ZENLIT PRIVACY POLICY
Effective Date: March 21st, 2026
Version 1.2
Zenlit Lab Inc., its affiliates, and its subsidiaries (collectively, the "Company", "Zenlit", "we" or "us") is a wholly owned subsidiary of Telenav, Inc. ("Telenav"). We own, operate, and provide the mobile application "Zenlit -- Earn While You Drive" including all associated features, backend systems, reward mechanisms, social functions, referral programs, marketplace operations (including the Zexchange marketplace for gift card, Zenlit raffle and other rewards), blockchain integrations, fraud prevention systems, etc., (collectively, the "Zenlit Platform").
We understand that you value your privacy and that you may have questions about how we use the data collected through our Zenlit Platform. This Privacy Policy applies to the data we obtain directly and indirectly about yourself in the course of providing access to and use of the Zenlit Platform. By using or accessing the Zenlit Platform, you (a) accept how we may collect, use, disclose, and otherwise handle your information, as we specifically describe in this Privacy Policy, and (b) represent and warrant that you have the right, authority, and capacity to accept these conditions.
By using or accessing the Zenlit Platform, you also accept the Terms and Conditions. You may not access or use the Zenlit Platform if you are under the age of 18. If you do not agree with all of the conditions of this Privacy Policy or Terms and Conditions, do not access and/or use the Zenlit Platform.
[The Zenlit Platform is currently available for use exclusively within the United States. Geographic eligibility is verified through location data, and users attempting to access the Platform from outside supported regions will be restricted.]{.underline}
In connection with the provision of the Zenlit Platform, we may collect and process information related to you. This includes, but is not limited to, the following categories of data:
Contact and identification information, such as full name, email address, phone number, authentication credentials, and account username. Where social login functionality is used (e.g., Apple Sign-In, Google), we may receive basic profile metadata made available by the authentication provider, but we do not access passwords or unrelated third-party account content.
Telematics and driving behavior data, including precise geolocation data, GPS coordinates, trip start and end timestamps, route history, trip duration, speed metrics, acceleration patterns, braking intensity, sharp turn detection, late-night driving intervals, and other indicators.This data is used to calculate the ZenScore and determine "Safe Miles" through automated deduction logic.
Device and technical data, such as device model, operating system version, app version, Bluetooth connectivity status, motion sensor data (accelerometer, gyroscope), network provider metadata, connection type, pseudonymized device identifiers, IP address, session logs, app usage analytics, crash data, and diagnostic logs for app stability monitoring.
Health and fitness-related sensor data, used exclusively for automatic trip detection and driving behavior analysis (e.g., motion and activity recognition to determine when a trip begins and ends).
Location data. We collect information about your physical location from your device, including background location access when trips are being recorded. This data is necessary for trip recording, Safe Miles calculation, geographic eligibility verification, and crash detection functionality.
Referral program data, including referral codes, linkage between referring and referred accounts, completion of qualifying trip thresholds, reward eligibility status, timestamps of referral acceptance, and device-based verification markers to prevent self-referral, device farming, and multiple redemptions of referral codes on the same device.
Community and social features data (zShare, zROOM, myHub), including user-generated content (posts, comments, uploaded images), tags and categories applied to posts (e.g., "general," "safety tips," "need help," "official announcements"), engagement metrics, activity feeds and interaction history, content moderation logs, and eventual notification data related to community interactions.
Token, wallet, and blockchain data, including ZNLT points (off-chain, stored in Zenlit cloud), ZNLT token balances, token distribution records, monthly smart contract distribution logs, wallet addresses voluntarily linked by users (non-custodial wallets with 12-word recovery phrases), reward eligibility status, token earning history, and ZNLT token gift transactions between users within the community features.
Marketplace and purchase data (Zexchange), including purchase records, redemption logs (such as Visa gift card redemptions and Zenlit raffle participation entries), token balances and transaction history, vendor interactions and product selection data, commission allocation records associated with token buyback mechanisms, in-app purchase data related to the token purchase feature, and related accounting data.
Challenges and gamification data, including challenge enrollment and participation records, challenge progress and completion data, token rewards earned through challenges, and driving habit data analyzed for tailoring challenges to individual users.
Crash detection and emergency data, including sensor data indicative of a crash event (sudden deceleration, impact patterns), location data at the time of the detected event, emergency contact information provided by the user, and alerts sent to designated emergency contacts.
