Zonori
Privacy
Last updated 9 October 2026
Who we are
Zonori is built and run by Shaquille Hinds, as an individual. There is no company. Write to [email protected] about anything on this page and you will get a reply from the person who wrote the app. You can also write by post to 15 Mahogany Drive, Glen Acres, St.George, Barbados, BB19243.
Shaquille Hinds is also the person responsible for how Zonori handles personal information. In Quebec, that is the person in charge of the protection of personal information, and in Singapore, Zonori's data protection officer.
What we hold, and why
Your account — your email address, or the identifier Google or Apple gives us when you sign in with them, and a password if you set one. We hold it to give you an account and keep you signed in. If you sign in with Apple, we also keep a token Apple gives us for your account, used only to revoke Zonori's access to your Apple ID when you delete your account; it is never shown to anyone. If you sign in with a code we email you, we note that you confirmed the address. Basis: performing our agreement with you (PDPA s.24(3)). If you make your account on zonori.app when you RSVP to an event, we make it only after you confirm, with the name you confirm and, if you choose, a copy of your Google profile photo. It is an ordinary Zonori account.
Your phone number — you verify a number before you can post in chats, host an event, create a circle or connect with anyone. We hold it so that one person cannot make account after account. Basis: performing our agreement, and our legitimate interest in keeping Zonori free of spam accounts (s.24(5)). Your number is never shown to another member. When you verify a number it is locked to your account for seven days — you cannot change your own number until that lapses — and the lock outlives your account; see "How long we keep things".
Your age — we do not ask for your date of birth or hold any record of your age.
Your profile — display name, handle, photo, and the values you choose. If you want them: MBTI, Enneagram, and your sun, moon and rising signs, which you pick yourself — we never ask for your time or place of birth. All of it is optional and you can remove any of it at any time. Your handle is the address of your public page. You can choose it when you join and, once your phone number is verified, change it later. If you don't choose one, we make one from the first word of your name, with a few random characters added. If we can't make one from your name, we may use the first part of your email address instead: the letters before the first character that isn't a letter, and only when your address has more after them, so a handle never shows your whole address. We never use an Apple private relay address. Basis: performing our agreement.
The circles and chapters you join, the events you post or RSVP to, your place on a waiting list, and your check-ins — this is what the app is for. The hosts of an event you RSVP to see your display name, handle and profile photo, your answer (going, maybe or on the waiting list), whether it's your first time, and whether you were checked in, in the app and on zonori.app, and can download that list. They never see your email address or phone number. Basis: performing our agreement.
Circles about private matters — some circles are about something private, such as health, recovery, faith, sexuality or politics, so being in one can say something about you. Our review marks these circles. We keep them and their events off zonori.app, out of your public profile page and out of the weekly roundups.
Your public profile page — anyone with the link to your profile on zonori.app, or who knows your handle, sees your display name, handle, photo, bio, city, the public circles you're in, and the upcoming public events you host. It never shows your values, personality or signs, who you know, your private events, or the events you're going to, and we ask search engines not to list it. If you change your handle, your old link keeps opening your page for 90 days unless you turn that off. You can stop old links at any time, and they stop working within 10 minutes. Nobody else can choose your old handle. Basis: performing our agreement.
Invite links — if you open an event from a link a member shared with Bring someone and then say you're going, maybe, or join the waiting list, we note on your RSVP whose link it was. We keep only the first link, and we ignore it if either of you has blocked the other. When you're checked in at that event, the member who shared the link may get a notification with your display name saying you came. The host sees only how many people came through invite links, never whose. If you open such a link on an Android phone and install Zonori from the page's Google Play button, the button gives Google Play the event and the link's code, which is random and tells Google Play nothing about who shared it, and Google Play passes both to the app. The app may read them once, in the first week after you install it and while you aren't signed in, and uses them as if you had opened the link in the app. It keeps nothing else that Google Play passes on. If you claim a listing labelled "Listed by Zonori", the Google Play button on the page that gives you your claim code works the same way: it gives Google Play only that code, which is random, and the app may read it once, in the first week after you install it and while you aren't signed in, and uses it as if you had entered it in the app. Basis: performing our agreement.
