Legal
Privacy Policy
How Zenska collects, uses, and protects your personal data — in compliance with the Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission.
Zenska.ph ("Zenska", "we", "our", or "us") is an online marketplace and wellness-booking platform that connects Filipino shoppers with verified beauty and wellness sellers. Protecting your personal data is central to that trust.
This Policy explains what we collect, why we collect it, who we share it with, how long we keep it, and the rights you can exercise at any time. It is written to comply with Philippine data-protection law and to be genuinely readable — not buried in legalese.
Scope of this Policy
This Privacy Policy applies to everyone who interacts with Zenska, including:
- Visitors and registered users of zenska.ph and the Zenska mobile app
- Buyers, customers, and wellness-booking clients
- Sellers, vendors, and wellness partners onboarded to the platform
- Anyone who contacts us through email, chat, or our support channels
By creating an account or using the platform, you confirm that you have read and understood how we process personal data as described here. Where the law requires your consent, we will ask for it separately and clearly.
Who is responsible for your data
Zenska acts as the Personal Information Controller (PIC) for the data processed on the platform. For seller-fulfilled orders, verified sellers act as independent controllers for the order data they receive to fulfil your purchase.
Data Protection Officer (DPO)
You can reach our Data Protection Officer for any privacy matter at privacy@zenska.ph. We respond to legitimate data-subject requests within a reasonable period consistent with National Privacy Commission (NPC) guidance.
Personal data we collect
Information you provide
- Identity and contact details — full name, email, mobile number
- Delivery and billing addresses
- Account credentials and preferences
- Records of your communications with customer support
Seller, vendor & wellness-partner information
- Business or trade name and registration details (DTI/SEC, BIR)
- Government-issued identification of authorized representatives
- Permits, FDA registrations, certificates of authorization, and invoices
- Bank or e-wallet details used solely for settlement of payouts
Transaction & order information
- Order history, bookings, and fulfilment status
- Payment method used — processed by licensed third-party providers
- Returns, refunds, cancellations, disputes, and their resolutions
We never store full card details
Card and e-wallet payments are handled by our PCI-DSS-compliant payment provider (PayMongo). Zenska does not receive or store your complete card number, CVV, or PIN. If you save a card for faster checkout, it is securely tokenized and vaulted by PayMongo — we keep only a reference token. On our mobile app, an optional camera "scan card" feature reads card details on your device to pre-fill the payment form; those numbers go to PayMongo and are not stored by Zenska.
Sensitive personal information (with your consent)
Some features — mainly wellness bookings and seller onboarding — involve sensitive personal information as defined by the Data Privacy Act. We collect this only with your consent and only where genuinely needed:
- Health information you provide for wellness treatments — such as allergies, medical conditions, and current medications — and emergency-contact details
- Senior Citizen or PWD type and ID number, where you claim the corresponding statutory discount
- Date of birth, used to verify age eligibility for age-restricted treatments
- For sellers: government-issued IDs, business registrations (DTI/SEC, BIR/TIN), permits, and bank-account details used solely for payouts
AI & skin-analysis data (optional, consent-based)
If you choose to use our AI skin-analysis feature ("Ask Zenska"), we process:
- A selfie you choose to upload (optional)
- Skin concerns, budget, and preferences you select
- The AI-generated cosmetic analysis and product recommendations
How your selfie is handled
- Your selfie is uploaded to our private, access-controlled storage and analyzed by our AI provider, OpenAI (model GPT-4o), through a short-lived expiring link — solely to generate your cosmetic analysis
- Your photo is permanently deleted from our storage immediately after the analysis completes (or if it fails) — we do not keep the image
- The resulting analysis report is saved to your scan history so you can revisit it, and you can delete it anytime
- No facial recognition, identity verification, or biometric template is created; an on-device check only confirms a face is in frame before upload
- Results are cosmetic guidance only — not a medical diagnosis — and are never used for advertising or sold
