Privacy Policy
Last updated: [FILL IN: effective date]
This Privacy Policy explains how [FILL IN: legal entity / company name] ("ZapBuzzer", "we", "us") collects, uses, shares, and protects information in connection with the ZapBuzzer web app and the ZAP Buzzer mobile app (together, the "Service"). The data controller is [FILL IN: legal entity name], [FILL IN: registered address, country].
1. Information we collect
We collect only what we need to run the Service:
- Account details — your name, email address, password (stored only as a secure hash), and, optionally, a phone number if you add one.
- Sign in with Google (optional) — if you use Google sign-in, we receive your name, email address, and profile picture from Google.
- Workspace data you create — organization name, team/role assignments, rooms, catalog items, and the requests/orders and free-text notes you submit.
- Device & notification data — a Firebase Cloud Messaging (FCM) push token, a random per-install identifier we generate (not a hardware ID), the app version, and the platform, so we can deliver summons/alerts to your device.
- Technical/log data — such as IP address and basic request logs, used for security and troubleshooting.
We do not collect your precise location, contacts, photos or other media, or any advertising identifier. The app contains no ads and no in-app purchases.
2. How we use your information
- To provide and operate the Service — route requests to the right team and deliver notifications.
- To authenticate you and keep your account and workspace secure.
- To provide support and respond to your messages.
- To maintain, debug, and improve the Service.
We do not sell your personal data, and we do not use it for advertising.
3. Sharing & service providers (sub-processors)
We share data only with providers that help us run the Service:
- Google Firebase Cloud Messaging — receives your device push token and notification content to deliver push notifications.
- Google (Sign in with Google) — only if you choose Google sign-in.
- Email provider — transactional and escalation emails may be sent via an email/SMTP provider configured for your workspace.
- Anthropic (Claude AI) — only if your workspace uses the optional in-product AI assistant on the web, your typed questions and related workspace operational data (for example request details and co-worker names needed to answer) are sent to Anthropic to generate a response. The mobile app does not use AI.
- Hosting/infrastructure — [FILL IN: hosting provider, e.g. your Coolify/host + database region].
We may also disclose information where required by law or to protect the rights and safety of users.
4. Data retention
We keep your information for as long as your account is active or as needed to provide the Service. When you delete your account (see below), we delete or anonymize your personal data, except where we must retain limited records to comply with legal obligations or resolve disputes.
5. Security
Data is transmitted over encrypted connections (HTTPS/TLS). Passwords are stored as salted hashes, and authentication tokens on your device are held in the platform's encrypted secure storage. No method of transmission or storage is 100% secure, but we take reasonable measures to protect your data.
6. Your rights & account deletion
You can access and update your profile in the app's Settings. You can permanently delete your account and personal data at any time — see how to delete your account. Depending on where you live, you may have additional rights (access, correction, erasure, portability); contact us to exercise them.
7. Children
The Service is a workplace tool and is not directed to children under [FILL IN: minimum age, e.g. 16]. We do not knowingly collect data from children.
8. International transfers
Your data may be processed in countries other than your own, including where our providers operate.[FILL IN: describe transfer safeguards / regions if applicable].
9. Changes to this policy
We may update this policy from time to time; we will revise the "Last updated" date above and, where appropriate, notify you.
10. Contact
Questions or requests: [FILL IN: privacy/support contact email] ([FILL IN: company legal name and address]).