Your Privacy Matters

Zinifly Privacy Policy

Learn how we collect, use, and protect your personal information on the Zinifly platform.

ZINIFLY PRIVACY POLICY

Effective Date: August 25, 2026
Last Updated: August 25, 2026

Zinifly, Inc. (“Zinifly,” “Company,” “we,” “us,” or “our”) respects your privacy.

This Privacy Policy explains how we collect, use, disclose, retain, and otherwise process personal information when you access or use:

  • Zinifly.com;
  • the Zinifly platform;
  • Zinifly-powered marketplaces;
  • Market Owner websites and subdomains;
  • custom-domain websites powered by Zinifly;
  • Vendor portals and Vendor storefronts;
  • ecommerce functionality;
  • ticketing and event-management functionality;
  • payment integrations;
  • communications features;
  • Community Board functionality;
  • venue-management tools;
  • mobile-responsive services;
  • customer support;
  • and other products and services that link to this Privacy Policy,

collectively, the “Platform.”

This Policy also describes privacy rights that may be available to you under applicable law.

This Policy should be read together with our Terms of Service and Cookie Policy.

1

SCOPE OF THIS PRIVACY POLICY

This Privacy Policy applies to personal information processed by Zinifly in connection with the Platform.

It may apply to information concerning:

  • Market Owners;
  • Market Owner employees and administrators;
  • Vendors and Sellers;
  • Vendor employees;
  • Buyers and customers;
  • event attendees;
  • ticket purchasers;
  • volunteers;
  • artists;
  • speakers;
  • sponsors;
  • website visitors;
  • prospective customers;
  • customer-support contacts; and
  • other individuals interacting with Zinifly or a Zinifly-powered Marketplace.

This Policy does not apply to information processed solely by an independent third party under that third party's own privacy policy.

2

ZINIFLY'S ROLE IN PROCESSING PERSONAL INFORMATION

Zinifly's legal role may vary depending on the particular processing activity.

2.1 When Zinifly Determines the Purpose of Processing

Zinifly generally acts as an independent business, controller, or similar legally defined entity when processing information for its own purposes, including:

  • managing Zinifly accounts;
  • administering subscriptions;
  • billing Zinifly customers;
  • managing Platform security;
  • preventing fraud and abuse;
  • providing customer support;
  • operating Zinifly's corporate website;
  • conducting Zinifly analytics;
  • maintaining business records;
  • improving the Platform;
  • administering legal compliance;
  • communicating with Zinifly customers;
  • managing Zinifly marketing, where permitted; and
  • protecting Zinifly's legal rights.

2.2 When Zinifly Processes Information for a Market Owner

When a Market Owner uses the Platform to collect and process information about its Vendors, customers, attendees, volunteers, applicants, artists, sponsors, or other individuals, the Market Owner may determine why and how that information is used.

In those circumstances, the Market Owner may be the applicable controller, business, or similar legally defined entity, and Zinifly may act as its processor, service provider, contractor, or similar service provider.

If your inquiry concerns information controlled by a particular Market Owner, we may direct your request to that Market Owner or assist the Market Owner in responding.

2.3 Independent Market Owners and Vendors

Market Owners and Vendors may collect or use personal information for their own independent purposes.

Their privacy practices are governed by their own privacy notices and applicable law.

Zinifly is not responsible for a Market Owner's or Vendor's independent privacy practices.

3

PERSONAL INFORMATION WE COLLECT

The information we collect depends on how you interact with the Platform.

We may collect the following categories of personal information.

3.1 Identity and Contact Information

This may include:

  • first and last name;
  • username;
  • mailing address;
  • business address;
  • email address;
  • telephone number;
  • profile photograph;
  • business name;
  • job title;
  • organization affiliation; and
  • other contact information.

3.2 Account Information

This may include:

  • account ID;
  • login information;
  • password or password-derived authentication data;
  • account roles and permissions;
  • authentication status;
  • account preferences;
  • profile information;
  • registration date;
  • account activity;
  • account status; and
  • security information.

We generally store passwords in protected authentication form rather than readable plaintext.

3.3 Business and Professional Information

For Market Owners, Vendors, Sellers, artists, sponsors, contractors, and other business users, we may collect:

  • business name;
  • business type;
  • business address;
  • contact information;
  • website address;
  • business description;
  • product or service information;
  • licenses;
  • permits;
  • insurance information;
  • tax information;
  • Vendor application information;
  • professional qualifications;
  • event participation history;
  • booth or space assignments;
  • business documents; and
  • other professional information.

3.4 Transaction and Commercial Information

When you purchase, sell, reserve, register for, or otherwise participate in a transaction through the Platform, we may collect:

  • transaction ID;
  • products or services purchased;
  • amount paid;
  • ticket type;
  • Vendor fees;
  • event registrations;
  • booth bookings;
  • order history;
  • refund information;
  • cancellation information;
  • transaction dates;
  • payment status;
  • payout status;
  • discounts;
  • promotional codes;
  • transaction disputes; and
  • related commercial records.

3.5 Payment Information

Payment transactions may be processed through third-party payment providers such as Stripe, Square, PayPal, financial institutions, card networks, or other payment processors.

Depending on the transaction, payment information may include:

  • payment card information;
  • billing address;
  • bank-account information;
  • payout information;
  • payment tokens;
  • transaction status;
  • chargeback information;
  • tax information; and
  • payment-verification information.