Invites to host — if an organiser invites you to host on Zonori, the link they share carries a random code, never their name or their account. If you open Zonori from that link, we note on your account whose invite it was. Installing Zonori on Android from the Google Play button on that page works the same way: the button gives Google Play only the code, and the app may read it once, in the first week after you install it and while you aren't signed in. We keep only the first, and we ignore it if it's your own, if you have already hosted an event on Zonori, or if either of you has blocked the other. When people are checked in at the first event you host, the organiser who invited you may get a notification with your display name saying you hosted your first night on Zonori. Nobody else is told whose invite it was. Basis: performing our agreement.
Calendars you connect — if you connect the link of a public calendar of events you run, so the app can draft your events from it, we keep the link and the calendar's name, the circle you chose for it and whether its new events go to review by themselves. We treat the link like a password: we never show it to anyone, you included (the app shows only the calendar's name, or the site it's on). About once an hour we read the calendar's upcoming events, and from each one only its title, description, times, place, web link and whether it was cancelled. We never read who is invited to it or who organises it. What we read about each event is kept as a draft for you to review, or to compare with the event you posted from it, until a week after the event ends. Removing the calendar deletes the link and every draft from it; events you already posted from it stay, like any event you post. Deleting your account deletes all of it. Basis: performing our agreement.
Page views — we count how many times each public event page, and the page for hosts, is opened. The count isn't linked to you: we keep one number per page per day (for the hosts page, one per kind of link it was opened from, such as the app's check-in screen), with no IP address, cookie or other identifier attached. Each public profile page is counted the same way, as one number per host per day, together with how many event page opens came through that host's own invite links. We use those two numbers to choose hosts for Zonori's weekly video, only among hosts who switched on "Feature my nights in the weekly video". We count opens of the home page, the What’s on pages, the activity pages, the circle pages and the page for signing up to new dates by email the same way: one number per page per day, by place and activity where the page has them, and by the kind of link it was opened from (such as one of our emails, a search engine or another website), with no IP address, cookie or other identifier attached.
Zonori lists on other websites. When a website shows a Zonori list of events (a What’s on list, or an organiser's own events), we count how many times the list is seen and, for What’s on lists, how many events are opened from it. That's one number per website and place, or per organiser, per day, with no IP address, cookie or other identifier attached. We keep the website counts for 35 days, and an organiser's counts for as long as their Zonori account exists. To limit how often one address can ask, our server counts its requests for up to a minute and then lets the count go. Like every request to Zonori, these also appear in our server traffic logs (see "How long we keep things"). Basis: our legitimate interest in showing sites and organisers how their lists are used (s.24(5)).
Visits to zonori.app — if you visit zonori.app from outside the EU and the UK, Cloudflare counts the visit and measures how fast the page loads, without cookies. We use those counts to see how the site is used and to keep it fast. Basis: our legitimate interest in knowing how the site is used and keeping it fast (s.24(5)).
If you host — you can sign in to your events on zonori.app with a code we email to your account's address. That keeps you signed in there for 30 days, and you can sign out at any time. There you see the names on your guest list and who checked in, as you do in the app, and can download them; never their email addresses. The attendance report after a night, and its share card, show counts only: how many came, how many were new and how many didn't make it. We may email and notify you once a week with your own numbers, and a few times after you first claim a listing; turn these off with Reminders in the app. Basis: performing our agreement.
How you found us — when you sign up or RSVP, we may note how you first reached Zonori: the campaign tags on the link you followed (for example "newsletter"), the website you came from (its name, not the page), and the first Zonori page you opened (for a page that isn't public, only which part of the site it was in). Your browser or phone keeps this for up to 30 days until then, with no identifier. We keep it with your account and only ever count it by channel, to learn which of our links bring people. We don't use third-party trackers or advertising cookies.
The weekly video — each week Zonori makes a short video of a city's public events for that week, and posts it on YouTube, TikTok and Instagram. If you switched on "Feature my nights in the weekly video" and you are chosen, the video shows and says your display name, with one of your upcoming public events and its flyer, if it has one. To write the voiceover, Anthropic gets your display name and that event's public details. Switch it off in the app at any time and we stop choosing you. Basis: your consent, which you withdraw with that switch.
Your chats and direct messages — we hold message content so it can be delivered and read. Basis: performing our agreement.
