Privacy Notice
Governing language: Polish. The full, binding privacy policy is published in Polish at zapyo.app/polityka-prywatnosci. This page is a short, good-faith summary for English-speaking visitors and is not itself a substitute for the Polish document. If the two ever disagree, the Polish version governs.
1. Who processes your data
Zapyo is operated by Flamin Joe Studio Dominika Kasprzyk, VAT ID (NIP) 5792303226 (contact: hej@flaminjoe.studio). Write to this address for any question about your data, including account or data deletion requests.
2. What we collect, in short
- Account email — to create your account and sign you in (magic link / one-time code).
- Content you enter — your clients, quotes, reminders and notes — so the app can store and show them back to you.
- Feedback you submit — to improve the product and reply to you.
- Push subscription — a device/browser identifier, only if you turn push notifications on.
We do not sell your data or build advertising profiles inside Zapyo. Measurement differs by surface: on the public zapyo.app marketing pages, Google Analytics and Meta Pixel may, after consent, measure page views, interactions and campaign source. Meta Pixel is disabled in the app.zapyo.app application. After consent, the app starts Google Analytics only when it submits an account-created event, with automatic page views, Google Signals and ad personalisation disabled. The event we submit contains the sign-up method (email or Google), an empty referrer and a fixed safe page address. It does not contain your email, Supabase user ID, client records, app content or the actual application route. The Supabase ID is used only in browser storage to prevent the same event from being sent twice and is never sent to Google.
The public marketing pages also use cookie-free Ahrefs Web Analytics for aggregate traffic measurement. Ahrefs stores the page URL and referrer, browser/device data, language and approximate location; the raw IP address is discarded and the daily hash is not a persistent identifier. This is based on our legitimate interest in evaluating our marketing pages (Article 6(1)(f) GDPR).
Google Analytics and Meta Pixel operate on the basis of your consent (Article 6(1)(a) GDPR and
the applicable rules on storing information on a device). Refusing or later withdrawing consent does
not limit the application. The providers nevertheless receive technical connection data such as IP
address, browser and device information, and their own cookie/measurement identifiers; on marketing
pages they may also receive the visited URL and referrer. Recipients are Google Ireland Ltd / Google
LLC and — for the marketing surface only — Meta Platforms Ireland Ltd / Meta Platforms Inc. Ahrefs
Pte Ltd also receives aggregate marketing-page measurement data. Depending
on the provider and transfer, transfers outside the EEA rely on Standard Contractual Clauses (SCCs)
or the EU–US Data Privacy Framework; Google Ireland Ltd processes Google Analytics data on our behalf as a
processor. Consent is handled by the website's own mechanism (the open-source CookieConsent library): your
choice is stored only on your device, in the cc_cookie file, and is not sent to any external
provider. You can change or withdraw consent at any time through the “Cookie settings” button (in the footer
of the marketing pages and in the account menu of the app); withdrawal removes Google Analytics and Meta Pixel
cookies and does not limit your account. Withdrawal does not affect the lawfulness of earlier processing.
| Cookie | Category | Provider | Purpose and expiry |
|---|---|---|---|
| cc_cookie | Necessary | zapyo.app / app.zapyo.app | remembers your cookie choice — 182 days |
| _ga, _ga_EMG81V3Q1B | Statistics | Google Analytics 4 — 2 years | |
| _fbp | Marketing | Meta | Meta Pixel (marketing pages only) — 90 days |
3. Your clients' data
If you store your own clients' details in Zapyo, you are the controller of that data and we process it only on your behalf and instructions, as a data processor. We don't look into it or use it for our own purposes, and it is deleted together with your account.
4. Where data lives
- Database: Supabase, Frankfurt region (AWS
eu-central-1) — your data stays within the European Union, and GDPR applies in full. - App hosting: Vercel Inc. — serves the application code, and every connection passes through it, so it processes technical request data (IP address, requested path, browser headers). We run no analytics there, and the contents of your database are neither copied nor stored on Vercel's side.
- Push delivery: your browser's own push service (Apple, Google, Mozilla); notification content is encrypted in transit.
- Payments: Stripe Payments Europe, Ltd. (Ireland) — handles payments and subscriptions. We pass on your email address and account identifier so a payment can be matched to an account. We neither receive nor store card details.
Where a provider sits outside the EEA, transfers rely on Standard Contractual Clauses (SCCs) and a data processing agreement is in place.
5. How long we keep it
For as long as you keep your account. Deleting your account permanently deletes your data (including your clients' data) from the live database; database backups roll over on a cycle of up to 30 days.
Google Analytics event and user data is subject to a retention setting of no more than 14 months. Under Meta's terms, Business Tools Event Data may be retained for up to two years. The app's local pending confirmed-signup event is removed after refusal or after the tag invokes its delivery-completion callback; without that callback it remains and is retried on the next app start. The consent choice and local duplicate-prevention marker remain until you change the privacy setting or clear the browser's site data. Ahrefs may retain aggregated measurement history without a fixed end date; you may object to that measurement by contacting the controller.
6. Your rights
Under GDPR you have the right to access, rectify, delete, restrict processing of, and port your data, and to object to processing. To exercise any of these — including deleting your account and all its data — email hej@flaminjoe.studio. We reply within 30 days, usually much sooner. You may also lodge a complaint with your local data protection authority, or with Poland's UODO (uodo.gov.pl), the supervisory authority for the controller named above.
7. Security
Connections are encrypted (TLS) and database access is isolated per user via Row Level Security — every user can reach only their own records. Sign-in uses one-time links/codes; we don't store passwords for accounts created that way.
8. Changes
We'll announce material changes by email or in the app. The current version of both this summary and the binding Polish policy is always available at these addresses.