Zinifly generally does not need to receive or store complete payment-card numbers when a third-party Payment Processor collects them directly through its secure payment interface.

Payment Processors may independently process personal information according to their own privacy policies.

3.6 Seller Verification and Compliance Information

Where required to support marketplace, tax, payment, fraud-prevention, or legal-compliance obligations, Zinifly or its service providers may request:

  • legal name;
  • date of birth;
  • physical address;
  • telephone number;
  • email address;
  • government-issued identification;
  • taxpayer identification information;
  • business registration information;
  • beneficial ownership information;
  • banking information;
  • seller certification information; and
  • other information necessary to verify identity or business status.

We seek to limit access to sensitive verification information to persons and service providers that reasonably need it.

3.7 Event and Ticketing Information

When you register for or attend an Event, we may process:

  • attendee name;
  • email address;
  • telephone number;
  • ticket number;
  • ticket category;
  • QR code;
  • registration date;
  • Event selections;
  • accessibility requests voluntarily provided;
  • check-in status;
  • guest information;
  • Event communications;
  • order history; and
  • other information requested by the applicable Event Organizer.

Market Owners are responsible for ensuring that information they request through custom registration fields is legally appropriate.

3.8 Vendor, Volunteer, Artist, Speaker and Sponsor Information

Depending on the feature used, we may process:

  • applications;
  • availability;
  • Event assignments;
  • booth assignments;
  • schedules;
  • contracts;
  • uploaded licenses;
  • certifications;
  • insurance documents;
  • biographies;
  • photographs;
  • business descriptions;
  • sponsorship details;
  • communication history; and
  • other participation information.

3.9 User Content

Users may upload or submit:

  • photographs;
  • videos;
  • graphics;
  • logos;
  • product listings;
  • business descriptions;
  • comments;
  • Community Board posts;
  • reactions;
  • blog content;
  • reviews;
  • messages;
  • documents;
  • contracts;
  • forms;
  • licenses;
  • attachments; and
  • other content.

Publicly posted Content may be visible to other Users or the general public.

Do not submit information you do not want disclosed publicly into fields clearly designated as public.

3.10 Communications

We may collect information contained in communications with Zinifly, including:

  • customer-support requests;
  • emails;
  • telephone communications;
  • SMS communications;
  • chat messages;
  • feedback;
  • survey responses;
  • dispute correspondence; and
  • other communications.

Where permitted by law and disclosed at the time, customer-support calls or other communications may be recorded or monitored for quality, security, training, or compliance purposes.

3.11 Device and Technical Information

When you access the Platform, we may automatically collect information such as:

  • IP address;
  • browser type;
  • operating system;
  • device type;
  • device identifiers;
  • approximate geographic location derived from IP address;
  • language;
  • time zone;
  • referring URL;
  • pages viewed;
  • date and time of access;
  • session information; and
  • technical identifiers.

3.12 Usage and Interaction Information

We may collect information about your interactions with the Platform, including:

  • features used;
  • pages viewed;
  • buttons clicked;
  • search activity;
  • navigation patterns;
  • session duration;
  • account actions;
  • Marketplace interactions;
  • errors;
  • system events;
  • performance information; and
  • communications preferences.

3.13 Cookies and Similar Technologies

We and our service providers may use:

  • cookies;
  • pixels;
  • tags;
  • SDKs;
  • local storage;
  • analytics tools;
  • session identifiers; and
  • similar technologies.

Additional information is provided in our Cookie Policy.

3.14 Approximate Geolocation

We may infer approximate location from an IP address or information supplied by you.

We do not intentionally collect precise GPS location unless a specific Platform feature requires it and appropriate notice or permission is provided.

3.15 Information We Infer

We may derive limited information from other information we collect, such as:

  • probable business interests;
  • feature preferences;
  • fraud risk;
  • account security risk;
  • marketing attribution;
  • Platform engagement; and
  • likely service interests.

We do not use solely automated processing to make decisions producing legal or similarly significant effects about individuals unless separately disclosed and permitted by applicable law.

4

SOURCES OF PERSONAL INFORMATION

We may obtain personal information from:

4.1 You

For example, when you:

  • register;
  • create an account;
  • contact us;
  • submit an application;
  • purchase a subscription;
  • purchase a product;
  • purchase a ticket;
  • register for an Event;
  • upload Content;
  • communicate through the Platform; or
  • submit information through a form.

4.2 Market Owners

Market Owners may provide information concerning:

  • Vendors;
  • event attendees;
  • applicants;
  • volunteers;
  • sponsors;
  • artists;
  • customers;
  • administrators; and
  • other Marketplace participants.

4.3 Vendors and Sellers

Vendors may provide information relating to:

  • transactions;
  • customers;
  • fulfillment;
  • refunds;
  • disputes; and
  • Marketplace participation.

4.4 Payment and Financial Service Providers

We may receive transaction status, identifiers, fraud information, payout information, and other payment-related information from Payment Processors.

4.5 Service Providers

Hosting, analytics, communications, identity-verification, fraud-prevention, mapping, security, and other providers may provide information to us.

4.6 Public Sources

We may obtain business-related information from publicly available sources where legally permitted.