What’s on by email — if you sign up on a What’s on page, we hold your email address, the city, and when you signed up and confirmed, to send you that city's week once a week. Nothing is sent until you confirm from the link we email you, and every email has a link to stop them that works whenever you use it. Each email is put together automatically, with AI, from that week's listings. Resend sends them. Basis: your consent, which you withdraw with that link.
Places you ask us about — if you name a city on zonori.app ("Going somewhere next? Tell me when Zonori is there"), we hold your email address, the place (the city we matched), the page you asked from, and when you asked and confirmed. It makes no account, and we use the address only for these emails. We send one email to confirm each request (another only if you ask again), and nothing else until you confirm; a request you don't confirm is deleted after 7 days. When Zonori opens in a city we matched, we send you one email to say so, and then delete the request. If we can't match the place you type, we keep only what you typed, to count it, and not your email address. Every request is deleted after 12 months, whether or not the city opens, and the link in each of these emails deletes all of yours whenever you use it. If you ask in the app, the request is kept with your account, you're told with a notification instead of an email, and it is deleted when you take it back, once you've been told, after 12 months, or with your account. We count requests by city to choose where Zonori goes next; the counts never say who asked. Resend sends the emails. Basis: your consent, which you withdraw with that link or in the app.
Messages to Zonori — if you write to [email protected] or [email protected], or message @zonori.app on Instagram or Zonori's LINE account, we hold what you send, the address, handle or LINE account you wrote from, the language you wrote in, and our replies, so we can answer you. An automated service reads each email and LINE message with AI (see Anthropic below) and may answer common questions itself. A person reads and answers messages sent on Instagram. Basis: our legitimate interest in answering the people who write to us (s.24(5)).
Location — see "Location" below. Basis: your consent, separately for each setting.
Safety reports, blocks and moderation decisions — including a copy of the message or listing that was reported, taken at the time so it cannot be edited away. Basis: our legitimate interest in keeping people safe (s.24(5)).
Purchases — what you bought and when. The store you installed Zonori from takes the payment — Apple on iPhone, Google Play on Android; we never see your card, and we never hold your card details. Basis: performing our agreement, and keeping the records we are required to keep.
If you RSVP on the web
On some public event pages at zonori.app you can RSVP by signing in with Google or Apple, or with a 6-digit code we email you, without installing Zonori first. This section stays here for as long as we send emails about web RSVPs, including after we stop offering them.
- It is your Zonori account — signing in finds the Zonori account that uses that Google or Apple sign-in, or that email address. If there isn't one, we ask before we make one. The RSVP is an ordinary RSVP on that account: people going and the host see your name, handle and photo, and your first-time choice if you made one, just as if you had RSVP'd in the app. Everything else on this page applies to it.
- What we take from Google or Apple — the identifier they give us and the email address they share (with Apple this can be a private relay address). When we make your account, we use the name you confirm on the page, which we fill in from Google, or from Apple the first time you sign in with Apple, and, if you choose, a copy of your Google profile photo, which we check like any photo you add.
- A code by email — if you choose email, we send a 6-digit code to the address you type. It works for 15 minutes, for that one event, and only on the web. We keep it only in a scrambled form, and delete it once you use it, when it expires, or after 5 wrong tries. The email holds the code and nothing about the event. When you RSVP with the code, we note on your Zonori account that you confirmed the address, and if we make your account, that address is its email address. To stop codes being sent over and over, we count how many go to an address in an hour, kept under a scrambled form of the address and deleted after that hour. In the app you can sign in the same way, with a new code.
- The event's circle — if we make your account, or you haven't finished setting it up in the app, we add the event's city to your account and add you to the event's circle (and the main circle it belongs to, for a smaller one), the same as picking it in the app. You can leave either in the app at any time. If your account is already set up and you're not in the circle, we ask you to join it in the app first.
- Emails — if you sign in with a code, we email you that code. Until you use the app with notifications on, we also email you a confirmation; a reminder the day before the event and another a couple of hours before; a short note if the host changes the time or place or cancels the event; and, about 15 minutes after the event starts, if you haven't checked in, one email asking if you're there, with a button to check in; and, about 14 hours after an event you checked in at, if others from Zonori checked in too, one email saying how many, with a link to see who they were in the app. We send nothing else. Basis: performing what you asked us to do (s.24(3)).
