ZDrive

ZDrive

Privacy Policy

Last updated: July 28, 2026

This Privacy Policy explains how ZennialHub ("we", "us", "our"), the developer and operator of the ZDrive web application and the website at zennialhub.in, collects, uses, discloses, stores, and protects information when you use ZDrive at zhdrive.in(together, the "Service").

This Policy is published in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and the Digital Personal Data Protection Act, 2023 ("DPDP Act") of India. Under the DPDP Act, ZennialHub acts as the Data Fiduciary and you, as the user of the Service, are the Data Principal.

1. Information We Collect

Account information. When you register, we collect your email address, name, and a password (stored only as a salted, irreversible hash - we never store or have access to your plain-text password).

Profile information. You may optionally upload a profile avatar image.

Files you upload. We store the files you choose to upload, along with metadata about them (file name, size, file type, upload date, and folder location). Files are encrypted at rest on our storage infrastructure.

Two-factor authentication data. If you enable two-factor authentication, we store your authenticator secret and one-way hashes of your recovery codes - never the recovery codes themselves in readable form once you've saved them.

Session data. If you sign in, we keep a record of each active session (device/browser type, IP address, and sign-in time) so you can view and remotely sign out your own sessions from account settings.

Subscription and billing information. If you subscribe to a paid plan, your subscription is managed and payment is processed through Razorpay, our payment gateway. Razorpay's checkout runs in a secure hosted frame and receives your payment details directly - we do not directly store your full card, UPI, or bank account details ourselves.

Partner-provisioned accounts. If your account was created on your behalf by one of our reseller or ISP partners (see Section 4), we also record which partner tenant your account belongs to, so that partner's plan, suspension, and usage actions on your account can be attributed and applied correctly.

Device and diagnostic information. To find and fix crashes and errors, the app may collect technical diagnostic data such as device model, operating system version, app version, IP address, and crash/error logs.

Usage and log information. We log basic technical information about how the Service is used (such as login timestamps, feature usage, and error events) for security monitoring, abuse prevention, and to maintain and improve the Service.

2. Legal Basis and Consent

We process your personal data on the basis of the consent you provide at the time of account creation and continued use of the Service, and, where applicable, for the performance of our contract with you (providing the Service you've signed up for) and compliance with our legal obligations under Indian law. You may withdraw consent at any time by deleting your account, subject to any information we are legally required to retain (see Section 6).

3. How We Use Your Information

  • To create, authenticate, and maintain your account
  • To let you enable and manage two-factor authentication and your active sessions
  • To store, encrypt, retrieve, and let you share the files you upload
  • To scan uploads for malware and keep the Service secure
  • To process and manage your subscription and billing
  • To send account-related emails (such as email verification and password reset)
  • To diagnose, debug, and fix technical problems and crashes
  • To maintain the security of the Service, including detecting, investigating, and preventing fraud, abuse, and unauthorized access
  • To comply with applicable Indian law, including responding to lawful requests from government or regulatory authorities

4. How We Share Your Information

We do not sell your personal information. We share information only with:

  • Service providers ("Data Processors") who help us operate the Service under contractual confidentiality obligations, currently including our payment gateway (Razorpay, which directly receives your payment instrument details to process a paid subscription), our malware-scanning provider (VirusTotal, which receives a hash of each uploaded file and, if that hash isn't already known to VirusTotal, the file content itself), a crash-reporting/diagnostics provider (Sentry), and a privacy-focused, cookieless web analytics provider (Cloudflare Web Analytics, which sees aggregate page-view data such as the pages visited and referring site, not tied to your account or a persistent identifier).
  • Your reseller/ISP partner, only if your account was provisioned by one of our partners as part of their own bundled product or service. That partner can access account-level information about you - your email, name, plan, account status, and storage usage - through our partner API, in order to manage the plan and billing arrangement you have with them. Your partner never receives the contents of your files.
  • Other users, only when you choose to share a file - sharing a file with someone (via a share link) makes that specific file accessible to whoever holds that link, until you revoke it.
  • Law enforcement, courts, or regulators, only where required or permitted by applicable Indian law, including under a lawful order, summons, or direction from a competent authority.

5. Cross-Border Data Transfer

Our infrastructure providers may process or store data on servers located outside India. Where personal data is transferred outside India, we take reasonable steps to ensure it continues to receive a standard of protection consistent with this Policy and applicable Indian law. As of the date of this Policy, the DPDP Act does not restrict transfers except to countries specifically notified by the Government of India from time to time.

6. Data Storage, Security, and Retention

Your files are encrypted at rest on our servers, and we apply "reasonable security practices and procedures" as required under the SPDI Rules, including hashed passwords, encrypted storage, and access-token-based authentication. Optional two-factor authentication and self-service session management (viewing and remotely signing out your own active sessions) are available from account settings. No method of storage or transmission is 100% secure, and we cannot guarantee absolute security. Our full vulnerability-disclosure process is published at /security-policy.

We retain your account information and files for as long as your account is active. Deleted files are moved to a trash area before permanent deletion. Certain technical and security logs may be retained for a longer period as required for security, audit, or legal-compliance purposes, consistent with directions issued by India's Computer Emergency Response Team (CERT-In). You may permanently delete your account and associated data at any time from within the app's Settings; we take reasonable steps, including automatic retries, to ensure that deletion is actually completed rather than only attempted.

Security incident reporting. In the event of a data breach or cybersecurity incident affecting your personal data, we will take reasonable steps to notify affected users and, where legally required, report the incident to CERT-In and/or the Data Protection Board of India within the timelines prescribed by applicable law.

7. Your Rights as a Data Principal

  • Access and correction: you can view and update your profile information within the app.
  • Erasure:you can delete individual files, or permanently delete your entire account and associated personal data, from the app's Settings screen.
  • Revoking shared files: you can revoke access to any file you've previously shared at any time.
  • Revoking sessions: you can view and remotely sign out any of your own active sessions at any time.
  • Grievance redressal: you may raise a grievance regarding the processing of your personal data with our Grievance Officer (Section 9).
  • Nomination: you may nominate another individual to exercise your rights under the DPDP Act in the event of your death or incapacity, by writing to our Grievance Officer.

If you are located outside India in a region with additional data protection rights (such as the EU/EEA or California), you may have further rights available to you under those laws; contact us using the details below to exercise them.

8. Children's Data

Under the DPDP Act, a "child" is any individual under the age of 18. The Service is not intended for use by children, and we do not knowingly collect personal data from children without verifiable parental or guardian consent. If we become aware that we have collected personal data from a child without such consent, we will take steps to delete it promptly.

9. Grievance Officer

In accordance with the Information Technology Act, 2000, the rules made thereunder, and the DPDP Act, 2023, the Grievance Officer for ZennialHub / ZDrive is:

Name: Vivek Jaiswar
Designation: Founder
Email: info@zennialhub.in
Address: ZennialHub Technologies, 613, 6th floor, Shivai Plaza, Gamdevi, Marol, Andheri East, Mumbai, Maharashtra 400059

The Grievance Officer will acknowledge complaints and grievances within the timelines prescribed under applicable Indian law.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will update the "Last updated" date above when we do. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.

11. Contact Us

If you have questions about this Privacy Policy or how your data is handled, contact us at info@zennialhub.in.

This Policy is provided as a general compliance framework and does not constitute legal advice. ZennialHub should have this Policy reviewed by a qualified Indian legal professional before wide public release, particularly to finalize the Grievance Officer's identity and registered address, and to account for any DPDP Act rules notified by the Government of India after this Policy's last-updated date.