Legal

Privacy Policy

What zapgocart collects, why it is collected, who it is shared with, and what you can require us to do about it.

In effect from 15 August 2026

This document is not finished.

It is missing the registered legal name, trade licence number and issuing authority, registered address, emirate for the governing-law clause — supply them in apps/website/lib/legal.ts and every legal page updates together. Have a qualified adviser review the text before relying on it.

01Who we are

zapgocart is a commerce platform operated by [registered legal name], a company registered in the United Arab Emirates under trade licence [trade licence number].

Our registered address is:

[registered address]

For anything on this page, write to privacy@v2.zapgocart.com. We are the data controller for the processing described in clauses 4 and 5.

02What this covers

This policy covers the zapgocart marketing website, the signup process, and the accounts of merchants who use the platform.

It does notgovern what an individual merchant does with data collected through their own shop. Each shop is run by an independent business that sets its own practices; when you buy from one, that merchant's policy applies to your order. See clause 6.

03Controller and processor

Data-protection law distinguishes the party who decides why data is processed from the party who processes it on instruction. Which one we are depends on whose data it is, and it changes what we are permitted to do at your request.

  • Visitors to this website — we are the controller. We decide what is collected and why.
  • Merchant account holders — we are the controller for your account, billing and support records.
  • Shoppers, diners and guests of a merchant — the merchant is the controller and we are their processor. We hold that data to run their shop and act on their instructions.

The practical consequence: if you are a shopper asking us to delete an order, we will refer you to the merchant, because deleting their records on our own initiative would breach our obligations to them. We will pass your request on and tell you we have.

04Data from this website

Advertising attribution

If you arrive from an advertisement, we read the campaign parameters from the link you followed — Meta's click identifier fbclid and the standard utm_* tags — and store them in a cookie named zk_attr on your device for 30 days.

It exists for one purpose: to know which advertisement led to a signup, so we can judge whether the advertising is worth continuing. It records the campaign, not you. Only the first such visit is stored — a later click does not overwrite it.

Analytics and measurement

We use the Meta Pixel, which tells Meta that a browser visited this site and which pages it viewed. What that involves, and how to refuse it, is set out in full in our Cookie Policy.

Server logs

Our servers record the usual request data — IP address, timestamp, page requested, browser and referrer — for security and for diagnosing faults. These logs are not used to build a profile of you.

05Data from your account

Opening a shop requires your name, business name, email address, phone number and location. We use these to create and run your account, verify your email address, provide support, invoice you, and contact you about the service.

We also generate records as you use the platform: sign-in times, the actions taken in your dashboard, and support correspondence. These exist for security, billing accuracy, and answering the question of what happened when something goes wrong.

We do not sell your personal information, and we do not share it with advertisers beyond what clause 7 describes.

06Your customers' data

Data your customers give you through your shop — names, contact details, orders, addresses, table and queue records — belongs to you. We process it solely to operate your shop.

We do not:

  • use it for our own marketing;
  • sell it, or share it with other merchants;
  • contact your customers on our own behalf, other than to deliver messages your shop sends.

As the controller, you are responsible for having a lawful basis to collect it and for publishing your own privacy notice. We will help you respond to a request from one of your customers.

07Advertising and Meta

We advertise on Meta's platforms and measure whether it works. Two separate flows are involved.

  • In your browser — the Meta Pixel reports page views and signup intent to Meta. Meta may use this to show you our advertisements again and to measure their performance.
  • From our servers — when a signup completes, we tell Meta that a signup happened and which campaign it came from. Where contact details are included in that message they are hashed first, so Meta receives an irreversible fingerprint rather than your email address or phone number.

Meta acts as an independent controller for the data it receives; its own terms govern what it then does with it. You can limit this through your Meta ad preferences, and block the browser half entirely with any standard content blocker. Neither affects your ability to use this site or your shop.

08Why we are allowed to

Where the GDPR applies to you, we rely on the following lawful bases. Where UAE Federal Decree-Law No. 45 of 2021 applies, the equivalent grounds under Article 4 are relied on.

  • Performance of a contract — running your account, providing the platform, taking payment.
  • Legitimate interests — security, fraud prevention, service diagnostics, and measuring whether our advertising works. We have weighed these against your interests and consider them proportionate; you may object, at the address in clause 16.
  • Consent — non-essential cookies and the advertising described in clause 7, where consent is required in your jurisdiction. You may withdraw it at any time without affecting what was done beforehand.
  • Legal obligation — tax, accounting and records we are required to keep.

09Who we share it with

We share personal data only with service providers who need it to deliver the platform, and only under contract terms that bind them to our instructions. In each case the category, not a fixed vendor, is what matters:

  • hosting and infrastructure providers;
  • email and messaging delivery providers;
  • payment processors, for subscriptions and shop payments;
  • advertising and analytics platforms, as set out in clause 7;
  • professional advisers, and authorities where we are legally required to disclose.

If the business is sold or reorganised, data may transfer with it. You will be told before that changes how your data is handled.

A current list of the processors we use is available on request from privacy@v2.zapgocart.com.

10International transfers

Our infrastructure and our providers may be located outside the country you are in, so your data may be transferred across borders.

Where data leaves the UAE, we transfer it in line with Articles 22 and 23 of the PDPL — to jurisdictions recognised as offering adequate protection, or under contractual safeguards where they are not. Where data leaves the UK or EEA, we rely on adequacy decisions or on standard contractual clauses. You can request a copy of the safeguards that apply to a specific transfer.

11How long we keep it

  • Attribution cookie — 30 days on your device, then it expires on its own.
  • Server logs — a short operational window, then deleted on rotation.
  • Account and shop data — for as long as your account is open, and for a limited period afterwards so the account can be restored if closure was a mistake.
  • Invoices and tax records — for the period the law requires us to retain them, which outlasts the account.

When you close your account we delete or anonymise what we no longer need. Tell us at privacy@v2.zapgocart.com if you want your data exported first.

12How we protect it

Traffic to the platform is encrypted in transit. Access to production data is limited to those who need it to operate the service, passwords are stored hashed rather than recoverable, and each merchant's data is scoped to their own shop so one tenant cannot read another's.

No system is immune. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant authority and affected individuals as the PDPL and GDPR require, without undue delay.

13Your rights

Subject to the conditions in the applicable law, you may ask us to:

  • tell you what we hold about you, and give you a copy;
  • correct anything inaccurate or incomplete;
  • delete data we no longer have grounds to keep;
  • restrict or object to a particular use, including profiling;
  • provide your data in a portable, machine-readable form, or send it to another provider;
  • withdraw a consent you previously gave.

Write to privacy@v2.zapgocart.com. We will respond within 30 days, and we may need to verify your identity first — that check exists to stop someone else exercising your rights for you. Exercising any of these is free and will never worsen the service you receive.

If your request concerns data held inside a merchant's shop, see clause 3: we will pass it to the merchant, who is the controller.

14Children

The platform is sold to businesses and is not directed at children. We do not knowingly collect data from anyone under 18 through this site or the signup process. If you believe a child has given us data, write to privacy@v2.zapgocart.com and we will delete it.

15Changes

When this policy changes we update the date at the top of the page. Where a change materially affects how we use data you have already given us, we will tell account holders directly rather than relying on you to notice the date.

16Contact and complaints

Privacy questions and rights requests: privacy@v2.zapgocart.com. Anything else: hello@v2.zapgocart.com, or the routes on our contact page.

If you are not satisfied with our answer, you may complain to the UAE Data Office, or — where the GDPR applies to you — to the supervisory authority in the country where you live or work. We would rather you came to us first, but you are not required to.