- A cookie — zonori.app keeps a cookie in your browser for that one event, so the page can show that you're going and let you cancel. It holds a random token and nothing else. The page's scripts cannot read it, it does nothing on any other page, and it goes when you cancel, when you tap "Not you?", or 7 days after the event.
- How long — your account stays until you delete it. If we made it when you RSVP'd and you never set it up in the app, we delete it 6 months after the last event you RSVP'd to on zonori.app, and email you two weeks before so you can keep it by signing in to the app. The record that links your browser to this RSVP, and the copy of the email address we use for the emails above, are deleted 7 days after the event ends, or when you delete your account. Your account keeps its own email address like any account.
- Who processes it — Resend sends the emails, including the codes. Google or Apple confirm who you are when you sign in with them. The page only loads Google's and Apple's sign-in buttons when you choose to use them, and from then on Google or Apple can see that you opened it. Choosing email never loads them.
If you ask us to email you new dates
On zonori.app/join you can choose a place and up to 3 activities there, and we email you new dates for them. This section stays here for as long as we send these emails, including after we stop taking new sign-ups.
- It is your Zonori account — you sign in with Google, Apple or a 6-digit code we email you, as when you RSVP on the web. That finds the Zonori account that uses that sign-in or that email address. If there isn't one, we ask before we make one, with the name you confirm. Everything else on this page applies to it.
- What we take from Google or Apple — the identifier they give us and the email address they share (with Apple this can be a private relay address), and, if you choose when we make your account, a copy of your Google profile photo, which we check like any photo you add.
- A code by email — if you choose email, we send a 6-digit code to the address you type. It works for 15 minutes and only for this sign-up. We keep it only in a scrambled form, and delete it once you use it, when it expires, or after 5 wrong tries. The email holds the code and nothing else.
- What we keep — with your account: the place and its time zone, the activities you chose, the email address the emails go to (the one Google or Apple shared, or the one you confirmed with a code), when you signed up, when we last emailed you, and when you last opened an event from one of these emails. Nothing about your browser or device. Choosing again replaces what you chose before.
- The emails — at most one a week, sent on Thursday or Friday, listing events in the activities you chose that were listed since our last email. In a week with nothing new, we send nothing. If you use the Zonori app with notifications on, you get those instead and no email. Every email has a link to stop them, and your email app's unsubscribe button works too. Basis: performing what you asked us to do (s.24(3)).
- Opening an event from an email — the link goes through zonori.app, which notes when you opened it and then shows the event. We use that only to keep an account you haven't set up from being deleted (below).
- How long — until you stop the emails or delete your account. When you stop them we send nothing more, and what you chose stays with your account, marked as stopped, until you delete the account; signing up again replaces it. Your account stays until you delete it. If we made it when you signed up and you never set it up in the app, we delete it 6 months after the latest of your sign-up, the last event you RSVP'd to on zonori.app, and the last time you opened an event from one of these emails, and email you two weeks before so you can keep it by signing in to the app.
- Who processes it — Resend sends the emails, including the codes. Google or Apple confirm who you are when you sign in with them. The page only loads Google's and Apple's sign-in buttons when you choose to use them. Choosing email never loads them.
If you ask an AI assistant about Zonori events
Assistants such as Claude and ChatGPT can look up public events on Zonori for you through our MCP server (zonori.app/developers). You don't sign in, and it only reads.
- What reaches us — your assistant's request, not your conversation: the place, and if you asked, the activity and the days. Your assistant decides what to send; its own privacy policy covers your conversation with it.
- What we answer — only what each event's public page on zonori.app shows: the title, start time, venue and area, how many are going, and who runs it, with a link.
- What we keep — one count per day of the requests from each assistant (for example "Claude" or "ChatGPT"), kept 35 days. Nothing about who asked or what was asked. To limit how often one address can ask, our server counts its requests in memory under a scrambled form of the address that can't be turned back into it, starts the counts again each minute, and never writes them to disk. Like every request to Zonori, these also appear in our server traffic logs (see "How long we keep things").
- The links — each link says it came from an AI assistant and which one. When you open one, we count it the same way as other page opens: one number per assistant per day, with no IP address, cookie or other identifier attached. If you then make a Zonori account, we note that you first came from an AI assistant, as we do for other links (see "How you found us").
Location
Every location feature is off until you switch it on, and each one has its own switch.
- Your city. You choose which city you are in. That is a city, not a place.