Fraud investigation and identity verification data, including full name and residential address for identity confirmation, phone number verification, government-issued identity documents (such as a driver's license or state ID that validates the user's address), device-level identifiers used to detect patterns (multiple accounts per device, device-level suspension records, device farming indicators), and correspondence related to account disputes.
Insurance integration data, such as name, date of birth, and vehicle information, which may be transmitted to third-party insurance providers when a user voluntarily initiates an insurance quote flow within the Platform.
Leaderboard and competitive features data, including comparative driving performance data, rankings, and user profile photo, which may be processed as the Platform introduces competitive reward structures.
Raffle draw data, including raffle draw entries and the number of entries held per draw, the date and timestamp of each entry, the raffle draw identifier and prize tier, entry source (e.g., ZNLT tokens or points redeemed for entries), draw outcome records (including winner selection logs generated through the Platform's randomized draw mechanism), prize fulfillment data for winners (such as delivery address or digital delivery details where applicable), and raffle participation history. Where a user is selected as a winner, limited identification data (such as profile photos, first name and last initial) may be used for winner announcement purposes within the Platform.
Blockchain transactions involving ZNLT tokens are inherently public and immutable. Zenlit does not store users' private keys or recovery phrases and does not operate custodial wallet services. Users are solely responsible for the security of their wallet credentials.
We may obtain your personal data:
a) Directly from you, i.e., when (i) you register an account on the Zenlit Platform, (ii) you or other users use or access the Zenlit Platform, (iii) you directly provide us with information (e.g., by filling out a profile, creating community posts, uploading images, submitting identity verification documents, or providing emergency contact details), (iv) you participate in driving activities and the Platform's telematics monitoring records your driving behavior, (v) you engage in the referral program, driving challenges, or marketplace transactions, or (vi) you contact us through various customer support channels.
b) Automatically from your device, including telematics data generated through device sensors (GPS, accelerometer, gyroscope), device identifiers, technical diagnostics, crash data, Bluetooth connectivity information, health and fitness sensor data for trip detection, and app usage analytics collected through software development kits (SDKs) and standard mobile analytics tools.
c) From the blockchain, where publicly available transaction records related to ZNLT token distributions, transfers, and wallet activity may be referenced for ecosystem administration and token supply monitoring.
d) From third-party sources, such as authentication providers (Apple, Google) when you use social login, insurance partners when you initiate an insurance integration, and analytics or attribution providers that support our platform operations.
By choosing to use the Zenlit Platform, you consent to the collection, processing, and use of personal data related to your driving behavior, device usage, community participation, and token-related activities. This data will be used for the purposes described in this Privacy Policy.
We may use the information we obtain in connection with the following activities and based on the following legal grounds:
3.1 ZenScore Calculation and Safe Miles Determination
We collect and process telematics data (e.g., trip history, driving behavior, speed, braking, acceleration, distraction, and late-night driving patterns) through our AI-driven ZenScore engine to calculate a dynamic safety score based on the last 30 days of driving activity. This includes applying automated deduction logic to determine Safe Miles for each trip and computing the resulting token reward amounts.
Legal ground: Performing services you have requested on behalf of the business-- including maintaining and servicing accounts, providing the core driving reward service, and processing transactions;
This processing involves precise geolocation data, which constitutes sensitive personal information under CPRA. This data is used strictly as necessary to perform the services reasonably expected by the consumer (i.e., telematics-based driving analysis and reward calculation). Consumers have the right to limit the use of sensitive personal information as described in Section 12.
3.2 Token Distribution and Blockchain Operations
We process your token-related data to administer ZNLT point allocation, enforce the 1-month lock-up period before tokens become transferable, execute monthly smart contract distributions on Base L2 / Ethereum, monitor halving thresholds (rewards halve every 0.5 billion tokens distributed), and manage the overall token ecosystem, including ZNLT gift transactions between community members.
Legal ground: Performing services you have requested on behalf of the business -- including maintaining and servicing accounts, providing the core driving reward service, and processing transactions;
3.3 Marketplace Operations (Zexchange)
We process purchase records, redemption logs, token balances, and vendor interaction data to operate the Zexchange marketplace, facilitate gift card redemptions (including Visa gift cards), process in-app purchases, administer token buyback mechanisms ( part of marketplace commissions flow back to the community), and maintain related accounting records.