4.7 Automatically

We collect technical, device, usage, cookie, and interaction information automatically when you use the Platform.

5

HOW WE USE PERSONAL INFORMATION

We may use personal information for the following purposes.

5.1 Provide and Operate the Platform

Including to:

  • create and manage accounts;
  • authenticate Users;
  • provide websites and Marketplace functionality;
  • process Vendor applications;
  • manage Events;
  • provide ecommerce services;
  • issue tickets;
  • provide QR check-in functionality;
  • manage booth assignments;
  • manage Vendor participation;
  • enable communications;
  • maintain User preferences; and
  • deliver requested Platform features.

5.2 Facilitate Transactions

Including to:

  • process purchases;
  • facilitate payments;
  • process payouts;
  • administer refunds;
  • administer chargebacks;
  • maintain transaction records;
  • verify transactions;
  • prevent transaction fraud; and
  • facilitate communications among transaction participants.

5.3 Administer Subscriptions

Including to:

  • process subscription payments;
  • administer renewals;
  • manage plans;
  • communicate billing information;
  • manage upgrades and downgrades;
  • prevent subscription fraud; and
  • maintain billing records.

5.4 Provide Customer Support

Including to:

  • respond to requests;
  • troubleshoot problems;
  • investigate errors;
  • respond to complaints;
  • provide technical support; and
  • communicate about accounts.

5.5 Protect the Platform and Users

Including to:

  • authenticate Users;
  • detect suspicious activity;
  • prevent fraud;
  • detect abuse;
  • prevent unauthorized access;
  • enforce our Terms;
  • prevent spam;
  • detect malicious activity;
  • investigate security incidents; and
  • protect Users and third parties.

5.6 Improve and Develop Zinifly

Including to:

  • understand Platform usage;
  • identify errors;
  • measure performance;
  • analyze trends;
  • develop new functionality;
  • improve usability;
  • conduct testing; and
  • evaluate product performance.

Where legally required, we will obtain consent before using information for materially different purposes.

5.7 Communications

We may communicate with you about:

  • account administration;
  • security;
  • subscription changes;
  • payments;
  • orders;
  • tickets;
  • Event changes;
  • Vendor applications;
  • support;
  • legal notices;
  • product updates; and
  • other Platform-related matters.

5.8 Marketing

Where legally permitted, we may use contact information and engagement information to:

  • send Zinifly marketing communications;
  • promote Platform features;
  • measure campaigns;
  • customize marketing; and
  • understand how Users discover Zinifly.

You may opt out of marketing email communications at any time using the unsubscribe mechanism in the message.

Marketing SMS messages, where used, are subject to additional consent requirements.

5.9 Analytics

We may use information to understand:

  • traffic;
  • conversions;
  • account usage;
  • feature adoption;
  • campaign performance;
  • Platform reliability; and
  • general business performance.

5.10 Advertising

Where permitted by applicable law and your privacy choices, Zinifly or third parties may use certain online identifiers and Internet activity information for:

  • advertising measurement;
  • attribution;
  • retargeting;
  • audience measurement; and
  • interest-based or targeted advertising.

Some disclosures for advertising may be considered a “sale,” “sharing,” or processing for “targeted advertising” under certain U.S. state privacy laws even when no money is exchanged.

See Section 15 — Sale, Sharing and Targeted Advertising.

5.11 Legal and Regulatory Compliance

We may process information to:

  • comply with laws;
  • respond to lawful requests;
  • comply with tax obligations;
  • comply with marketplace regulations;
  • comply with payment requirements;
  • investigate legal claims;
  • preserve evidence;
  • respond to subpoenas;
  • enforce contracts;
  • protect legal rights; and
  • cooperate with governmental authorities where legally appropriate.

5.12 Corporate Transactions

We may use information as reasonably necessary to evaluate, negotiate, or complete:

  • financing;
  • investment;
  • acquisition;
  • merger;
  • restructuring;
  • reorganization;
  • bankruptcy;
  • sale of assets; or
  • similar corporate transactions.
7

HOW WE DISCLOSE PERSONAL INFORMATION

We may disclose personal information as described below.

We do not sell personal information for money in the conventional sense.

Certain advertising disclosures, however, may constitute a statutory “sale” or “sharing” under some state privacy laws.

7.1 Market Owners

We may disclose information to a Market Owner when necessary to administer its Marketplace, including information concerning:

  • Vendors;
  • applicants;
  • customers;
  • tickets;
  • attendees;
  • volunteers;
  • transactions;
  • sponsors;
  • artists;
  • Event participation; and
  • communications.

7.2 Vendors and Sellers

When you purchase a Vendor's product or service, we may provide the Vendor with information needed to fulfill the Transaction, such as:

  • name;
  • contact details;
  • order information;
  • delivery or pickup information; and
  • transaction details.

7.3 Payment Processors and Financial Providers

We may disclose information to:

  • Stripe;
  • Square;
  • PayPal;
  • banks;
  • payment networks;
  • payment facilitators;
  • fraud-prevention providers; and
  • related financial service providers

as necessary to facilitate payments, payouts, refunds, chargebacks, verification, fraud prevention, and compliance.

