Loading...
Effective: June 1, 2026
Zoopos is operated by jzyrdev (referred to as "we", "us", or "our"). This Privacy Policy explains how we collect, use, and protect information when you use the Zoopos Business Portal and related applications. For questions, contact privacy@jzyrdev.com.
We collect information you provide directly: account details (name, email address, phone number), business information (business name, outlet addresses, branding), payment details (processed by our payment provider — we do not store raw card numbers), and content you create (menus, orders, staff records). We also collect data automatically: log data (IP address, browser type, pages visited, timestamps), device identifiers, and usage analytics.
We use your information to: (a) provide, operate, and improve the Service; (b) process payments and send receipts; (c) send transactional emails (account creation, password resets, invoices); (d) send product updates and announcements — you may unsubscribe at any time; (e) detect and prevent fraud and abuse; (f) comply with legal obligations.
Your data is stored on Supabase infrastructure. We apply industry-standard security measures including encryption in transit (TLS), encryption at rest, role-based access controls, and multi-tenant isolation. Access to production data is restricted to authorised personnel only. Despite these measures, no system is fully secure; we cannot guarantee absolute security.
We do not sell your data. We share data only with: (a) service providers who help us operate the Service (Supabase, payment processors, email delivery) under data processing agreements; (b) professional advisors (lawyers, accountants) bound by confidentiality; (c) law enforcement or regulatory authorities when legally required. We require all third parties to protect your data consistent with this Policy.
Each business account's data is logically isolated. Employees and managers can only access data within the outlets and roles assigned to them. We do not share or expose one business's data to another. Postgres Row Level Security policies enforce this separation at the database level.
We use session cookies to keep you logged in and local storage to remember preferences (theme, selected outlet). We use analytics to understand usage patterns; this data is aggregated and does not identify individual users. We do not use advertising cookies or cross-site tracking.
We retain your data for as long as your account is active. After account closure, we retain data for 90 days to allow export and dispute resolution, then delete it permanently. Anonymised aggregate data (e.g., usage statistics) may be retained indefinitely. Certain records may be retained longer if required by applicable law.
Depending on your jurisdiction, you may have the right to: access a copy of your personal data; correct inaccurate data; request deletion of your data; object to or restrict processing; and data portability. To exercise these rights, email privacy@jzyrdev.com. We will respond within 30 days. You may also export your business data at any time from the dashboard.
The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
Your data may be processed in countries outside your own, including countries where data protection laws may differ. Where we transfer data internationally, we ensure appropriate safeguards are in place (such as standard contractual clauses) in accordance with applicable law.
We may update this Privacy Policy from time to time. We will notify you by email or via an in-app notice before material changes take effect. The effective date at the top of this page reflects the most recent revision. Continued use of the Service after the effective date constitutes acceptance.
For privacy-related questions, requests, or complaints, contact us at privacy@jzyrdev.com or write to: jzyrdev, Dubai, United Arab Emirates. If you believe we have not adequately addressed your concern, you may lodge a complaint with the relevant data protection authority in your jurisdiction.