With respect to Zenlit Raffle draws specifically: the raffle feature allows users to exchange ZNLT tokens or points for raffle entries, granting a chance to win prizes (including cash-equivalent gift cards and other rewards visible within the Platform). Each draw operates over a defined period, during which users may acquire and hold multiple entries. At the close of each draw period, a winner is selected through the Platform's automated random draw mechanism. The number of entries a user holds influences the statistical probability of selection but does not guarantee a win. Upon being selected as a winner, the user is notified through the Platform and may be required to provide additional details for prize fulfillment. Raffle participation data, entry records, and draw outcome logs are retained as part of the Platform's reward administration records.
Legal ground: Performing services you have requested on behalf of the business -- including processing and fulfilling consumer transactions, maintaining accounts, and providing customer service; Undertaking activities to verify or maintain the quality or safety of a service.
3.4 Community Features and Social Interactions (zShare, zROOM, myHub)
We process user-generated content, engagement metrics, activity feeds, and moderation data to operate the zShare social platform, display content in the zROOM community feed, maintain personalized activity feeds in myHub, facilitate ZNLT token gifting between users, enforce community guidelines, and moderate reported content. Community activity is visible to other users as part of the social functionality of the Platform.
Legal ground Performing services you have requested on behalf of the business -- including maintaining and servicing accounts, providing the community features, and processing user interactions; Helping to ensure security and integrity-- content moderation and enforcement of community guidelines; Short-term, transient use -- displaying personalized activity feeds and engagement notifications during the current session.
3.5 Referral Program Administration
We process referral codes, account linkages, qualifying trip thresholds, and device-based verification markers to administer referral rewards, verify eligibility (referred persons must complete 3 trips), and prevent abuse including self-referral and multiple referral code redemptions on the same device.
Legal ground: Performing services you have requested on behalf of the business -- including processing transactions and maintaining referral reward accounts; Helping to ensure security and integrity-- preventing referral fraud and abuse; Detecting security incidents and protecting against malicious, deceptive, fraudulent, or illegal activity.
3.6 Driving Challenges
We process challenge enrollment, progress, completion data, and driving habit information to administer driving challenges tailored to individual users, track challenge milestones, and distribute token rewards earned through challenge completion.
Legal ground: Performing services you have requested on behalf of the business -- including providing the challenge features and processing associated token rewards; Undertaking internal research for technological development and demonstration -- analyzing driving habits to improve challenge personalization.
Challenge personalization may involve analysis of precise geolocation data (sensitive personal information under CPRA). This use is limited to what is necessary to perform the services reasonably expected.
3.7 Fraud Prevention and Platform Integrity
We use technical and behavioral data to detect, prevent, and respond to fraud, unauthorized access, and other deceptive or abusive conduct. This includes: preventing abuse of the reward system (including detection of simulated trips and GPS spoofing); enforcing account limits (maximum of 2 accounts per device); preventing self-referral schemes and device farming patterns; enforcing the restriction that referral codes cannot be used more than once per device; detecting behavioral anomalies (abnormal trip durations, unrealistic mileage patterns, GPS inconsistencies, referral loops); verifying geographic eligibility (the Platform is available only in the United States); and suspending or restricting accounts and devices pending investigation.
Legal ground: Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and prosecuting those responsible for that activity; Helping to ensure security and integrity to the extent the use of the consumer's personal information is reasonably necessary and proportionate for these purposes; Debugging to identify and repair errors that impair existing intended functionality; Undertaking activities to verify or maintain the quality or safety of a service;
Fraud detection may process precise geolocation data and government-issued identification information (sensitive personal information under CPRA). Use of such data for fraud prevention is permitted as reasonably necessary and proportionate to detect security incidents and protect against fraudulent activity.
3.8 Identity Verification and Dispute Resolution
In cases of suspected fraud or Terms and Conditions violations, we may process identity verification data including government-issued identification documents (driver's license, state ID), residential address confirmation, and correspondence related to account disputes. Users who dispute a suspension are asked to provide this data within 7 days; failure to do so may result in permanent account closure and forfeiture of all tokens.
Legal ground: Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity; Performing services on behalf of the business-- including resolving consumer disputes and maintaining account integrity; Exercising or defending legal claims.
Government-issued identification numbers (driver's license, state ID) constitute sensitive personal information under CPRA and this is collected only when necessary for identity verification in fraud and dispute contexts, and its use is limited to what is reasonably necessary for these purposes.