7.4 Service Providers and Contractors

We may disclose information to providers supporting:

  • cloud hosting;
  • infrastructure;
  • data storage;
  • security;
  • authentication;
  • customer support;
  • communications;
  • email;
  • SMS;
  • analytics;
  • mapping;
  • monitoring;
  • tax services;
  • payment services;
  • software development;
  • identity verification; and
  • other Platform operations.

These providers are permitted to process information subject to applicable contractual and legal requirements.

7.5 Analytics and Advertising Providers

Where enabled and permitted, we may disclose identifiers, device information, cookie identifiers, and Internet activity information to analytics, measurement, and advertising providers.

Depending on applicable law and how such providers use the information, these disclosures may constitute:

  • “sharing”;
  • a “sale”; or
  • processing for targeted advertising.

See Sections 14 and 15.

7.6 Professional Advisers

We may disclose information to:

  • attorneys;
  • accountants;
  • auditors;
  • insurers;
  • consultants; and
  • other professional advisers

subject to appropriate confidentiality obligations.

7.7 Government, Regulators and Law Enforcement

We may disclose information where we reasonably believe disclosure is:

  • required by law;
  • required by legal process;
  • necessary to respond to a valid governmental request;
  • necessary to investigate illegal activity;
  • necessary to protect safety;
  • necessary to prevent fraud; or
  • necessary to protect our legal rights.

Where legally permitted and appropriate, Zinifly may scrutinize governmental requests and object to requests that appear invalid or overly broad.

7.8 Safety and Abuse Reporting

Where permitted or required by law, Zinifly may provide information concerning:

  • child exploitation;
  • credible threats;
  • fraud;
  • terrorism;
  • illegal activity;
  • nonconsensual intimate imagery;
  • security incidents; or
  • other serious abuse

to appropriate authorities or organizations.

7.9 Corporate Transactions

Personal information may be disclosed as part of:

  • a merger;
  • acquisition;
  • sale;
  • financing;
  • reorganization;
  • bankruptcy;
  • corporate restructuring; or
  • transfer of all or part of our business.

7.10 With Your Direction or Consent

We may disclose information when you direct us to do so or provide legally valid consent.

8

PUBLIC INFORMATION

Certain parts of the Platform are designed to be public.

For example, a Vendor may choose to publish:

  • business name;
  • logo;
  • photographs;
  • business description;
  • website;
  • product listings;
  • social media links;
  • market schedule; and
  • contact information.

Community Board posts, comments, public Marketplace pages, blog content, product listings, and other public Content may be accessible by:

  • other Users;
  • website visitors;
  • search engines; and
  • third-party services.

Once information is made public, Zinifly cannot control how every independent third party may copy or use it.

Users should not publish sensitive personal information in publicly visible areas.

9

MARKET OWNER-CONTROLLED DATA

When Zinifly processes personal information on behalf of a Market Owner, the Market Owner generally controls:

  • what information it requests;
  • why it collects the information;
  • who receives it;
  • how it uses it;
  • how long it requires it;
  • and whether particular communications are sent.

For example, a Market Owner may create custom fields requesting information from Vendors or Event registrants.

Zinifly does not necessarily determine the purpose of those fields.

If you want to exercise privacy rights concerning information controlled by a Market Owner, you should contact that Market Owner.

You may also contact Zinifly, and where appropriate we may forward or assist with your request.

10

PAYMENT INFORMATION

Payment information is generally processed by third-party Payment Processors.

Zinifly may receive information such as:

  • transaction identifiers;
  • partial payment-card information;
  • payment status;
  • payout status;
  • refund information;
  • chargeback information;
  • fraud indicators; and
  • billing information.

We do not intentionally store full payment-card security codes.

Payment Processors may independently collect information directly from Users.

Their privacy policies apply to their independent processing.

11

IDENTITY AND SELLER VERIFICATION

Certain Sellers may be required to provide information for:

  • payment onboarding;
  • identity verification;
  • tax reporting;
  • fraud prevention;
  • sanctions compliance;
  • marketplace compliance; or
  • other legal obligations.

This information may be processed by Zinifly or specialist verification providers.

Where law requires marketplace operators to disclose certain Seller information to consumers, Zinifly may make the legally required disclosures.

12

COMMUNICATIONS AND MARKETING

12.1 Transactional Communications

We may send communications reasonably necessary for:

  • account management;
  • security;
  • purchases;
  • tickets;
  • Events;
  • Vendor applications;
  • billing;
  • refunds;
  • subscription administration;
  • support;
  • legal notices; and
  • Platform administration.

You generally cannot opt out of communications that are necessary to provide a service you requested or maintain account security.

12.2 Marketing Email

You may opt out of Zinifly marketing email by:

  • using the unsubscribe link in the message; or
  • contacting us.

Opting out of marketing does not prevent transactional communications.

12.3 SMS

If you consent to receive applicable SMS communications, message and data rates may apply.

Where supported, you may reply:

STOP to opt out.

You may reply:

HELP for assistance.

Other legally recognized revocation methods may also be honored.

Consent to receive marketing SMS is not a condition of purchasing Zinifly services where prohibited by law.

12.4 Market Owner Communications

Market Owners may independently communicate with their Vendors, customers, or attendees through Zinifly.

Those communications may be sent on the Market Owner's behalf rather than Zinifly's.

Contact the applicable Market Owner regarding its independent marketing practices.

