Skip to main content

Privacy Policy

Last updated: August 23, 2026

This Privacy Policy explains how Zeckout ("Zeckout," "we," "us," or "our") collects, uses, and protects information when you use our inventory and space management platform (the "Service").

1. Information We Collect

We collect the following categories of information:

  • Account information: name, email address, and authentication details (including Google Sign-In identifiers) provided when you register or are invited to a department.
  • Organizational data: department membership, role, and permissions assigned by your organization's administrators.
  • Operational data: inventory records, checkout and return history, space reservations, maintenance logs, and other data entered by you or your organization while using the Service.
  • Billing information: for paid plans, billing contact details and subscription status. Full payment card data is collected and processed directly by our payment processor, Stripe, and is never stored on our servers.
  • Usage and device data: log data, IP address (truncated for security records), browser type, and general usage patterns collected automatically to operate and secure the Service.

2. How We Use Information

We use the information described above to:

  • Provide, maintain, and improve the Service;
  • Authenticate users and enforce department- and role-based access controls;
  • Send transactional notifications (e.g. checkout confirmations, overdue reminders, approval requests);
  • Process payments and manage subscriptions;
  • Detect, investigate, and prevent fraud, abuse, or security incidents;
  • Respond to support requests and communicate with you about the Service.

We do not sell personal information to third parties.

3. Data Isolation Between Organizations and Departments

Zeckout is architected as a multi-tenant system with server-enforced access controls: each organization's and department's data — including inventory, orders, and user records — is isolated from every other organization and department. Users can only access data belonging to the department(s) they are actively assigned to, unless granted platform-wide administrative access.

4. Educational Records (FERPA)

For customers using Zeckout in an educational context, certain data (such as a student's checkout history) may constitute an "education record" under the Family Educational Rights and Privacy Act (FERPA). Zeckout acts as a service provider under the "school official" exception where applicable, uses education records solely to provide the Service to the institution, and does not use such records for independent purposes. Institutions remain responsible for ensuring their use of the Service complies with their own FERPA obligations and for controlling which staff have access to student data.

5. Sharing of Information

We share information only with:

  • Service providers who process data on our behalf (e.g. hosting, email delivery, payment processing) under confidentiality obligations;
  • Your own organization's administrators, to the extent necessary for them to manage their department;
  • Law enforcement or regulators when required by law or to protect the rights, safety, or property of Zeckout or others;
  • A successor entity in the event of a merger, acquisition, or sale of assets, subject to this Policy.

6. Data Retention

We retain account and operational data for as long as your account is active, and for a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce our agreements. Backups may persist for a limited time after deletion for disaster-recovery purposes.

7. Your Rights and Choices

You may request access to, correction of, or deletion of your personal information by contacting team@zeckout.app or your organization's administrator. Because organizational and inventory records are controlled by your organization, some requests may need to be fulfilled by your organization's administrator rather than Zeckout directly. We will respond to verified requests within a reasonable time.

8. Security

We use industry-standard safeguards, including encrypted connections, role-based access control, and server-side enforcement of tenant isolation, to protect information against unauthorized access, alteration, or disclosure. No system is completely secure, and we cannot guarantee absolute security.

9. Children's Privacy

The Service is intended for use by employees, staff, faculty, and students of our customer organizations in a professional or academic capacity. We do not knowingly collect personal information from children under 13 outside of an institutional relationship with a customer.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the Service or by email. Continued use of the Service after changes take effect constitutes acceptance of the revised Policy.

11. Contact

Questions about this Privacy Policy can be sent to team@zeckout.app.