- Nearby. When it is on, people in your circles can see that you are roughly nearby. The position used for this is rounded to about a kilometre before anybody sees it.
- Live location. When you switch it on, you choose your friends or one of your circles, and your friends, or the members of that circle in your city, can see exactly where you are while it is on. The app tells you who will see you before you share. Turning it off removes your position straight away. If the session simply lapses — you close the app, or the time runs out — nobody can see you any more, and the last position we held is deleted from our cache within four hours of your last update. Leaving the circle, or deleting your account, removes it at once.
- Last seen. A coarse indication of when you were last active.
Your exact location is never saved to your profile or our database. For Nearby the server keeps only the rounded position, and only while Nearby is on. For Live location it keeps your latest reading in a short-lived cache while Live location is on, as described above, and nowhere else.
When you create an event you can search for a venue, which uses Google's Places service. When you pick one we keep that venue's name, address and coordinates, because that is the event's location, not yours.
Who processes your data, and where
We use other companies to run Zonori. Each one only gets what it needs.
- MongoDB Atlas — the database. Amazon Web Services, us-east-1 (Northern Virginia), United States.
- Redis Cloud — short-lived caches and queues. Amazon Web Services, us-east-1, United States.
- The server itself — one virtual machine at netcup in Manassas, Virginia, United States, reached through a Cloudflare Tunnel.
- Cloudflare — the tunnel in front of the server, and R2 object storage in the Asia-Pacific region, for photos and other images you add. If you visit zonori.app from outside the EU and the UK, Cloudflare also counts the visit and measures how fast the page loads, without cookies.
- Anthropic — reviews new circles, sub circles, links between circles, events and event edits against our published community guidelines. When you import an event from a link and the page doesn't clearly give the event's name or time, Anthropic also reads that page's text to fill in the form for you. Nothing that identifies you is sent with those. For the events Zonori lists from organisers' own pages, it also reads those public pages, writes each listing's short summary, reviews each listing, and checks every email Zonori writes to an organiser before it goes (see "If you run events Zonori lists"). It reads and labels the messages people send to [email protected], [email protected] and Zonori's LINE account, so each gets the right answer (it doesn't read messages sent to @zonori.app on Instagram: a person does), and checks Zonori's replies, weekly email and weekly video before they go out. It also writes the weekly video's voiceover, which names the host the video features, so a featured host's display name is sent to it (see "The weekly video").
- OpenAI — turns the name and description of a circle, and of one you propose, into numbers, so we can tell when a new one is the same thing as an existing one. For the events Zonori lists from organisers' own pages, it does the same with an event's title and the organiser's public name, so the same event is never listed twice. Nothing else is sent to it, and nothing that identifies you as a member.
- Sightengine — checks profile photos and other images you add, including a photo we copy from Google when you choose it.
- Google — Firebase Authentication for phone verification, Sign in with Google, the Places service for venue search, including finding the place of an event in a calendar you connect, and Google Play, which takes every in-app purchase made on Android. Google Cloud Translation also translates the app's own words, and the names and descriptions of circles, into the language you choose. It gets only the text, never who asked for it.
- Apple — Sign in with Apple, and every in-app purchase made on iPhone.
- Expo — delivers push notifications to your device, and the app's updates.
- Resend — sends the emails we send you, such as a password-reset or sign-in code, and What’s on by email. United States.
- RevenueCat — checks that an in-app purchase really happened.
- Google Workspace — the [email protected] mailbox that Zonori's emails to organisers come from, and that their replies go to, and its [email protected] address, where anyone can send us links to events.
- Meta — carries the messages you send to @zonori.app on Instagram, the comments on its posts, and our replies, and publishes Zonori's posts there, including the weekly video.
- LINE — carries the messages you send to Zonori's LINE account, our replies, and our weekly posts there.
- YouTube and TikTok — publish Zonori's weekly video. The video reaches YouTube through YouTube API Services; see "YouTube" below.
YouTube
Zonori uses YouTube API Services to upload the weekly video to Zonori's own YouTube channel. The only YouTube account Zonori connects to is its own. No part of Zonori asks you to connect your YouTube or Google account to it, and through YouTube API Services we don't access, collect, store or share any information about you or your YouTube account. What reaches YouTube is the video itself, described under "The weekly video".
