Privacy Policy
Last updated: July 22, 2026
Zapto lets a local business publish a booking page and lets that business’s clients book an appointment on it. This policy explains what we collect from each of those two groups, why, and how to have it removed.
Two kinds of people, two different roles
This is the most important section, because Zapto is not a single-user app and the distinction changes who is responsible for what.
- Business owners create an account with us. For their data we are the controller — we decide what is collected and we answer directly for it.
- Clients who book an appointment do not have an account with us and never agreed to anything with us. They give their details to the business. For that data we act as a processor — a service provider storing it on the business’s behalf and under its instructions. The business is the controller of its own client list, and it is the business that is responsible for telling its clients how it handles their details.
In practice this means a client asking us to delete their booking will normally be directed to the business they booked with. We will still act on such a request ourselves if the business cannot be reached — see Your rights below.
What we collect from business owners
- Account details: email address and password. Passwords are stored hashed by our authentication provider; we never see them.
- Business profile: business name, description, page address (slug), photo, and time zone.
- Operating data you enter: services with their names, prices, durations and photos; weekly working hours; days and hours off.
- Subscription status and expiry date, so the app knows whether the paid plan is active.
- A push notification token for each device you sign in on, so we can tell you about new bookings. Tokens identify a device, not a person, and are deleted with your account.
What we collect from clients
Only what a booking needs. When someone books through a business’s page we store their first name, last name, phone number, the service chosen and the appointment time.
We do not ask clients for an email address, a password, an account, or a payment method. There is no client login, and we do not build a profile of a client across different businesses.
A business owner can also record a walk-in client manually from the app, in which case the phone number is optional.
What we collect automatically
- Standard server logs kept by our hosting and database providers, which include IP addresses and are used for security and troubleshooting.
- One cookie,
zapto_locale, set only if you pick a language with the switcher, so the page opens in that language next time. It stores a language code and nothing else.
We do not use analytics, advertising, tracking pixels or third-party cookies of any kind, and we do not sell or share personal data with anyone for advertising.
How we use the information
Solely to operate the booking service: to show a business’s page and available times, to record and display appointments, to notify an owner when a booking is made or cancelled, and to keep the paid plan working. We do not use it for advertising or profiling, and we do not sell it.
Where the data is stored and who processes it
Data is stored in a Supabase Postgres database with row-level security enabled, so a business can only reach its own records. We take reasonable technical measures to protect it, but no method of transmission or storage is completely secure.
These are the only third parties involved:
- Supabase — database, authentication and file storage. supabase.com/privacy
- Vercel — hosting for this website. vercel.com/legal/privacy-policy
- Expo — delivery of push notifications to the business owner’s device. Only the device token and the notification text pass through it; client phone numbers do not. expo.dev/privacy
- Apple — payment processing for the subscription and delivery of the app. apple.com/legal/privacy
We are not responsible for the privacy practices of these services.
Payments
The optional subscription is sold through Apple’s in-app purchase system. Apple handles the payment; we never receive or store card numbers or any other payment details. What we receive from Apple is a signed confirmation that a subscription is active and when it expires. Subscriptions are managed and cancelled in your Apple ID account settings.
How long we keep it
- Booking records: 24 months. After that the client’s name and phone number are erased and only the anonymous fact of an appointment remains, so a business keeps its longer-term statistics without keeping a stranger’s phone number indefinitely.
- Business account data: until you delete it. Delete your account in the app under Settings and your business, services, schedule, photos, device tokens and bookings are removed immediately and permanently. This cannot be undone.
Your rights
Depending on where you live you may have the right to access, correct, export or delete your personal data, and to object to how it is used. Residents of California have the right to know what is collected and to request deletion; we do not sell personal information, so there is nothing to opt out of.
Business owners can exercise most of these rights directly in the app, or by writing to us. Clients should contact the business they booked with, since it holds the record; if that is not possible, write to us at the address below and we will act on the request.
International transfers
Our providers store and process data on servers in the United States. If you use Zapto from elsewhere, your information is transferred to and processed there.
Children
Zapto is not directed at children under 13 and we do not knowingly collect their data. If you believe a child’s information has been given to us, contact us and we will delete it.
Changes to this policy
We may update this policy. The date at the top of the page always shows when it last changed, and material changes will be announced in the app before they take effect.
Contact
Questions, or a request about your data: vaultomoney@gmail.com.
See also our Terms of Service.