13

COOKIES AND TRACKING TECHNOLOGIES

We use cookies and similar technologies for purposes that may include:

Essential

Necessary for:

  • authentication;
  • security;
  • fraud prevention;
  • account sessions;
  • shopping-cart functionality;
  • user preferences; and
  • core Platform functionality.

Functional

Used to remember settings and enhance Platform features.

Analytics

Used to understand how Users interact with Zinifly and measure Platform performance.

Advertising and Marketing

Where enabled and legally permitted, these technologies may support:

  • campaign attribution;
  • advertising measurement;
  • retargeting;
  • interest-based advertising; and
  • targeted advertising.

Where legally required, nonessential technologies will be subject to consent or opt-out controls.

For more information, see our Cookie Policy.

14

GLOBAL PRIVACY CONTROL, DO NOT TRACK AND UNIVERSAL OPT-OUT SIGNALS

14.1 Global Privacy Control

Where applicable law requires Zinifly to recognize a qualifying browser-based universal opt-out preference signal, including Global Privacy Control (“GPC”), we will process the signal as an opt-out request for the legally applicable purposes.

Depending on applicable law, this may include opting out of:

  • sale of personal information;
  • sharing for cross-context behavioral advertising; and
  • targeted advertising.

Where required by law, Zinifly will provide a reasonable indication that a recognized opt-out preference signal has been honored.

A browser signal generally applies to the browser or device sending the signal unless Zinifly can associate the preference with an authenticated account as permitted or required by law.

14.2 Legacy “Do Not Track” Signals

Some browsers provide a “Do Not Track” or “DNT” signal for which no universally accepted industry standard exists.

Zinifly does not necessarily respond to legacy DNT signals unless legally required.

We do, however, honor legally recognized universal opt-out mechanisms where applicable.

14.3 Third-Party Tracking

Third-party analytics, advertising, and similar providers may collect information regarding your online activity over time and across websites or online services where their technologies are enabled.

Your ability to limit this activity is described in this Policy and our Cookie Policy.

15

SALE, SHARING AND TARGETED ADVERTISING

Zinifly does not sell personal information for monetary payment in the conventional sense.

However, some U.S. privacy statutes define “sale” or “sharing” broadly.

For example, disclosure of online identifiers or Internet activity to an advertising provider in exchange for advertising, analytics, measurement, or other value may qualify as a sale, sharing, or targeted advertising under applicable law.

Accordingly, where applicable, you may have the right to opt out of:

  • sale of personal information;
  • sharing of personal information for cross-context behavioral advertising; and
  • targeted advertising.

You may exercise applicable rights by:

  • using the Your Privacy Choices link available on Zinifly;
  • adjusting cookie settings;
  • enabling a legally recognized universal opt-out mechanism such as GPC; or
  • contacting us at privacy@zinifly.com.

Zinifly does not knowingly sell or share the personal information of individuals under sixteen (16) in circumstances requiring affirmative authorization under applicable law.

16

SENSITIVE PERSONAL INFORMATION

Depending on how the Platform is used, Zinifly or its service providers may process limited information considered “sensitive” under certain laws, such as:

  • account login credentials;
  • financial-account information;
  • government identification used for verification;
  • taxpayer identification information;
  • precise location if expressly enabled by a feature;
  • information concerning a known child where lawfully provided; and
  • other information a Market Owner chooses to request.

Zinifly seeks to use sensitive personal information only where reasonably necessary for purposes such as:

  • account authentication;
  • security;
  • payment processing;
  • fraud prevention;
  • seller verification;
  • tax compliance;
  • legal compliance;
  • providing requested services; or
  • another disclosed purpose.

Zinifly does not use sensitive personal information to infer characteristics about individuals for unrelated purposes unless separately disclosed and legally permitted.

Where consent is required to process sensitive personal information, we or the responsible Market Owner will be responsible for obtaining the required consent.

Where applicable law provides a right to limit certain uses of sensitive personal information, Zinifly will honor that right when legally required.

17

DATA RETENTION

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, subject to applicable legal, accounting, security, fraud-prevention, backup, and contractual requirements.

Retention periods vary according to the type of information and purpose.

Factors considered include:

  • length of the customer relationship;
  • account status;
  • contractual obligations;
  • legal requirements;
  • tax and accounting requirements;
  • payment rules;
  • fraud and chargeback exposure;
  • dispute-resolution periods;
  • security needs;
  • limitation periods;
  • Market Owner instructions; and
  • operational requirements.

Typical practices may include:

Account Information

Generally retained while an account remains active and for a reasonable period afterward.

Customer and Marketplace Data

Generally retained while necessary to provide services to the applicable Market Owner and during applicable post-termination export or retention periods.

Transaction Records

May be retained for several years where reasonably necessary for:

  • tax;
  • accounting;
  • payments;
  • fraud prevention;
  • dispute resolution; and
  • legal compliance.

Communications

May be retained as reasonably necessary for support, security, business records, and dispute resolution.

Analytics and Technical Data

May be retained for periods appropriate to security, analytics, troubleshooting, and product improvement.

Legal Holds

Information subject to litigation, investigation, regulatory inquiry, legal hold, or other preservation obligation may be retained until the applicable matter is resolved.

Backups

Information deleted from active systems may temporarily remain in backups until overwritten or deleted through ordinary backup cycles.

We may retain deidentified or aggregated information where legally permitted.