YouTube is run by Google, and the Google Privacy Policy covers what Google does with information. You can see, and revoke, the access you have given any app to your Google account, including Sign in with Google, on Google's security settings page.
Sending data abroad
Zonori runs on servers outside Thailand, and the companies above are outside Thailand. We rely on the transfer being necessary to perform our agreement with you (PDPA s.28(3)), together with each company's own data-processing terms. Most of these companies are in the United States, and some are in the European Union. Cloudflare keeps images in the Asia-Pacific region.
If you're in the UK or the EU, we rely instead on safeguards those laws recognise. Our server is run by netcup, a company in Germany. The EU GDPR applies to netcup, even though the server is in the United States. Each company in the United States that processes data for us has one of two safeguards. Either it is certified under the Data Privacy Framework (UK GDPR Art. 45A; EU GDPR Art. 45), or its terms include the standard contractual clauses (Art. 46). For data from the UK, those clauses come with the UK's addendum to them. Write to [email protected] for a copy.
For other countries, see "The law where you live".
How long we keep things
- Your account and profile — until you delete it. A request made through the web page is completed within 30 days. An account we made when you RSVP'd on zonori.app and that you never set up in the app is deleted 6 months after the last event you RSVP'd to there, with an email two weeks before.
- A calendar you connect — until you remove it or delete your account. What we read about each of its events goes a week after that event ends.
- Your messages — for as long as the chat they were sent to exists. A message you delete is hidden from everyone straight away. When you delete your account, the messages you sent stay in the chats they were sent to, under "Deleted account", with your name and photo removed, so the conversation still makes sense to the other people in it.
- Messages to Zonori's mailboxes, Instagram and LINE — a year, then deleted, keeping only how many there were.
- Your latest raw location reading — see "Location".
- A verified phone number — the seven-day lock on that number stays after the account is deleted, and then expires. It exists only so a number cannot be recycled by deleting and signing up again.
- Handles you have used — if you verified a phone number, every handle you have used stays reserved, even after you delete your account, so nobody else can choose it and pick up your old links. If you never verified one, your handle is freed 90 days after you delete your account. We keep a scrambled form of it, not the handle itself, and once your account is deleted nothing links it to you. The one exception: if a handle was used to pretend to be someone, we may give it to the person it pretended to be.
- Safety reports and moderation decisions, with the snapshot taken at the time — up to 12 months, for security and fraud prevention.
- Server traffic logs — at least 90 days.
- Purchase records — 5 years from the end of the accounting year they fall in, the period Thailand's Revenue Department requires for accounting records.
If you run events Zonori lists
Zonori lists some public events from organisers' own public pages, labelled "Listed by Zonori", so people can see what's on in their circles. An automated service does this, using AI, with a crawler called ZonoriBot (how it works, and how to block it). This section is for the organisers of those events. Zonori, as described under "Who we are", is responsible for this data; write to [email protected] about it.
- What we collect, and from where — from your own public event pages, your website and your public social profiles: the public facts of a public event (its title, date, time, venue name and the venue's address as printed on the page, and a short factual summary we write from its description), your public name as an organiser, and the public pages and handles your events came from. Where the law lets us email you about a listing (the United States and the United Kingdom), also one contact address you published on your own website, with the page and the date we found it; in the United Kingdom, only a general address on the website of a registered company, whose company number we check against Companies House's public register. In Thailand we collect no contact address, and we email you only to answer you if you write to us. We never collect a contact address anywhere else, never guess or construct one, never take one from a site that says it won't share it, and never read anything behind a login. If you write to us, claim a listing or make a request, we also hold what you send and the address or handle you used.
- Why — to list public events in the circles they fit, to include them in Zonori's weekly roundups of what's on (the What’s on pages, the weekly email, our LINE posts, and the weekly video on YouTube, TikTok and Instagram, whose Instagram caption may @mention your Instagram business account), and to tell you about your listings: what we listed, where it came from, what we hold, and how to claim, correct or remove it.
- Basis — our legitimate interests (UK GDPR Art. 6(1)(f); EU GDPR Art. 6(1)(f); Thai PDPA s.24(5)). We have an interest in showing people public events that their organisers already published, with credit and a link back to the organiser's page. We also have an interest in letting organisers take them over or take them down. You can object at any time, and we stop.