3.9 Crash Detection and Emergency Alerting
We process sensor data indicative of crash events (sudden deceleration, impact patterns), location data at the time of the detected event, and emergency contact information to provide crash detection alerts and notify designated emergency contacts.
Legal ground: Performing services you have requested on behalf of the business -- providing the crash detection and emergency alert features requested by the consumer; Helping to ensure security and integrity-- protecting the physical safety of the consumer.
This processing involves precise geolocation data. The use is strictly limited to performing the emergency alerting service reasonably expected by the consumer and is necessary to protect the life or physical safety of the consumer.
3.10 Push Notifications and Communications
Throughout your use of the Zenlit Platform, you may receive a variety of notifications and communications through the app and/or via push notifications. These include: notifications upon successful registration and app setup; trip completion notifications and their impact on your ZenScore; challenge updates and token opportunity alerts; community interaction notifications (when someone interacts with your posts); and system updates and new feature announcements. Notifications are configurable in settings so you stay informed without feeling overwhelmed.
Legal ground: Performing services you have requested on behalf of the business -- providing essential service communications related to the consumer's account and participation in the Platform (trip summaries, token distributions, challenge updates); Advancing the commercial interests of the business-- for non-essential promotional communications, including new feature announcements and engagement-related notifications. Consumers may opt out of non-essential notifications through app settings at any time.
3.11 Insurance Integration
Where you voluntarily initiate an insurance quote flow within the Platform, we process limited pre-fill information (such as name, date of birth, and vehicle information) to transmit to the insurance provider. Once redirected to the insurer's environment, the insurer acts as an independent data controller and governs underwriting, payment processing, telematics-based premium adjustments, and policy issuance in accordance with its own privacy documentation.
Legal ground: Performing services you have requested on behalf of the business -- facilitating the insurance integration service at the consumer's request. Data is shared with the insurance provider as a "service provider" or "third party" depending on the nature of the provider's independent processing. The consumer voluntarily initiates this data sharing.
3.12 Analytics, Platform Improvement, and Diagnostics
We collect and analyze data about how you use the Zenlit Platform to continuously improve the user experience, interface design, service quality, system performance, and security of our services. This may include usage patterns, feature engagement, technical diagnostics, crash data, and navigation behavior. We may use aggregated or pseudonymized data for analytics, statistical analysis, and product development.
Legal ground: Debugging to identify and repair errors that impair existing intended functionality; Undertaking internal research for technological development and demonstration; Undertaking activities to verify or maintain the quality or safety of a service owned or controlled by the business.
3.13 Legal Compliance, Auditing, and Law Enforcement Cooperation
We process your personal data to support internal and external audits, respond to requests from regulators or law enforcement, comply with applicable laws (including subpoenas or court orders), enforce the Terms and Conditions, and protect our legal rights or the safety of individuals.
Legal ground: Auditing related to counting ad impressions to unique visitors, verifying positioning and quality of ad impressions, and auditing compliance with specifications and other standards; Helping to ensure security and integrity; Complying with federal, state, or local laws, and cooperating with law enforcement agencies concerning conduct or activity reasonably and in good faith believed to violate federal, state, or local law; Exercising or defending legal claims.
3.14 Establishing or Defending Legal Claims
We process data necessary to investigate, establish, exercise, or defend against legal claims or allegations that may arise during the course of business.
Legal ground: Exercising or defending legal claims; This purpose is recognized as a permissible use under CPRA implementing regulations, including for sensitive personal information where such use is reasonably necessary and proportionate.
3.15 Training of Algorithms and Machine Learning
We may use personal data -- preferably anonymized or pseudonymized -- to train, test, or improve machine learning and algorithmic systems, such as those used for ZenScore calculation, driving behavior analysis, trip detection, fraud detection, or challenge personalization. This supports the development of fairer, more accurate, and efficient automated processes.
Legal ground: Undertaking internal research for technological development and demonstration; Undertaking activities to verify or maintain the quality or safety of a service owned or controlled by the business. Where personal information is used (rather than anonymized data), processing is limited to what is reasonably necessary for these purposes.
Where algorithm training involves precise geolocation data or other sensitive personal information, Zenlit will use anonymized or pseudonymized data to the greatest extent practicable. Consumers retain the right to limit the use of their sensitive personal information as described in Section 12.
3.16 Service Personalization
We process interaction and usage data to personalize the user experience, including the type and timing of notifications, driving challenge recommendations, community feed curation, and marketplace display. This helps ensure communications are relevant and the Platform adapts to your needs.