18

DATA SECURITY

Zinifly uses administrative, technical, and organizational safeguards intended to protect personal information against risks such as:

  • unauthorized access;
  • unauthorized disclosure;
  • alteration;
  • loss;
  • misuse; and
  • destruction.

Depending on the system and information involved, safeguards may include:

  • encrypted network transmission;
  • authentication controls;
  • access controls;
  • logging;
  • infrastructure protections;
  • role-based permissions;
  • security monitoring;
  • backup processes;
  • vendor-management practices; and
  • other security measures.

No Internet transmission, software platform, cloud service, or information-storage system is completely secure.

Accordingly, Zinifly cannot guarantee that security incidents will never occur.

Users are responsible for protecting their own login credentials, devices, administrator permissions, and account access.

If you believe your account or personal information has been compromised, contact us promptly at:

security@zinifly.com

If that email address is not implemented before publication, security reports should be directed to:

support@zinifly.com

19

DATA BREACHES AND SECURITY INCIDENTS

If Zinifly becomes aware of a security incident affecting personal information, we will investigate and respond as appropriate.

Where applicable law requires notification to:

  • affected individuals;
  • Market Owners;
  • government agencies;
  • regulators;
  • law enforcement; or
  • other parties,

Zinifly will provide legally required notifications in accordance with applicable requirements.

Where Zinifly acts as a processor or service provider for a Market Owner, Zinifly may notify the Market Owner so the Market Owner can fulfill its own obligations.

20

CHILDREN'S PRIVACY

Zinifly's business-account functionality is not directed to children under thirteen (13).

Children under thirteen may not independently create Zinifly accounts or directly provide personal information to Zinifly unless Zinifly has expressly implemented an appropriate legally compliant workflow.

Certain Events may involve minors.

A parent, legal guardian, or authorized Market Owner may provide limited information concerning minors where legally permitted.

Market Owners are responsible for determining whether parental notices, consents, releases, supervision, or other safeguards are required for their Event or activity.

If Zinifly learns that it has directly collected personal information from a child under thirteen in circumstances requiring parental consent and such consent was not obtained, we will take appropriate steps consistent with applicable law, which may include deletion.

Parents or guardians who believe a child has improperly provided personal information may contact:

privacy@zinifly.com

Zinifly does not knowingly use children's personal information for targeted advertising in violation of applicable law.

21

INTERNATIONAL DATA TRANSFERS

Zinifly is based in the United States.

Personal information may be processed in the United States and other countries where Zinifly or its service providers operate.

These countries may have privacy laws different from the laws in your jurisdiction.

Where applicable law requires safeguards for international transfers, Zinifly will use an appropriate lawful transfer mechanism.

Depending on the circumstances, such mechanisms may include:

  • an adequacy decision;
  • European Commission Standard Contractual Clauses;
  • the UK International Data Transfer Addendum or other UK-approved mechanism;
  • contractual safeguards; or
  • another legally recognized transfer mechanism.

You may contact privacy@zinifly.com for additional information regarding applicable transfer safeguards.

22

EEA AND UK PRIVACY RIGHTS

If GDPR or UK GDPR applies to Zinifly's processing of your personal information, you may have rights including:

  • access to personal information;
  • correction of inaccurate information;
  • deletion in certain circumstances;
  • restriction of processing;
  • data portability;
  • objection to certain processing;
  • objection to direct marketing;
  • withdrawal of consent;
  • protection concerning certain automated decision-making; and
  • the right to lodge a complaint with a data-protection supervisory authority.

These rights are subject to statutory conditions and exceptions.

Where Zinifly acts only as a processor for a Market Owner, the Market Owner may be responsible for responding to your request.

You may submit a request to:

privacy@zinifly.com

You also have the right to lodge a complaint with the supervisory authority in the country where you reside, work, or believe an infringement occurred.

23

U.S. STATE PRIVACY RIGHTS

Depending on where you reside and whether an applicable privacy law applies to Zinifly's processing, you may have some or all of the following rights:

23.1 Right to Confirm Processing

You may have the right to confirm whether Zinifly is processing your personal information.

23.2 Right to Access

You may have the right to obtain access to personal information we maintain about you.

23.3 Right to Correct

You may have the right to correct inaccuracies in your personal information.

23.4 Right to Delete

You may have the right to request deletion of certain personal information.

Exceptions may apply for information needed for:

  • transactions;
  • security;
  • fraud prevention;
  • legal compliance;
  • exercising legal rights;
  • accounting;
  • tax obligations;
  • or other legally recognized purposes.

23.5 Right to Data Portability

You may have the right to obtain certain personal information in a portable and usable format.

23.6 Right to Opt Out of Sale

Where applicable, you may opt out of legally defined sales of personal information.

23.7 Right to Opt Out of Targeted Advertising

Where applicable, you may opt out of processing of personal information for targeted advertising.

23.8 Right to Opt Out of Sharing

California residents may have the right to opt out of sharing personal information for cross-context behavioral advertising.

23.9 Right to Opt Out of Certain Profiling

Residents of certain states may have the right to opt out of qualifying profiling used to make decisions producing legal or similarly significant effects.

Zinifly does not currently use solely automated processing to make such decisions about Consumers unless separately disclosed.

23.10 Sensitive Data Rights

Certain states provide rights concerning sensitive data, including a right to consent to or limit certain processing.

