Privacy Policy
1. Who We Are and Roles
ZIV ("we", "us", "our") is operated by ZIV Live, Inc., a Delaware corporation.
- Data Controller: ZIV Live, Inc. serves as the Data Controller for Host account data, billing records, customer support communications, and platform security telemetry.
- Data Processor: For user media (photos and videos) contributed to an Event Gallery, the Event Host administers the event space, and ZIV processes and hosts that media on the Host's behalf to deliver the service.
- Data Protection Contact: privacy@ziv.live
2. Scope
This Privacy Policy explains how we collect, use, store, and share personal data when you:
- Visit ziv.live or any ZIV subdomain
- Create or manage an Event as a Host
- Upload photos or videos as a Guest
- Communicate with us
It applies to all users globally. Where we note specific rights for EU/EEA residents (under GDPR) or California residents (under CCPA/CPRA), those sections apply to you accordingly.
3. Data We Collect
3.1 Host accounts
| Data | Why we collect it |
|---|---|
| Email address | Account creation, sign-in codes, transactional notices |
| Event administration details | Operating the service, title, date, vanity URL, and configuration settings |
| Billing records | Processed securely by our payment processor; we do not store raw card numbers |
| Technical connection data | IP address and browser user agent for security and fraud prevention |
| Service usage metrics | Quota enforcement, product analytics, and tier administration |
| Terms acceptance record | The version and time you accepted, stored with your account or moderator invitation; for each purchase, your consent to immediate delivery, stored with the Event. Kept to show what you agreed to and when |
| Event change history | Who opened, closed, froze or resumed an Event's uploads and who changed its screening settings, with the time. For screening-setting changes, also the IP address and browser user agent. Kept to prove how an Event's safety settings were set |
| Pilot invitation | If we invited you to our pilot: the address we invited, an optional internal note, and when you joined. Kept to make your Events free during the pilot |
| Support access records | When ZIV staff act on your account to help you or to investigate a breach of the terms: who, when, why, every page viewed and every change made |
3.2 Guest uploads
| Data | Why we collect it |
|---|---|
| Uploaded photos and videos | Display in the Event Gallery and Canvas; deliver to Host archive. Every stored photo and video file is cleaned at upload, before anyone can see it. It keeps only the capture date and time, orientation, and a "ziv.live" processing marker; location, device identifiers, and all other embedded metadata are removed, and pixels are not altered. Files withheld for a safety or legal violation keep their metadata as evidence. |
| Media file metadata | File format, size, dimensions, and camera orientation for display optimization. Technical EXIF (camera make/model, ISO, capture timestamp) and coarse location (country, region, timezone) are parsed into database records. Embedded GPS coordinates are never retained, except in files withheld for a safety or legal violation, which are preserved as evidence. |
| Connection identifiers | IP address and browser user agent are evaluated for rate limiting, which keeps only a keyed hash of the IP address, for at most an hour. Both are discarded (null) in storage for approved, unflagged uploads. Full connection identifiers and request telemetry are recorded in moderation audit logs only if an upload is flagged, rejected, or blocked for statutory crimes or terms violations. They are also kept for every upload to an Event whose Host has chosen not to use automated screening, so that unlawful uploads to an unscreened Event can still be traced. |
| Upload session tokens | Validating Event upload permissions and managing upload concurrency |
| Terms acceptance record | A server-signed record of the terms version accepted and when, made before your first upload and carried with each upload |
| Automated safety signals | Algorithmic screening scores and hash signatures to detect unlawful content |
| Photo reports | When you report a photo, a one-way hash of your session identifier and that photo, so that each guest counts once. It cannot be turned back into your identifier. On a demo, ZIV is emailed the photo, not who reported it |
| Email address (archive request) | Sending one email with a one-use link to the full archive of an Event or demo, at the guest's request. The address is passed to our transactional email provider for that one message and is not stored. A keyed hash of it is kept for at most an hour to rate-limit requests, then deleted. The address itself is never stored. |
Guests do not create accounts. Guest participation is decoupled from Host profiles, and we do not link Guest upload activity to a persistent cross-Event identity. We never send Guests marketing or promotional email, and we keep no Guest email address to send it to.
