zapyo

Privacy Notice

Interim English summary — last updated 17 July 2026

Governing language: Polish. The full, binding privacy policy is published in Polish at zapyo.app/polityka-prywatnosci. This page is a short, good-faith summary for English-speaking visitors and is not itself a substitute for the Polish document. If the two ever disagree, the Polish version governs.

1. Who processes your data

Zapyo is operated by Flaminjoe Studio (contact: hej@flaminjoe.studio). Write to this address for any question about your data, including account or data deletion requests.

2. What we collect, in short

We do not sell your data, do not build advertising profiles from it, and the app itself does not load analytics cookies. Our marketing pages (landing, blog) may load privacy-respecting or consent-gated analytics and, where applicable, ad-measurement scripts (e.g. Google Analytics, Meta Pixel, Ahrefs) — you can decline non-essential cookies in the banner shown on those pages. The application itself sets only what is strictly needed to keep you signed in.

3. Your clients' data

If you store your own clients' details in Zapyo, you are the controller of that data and we process it only on your behalf and instructions, as a data processor. We don't look into it or use it for our own purposes, and it is deleted together with your account.

4. Where data lives

Where a provider sits outside the EEA, transfers rely on Standard Contractual Clauses (SCCs) and a data processing agreement is in place.

5. How long we keep it

For as long as you keep your account. Deleting your account permanently deletes your data (including your clients' data) from the live database; database backups roll over on a cycle of up to 30 days.

6. Your rights

Under GDPR you have the right to access, rectify, delete, restrict processing of, and port your data, and to object to processing. To exercise any of these — including deleting your account and all its data — email hej@flaminjoe.studio. We reply within 30 days, usually much sooner. You may also lodge a complaint with your local data protection authority, or with Poland's UODO (uodo.gov.pl), the supervisory authority for the controller named above.

7. Security

Connections are encrypted (TLS) and database access is isolated per user via Row Level Security — every user can reach only their own records. Sign-in uses one-time links/codes; we don't store passwords for accounts created that way.

8. Changes

We'll announce material changes by email or in the app. The current version of both this summary and the binding Polish policy is always available at these addresses.