23.11 Right to Non-Discrimination

Zinifly will not unlawfully discriminate against you because you exercised an applicable privacy right.

23.12 Authorized Agents

Where permitted by applicable law, an authorized agent may submit certain requests on your behalf.

We may require proof of the agent's authority and may separately verify your identity.

23.13 Appeals

If Zinifly denies a privacy-rights request and applicable state law provides a right to appeal, you may appeal the decision by emailing:

privacy@zinifly.com

Use the subject line:

PRIVACY REQUEST APPEAL

Include sufficient information to identify the original request.

We will review the appeal and respond within the time required by applicable law.

Where applicable law provides a right to contact a state Attorney General or other regulator following an unsuccessful appeal, our response will provide appropriate information.

24

HOW TO EXERCISE YOUR PRIVACY RIGHTS

You may submit a privacy request through one or more of the following methods:

Email

privacy@zinifly.com

Online

https://zinifly.com/privacy-request

Telephone

(615) 561-7007

Where required, a Your Privacy Choices link will also be provided on the Platform for applicable sale, sharing, or targeted-advertising opt-outs.

We may request information reasonably necessary to:

  • locate your information;
  • verify your identity;
  • prevent fraudulent requests; and
  • determine which privacy law applies.

We will not require more information than reasonably necessary to verify or fulfill the request.

Where permitted, requests may be denied or limited if:

  • identity cannot reasonably be verified;
  • an exception applies;
  • fulfilling the request would adversely affect another person's rights;
  • the request is fraudulent;
  • Zinifly is acting solely as a processor and must refer the request to the controller; or
  • another legal basis permits or requires retention.

We will respond within the period required by applicable law and may use an authorized extension where permitted.

25

CALIFORNIA PRIVACY NOTICE

This Section supplements the remainder of this Privacy Policy for California residents where the California Consumer Privacy Act, as amended (“CCPA”), applies.

25.1 Categories of Personal Information

During the preceding twelve (12) months, Zinifly may have collected the following categories of personal information, depending on the User and Platform features used:

Category Examples
Identifiers Name, username, email, telephone number, postal address, account ID, IP address
California Customer Records information Contact details and certain financial or business information
Commercial information Purchases, subscriptions, tickets, transaction history, Vendor bookings
Internet or electronic network activity Browsing activity, Platform interactions, session activity, device information
Geolocation information Approximate location derived from IP address
Professional or employment-related information Business name, job title, professional or Vendor information
Audio, electronic, visual or similar information Uploaded photographs, videos, profile images, support recordings where applicable
Inferences Limited preferences, engagement, fraud-risk, or service-interest information derived from other data
Sensitive personal information Account credentials and, where applicable, financial, tax, identity-verification, or precise-location information

The specific categories collected from a particular person depend on their interaction with Zinifly.

25.2 Sources

We may collect these categories from:

  • Consumers directly;
  • Market Owners;
  • Vendors and Sellers;
  • Payment Processors;
  • service providers;
  • advertising and analytics providers;
  • publicly available sources; and
  • automatic collection through the Platform.

25.3 Purposes

We may use these categories for:

  • providing the Platform;
  • administering accounts;
  • processing Transactions;
  • customer support;
  • Event management;
  • Vendor management;
  • ticketing;
  • payments;
  • security;
  • fraud prevention;
  • legal compliance;
  • analytics;
  • Platform improvement;
  • communications;
  • marketing; and
  • advertising where permitted.

25.4 Business-Purpose Disclosures

During the preceding twelve (12) months, Zinifly may have disclosed applicable categories of personal information for business purposes to:

  • Market Owners;
  • Vendors and Sellers;
  • payment providers;
  • cloud and hosting providers;
  • security providers;
  • analytics providers;
  • communications providers;
  • customer-support providers;
  • professional advisers;
  • verification providers;
  • tax and compliance providers; and
  • other service providers and contractors.

The category disclosed depends on the services provided.

25.5 Sale and Sharing

Zinifly does not sell personal information in exchange for money in the conventional sense.

However, when advertising or marketing technologies are enabled, certain disclosures of:

  • identifiers;
  • cookie identifiers;
  • device information; and
  • Internet or network activity

to advertising or analytics providers may constitute “sale” or “sharing” under the CCPA.

California Consumers may opt out using:

Your Privacy Choices

or by using a qualifying opt-out preference signal such as GPC.

Zinifly does not knowingly sell or share the personal information of Consumers under sixteen (16) without the authorization required by applicable law.

25.6 Sensitive Personal Information

Zinifly may process limited sensitive personal information for purposes such as:

  • authentication;
  • payment processing;
  • security;
  • fraud prevention;
  • seller verification;
  • tax compliance; and
  • providing requested Platform functionality.

We do not use sensitive personal information to infer characteristics about California Consumers for unrelated purposes unless separately disclosed.

Where our use of sensitive personal information triggers a statutory right to limit, California Consumers may exercise that right through the methods described in this Policy.

25.7 California Consumer Rights

Subject to applicable exceptions, California Consumers may have the right to:

  • know categories of personal information collected;
  • know sources;
  • know purposes;
  • know categories disclosed, sold, or shared;
  • know categories of recipients;
  • access specific pieces of personal information;
  • request deletion;
  • request correction;
  • opt out of sale;
  • opt out of sharing;
  • limit certain uses of sensitive personal information; and
  • receive equal service and pricing when exercising privacy rights.

