OneNect
OneNect privacy policy
Last updated: 12 August 2026
Zinpro Corporation, 10400 Viking Drive, Suite 240, Eden Prairie, Minnesota 55344, United States, is the controller of the personal data described here.
In short
You can use most of OneNect without an account and without giving us anything. Browsing our species guides, research, the Anderson Foundation, sustainability pages, our values and the wellness content requires no sign in.
If you contact us, sign in as a customer, or sign in as a Zinpro employee, we collect what is described below. We do not sell your personal data, we do not share it with advertisers, and we do not track you across other companies' apps or websites.
What we collect, and why
If you browse without signing in
We collect no personal data. The app fetches public content and nothing about you is sent to us.
If you contact us through the app
When you use "Talk to Zinpro" we collect your name and email address, the species you are asking about, and your topic and message, so that a Zinpro representative can respond. You can also give us a phone number and the name of your farm or company, both optional, if you would rather we called or you want us to know who you are with. Legal basis: your consent, and our legitimate interest in responding to an enquiry about our products.
If you sign in
Account and profile. Name, work email address, job title, department, office or site, profile photo, and language preference. For employees this comes from your Zinpro single sign on account. Legal basis: performance of your contract of employment, or our legitimate interest in operating an internal application. For customers it comes from the account we issue you.
Precise location. Only while the app is open, and only if you allow it. We collect your exact coordinates rather than a rounded or approximate position. We do this because a safety alert can be aimed at an area as small as 100 metres across, and because an emergency alert you raise yourself has to tell a responder where you actually are. We use it for three things: to reach you with safety alerts that apply to the site you are at, to pass your position to responders if you raise an emergency alert, and to show relevant local content. We do not track your location in the background, and we do not build a location history: only your most recent position is stored, and each update overwrites the one before it. You can refuse or withdraw this at any time in your device settings, and the app continues to work, though geo targeted safety alerts will not be able to reach you. Legal basis: your consent, and for employees our legitimate interest in workplace safety.
Step counts. If you turn on step counting, we read the daily step total from your device's motion sensor to power your personal goal. We store a daily total, not a movement trace, not a route, and not continuous activity data. This is optional and off until you enable it. Under GDPR this is health data, so our legal basis is your explicit consent, which you can withdraw at any time by turning step counting off. Withdrawing deletes the daily totals we hold: we do not merely stop adding to them. Your calendar goes back to holding no reading for those days, your figure stops appearing on any challenge or club board, and if you had agreed to show your figure to a step club that agreement ends with it. A score already recorded in a challenge that has finished stays as that challenge's result, because it is a record of a competition rather than a reading of your walking.
Reading today's total from your phone's health record. Your phone keeps a health record of your walking: Apple Health on an iPhone, Health Connect on an Android phone. Reading today's daily total out of that record is a separate choice from step counting, asked for on its own, and off until you turn it on yourself. That includes everybody who turned step counting on before this existed: agreeing to one has never been agreeing to the other, and nobody is opted in by default.
It is worth having if you wear an Apple Watch or a fitness band, or if your phone spends the day on a desk. That walking is recorded by the watch rather than by the phone, so without this your figure here can be far lower than the one your own Health app shows. We read one number per day, the total, and nothing else: never a route, a location, a time of day, a workout, or any other measurement the record holds. We never write anything to your health record.
Leaving it off does not stop your steps. Your phone keeps counting with its own motion sensor exactly as it does now, and your calendar, your streaks, and any challenge or club board carry on. The only difference is that walking your phone did not see is not added in.
Under GDPR this is health data, so our legal basis is your explicit consent, which you can withdraw at any time under Devices & activity in your profile, and the reading stops at once. Unlike step counting, withdrawing this one does not delete the daily totals already recorded. Each of those is a single figure your phone and your health record contributed to together, and there is no way to take only the record's part back out; those days are also held under your step counting consent, which is still live. Your figure goes back to what your phone counts on its own, and if you want the days deleted as well, turning step counting off deletes all of them.
Showing your step figure to other people. Turning step counting on does not show your figure to anybody. Publishing it to colleagues is a separate choice, and there are two ways to make it, each asked for on its own:
- Joining a step challenge. The people in that challenge see your daily total and your position in it.
- Agreeing to show your figure to a step club you are in. The members of that club, and nobody else, see your daily total and your position on that club's board. This is asked per club: agreeing in one club says nothing about any other, and it does not publish you to the wider company. You can change the answer at any time on the club's own screen, and leaving the club ends it.