Legal ground: Short-term, transient use, including, but not limited to, the contextual customization of content displayed as part of the same interaction; Performing services on behalf of the business-- providing a personalized user experience as part of the services requested. This processing does not involve cross-context behavioral advertising and does not constitute "sharing" of personal information as defined under CPRA.
3.17 Business Continuity and Disaster Recovery
We store and back up personal data to maintain service continuity, enable system recovery, and restore access in case of outages, cyber incidents, or technical failures.
Legal ground: Helping to ensure security and integrity to the extent the use of the consumer's personal information is reasonably necessary and proportionate for these purposes; Undertaking activities to verify or maintain the quality or safety of a service owned or controlled by the business.
3.18 Raffle Draw Operations
We process raffle participation data to operate the Zenlit raffle draw feature available within the Zexchange marketplace. The raffle draw mechanism functions as follows: users may exchange ZNLT tokens or redeemable points for one or more entries into an active raffle draw. Each active draw has a defined entry period, a prize tier (e.g., a cash-equivalent gift card of a specified value), and a maximum or open-ended number of total entries. At the conclusion of the entry period, the Platform's randomized draw algorithm selects a winner from among all valid entry holders. The probability of winning is proportional to the number of entries held. Once a winner is selected, the Platform processes the following data: (i) verification of the winning entry and its associated account; (ii) notification to the winner through in-app messaging and/or push notification; (iii) collection of any prize fulfillment information required to deliver the prize (such as a delivery address or digital redemption details); and (iv) recording of the draw outcome in the Platform's reward administration logs. Non-winning entries are recorded for historical and audit purposes. Raffle draws are administered by Zenlit and, where prize fulfillment involves third-party gift card vendors or logistics partners, limited data may be shared with those vendors solely for fulfillment purposes.
Legal ground: Performing services you have requested on behalf of the business --- including processing and fulfilling raffle transactions, maintaining reward accounts, and providing the raffle feature as part of the Zexchange marketplace; Undertaking activities to verify or maintain the quality or safety of a service --- ensuring the integrity of the randomized draw mechanism and audit logging of all draw outcomes.
The personal and technical data we collect is reasonably necessary to (i) perform the services you have requested and maintain your account on the Zenlit Platform, (ii) detect security incidents, protect against fraudulent or illegal activity, and ensure the security and integrity of the Platform, (iii) debug, identify, and repair errors that impair existing functionality, (iv) undertake internal research for technological development and improve, verify, or maintain the quality and safety of our services, and (v) comply with applicable federal, state, or local laws and cooperate with law enforcement as required as described in this Privacy Policy.
If you choose not to provide certain required information, we may not be able to:
create or maintain your account on the Zenlit Platform; calculate your ZenScore or distribute ZNLT token rewards; enroll you in driving challenges or the referral program; process marketplace transactions or gift card redemptions; enable core app features or functionality that rely on device sensors, location data, or mobile permissions; comply with regulatory requirements such as identity verification or fraud prevention; provide crash detection and emergency alerting services, or participate in raffle draws or redeem raffle entries;
In cases where optional data is requested (e.g., for push notification preferences, community participation, or challenge enrollment), we will make it clear that the information is voluntary, and your refusal will not affect access to core driving and reward services.
We may share the information we obtain from you with our affiliates and eventual third parties in connection with the following activities:
With your consent: for any purpose to which you expressly consent, such as initiating an insurance quote flow or enabling optional data-sharing features.
Business Transactions: to facilitate a merger, acquisition, bankruptcy, dissolution, reorganization, sale of some or all of our assets, financing, or a similar transaction or proceeding, or steps in contemplation of such activities (e.g., due diligence). You will be informed of any material changes to how your data is processed.
Legitimate Business Activities: to conduct any other legitimate business activities not otherwise prohibited by law.
Legal Obligation: in addition, we reserve the right to access, read, preserve, and disclose any information as we reasonably believe is necessary to: (i) satisfy any applicable law, regulation, legal process, subpoena, or governmental request; (ii) investigate potential violations of your agreement(s) with us; (iii) detect, prevent, or otherwise address fraud, security, or technical issues; (iv) cooperate with law enforcement authorities; (v) respond to user support requests; or (vi) protect our, our users', or the public's rights, property, or safety.