- Your organiser page — if you are a group, club, school, venue or business and Zonori lists at least 3 of your upcoming events, or 6 in the last 90 days, we gather them on one page at zonori.app/o/ followed by your organiser name. It shows your public name and what each listing already shows: the dates, venues and neighbourhoods and how many people are going (a number, never who), with a calendar feed and a link to claim it. We never make one under a person's name. It goes when you remove your listings or ask us to stop. Search engines see it only once we release it, which needs enough events to be useful, and not after 60 days with no events. Our emails to you may link to it. If you claim it, it shows your Zonori display name as the host. Basis: the same legitimate interests as the listings.
- Telling you — this data comes from your pages rather than from you, so we tell you about it (UK GDPR Art. 14; EU GDPR Art. 14; Thai PDPA s.25). We tell you by email, where we hold an address you published and the law lets us send one (never in Thailand). We always tell you on this page, on /bot and on every listing, which carries "Organiser? Claim or remove".
- Who else processes it — only our email, hosting, AI and place-search service providers: Google Workspace for our emails to you, Resend for the weekly email, the hosting providers listed above, Anthropic and OpenAI as described above, and Google's Places service, which gets the venue's name and printed address to find the place. The weekly video is published on YouTube, TikTok and Instagram, and our weekly posts on LINE. If you message @zonori.app on Instagram, Meta carries that conversation, and if you message Zonori's LINE account, LINE does. We never sell it.
- Sending it abroad — our servers and most of these providers are in the United States. This data leaves the United Kingdom, the European Union, Thailand and the other countries where we list events. Our safeguard is each provider's data-processing terms (Thai PDPA s.29). Our server is run by netcup, a company in Germany, and the EU GDPR applies to it. For data from the UK and the EU, each company in the United States that processes it for us has one of two safeguards. Either it is certified under the Data Privacy Framework (UK GDPR Art. 45A; EU GDPR Art. 45), or its terms include the standard contractual clauses (UK GDPR Art. 46; EU GDPR Art. 46). For data from the UK, those clauses come with the UK's addendum to them.
- How long — a listing stays on Zonori like any other event until you claim it or it is removed, which you can ask for at any time. Pages we fetch are deleted after 30 days, and so is anything we found but never listed. A contact address is deleted 180 days after your last listing unless you claim your listings, and straight away if you ask. Emails and messages between us are kept for a year, then deleted, keeping only how many there were. A record of each removed listing (where it came from, and your organiser name) is kept for a year so it doesn't come back. If you ask us to stop, we keep a scrambled form of your address for good, so we never email it again, and your organiser name and the pages or handles you named on a block list, so we never list you again. Once you claim your listings, they are your events, and the rest of this page applies to you as a member.
- Your rights — you can ask for a copy of what we hold about you, and ask us to correct it, delete it, limit it or stop using it (object), at any time. Write to [email protected], or use the data request form for any of these except limiting it. The form confirms the request with a code sent to your address. To take down one listing or all of them, use "Organiser? Claim or remove" on any of them. Every email we send has a link to stop them. We answer within 30 days.
- Complaints — you can complain to the UK's Information Commissioner's Office (ico.org.uk) or to Thailand's Personal Data Protection Committee. Elsewhere, you can complain to the authority for your country that "The law where you live" names, in the way it describes.
Your rights
You can ask us for a copy of your data, or to send it to you in a portable form. You can ask us to correct it, delete it, or limit or stop a particular use of it. You can also withdraw a consent you gave. Write to [email protected] and you will get an answer within 30 days. If we can't do what you ask, we tell you why, and you can ask us to look at it again. If our automated review turns down an event or circle you made, or a change to your event, you can also ask a person to look at it.
If you're unhappy with how we've handled your data, you can tell us at the same address, and we confirm we have your complaint within 30 days. You can also complain at any time to Thailand's Personal Data Protection Committee. Elsewhere, you can complain to the authority for your country that "The law where you live" names, in the way it describes.
You can delete your account yourself, in the app: You → Delete account. If you cannot get into the app, use zonori.app/delete-account.
The law where you live
Zonori is used in many countries. This section says what changes under the law where you live.