Neither choice is retroactive. We publish only the days you walked from the moment you agreed onwards; days walked before that stay private. If you decline, or have not been asked yet, you still appear in the club's member list with your name and photo, as you already do, and carry no step figure. Under GDPR this is health data, so our legal basis for publishing it is your explicit consent.
Reading your step record while you are not using the app. The choices above say WHAT we read. This one is about WHEN, and it is asked separately because it is a real change rather than a detail.
If you allow it, the app can read the daily step total out of your phone's health record while the app is closed or in the background. Nothing else changes. It is still one number per day, the daily total, and still nothing else: no route, no location, no time of day, no workout or activity type, no heart rate, and no other measurement your record may hold. It is still only your own record, still kept no longer, and still shown to nobody unless you have separately chosen to publish your figure.
We ask for this because a step count that is only correct while you have the app open is not much use. Your phone counts all day; without this, your figure only catches up when you happen to look at it, which is why a figure on a club board can be hours behind what your phone knows.
On an Android phone this is a permission Health Connect asks you for in its own screen, separate from the one that lets us read your steps at all. On an iPhone it is part of the health permission you grant Apple Health. On both, you can withdraw it there at any time without turning step counting off, and the app falls back to reading your figure while you are using it.
Being explicit about the trade, because it is your data and the honest answer matters more than the feature: allowing this means the app looks at your health record at moments when you are not looking at your phone. We think that is worth it for a figure that is right rather than stale, and it is why it is a separate choice you can decline and still use everything else.
Step history already in your phone's health record. Separately, and only if you turn it on yourself, the app can read daily step totals out of the health record your phone keeps: Apple Health on an iPhone, Health Connect on an Android phone. That record is not only this phone's own counting. It can include days from before you installed OneNect, and days recorded by an Apple Watch, a fitness band or another health or fitness app you use, because these stores aggregate what every device and app signed into them has written. So a day we import may be a day this phone never counted, and may have been measured by a device Zinpro has no relationship with.
This is a second choice, not part of turning step counting on: counting your steps from today onwards and reading what was already recorded in the past are different things, and we ask for them separately. We read one number per day, the daily total, and nothing else - no route, no location, no time of day, no workout or activity type, no heart rate, and no other health measurement your record may hold. We do not read which device or app recorded a day, beyond storing which health store the figure came from. We read back as far as the start of the previous calendar year and no further, matching how long we keep step totals at all. On Android, Health Connect normally limits an app to the last 30 days unless Google has separately approved deeper access, so less is usually available there. A day your record holds nothing for is left blank rather than recorded as a zero.
Imported days are shown only to you: they do not earn points, do not count towards streaks, awards or any leaderboard, and do not change where you or anyone else stands. Under GDPR this is health data, so our legal basis is your explicit consent, which you can withdraw at any time in your profile. Withdrawing deletes the days that were imported: we do not merely stop adding to them. Days the app counted itself are not affected, and declining or withdrawing leaves the rest of the app working exactly as it did.
Photos and videos. Only files you choose. The app reads nothing from your photo library until you pick something to attach to a post, a volunteer log or your profile picture.
Content you create. Posts, comments, messages, IT and legal requests, volunteer logs, event responses and similar.
Shipping addresses. If you request Zinpro branded promotional items or printed material through the app, we keep the delivery addresses you save in your address book, including the recipient name, street address, city, region, postcode and country, so that the items can be shipped and so you do not have to type an address twice. Nothing in the app is sold or paid for, so we never collect a payment card, billing address or bank detail.
Requests you place for promotional items. What you asked for, how many, the delivery address you chose, and the status history of the request. Nothing here is a purchase: the items are promotional goods Zinpro supplies free of charge, no payment is taken and no price is charged to you. For Zinpro employees the request is visible to the colleagues who fulfil and approve it, and the internal cost of the goods is attributed to a department for Zinpro's own budgeting. Legal basis: our legitimate interest in running an internal supply and fulfilment process.
Activity totals for points and leaderboards. If you take part in the wellness, volunteering and recognition features, we count what you have done across the app, for example how many volunteer hours you have logged, posts and comments you have made, kudos you have sent, polls you have voted in and requests you have placed. These counts drive your points balance, your level and the achievements you unlock, and where you have joined a leaderboard your name and score are visible to other participants. This is not used to evaluate your performance at work. Legal basis: our legitimate interest in running the programme, and your choice to take part.
Device information for notifications. A push notification token that identifies your device to Apple's or Google's notification service, plus the device name and platform, so that alerts reach you and so you can see which of your devices is counting your steps.
Diagnostics. If the app crashes or hits an error we collect a technical report through Sentry: the error, a stack trace, the app version, the device model and operating system version. This is used to fix faults. Legal basis: our legitimate interest in a working, secure application.