Service Providers: the third parties with whom we may share information include cloud hosting and storage providers, analytics and attribution providers, fraud detection services, customer support platforms, blockchain infrastructure services (Base L2 / Ethereum), marketplace fulfillment and gift card vendors, push notification delivery services, and other business partners. These service providers are contractually obligated to process your information only as necessary to provide the services agreed and to maintain appropriate confidentiality and security safeguards.
Insurance Providers: where you voluntarily initiate insurance integrations, limited data may be shared for quote pre-fill purposes. The insurance provider thereafter acts independently as data controller.
Blockchain Networks: blockchain transactions involving ZNLT tokens are publicly recorded on the Base L2 / Ethereum distributed ledgers and cannot be altered or deleted. Zenlit does not control public blockchain explorers or third-party indexing services. Wallet addresses associated with token transactions are visible on the public blockchain.
Community Visibility: content posted in zROOM (community feed) and associated engagement metrics (likes, comments, ZNLT gifts) are visible to other Platform users. Users should exercise discretion when sharing personal information in community posts.
Raffle Prize Fulfillment: where a user is selected as a winner in a Zenlit raffle draw, limited identification and fulfillment data (such as account details and, where required, delivery or redemption information) may be shared with third-party gift card vendors or prize fulfillment partners solely for the purpose of delivering the prize. Winner first name and last initial may be published within the Platform for transparency and community announcement purposes. No additional personal information is disclosed publicly without the winner's explicit consent.
[Zenlit does not sell personal data.]{.underline}
The Zenlit Platform may contain links to or integrations with third-party websites, services, or platforms, including insurance providers, gift card vendors, blockchain explorers, and/or other service partners. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party websites or services. By including a link to a third-party website, we do not endorse or recommend any products or services offered or information contained at the third-party website. Such third parties may have privacy notices different from ours. If you decide to visit a third-party website via a link contained on the Zenlit Platform, please ensure that you read their privacy notice, as we are not responsible for these third-party sites.
We maintain high physical, electronic, and procedural safeguards to preserve the integrity and security of the collected information. These measures include inter alia measures as: (a) Encryption of data in transit (TLS/SSL) and at ress, (b) Role-based access controls limiting internal access to personal data; (c) Logging and monitoring systems for security event detection; (d) Fraud detection algorithms and behavioral anomaly analysis; (e) Smart contract audits by qualified third parties; (f) Secure handling and limited retention of identity verification documents; (g) Regular security assessments and vulnerability testing;
No system can guarantee absolute security. Users are responsible for safeguarding their login credentials, wallet recovery phrases (12-word seed phrases), and device access.
[Zenlit will never ask users for their recovery phrases.]{.underline} In the event of a data breach, we will notify you in accordance with the laws applicable in the state and/or states where such breach occurred.
You may request to review your personal information in our records by contacting us at any time, as provided in the "Contact Us" section below. If you believe that the information is incomplete or inaccurate, you can request that we correct it. We will respond to your requests within a reasonable timeframe.
Accounts that are permanently closed due to Terms and Conditions violations (including fraud) will result in forfeiture of all tokens and points. Device-level restrictions associated with terminated accounts may continue to apply.
Please note that rights do not extend to immutable blockchain records or data required to prevent fraud, enforce token supply integrity, comply with financial reporting obligations, or maintain device-level restriction records necessary for Platform security.
Zenlit is committed to protecting your privacy and responsibly managing your personal information. We retain your information only as long as necessary to fulfill the purposes outlined in this Privacy Policy, maintain active accounts or relationships, and comply with applicable legal and regulatory requirements. We prioritize data minimization and offer you the right to access and delete your information. Specific retention practices include:
Account Data: Retained for the duration of the active account and for a reasonable period thereafter for legal and compliance purposes, but not more than 3 (three) years.
Telematics and Driving Data: Retained for ZenScore recalculation (rolling 30-day window for active scoring), audit purposes, and regulatory compliance. Historical trip data may be retained in aggregated or anonymized form for research, statistical analysis, and product development, provided it cannot be used to re-identify any individual.
Fraud Investigation Data: Retained until resolution of the investigation and expiration of applicable limitation periods. Device-level suspension records are retained to enforce ongoing device restrictions.
Community Content: Remains visible until deleted by the user or removed under policy enforcement.
Identity Verification Documents: Retained only for the duration necessary to complete the verification process and resolve the relevant dispute, after which they are securely deleted unless retention is required by law.