The bases on this page use Thailand's terms. Under the UK GDPR and the EU GDPR, performing our agreement, or what you asked us to do, is Art. 6(1)(b), and our legitimate interests are Art. 6(1)(f). Your consent is Art. 6(1)(a). For purchase records, the basis is our legitimate interest in keeping the records Thai law requires of us, Art. 6(1)(f).
- The United Kingdom — the UK GDPR and the Data Protection Act 2018. You can complain to the Information Commissioner's Office (ico.org.uk).
- The European Union, including Germany, Spain, Ireland, the Netherlands, France and Portugal — the EU GDPR. You can complain to the data protection authority where you live or work. In Germany, that is your state's, such as the Berlin Commissioner for Data Protection and Freedom of Information. In Spain, it is the AEPD, and in Ireland, the Data Protection Commission. In the Netherlands, it is the Autoriteit Persoonsgegevens, in France the CNIL, and in Portugal the CNPD. In France, you can also tell us what should happen to your data after your death, and name someone to receive it. If you leave no instructions, we keep your data as this page describes, and your heirs can ask us to close your account.
- Canada — the Personal Information Protection and Electronic Documents Act. In Quebec, also Quebec's Act respecting the protection of personal information in the private sector, and in British Columbia, its Personal Information Protection Act. Under these laws we rely on your consent. You give it by making an account and using the features this page describes. We act without it only where the law allows, such as to look into a safety report. You withdraw it by switching a feature off or deleting your account. Your data is kept and used outside Canada, mainly in the United States, with images in the Asia-Pacific region. Courts, police and security agencies there may be able to get it under their laws. In Quebec, you can also ask us to stop showing information about you publicly, where the law allows. You can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca). In Quebec, you can complain to the Commission d'accès à l'information, and in British Columbia to its Information and Privacy Commissioner. If you run events Zonori lists, we rely on your implied consent, since you published them so people would come. Withdraw it at any time with "Organiser? Claim or remove".
- Australia — we disclose your data to the companies named above, mainly in the United States and the European Union, with images in the Asia-Pacific region, so they can run Zonori for us. If you want to complain, tell us first. If we haven't settled it within 30 days, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
- Singapore — the Personal Data Protection Act 2012. We rely on your consent, which you give by using the features this page describes. Where this page says "legitimate interest", we rely on the Act's legitimate interests exception. You can complain to the Personal Data Protection Commission (pdpc.gov.sg). If you run events Zonori lists, we rely on the Act's exception for publicly available data.
- Japan — the Act on the Protection of Personal Information. We use your data only for the purposes on this page. You can ask us to disclose it, correct or add to it, delete it, stop using it or stop giving it to others. Write to [email protected], which is also where we deal with complaints. Our providers handle your data mainly in the United States and the European Union. Cloudflare, a company in the United States, keeps images in the Asia-Pacific region, and tells us the region, not the country. The United States has no general federal privacy law, only laws for some sectors and states. The European Union applies the EU GDPR. The Act is overseen by Japan's Personal Information Protection Commission (ppc.go.jp).
- The United States — we never sell your data, and we don't share it for advertising. We don't track you across other sites or apps, and we use no advertising trackers from other companies, so nothing changes when your browser sends a Do Not Track signal. Google or Apple gets data on zonori.app only after you choose to sign in with one of them, or tap one of their links, such as to get the app. We don't collect, use or sell personal data to train large language models. If we turn down your request, reply to our answer to appeal. We answer an appeal within 60 days. If we still say no, you can complain to your state's attorney general.
You must be 13
You must be 13 or over to use Zonori. We do not ask for your date of birth. If we find out that someone under 13 has an account, we delete it.
If something goes wrong
If your personal data is exposed, we will tell Thailand's Personal Data Protection Committee within 72 hours of becoming aware of it. We will also tell any other authority the law requires, such as the UK's Information Commissioner's Office or an EU authority, in the time that law sets. We will tell you in plain words what happened and what we did.
If Zonori is sold
If Zonori, or substantially all of its assets, is sold, merged, reorganised or transferred, including to a company Zonori's founder forms, your personal data may be transferred to the new owner, who will be bound by this policy. We'll tell you before your data becomes subject to a different privacy policy.
Changes to this page
When we change this page we update the date at the top. If a change affects what we do with your data, we will tell members in the app or by email before it takes effect.
Zonori is an independent app, available on the App Store and Google Play. See where Zonori is live. The app is available in 26 languages; we answer support in English.