Legal
Privacy Policy
This Privacy Policy explains how Zetaap (“Zetaap”, “we”, “us”, or “our”), the operator of zetaap.com, collects, uses, stores, shares, and protects personal data when you use our websites, account portal, store applications, and related services (together, the “Services”).
We design our practices to align with personal data protection principles commonly applied across the Middle East, including the United Arab Emirates Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), the Kingdom of Saudi Arabia Personal Data Protection Law, Qatar Law No. 13 of 2016 on Personal Data Protection, and Oman’s Personal Data Protection Law (Royal Decree 6/2022), as well as related implementing regulations where applicable.
1. Who this policy covers
This policy applies to:
- Visitors to zetaap.com and related marketing pages
- Account holders who register, verify email, or apply for a store
- Store staff who sign in with a store code, username, and password
- Users of Zetaap web apps and future Android / mobile apps
- Individuals whose data is entered into a store workspace by a customer of Zetaap (for example, staff or end-customer records), to the extent we process that data as a service provider
2. Roles: controller and processor
- Zetaap as controller. For account registration, store applications, platform administration, billing/trial status, support communications, and website analytics/security logs, Zetaap typically acts as a data controller.
- Zetaap as processor / service provider. For business data that a store customer enters into its isolated tenant workspace (catalog, inventory, sales lane activity, roles/users configured by the store, and similar operational records), Zetaap typically processes that data on behalf of the store customer. The store customer remains responsible for its own lawful basis and notices to its staff and end customers.
3. Personal data we may collect
Depending on how you use the Services, we may process:
3.1 Account and onboarding data
- Name, email address, password (stored in hashed/secured form)
- Store application details (store name, country, contact details, selected features/app type)
- Verification and authentication records
3.2 Store operations data
- Store codes, usernames, role/permission assignments
- Operational records you choose to enter (products, vendors, purchases, inventory, terminal pairing metadata, print configuration, and similar)
- Device/terminal identifiers used for register-and-approve flows and local print-agent pairing
3.3 Technical and usage data
- IP address, browser/app type, device type, operating system
- Approximate location derived from IP (country/region level)
- Log files, security events, performance diagnostics, crash reports
- Cookies or similar technologies on the website (see Section 8)
3.4 Support and communications
- Messages you send to us, and related contact details
- Trial / subscription status and related service notices
We do not intentionally collect special-category sensitive data (such as health, biometric templates, or religious beliefs) as part of the standard Zetaap product. Please do not upload such data unless a written agreement expressly covers it.
4. How we use personal data
We use personal data to:
- Provide, operate, secure, and improve the Services
- Create and manage accounts, store applications, and tenant workspaces
- Authenticate users and enforce access controls / roles
- Enable POS lane, inventory, catalog, purchasing, print-agent, and settings features
- Offer and administer free trials (including one-month full-feature trials) and related notices
- Send service, security, and transactional emails
- Detect, prevent, and investigate fraud, abuse, or security incidents
- Comply with legal obligations and respond to lawful requests
- Establish, exercise, or defend legal claims
5. Legal bases / lawful grounds
Where required under applicable Middle East data protection laws, we rely on one or more of the following:
- Performance of a contract or steps prior to entering a contract
- Legitimate interests (for example securing our platform, improving reliability, preventing abuse), balanced against your rights
- Consent, where we ask for it (and you may withdraw it where consent is the basis)
- Compliance with a legal obligation
- Vital interests or other grounds recognized under applicable local law, where relevant
6. Sharing of personal data
We do not sell personal data. We may share data with:
- Service providers who help us host, email, monitor, or secure the Services (under contractual confidentiality and data protection terms)
- Identity / authentication infrastructure used for store staff login
- Professional advisers (legal, accounting) under confidentiality
- Authorities when required by applicable law, court order, or to protect rights, safety, and security
- Business transferees in connection with a merger, acquisition, or reorganization, subject to appropriate safeguards
Store customers control who they invite into their workspace and what operational data they enter. Zetaap does not use one store’s business data to serve another store.
7. International transfers and hosting
Our Services may be hosted or supported using infrastructure in or outside your country. Where personal data is transferred across borders, we take steps designed to provide an appropriate level of protection consistent with applicable Middle East requirements (including contractual safeguards and access controls). If your organization requires residency in a specific country or region, contact us to discuss available options.
8. Cookies and similar technologies
Our websites may use cookies or local storage that are necessary for authentication, security, language preference, or basic site function. Where configured, we may use Google Analytics 4 to understand aggregate traffic on the marketing site and account portal (for example page views). Analytics cookies are not required for login or checkout. You can control cookies through your browser settings; disabling some cookies may affect login or site functionality.
9. Mobile applications (including Android)
When you use a Zetaap Android or other mobile app (now or in the future), we may process:
- App account / store login credentials and session tokens
- Device identifiers needed for security, terminal pairing, crash diagnostics, and push notifications (if enabled)
- Permissions you grant on the device (for example camera for barcode scanning, Bluetooth/network for printers or local agents, storage for offline cache) — only for the stated feature
- Approximate network information for connectivity and fraud prevention
Mobile permissions are requested in-context. You can revoke permissions in your device settings; some features may then stop working. App store listings will link to this Privacy Policy at https://zetaap.com/privacy/ (or the equivalent deployed domain serving this page).
10. Data retention
We retain personal data only as long as needed for the purposes described above, including to provide the Services, meet legal, accounting, or reporting requirements, and resolve disputes. Account and tenant data is generally retained for the life of the account / store plus a limited period afterward for backup, security, and legal compliance, unless a longer period is required by law or a shorter period is agreed in writing. You may request deletion subject to Section 11 and any mandatory retention duties.
11. Your rights
Subject to applicable Middle East data protection laws and any exemptions, you may have rights to:
- Access personal data we hold about you
- Request correction of inaccurate or incomplete data
- Request deletion or destruction of personal data
- Request restriction of, or objection to, certain processing
- Withdraw consent where processing is based on consent
- Lodge a complaint with a competent supervisory authority in your country
To exercise rights, contact support@zetaap.com. We may need to verify your identity. If your request relates to data stored in a store workspace that we process on behalf of a store customer, we may redirect you to that store customer as the primary controller for that data.
12. Security
We implement administrative, technical, and organizational measures appropriate to the risk, including access controls, encryption in transit where supported, tenant isolation controls, logging, and least privilege for operational staff. No method of transmission or storage is completely secure; please use strong passwords and protect your devices and credentials.
13. Children
The Services are intended for business use by adults. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will take appropriate steps to delete it.
14. Third-party links and local software
The Services may link to third-party sites or rely on local components (such as a print agent running on your computer). Those third parties and local environments are governed by their own terms and privacy practices. Review them carefully before use.
15. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Last updated” date. For material changes, we may provide additional notice (for example by email or in-product notice). Continued use of the Services after an update means you accept the revised policy, except where applicable law requires a different approach.
16. Governing region and contact
This policy is prepared for customers and users in the Middle East markets we serve (including the UAE, Saudi Arabia, Qatar, and Oman) and for users accessing zetaap.com from those regions. Local mandatory law prevails where it conflicts with this notice.
Privacy requests and questions:
Email:
support@zetaap.com
Web: https://zetaap.com/
Policy URL (for web and Android store listings):
https://zetaap.com/privacy/