Blockchain Transaction Records: Cannot be deleted due to their immutable nature.
Token and Reward Data: Retained for the duration necessary to administer the token ecosystem, including lock-up periods, halving enforcement, and financial reporting.
Raffle Draw Data: Raffle entry records, draw participation logs, and draw outcome records (including winner selection logs) are retained for a minimum of 3 (three) years from the date of the relevant draw, for audit, dispute resolution, and regulatory compliance purposes. Prize fulfillment data (such as winner delivery details) is retained only for the period necessary to complete fulfillment and resolve any disputes, after which it is securely deleted. Non-winning entry records are retained in anonymized or aggregated form beyond this period for statistical and product improvement purposes.
Push Notification Data: Device tokens are retained as long as notifications are enabled; interaction data is retained for analytics purposes and periodically purged.
Crash Detection Data: Retained for a limited period to support follow-up and potential insurance or legal processes.
We do not target the Zenlit Platform to anyone under age 18. The App carries an 18+ age rating on the App Store. If you are under the age of 18, do not access or use the Zenlit Platform and do not enter any personally identifiable information into the Zenlit Platform. If you are a parent or a guardian who has discovered that your child under age 18 has submitted his or her personally identifiable information to us without your permission or consent, we will make reasonable efforts to remove the information from our database, at your written request. To request the removal of your child's information, please contact us as described in the "Contact Us" section below and include in your message your child's name and the email address that your child submitted. Accounts identified as belonging to minors may be immediately terminated.
We are a wholly owned subsidiary of Telenav, Inc. ("Telenav"). Zenlit operates as a telematics-based driving rewards platform. The ZNLT token is issued as an ERC-20 token on Ethereum, with operations on Base L2 for scalability and lower transaction costs. The total fixed supply is 100,000,000,000 ZNLT.
Activities such as blockchain infrastructure, smart contract management, marketplace fulfillment, and gift card vendor operations may involve third-party service providers who are contractually obligated to maintain the confidentiality and security of your information.
Where insurance integration is offered, auto insurance quotes may be facilitated through third-party insurance providers who act as independent data controllers for underwriting, premium calculation, and policy issuance.
12.1 Your Rights Under CPRA
You may have specific rights regarding your personal information under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. These rights, subject to certain exceptions, include:
Right to Know / Right to Access. You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you over the past twelve months, the sources from which it was collected, the business or commercial purpose for collecting it, and the categories of third parties to whom we disclosed it.
Right to Delete. You can request the deletion of personal information we have collected from you. Upon verifying your request, we will delete your personal information and direct our service providers to do the same, unless an exception applies --- such as where the information is necessary to complete a transaction, detect fraud, comply with a legal obligation, exercise or defend legal claims, or where immutable blockchain records of ZNLT token transactions are concerned.
Right to Correct. You have the right to request correction of inaccurate personal information we maintain about you.
Right to Opt-Out of Sale or Sharing. You have the right to direct us not to sell or share your personal information with third parties. Zenlit does not sell personal information and does not share personal information for cross-context behavioral advertising. Should our practices change, we will provide a clear "Do Not Sell or Share My Personal Information" mechanism as required by law.
Right to Limit Use of Sensitive Personal Information. You have the right to direct us to limit the use of your sensitive personal information to what is necessary to perform the services you have requested. The sensitive personal information we process includes precise geolocation data (used for driving analysis, ZenScore calculation, crash detection, geographic eligibility, and fraud prevention) and government-issued identification numbers (collected only during fraud investigation and identity verification). Zenlit uses sensitive personal information only as reasonably necessary to deliver the services described in this Policy. To exercise this right, contact us at privacy@telenav.com.
Right to Non-Discrimination. Zenlit will not deny you services, charge you different rates, or provide a different level of service as a result of you exercising your privacy rights. Please note, however, that certain services (such as ZenScore calculation and token distribution) require specific personal information, and limiting or deleting such data may affect our ability to provide those services.
Right to Information About Automated Decision-Making. To the extent required by applicable regulations, you may request meaningful information about how our automated decision-making processes work, including ZenScore calculation, Safe Miles deduction logic, and fraud detection systems that may trigger account suspension. You may also contest automated decisions that materially affect your account.
12.2 How to Exercise Your Rights
To submit a request, you may contact us by email at privacy@telenav.com, use the data-deletion controls at zenlit.com, or send a written request to the address in the "Contact Us" section. You may also authorize an agent to submit a request on your behalf; in that case, we may require written proof of authorization and may verify your identity directly.
