English · Português
Zoka (“Zoka”, “we”, “us”) operates the Zoka mobile application, a hyperlocal delivery service connecting people with shops in their neighbourhood. This policy explains what personal data we collect, why, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR).
Data controller: Zoka · Contact: info@zoka.app
We only collect what we need to run the service.
| Data | When | Why |
|---|---|---|
| Phone number | When you sign in | To create and secure your account via a one-time SMS code, and to let the shop reach you about your order |
| Name (first and last) | In your profile | To identify your order to the shop |
| Email address (optional) | If you add it | Account-related contact; you can leave it blank |
| Profile photo (optional) | If you add one | To personalise your account |
| Location (approximate, and precise with your permission) | When you choose your area or place an order | To show shops within delivery range. You can enter a postcode instead of granting precise location |
| Delivery address (street, floor, notes) | When you place a delivery order | To deliver your order |
| Order history | When you order | To show your past and active orders and their status |
| Push notification token | When you enable notifications | To send order-status updates to your device |
We do not collect payment-card or bank details. Payment is settled directly with the shop (cash or MB WAY); Zoka never sees or stores card numbers. We do not use analytics, advertising, or crash-reporting SDKs.
These providers act as processors on our behalf. We do not sell your data or share it for advertising.
To exercise any right you cannot complete in-app, email info@zoka.app.
All traffic between the app and our servers is encrypted in transit (HTTPS/TLS). One-time sign-in codes are stored hashed, are single-use, and expire after ten minutes. Sign-in tokens are held in the device’s secure storage (Keychain / Keystore).
Zoka is not directed to children and is intended for users aged 18 and over. We do not knowingly collect data from children.
Our servers are located in the EU. Where a processor (e.g. Twilio, Google) processes data outside the EEA, that transfer is covered by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
We may update this policy. Material changes will be notified in-app or by email. The “Last updated” date above always reflects the current version.
Questions or requests: info@zoka.app