Legal

Privacy Policy

Last updated: September 2026

|Bahasa Indonesia

1. Who We Are

ZenMiles is a travel loyalty management application operated by PT Inovasi Berkat Modern, a company registered in Indonesia. As the Data Controller under Law No. 27 of 2022 on Personal Data Protection (UU PDP), we are responsible for how your personal data is collected, used, and protected.

Contact: support@zenmiles.app

2. Data We Collect

We only collect data necessary to provide the service:

  • Account data: name, email address, phone number, country.
  • Loyalty program data: program name, membership number, points balance, expiry dates.
  • Credit card data: card name, last four digits, validity period, statement and due dates, annual fee dates. We never store full card numbers.
  • Optional profile data: your date of birth, if you choose to provide it. The app works without it.
  • Usage data: a log of actions you take in the app — adding or removing a program or card, updating your profile — recorded against your account so we can support you and understand how the app is used.
  • Device data: device model, operating system version, and a push notification token, stored against your account so notifications reach the right device.
  • Crash data: anonymised error reports including device model, OS version, and stack traces via Firebase Crashlytics, used solely to identify and fix bugs.

3. What Stays On Your Phone

When you scan a screenshot or a statement to fill in a balance, the image is read entirely on your own device. The picture is never uploaded, never sent to us, and never reaches any third party. Only the values you confirm on the review screen are saved to your account.

We never see or store a full credit card number. The app reads at most the last four digits, and discards the rest before anything is saved.

4. Email Sync (optional)

Email Sync updates your balances from the statement emails your airline and bank already send you. It does nothing until you link a mailbox, and you can remove a mailbox at any time.

  • It runs on your phone. Your phone connects directly to your email provider (for example Gmail, iCloud or Yahoo) over an encrypted connection. Your email never passes through ZenMiles servers, and we never see it. Your email provider is not our service provider; its own privacy policy applies.
  • What is kept on your phone: the address and app password of each mailbox you link, and for each program or card the statement subject you set — plus, for a card, the password of its statement PDF. Passwords are held in the phone’s secure storage (the iOS Keychain, or Keystore-backed encrypted storage on Android) and are never uploaded.
  • What it reads: only emails from the last 90 days whose subject contains the words you set for that program or card. Nothing else in your mailbox is opened. Choose words that only your statement emails use, such as your bank’s name, and leave out dates, which change every statement.
  • What leaves your phone: only the figures read from a statement — a program’s balance and miles expiry date, or a card’s points balance, statement day and payment due day — saved to your account exactly as if you had typed them. Emails, attachments, statement PDFs, amounts owed and passwords are never uploaded.
  • Syncing by itself: once linked, the app checks for new statements each month. On iPhone, our server sends a silent notification that wakes the app to do this; it carries no content and nothing about your mailbox.
  • Your record: every change a sync makes is listed in You → Activity, which is kept on your phone only.
  • Stopping it: remove a mailbox in You → Email Sync, which erases its address and passwords from your phone, and revoke the app password at your email provider.

5. Legal Basis for Processing

We process your personal data on the following grounds:

  • Contract performance — to deliver the ZenMiles service you requested.
  • Legitimate interests — to improve security, fix bugs, and maintain service quality.
  • Consent — for marketing communications, which you can withdraw at any time.

6. Sharing Your Data

We do not sell your data. Data is shared only with the following service providers who help us operate ZenMiles:

  • Supabase — database, sign-in, and server functions (servers in Tokyo, Japan).
  • Google — sign in with Google.
  • Apple — sign in with Apple.
  • Bird — delivers your verification code by WhatsApp, or by email if you ask for it. Receives your phone number, and your email address only if you choose the email option.
  • Firebase (Google) — push notifications, feature flags, and usage analytics.
  • Firebase Crashlytics — anonymised crash reporting and error tracking (part of the Firebase platform).

Each provider processes data only as necessary to deliver their specific service and is bound by their own privacy policies and data protection obligations.

7. Your Rights

Under UU PDP, you have the right to:

  • Know what personal data we hold about you.
  • Correct inaccurate data.
  • Request deletion of your data — deleting your account removes your profile, cards and programs from ZenMiles immediately. To have the retained copy erased permanently, email us and we will destroy it. Full instructions, including how to delete without the app installed, are on our account deletion page.
  • Withdraw marketing consent at any time.
  • Data portability — export your data in a structured format.

To exercise any of these rights, email us at support@zenmiles.app.

8. Data Security

We apply appropriate technical and organisational measures including TLS encryption in transit, encryption at rest, role-based access controls, and continuous security monitoring.

9. Data Retention

Active account data is retained for as long as your account is active. When you delete your account, your profile, cards and programs are removed from the app immediately and retained only as an internal archive, which nothing in the app can read. That archive is kept so that a deletion made in error can be reversed on request. It is destroyed permanently when you ask us to, or where we are legally required to erase it, unless we are legally required to retain it longer.

10. Children

ZenMiles is not intended for anyone under the age of 17. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.

11. Changes to This Policy

We will notify you of material changes to this policy via in-app notification and email at least 14 days before they take effect.

12. Contact

For privacy questions or to exercise your rights: support@zenmiles.app