Safety alerts
OneNect can send urgent safety alerts to people at a Zinpro site, including alerts that take over the screen and sound an alarm. We do this to reach people quickly when there is an emergency such as severe weather or a plant incident. An alert is sent to the people assigned to the affected site, and to anyone whose most recent position falls inside the affected area. We consider this a legitimate interest in protecting health and safety, and in some cases a vital interest under GDPR Article 6(1)(d).
Who we share it with
We use the following processors. Each is bound by contract to process data only on our instructions.
| Processor | Purpose | Where |
|---|---|---|
| Supabase | Database and file storage | United States |
| Fly.io | Application hosting | United States |
| Upstash | Session and cache storage | United States |
| Expo (Expo Application Services) | Push notification delivery, app updates | United States |
| Apple, Google | Push notification delivery to your device | Global |
| Sentry | Crash and error reporting | United States |
| Anthropic | Machine translation of content into your language | United States |
| Techottic | IT service desk tickets | Per Zinpro agreement |
| ServiceNow | IT service desk tickets, where that desk is in use | Per Zinpro agreement |
| Twilio | SMS delivery of urgent alerts | United States |
When you report an IT problem, the ticket carries your name, work email, site and department to the service desk, so a technician knows who is affected and can reply to you. Nothing else about you is sent with it.
We also share data with a Zinpro representative when you ask us to contact you.
We do not sell personal data. We do not share it for advertising. We do not use it to train machine learning models.
International transfers
Zinpro Corporation is established in the United States, and this app and its data are operated from there. Zinpro has sales and research activity in the Netherlands, Spain, Brazil, Mexico, China, Japan, Singapore, Jordan and Russia. Personal data collected in the European Economic Area, the United Kingdom or Switzerland is transferred to the United States. Where it is, we rely on the European Commission's Standard Contractual Clauses together with supplementary measures, including encryption in transit and at rest.
How long we keep it
- Account and profile data: while your account is active, then removed within 90 days of it being closed, unless we must keep it longer by law.
- Step totals: daily totals are kept for the current and previous calendar year, then deleted. This applies to imported days as well, and it is also the limit on how far back we will read: we do not import days we would have to delete on arrival. Both are additionally deleted as soon as you withdraw the consent they were collected under, whenever that is: turning step counting off deletes the days we counted, and turning the history import off deletes the days we imported. Turning off the reading of today's total from your health record is the one exception: it stops the reading at once but keeps the days already recorded, because each is a single merged figure the motion sensor contributed to as well and those days are still held under your step counting consent. Turning step counting off deletes them.
- Location: only your most recent position is kept, and it is overwritten each time it updates.
- Content you create: until you delete it or your account is closed.
- Shipping addresses: until you delete the address or your account is closed.
- Promotional item requests and their status history: 7 years, because the internal cost of the goods is attributed to a department and belongs in Zinpro's accounting record.
- Activity totals for points and leaderboards: while your account is active.
- Diagnostic reports: 90 days.
- Safety alert delivery records: 3 years, because we may need to show who was notified during an incident.
Your rights
Depending on where you live you may have the right to access your data, correct it, delete it, restrict or object to how we use it, receive a copy in a portable format, and withdraw consent at any time.
If you are in the EEA, the UK or Switzerland these rights come from GDPR or UK GDPR. If you are in Brazil they come from the LGPD. If you are in California they come from the CCPA as amended by the CPRA, and we confirm that we have not sold or shared personal information in the preceding twelve months.
To exercise any of these, contact contact@technooptics.com. We respond within 30 days. If you are in the EEA you also have the right to complain to your local supervisory authority.
Children
OneNect is not directed at children under 13, and we do not knowingly collect data from them. Family members and students who take part in volunteering or wellness activities should be 13 or older, or should use the app with a parent or guardian.
Security
Data is encrypted in transit using HTTPS and at rest by our storage providers. Access to production data is limited to staff who need it. Sensitive values are encrypted with a dedicated key. We keep an audit trail of administrative actions.
Changes
If we change this policy we will update the date at the top and, where the change is significant, tell you in the app.
Contact
Zinpro Corporation, 10400 Viking Drive, Suite 240, Eden Prairie, MN 55344, USA
EEA availability and representative. Zinpro Corporation has no establishment in the European Economic Area. Pending appointment of a representative under GDPR Article 27, OneNect is NOT offered in EEA territories, and the app is withheld from those App Store and Google Play regions. Article 3(2) turns on offering a service to people in the Union, so withholding it is a lawful alternative to appointing a representative. If we later offer OneNect in the EEA, we will designate a representative under Article 27 and name them here before doing so.