Information collected automatically
- IP address, device identifiers, browser and operating system
- Cookies, session data, and usage logs
- Device and session identifiers used to count video and product views fairly (we deduplicate using a rotating, hashed identifier rather than storing your raw IP)
- Push-notification device tokens, if you enable notifications
- In-app interaction and navigation events used to improve the service
Lawful basis for processing
Consistent with Section 12 and 13 of the Data Privacy Act, we process personal (and, where applicable, sensitive personal) information on one or more of these bases:
- Contract — to create your account and fulfil orders, bookings, and payments
- Consent — for optional features such as AI skin analysis and marketing messages
- Legal obligation — tax, accounting, consumer-protection, and regulatory requirements
- Legitimate interests — platform security, fraud prevention, and service improvement, balanced against your rights
How we use your data
- Creating and managing your account
- Processing orders, wellness bookings, payments, deliveries, and returns
- Verifying sellers and preventing counterfeit or unsafe products
- Providing AI-assisted recommendations you opt into
- Securing the platform and detecting fraud, abuse, or policy violations
- Meeting legal, tax, audit, and regulatory obligations
- Sending service notices, and — only with consent — marketing you can withdraw anytime
Cross-border transfers
Some of the providers above process data outside the Philippines. In particular, our file storage runs on Amazon Web Services in Singapore, and providers such as OpenAI, Google, Meta, and Sentry may process data in the United States or other regions.
Where data is transferred abroad, we rely on appropriate safeguards and contractual protections so that your personal data continues to receive a level of protection consistent with the Data Privacy Act.
How long we keep your data
We keep personal data only for as long as necessary to:
- Fulfil the transaction or booking you made
- Comply with tax, accounting, and other legal retention periods
- Resolve disputes and enforce our agreements
When data is no longer needed for these purposes, it is securely deleted or anonymized.
Skin-scan photos are not retained
Selfies uploaded for AI skin analysis are deleted from our storage immediately after the analysis finishes. Only the resulting cosmetic report is kept in your scan history, and you can delete it at any time.
How we protect your data
We apply organizational, physical, and technical safeguards, including:
- Encryption in transit and access-controlled storage
- Authentication, role-based access, and least-privilege controls
- Continuous monitoring and logging
- Due-diligence and confidentiality agreements with third-party processors
Personal-data breach notification
In the event of a personal-data breach that meets the notification threshold, we will notify the National Privacy Commission and affected data subjects within seventy-two (72) hours of knowledge of the breach, as required by the Data Privacy Act and NPC Circular No. 16-03.
Your rights as a data subject
Under the Data Privacy Act of 2012, you have the right to:
- 1Be informed about how your data is collected and processed
- 2Access the personal data we hold about you
- 3Rectify inaccurate or outdated information
- 4Object to processing, including for direct marketing
- 5Erasure or blocking of your data, subject to legal limits
- 6Data portability — obtain a copy in a commonly used format
- 7Damages for violations of your data-privacy rights
- 8Lodge a complaint with the National Privacy Commission
How to exercise your rights
Send requests to privacy@zenska.ph. We may verify your identity before acting. If you believe your rights were violated, you may also contact the National Privacy Commission at privacy.gov.ph.
Children's data
The platform is intended for users who are at least 18 years old. We do not knowingly collect personal data from minors without the consent of a parent or legal guardian. If you believe a minor has provided us data, contact privacy@zenska.ph and we will take appropriate action.
Updates to this Policy
We may update this Privacy Policy to reflect changes in law, technology, or our services. Material changes will be posted on this page with a new "last updated" date, and where required, we will seek your renewed consent.
Contact us
For any privacy concern or to reach our Data Protection Officer:
- Email: privacy@zenska.ph
- Website: https://zenska.ph
- Regulator: National Privacy Commission — privacy.gov.ph
Related documents
Questions about this document? Email privacy@zenska.ph. This document is provided for transparency and does not constitute legal advice.