OAuth Permissions
Zeinto requests only the minimum permissions necessary to provide our financial tracking services:
- openid: Basic identity verification
- email: Account creation and communication
- profile: Display name and basic profile information
We do not request offline access or persistent tokens. Each session requires fresh authentication for enhanced security.
Security Compliance
- SOC 2 Type II: Security, availability, and confidentiality controls
- PCI DSS: Payment card industry data security standards
- GDPR Compliant: European data protection regulations
- Bank-Grade Encryption: AES-256 encryption for all data
- Multi-Factor Authentication: Required for all accounts
Data Usage
What We Do:
- Provide financial portfolio tracking and management tools
- Generate AI-powered insights for your investments
- Securely store your financial data with encryption
- Enable secure bank account connections via Plaid
What We Don't Do:
- Sell or share your personal information with third parties
- Access your accounts without explicit permission
- Store sensitive authentication tokens long-term
- Use your data for advertising or marketing purposes
Third-Party Integrations
Zeinto integrates with trusted, industry-standard services:
- Plaid: Secure bank account connections (read-only access)
- Stripe: Payment processing for subscriptions
- OpenAI: AI-powered financial insights (anonymized data)
- Postmark: Transactional email delivery
Contact Information
For questions about application verification or security concerns:
- Security Team: security@zeinto.com
- Support Team: support@zeinto.com
- Data Protection Officer: privacy@zeinto.com