minimize what we hold. We do not require government-ID KYC to create an account. We do not intentionally collect precise GPS location or payment-card PAN on the Service (crypto settlement is used instead).
4. How we use information
We use personal information to:
- Provide, operate, secure, and improve the Service
- Process marketplace sales, auctions, trades, capsule opens, vaulting, sell-backs, and shipping
- Create and maintain your account and embedded wallet
- Enforce eligibility, age, geo, sanctions, and the Terms of Service
- Detect fraud, abuse, wash trading, and integrity issues
- Provide customer support and send service notices
- Measure product usage and develop new features (aggregated where practical)
- Comply with law, respond to lawful requests, and handle disputes
5. Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on:
- Contract — to create your account and fulfill marketplace, auction, capsule, vault, and redemption requests you make
- Legitimate interests — security, fraud prevention, product improvement, public activity feeds that make a collectibles marketplace usable, and limited analytics that do not override your rights
- Consent — where required (for example certain cookies, or marketing in jurisdictions that require opt-in)
- Legal obligation — when we must retain or disclose information, or screen for sanctions
6. How we share information
We share personal information with:
- Service providers that help us run the Service (see Section 7)
- Custody, shipping, and logistics partners so we can vault items and fulfill redemptions
- Blockchain networks as needed to settle transactions; wallet addresses and transaction data become public on-chain
- Other collectors to the extent your activity is public (username, listings, bids you place in public auctions, pulls shown in feeds)
- Professional advisors (legal, accounting) under confidentiality
- Authorities when required by law, legal process, or to protect rights, safety, or the integrity of the Service
- A buyer or successor in a merger, financing, or sale of assets, subject to this policy or equivalent protections
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising. We do not run third-party advertising networks on collector profiles.
7. Service providers
Categories of processors we use include authentication and embedded-wallet providers (currently Privy), cloud hosting and content-delivery networks, email delivery, product analytics (currently PostHog, where enabled), error and performance monitoring (currently Sentry), shipping and address-validation providers, and blockchain infrastructure. These parties may process data only on our instructions, except to the extent they act as independent controllers (for example a blockchain network or a carrier).
8. Public blockchain
Marketplace settlements, auctions, capsule opens, and transfers may be recorded on a public blockchain. Wallet addresses, token IDs, and transaction hashes are inherently public. We cannot delete data from a public chain. Off-chain personal data we control (such as a shipping address) is handled under this policy and is not written to the chain.
9. Cookies and similar technologies
We use essential cookies and local storage for authentication, security, and load balancing, and limited analytics cookies or similar identifiers where enabled. You can control cookies in your browser; blocking essentials may prevent sign-in or checkout. We do not currently respond to “Do Not Track” signals because there is no consistent industry standard for them.
10. Analytics and diagnostics
We use product analytics to understand how the Service is used (for example which marketplace flows complete) and error monitoring to find and fix failures. Where practical we aggregate or pseudonymize. You may be able to opt out of non-essential analytics via cookie controls or by contacting us. Essential security and integrity logging is required to operate the Service.
11. International transfers
We are based in the United States and may process information in the U.S. and other countries. If we transfer personal data from the EEA, UK, or Switzerland, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and UK addenda as applicable), unless another lawful mechanism applies.
12. Retention
We keep account and transaction records for as long as your account is active and for a period afterward needed for disputes, tax, fraud prevention, security, and legal obligations. Shipping addresses are kept for fulfillment and related records. Public on-chain records persist independently of our databases. When you request deletion, we delete or anonymize personal data we control unless we must retain a limited copy (for example a transaction that must be kept for tax or sanctions reasons).
13. Security
We use technical and organizational measures appropriate to the nature of the data, including encryption in transit, access controls, and monitoring. No method of transmission or storage is 100% secure. Protect your devices, email, and auth factors. Report suspected account compromise to us promptly.
14. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of personal data, to object to certain processing, and to withdraw consent where processing is based on consent. You may lodge a complaint with a supervisory authority (for example your EU member-state DPA or the UK ICO).
Submit requests to privacy@zenkai.cards. We may need to verify your identity (for example by confirming control of the account email or wallet) before acting. We will not discriminate against you for exercising privacy rights.
15. California privacy rights
If you are a California resident, the CCPA/CPRA may give you the right to know, delete, and correct personal information, and to opt out of “sale” or “sharing” as those terms are defined by California law. We do not sell personal information and we do not share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes other than those permitted by the CPRA. Authorized agents may submit requests with proof of authorization. We will verify as described in Section 14.
16. Children
The Service is for adults 18 and older. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe we have, contact privacy@zenkai.cards and we will delete it.
17. Changes
We may update this policy. The “Last updated” date will change when we do. For material changes we will provide additional notice where required. Continued use after the effective date means you accept the updated policy. If you do not agree, stop using the Service and request deletion as appropriate.
18. Contact
Privacy: privacy@zenkai.cards
Legal: legal@zenkai.cards
General: hello@zenkai.cards
Also see Terms of Service and FAQ.
Zenkai Labs LLC
Address
2810 N Church St STE 89977
Wilmington, DE 19802
Delaware File Number: 10724584