3.3 All visitors
| Data | Why we collect it |
|---|---|
| Anonymised page-view analytics | Understand product usage and performance |
| Crash and error logs | Diagnose technical bugs and platform stability |
| Demo creator connection | The IP address of whoever created a demo, kept with the demo while it runs |
We use privacy-preserving analytics that do not set tracking cookies or fingerprint individual visitors. See our Cookie Policy.
3.4 No Biometric Data or Facial Recognition
ZIV does not collect, generate, or process biometric data, facial geometry, facial recognition templates, or biometric identifiers from uploaded photos or videos. Automated screening tools evaluate media solely for general content safety categories (such as adult or violent material) and do not identify or profile individuals.
3.5 No AI Training
ZIV does not use uploaded photos, videos, or guest metadata to train, fine-tune, or evaluate artificial intelligence models, and does not sell or license them to anyone who does. Automated safety screening analyses media only to detect prohibited content: our image-screening provider does not use that media to train its models, and our hash-matching provider receives only a numeric fingerprint, never the photo itself.
4. Legal Basis for Processing (GDPR)
For users in the EU/EEA, our legal bases under GDPR Article 6 are:
| Processing activity | Legal basis |
|---|---|
| Account creation and management | Performance of a contract (Art. 6(1)(b)) |
| Guest terms assent and upload session authorization | Performance of a contract (Art. 6(1)(b)) |
| Providing the Event Gallery and upload service | Performance of a contract (Art. 6(1)(b)) |
| Payment processing and billing | Performance of a contract (Art. 6(1)(b)) |
| Platform security and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Compliance with legal and statutory obligations | Legal obligation (Art. 6(1)(c)) |
| Marketing communications to Hosts (opt-in only) | Consent (Art. 6(1)(a)) |
| Product analytics (anonymised) | Legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, you have the right to object to that processing as set out in Section 8.
5. How We Use Your Data
We use personal data for the following specific purposes:
- Operate the service: Store and display uploaded photos and videos in the Event Gallery and Canvas display; enforce tier limits; generate secure upload URLs.
- Billing: Process payments through our payment processor; generate and dispatch receipts.
- Safety and moderation: Run automated screening on uploads to detect and intercept illegal or policy-violating content. Hold uploads for Host review when they arrive from a Tor exit node or, where the Host has asked, from a country the Event does not expect.
- Security: Detect and prevent abuse, unauthorized access, denial-of-service attempts, and fraud.
- Support: Respond to customer inquiries, technical troubleshooting, and account queries. ZIV staff may act on your account to help you or to investigate a breach of the terms; each time, we record who, when, why, every page viewed and every change made.
- Product improvement: Analyze aggregated, anonymised usage patterns to optimize performance and usability.
- Transactional notices: Send account confirmations, payment receipts, archive expiry notices, and system alerts. These notices are essential to service delivery and cannot be opted out of while an account is active.
- Marketing communications (Hosts, opt-in only): If a Host gives explicit consent, send occasional product updates. Consent may be withdrawn at any time. Guests never receive marketing or promotional email.
6. Data Sharing and International Transfers
We do not sell personal data. We share personal data only with trusted third-party service providers who process information on our behalf under binding data protection agreements:
| Provider Category | Processing Purpose | Location |
|---|---|---|
| Cloud infrastructure and database hosting | Secure database storage, authentication, and core application infrastructure | United States, European Union |
| Content storage and distribution networks | Scalable media file storage and global low-latency content distribution | Global edge network |
| Payment processing and fraud prevention | Secure payment card processing, billing, and transactional compliance | United States |
| Transactional communications services | Delivering account notifications, receipts, system announcements, and guest archive emails | United States |
| Safety and security screening services | Automated visual content analysis to detect illegal or policy-violating uploads | United States, European Union |
| Correspondence and mailbox services | Receiving and handling enquiries, support requests, and privacy rights requests sent to our published contact addresses | United States, European Union |
All service providers are bound by data processing agreements (DPAs) consistent with GDPR requirements. Where personal data originating in the European Economic Area (EEA) or United Kingdom (UK) is transferred to the United States or other non-EEA jurisdictions, transfers rely on Standard Contractual Clauses (SCCs) adopted by the European Commission, or statutory adequacy decisions under GDPR Chapter V.