25.8 California Opt-Out Preference Signals

Where required by the CCPA, Zinifly treats a qualifying opt-out preference signal as a request to opt out of sale and sharing for the browser or device from which it is sent.

Where required by applicable CCPA regulations, the Platform will provide a reasonable means for the Consumer to confirm that the opt-out preference has been honored.

25.9 Authorized Agents

California Consumers may use an authorized agent as permitted by law.

We may request written authorization and independently verify the Consumer where permitted.

25.10 Financial Incentives

Zinifly does not currently offer Consumers a financial incentive in exchange for personal information that requires a CCPA Notice of Financial Incentive unless a separate notice is provided.

If such a program is introduced, Zinifly will provide the disclosures and choices required by applicable law.

26

TENNESSEE PRIVACY RIGHTS

Where the Tennessee Information Protection Act applies, Tennessee Consumers may have rights including:

  • confirming whether personal information is being processed;
  • accessing personal information;
  • correcting inaccuracies;
  • requesting deletion;
  • obtaining a portable copy;
  • opting out of sale;
  • opting out of targeted advertising;
  • opting out of qualifying profiling; and
  • appealing a decision concerning a privacy-rights request.

Requests and appeals may be submitted using the methods described in Sections 23 and 24.

27

OTHER U.S. STATE PRIVACY LAWS

Residents of other U.S. states may have similar or additional rights under applicable comprehensive privacy laws.

Rather than requiring Users to identify a particular statute, Zinifly will evaluate privacy requests based on:

  • your state of residence;
  • Zinifly's role in the processing;
  • the type of personal information involved; and
  • applicable law.

Where applicable, rights may include:

  • access;
  • correction;
  • deletion;
  • portability;
  • opt-out of sale;
  • opt-out of targeted advertising;
  • opt-out of qualifying profiling;
  • rights concerning sensitive information;
  • authorized-agent rights;
  • appeal rights; and
  • protection against unlawful discrimination.
28

DEIDENTIFIED AND AGGREGATED INFORMATION

Zinifly may create aggregated or deidentified information that cannot reasonably be linked to an identified or identifiable individual.

We may use such information for:

  • analytics;
  • product improvement;
  • benchmarking;
  • research;
  • security;
  • business planning; and
  • other lawful purposes.

Where required by law, Zinifly will maintain deidentified information in deidentified form and will not attempt to reidentify it except for legally permitted purposes such as evaluating whether deidentification measures are effective.

29

THIRD-PARTY WEBSITES AND SERVICES

The Platform may contain links to or integrations with third-party services.

Examples may include:

  • Stripe;
  • Square;
  • PayPal;
  • Google services;
  • mapping providers;
  • social media platforms;
  • advertising platforms;
  • analytics providers;
  • website links submitted by Vendors; and
  • external Event or business websites.

If you leave the Zinifly Platform or interact directly with an independent third party, that party's privacy policy applies to its processing.

Zinifly is not responsible for independent third-party privacy practices.

30

SOCIAL MEDIA AND THIRD-PARTY PLATFORMS

If you interact with Zinifly through social media or another third-party platform, we may receive information according to:

  • your privacy settings;
  • that platform's policies; and
  • the permissions you provide.

Information you provide directly to the third party remains subject to that party's privacy practices.

31

BUSINESS TRANSFERS

If Zinifly is involved in a:

  • merger;
  • acquisition;
  • financing;
  • reorganization;
  • bankruptcy;
  • sale of assets; or
  • similar transaction,

personal information may be reviewed, transferred, or disclosed as part of that transaction.

Where required by law, affected individuals will receive appropriate notice of material changes to the handling of their personal information.

32

CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy periodically to reflect changes in:

  • Platform functionality;
  • legal requirements;
  • technology;
  • data practices;
  • service providers; or
  • business operations.

When we update the Policy, we will change the Last Updated date.

For material changes, we may provide additional notice through:

  • email;
  • account notification;
  • Platform notice;
  • website notice; or
  • another legally appropriate method.

Where applicable law requires consent to a change in processing, we will obtain such consent.

We encourage Users to periodically review this Privacy Policy.

33

CONTACT US

Questions concerning this Privacy Policy or Zinifly's privacy practices may be directed to:

Zinifly, Inc.

Wilson County, Tennessee, USA

Privacy Email: privacy@zinifly.com

Telephone: (615) 561-7007

Mailing Address:

210 Old Laguardo Rd. Lebanon, TN 37087

Privacy requests may also be submitted through:

https://zinifly.com/privacy-request

For applicable sale, sharing, or targeted-advertising choices:

https://zinifly.com/your-privacy-choices

34

DATA PROTECTION CONTACT

For privacy and data-protection inquiries:

privacy@zinifly.com

If Zinifly appoints a Data Protection Officer, EU representative, UK representative, or other legally required representative in the future, the applicable contact information will be published here.

35

ACKNOWLEDGMENT

This Privacy Policy describes Zinifly's privacy practices.

It does not create contractual rights beyond those provided by applicable law or Zinifly's Terms of Service.

Nothing in this Privacy Policy is intended to waive or restrict any privacy right that cannot legally be waived or restricted.