12.3 Verification and Response
To protect your privacy, we will verify your identity before fulfilling your request. This may involve matching the information in your request against our records. We will respond within forty-five days of receipt. If additional time is needed (up to forty-five additional days), we will notify you in writing with an explanation.
12.4 Service Providers
Zenlit engages service providers and contractors who are contractually prohibited from using personal information for any purpose other than performing the services specified in their agreements, and who are required to comply with applicable privacy law to the same extent as Zenlit.
12.5 Financial Incentive Program
The Zenlit reward program, in which users earn ZNLT points and tokens for safe driving, referrals, and community engagement, requires the collection of personal information including telematics and geolocation data. You may opt out at any time by deleting your account. The value of the data collected is reasonably related to the value of the rewards provided, as token allocation is calculated directly from Safe Miles derived from your driving data.
Participation in Zenlit raffle draws also constitutes a financial incentive program within the meaning of applicable law. Users exchange ZNLT tokens or points --- earned through personal data sharing (including driving behavior and telematics data) --- for raffle entries that confer a chance to win prizes. The value of the personal data collected in connection with earning the tokens or points used for raffle entry is reasonably related to the prize value offered in each draw. Users may decline to participate in raffle draws at any time; declining to enter a draw does not affect access to other Platform services or the accumulation of ZNLT rewards through driving.
We host the information we collect from the Zenlit Platform in the United States. The Zenlit Platform is currently available for use only within the United States. If you are using or accessing the Zenlit Platform from outside the United States or any other region with laws or regulations governing personal data collection, use, and disclosure that differ from United States laws, please be advised that through your use of the Zenlit Platform, which is governed by U.S. law, you are transferring information to and from the United States and you consent to that transfer.
Where data is transferred to service providers or infrastructure located outside the United States, Zenlit ensures appropriate safeguards are in place, including standard contractual clauses or other recognized transfer mechanisms as required by applicable law. Blockchain transactions are by nature distributed globally across network nodes and are not confined to any single jurisdiction.
The laws of the State of Delaware and applicable United States law govern all matters arising out of or relating to this Privacy Policy, including, without limitation, interpretation, construction, performance, and enforcement, without giving effect to such state's conflicts of law principles.
You may not transfer or assign any rights and permissions you grant to us hereunder. However, we may transfer or assign those same rights and permissions without restriction, including in connection with a merger, acquisition, or restructuring.
If we decide to sell, buy, merge, or otherwise reorganize our businesses, this may involve us disclosing your information to prospective or actual purchasers and their advisers, or receiving information from sellers and their advisers. In the event of such disclosures of information, we will comply with applicable legal requirements. Personal data will be transferred subject to continued privacy protections, and you will be informed of any material changes to how your data is processed.
ZNLT is a utility token within the Zenlit ecosystem and is designed for use in connection with rewards, marketplace access, and community participation.
Changes to token distribution rules, reward rates, or halving schedules are reviewed through the applicable governance process. Nothing in this Privacy Policy constitutes investment advice. ZNLT is not a security and should not be treated as such.
The Zenlit Platform may use standard mobile analytics tools and software development kits (SDKs) to collect usage data, crash reports, and performance metrics. These technologies help us understand how the Platform is used and improve the user experience.
Zenlit does not use cookies in the traditional web browser sense within the Mobile Application. Where the Platform interacts with web-based services (such as the Zexchange marketplace or insurance provider integrations), standard web tracking technologies of those third parties may apply under their respective privacy policies.
If you'd like to opt out of analytics data collection in our Mobile Application, please contact us at privacy@telenav.com, or adjust your device settings to limit data sharing. Please note that doing so may affect the functionality of certain app features.
We reserve the right at our discretion to change the Privacy Policy at any time. Material changes will be communicated through the Platform (via in-app notification or push notification) prior to taking effect. Any changes will be effective as of the date of publication. Continued use of the Zenlit Platform after changes become effective constitutes acceptance of the updated Policy.
Users are encouraged to review this Policy periodically for any updates.
Please feel free to contact us if you have any questions regarding this Privacy Policy or our practices. You may contact us using the following information: privacy@telenav.com.
If you believe that Zenlit has not adequately addressed your privacy concerns, you may have the right to lodge a complaint with a supervisory authority in your jurisdiction.