We may also disclose personal data:
- To comply with a valid legal obligation, court order, or lawful request by public authorities
- To protect the rights, property, or safety of ZIV, our users, or the public as permitted by law
- In connection with a corporate merger, acquisition, or sale of assets (with prior notice to registered Hosts)
7. Data Retention
| Data type | Retention period |
|---|---|
| Host account data | Retained until account deletion request, then purged within 30 days |
| Event metadata | Retained per the plan active lifecycle (see Terms of Service), then deleted |
| Unpaid event records (title and owner) | Deleted within 24 hours if the purchase is never completed |
| Accounts never verified | Deleted 24 hours after creation |
| Pilot invitations | Until account deletion. An invitation never accepted, or revoked, is deleted 30 days later |
| Uploaded photos and videos | Retained per the plan active lifecycle. After the Event ends, a courtesy archive window (one day for moment, three days for memory, ten days for milestone) keeps the archive downloadable through emailed archive links only; the Event is not reopened. Then permanently purged |
| Archive link records | A hash of each one-use archive link, the Event or demo it belongs to, and when it was used. No email address. Deleted when the Event's files are purged, or with the demo |
| Payment records | Seven years (statutory tax and accounting obligations) |
| Security and abuse logs | 90 days |
| Statutory safety records | One year (18 U.S.C. § 2258A; GDPR Art. 17(3)(b) exemption) |
| Event-scoped rejected hashes | Retained solely for editorial re-upload prevention during the event active lifecycle; deleted synchronously with the event |
| Event change history | One year after the Event is purged or deleted, including after account deletion |
| Staff action records | What ZIV staff did to an Event or account, by whom and why. One year after the Event or account is deleted; records about our own alerts, and about pilot invitations (which hold no address), are kept |
| Support access records | While your account exists, and one year after it is deleted |
| Terms acceptance records | Until account deletion; a moderator's, for as long as their invitation is kept |
| Guest terms acceptance records | With each upload's processing record and on statutory safety records |
| Demo creator IP | Deleted with the demo |
| Photo reports | Deleted with the photo, Event or demo they belong to |
| Purchase consent records | One year after the Event is purged or deleted |
| Anonymised analytics | Retained indefinitely (contains no personal data) |
Host account deletion may be initiated by contacting privacy@ziv.live, or self-service via the account deletion control in the Event Admin dashboard. Self-service deletion permanently purges all owned events' uploaded photos and videos immediately, regardless of any remaining time on an event's active lifecycle (see Terms of Service §8.5). Account and personal profile records are purged within 30 days.
All personal technical metadata captured during upload is separated from the media content. When a valid erasure request is fulfilled, personal technical metadata is permanently deleted. Pursuant to mandatory statutory obligations under 18 U.S.C. § 2258A (mandatory child safety reporting and evidence preservation) and GDPR Article 17(3)(b) (compliance with a legal obligation), statutory safety records (including cryptographic hashes and network telemetry) are strictly exempted from right-to-erasure and are purged after one year. A statutory safety record also keeps the uploader's session identifier, the time they accepted the terms and the terms version they accepted, the original file name, size and type, the Event it came from, the Event host's account identifier, email address and payment reference, and, for a demo, its creator's IP address. Event change history is kept for one year after the Event is purged or deleted, even after an erasure request, to establish or defend legal claims (GDPR Article 17(3)(e)). Staff action records are kept on the same basis for one year after the Event or account they concern is deleted.
8. Your Rights
All users
- Access: Request a copy of personal data we hold about you.
- Correction: Request correction of inaccurate personal data.
- Deletion: Request deletion of your personal data (subject to statutory retention obligations).
- Withdraw consent: Where processing is based on consent, withdraw consent at any time.
EU/EEA residents (GDPR)
In addition to the above:
- Portability: Receive personal data provided to us in a structured, machine-readable format.
- Restriction: Request restriction of processing while a dispute is investigated.
- Objection: Object to processing based on legitimate interests.
- Automated decisions: We do not make solely automated decisions producing legal or similarly significant effects on individuals.
Verification of Identity and Legitimate Authority
To protect user privacy and prevent unauthorized or malicious deletion requests (such as third-party disputes or hostile attempts to delete another person's Event or memories):
- We verify the identity and legal authority of any requester before fulfilling access, correction, or deletion requests.
- An individual may only request deletion of their own personal data. Third parties may not request the deletion of another user's Event, media, or account data without documented legal authorization.
- Guest Verification Standard: Because Guests participate without creating accounts, Guests requesting access or deletion of specific photos must provide the Event code or URL and clearly identify the specific media file. Where technical connection records cannot reliably verify the uploader's identity, requests may be coordinated with the Event Host or evaluated based on depicted likeness.
- The right to erasure is not absolute and does not apply where retention is necessary for the exercise of freedom of expression and personal social documentation (GDPR Art. 17(3)(a)), for compliance with statutory retention obligations (GDPR Art. 17(3)(b)), or for the defense of legal claims (GDPR Art. 17(3)(e)).
- We reserve the statutory right under GDPR Article 12(5) to refuse requests that are manifestly unfounded, excessive, or intended to interfere with another user's lawful use of the service.
To exercise any privacy right, email privacy@ziv.live. We respond to verified requests within 30 days (extendable by 60 days for complex requests with notice). We do not charge a fee for reasonable requests.
You also have the right to lodge a complaint with your local supervisory authority. In the EU, supervisory authority contacts are available at edpb.europa.eu.
California residents (CCPA/CPRA)
Under the California Consumer Privacy Act as amended by the CPRA:
- Know and Access: Request disclosure of categories and specific pieces of personal information collected, used, or disclosed.
- Delete: Request deletion of personal information collected (subject to statutory exceptions).
- Correct: Request correction of inaccurate personal information.
- Opt-Out of Sale or Sharing: ZIV does not sell personal information and does not share personal information for cross-context behavioral advertising, and has not done so in the preceding 12 months. Because we do not sell or share personal information, we do not provide a Do Not Sell opt-out link.
- Non-Discrimination: We will not discriminate against any user for exercising privacy rights.
To submit a CCPA request, email privacy@ziv.live. We will verify your identity before processing the request.
9. Children's Privacy
ZIV is a platform for adult and teenage users aged 13 and older. We do not knowingly collect personal data directly from children under 13.
Hosts are welcome to use ZIV to celebrate family milestones and children's occasions (such as birthdays, sports games, or family reunions), provided that the Host and uploading Guests operating the devices are adults or teens aged 13 or older. Hosts must not distribute Event QR codes or upload links to children under 13 to operate as app users.
If we become aware that personal data has been submitted directly by a child under 13 without verified statutory parental consent, we will delete that data promptly.
10. Security
We implement industry-standard technical and organizational security measures:
- TLS encryption in transit for all network traffic
- Encryption at rest for stored files and database records
- Cryptographically validated upload keys and session tokens for all upload operations
- Row-level database security policies isolating user and Event data
- Server-side isolation for credentials and administrative operations
No security system is impenetrable. In the event of a security incident affecting your rights and freedoms, we will notify affected users and competent supervisory authorities as required by applicable law.
11. Cookies
We use a minimal set of essential cookies and local storage tokens. See our Cookie Policy for full details.
12. Third-Party Links
Events may display external links or third-party content. We are not responsible for the privacy practices or content of external sites.
13. Changes to This Policy
We may update this Privacy Policy periodically. For material changes, registered Hosts will be notified by email or via the admin dashboard at least 30 days before the effective date. Continued use of ZIV after the effective date constitutes acceptance of the revised policy.
14. Contact
For any questions, requests, or notices regarding this Privacy Policy or our data practices:
- Data Protection Contact: privacy@ziv.live
- General Legal Inquiries: legal@ziv.live
- Controller: ZIV Live, Inc.
- Mailing Address: 1250 Wayzata Blvd E, Unit #1919, Wayzata, MN 55391, United States
For EU/EEA users unsatisfied with our response, you may escalate your inquiry to your national data protection authority.