This Privacy Policy ("Notice") is issued by Zapocuts Private Limited, a company incorporated under the laws of India, doing business as Zapocuts ("Company", "we", "us", or "our"), and governs the Zapocuts Partners mobile application, its associated backend services and APIs, and the partner-onboarding process (together, the "Services").
The Services are built exclusively for barbershops, salons, and comparable grooming businesses ("Partner", "Shop", "you", or "your") and for the owners, managers, and staff whom a Partner authorises to operate the Services on the Shop's behalf ("Authorised Users"). The Services are not directed at consumers. If you are a customer of a Shop looking for the consumer-facing Zapocuts application, its separate privacy notice is available at zapocuts.com/privacy-policy/app; this Notice does not apply to that application.
By downloading, accessing, registering for, or using the Services, you acknowledge that you have read and understood this Notice. If you do not agree with it, you must not use the Services. Capitalised terms not defined here have the meaning given in our Terms and Conditions.
This Notice describes how we collect, use, disclose, and safeguard three distinct categories of information in connection with the Services:
Section 5 explains, in detail, the separate and important obligations that apply to Customer information, because with respect to that category the Company and the Partner often act as independent data fiduciaries, each responsible for its own compliance.
Registration and business-verification information. When a Shop applies to join the Partner Waitlist, we collect the owner's or applicant's name, email address, and phone number; the Shop's name, category, and city; the Shop's approximate geographic coordinates; and, to verify that the Shop is a genuine, lawfully operating business, at least one of the Shop's Goods and Services Tax Identification Number (GSTIN) or trade licence number, together with your acceptance of the onboarding declaration. We do not independently verify GSTIN or trade licence numbers against government registries, and you remain solely responsible for the accuracy of what you submit.
Onboarding and Shop profile information. Once a registration is approved, we collect the operational details you configure to run your Shop on the Services: Shop name, address, and contact number; the names and roles of your barbers; your chair inventory; your service catalogue (names, categories, durations, and prices); your operating hours; Shop description, website, and social-media links; and any Shop photographs you upload, which are stored using Microsoft Azure Blob Storage.
Account and authentication data. Access to the Services is authenticated through our identity provider (Keycloak), which we operate. We collect the email address and password associated with your account. Passwords are never visible to Company personnel in plain text; Keycloak stores only a salted cryptographic hash. Each authenticated session is represented by a signed access token that our infrastructure validates before any request reaches our application servers.
Customer information visible to you. Because the Services exist to help you run your floor and manage relationships with the people you serve, we make certain personal data about your Shop's customers ("Customers") available to your Authorised Users, including: a Customer's name, visit history, and favourite barber; queue and appointment details (services selected, barber and chair assignments, timestamps, arrival method, and any manual check-in note your staff records); the content of chat conversations between your Shop and a Customer; and review content a Customer has posted about your Shop, including their display name, star rating, and comment text. Section 5 sets out important limits on how you may use this information.
Arrival-verification data. When a customer's arrival is confirmed by scanning a QR code or entering a one-time numeric code, our servers verify a cryptographic credential generated by the separate customer-facing Zapocuts platform. We store only a one-way hash of that credential — never the underlying QR payload or OTP in reversible form — and a timestamp marking when it was redeemed.
Camera data. The Services request camera access solely to power the Queue tab's "Scan QR" arrival-verification feature. QR decoding is performed entirely on-device using Google's ML Kit Barcode Scanning library. No camera image, video frame, or photograph is transmitted to, or stored on, our servers or any third party; only the short alphanumeric string decoded from the QR code leaves the device, over an encrypted connection, to redeem the arrival credential described above. We do not use the camera for any other purpose.
Location data. The Services request location access solely to power the "use my current location" convenience button when you set your Shop's address on the Shop Profile map. This is a one-time, foreground, user-initiated action — we do not track your device's location continuously, in the background, or at any time you are not actively using that specific feature. You can deny or revoke this permission at any time in your device settings without losing access to any other part of the Services.
Push-notification data. If you enable notifications, we register a device token, platform identifier, and device identifier, associated with your Shop, with Firebase Cloud Messaging so we can deliver alerts about queue activity, appointments, chat messages, and reviews. Notification tokens are scoped to the Shop, not to an individual Authorised User's personal identity.
Device and diagnostic data. We and our service providers automatically collect technical information when you use the Services, including device model and manufacturer, operating-system name and version, application version, IP address, mobile network information, crash and error diagnostics, and in-app usage events (such as which screens and features you use and when). This information is collected through Firebase Analytics, Firebase Installations, Firebase Remote Config, and the Mixpanel Android SDK, each described further in Section 6.
Advertising identifier. Because the Services bundle certain Google Play services libraries, the Android operating system may expose an advertising identifier (AD_ID) to the application. We do not use this identifier, or any other data, to serve advertisements, build advertising profiles, or engage in ad-tech data sharing. The Services carry no in-app advertising of any kind.
We process the information described in Section 2 for the following purposes:
We do not sell personal information, and we do not use Customer information made available to you for our own marketing purposes.
We process personal data in accordance with India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000 together with the rules made under it. Depending on the data and context, our processing is grounded in one or more of the following: your consent (for example, when you grant camera, location, or notification permissions, or accept the Partner Waitlist declaration); the performance of our contract with you (our Terms and Conditions) to provide the Services you have signed up for; our legitimate interests in operating, securing, and improving the Services, provided those interests do not override your rights; and compliance with our legal obligations, including tax, accounting, and business-verification record-keeping requirements.
This section is central to your use of the Services and to this Notice. The Company provides the technical means by which Customer information (names, visit and appointment history, chat messages, and review content) is surfaced to you so that you can run your Shop. With respect to that Customer information:
Nothing in this section limits the Company's own obligations, as a data fiduciary, for the personal data it independently collects and controls in connection with operating the Services and its relationship with Customers directly, which is described in the consumer-facing Zapocuts application's own privacy notice.
We do not sell personal information. We share information only as described below.
Service providers. We engage the following categories of third-party service providers to operate the Services. Each processes data under contractual confidentiality and security obligations, and only to the extent necessary to perform the function described:
| Function | Provider(s) | | --- | --- | | Cloud image storage and delivery pipeline | Microsoft Azure (Blob Storage, Event Grid) | | Identity and authentication | Keycloak (operated by us, self-hosted) | | Push notifications | Google Firebase Cloud Messaging | | App configuration and feature management | Google Firebase Remote Config, Firebase Installations | | Product usage analytics and crash/performance diagnostics | Google Firebase Analytics; Mixpanel | | Map display and location selection | Google Maps Platform (Maps SDK) | | Database and application hosting infrastructure | Our contracted infrastructure and hosting providers |
Mixpanel and Google process certain data as independent controllers under their own privacy notices, available at mixpanel.com/legal/privacy-policy and policies.google.com/privacy respectively. Our use of any information obtained through Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Legal and safety disclosures. We may disclose information where we believe in good faith that disclosure is necessary to comply with applicable law, regulation, legal process, or a lawful governmental request; to enforce our Terms and Conditions; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of the Company, our Partners, Customers, or the public.
Business transfers. If we are involved in a merger, acquisition, financing, reorganisation, or sale of all or a portion of our business or assets, information may be disclosed or transferred as part of that transaction, subject to standard confidentiality arrangements and this Notice (or a materially equivalent successor notice).
With your direction. We may share information with third parties where you have specifically directed us to do so.
Some of our service providers (including Microsoft and Google) operate infrastructure that may process or store data outside India. Where this occurs, we take reasonable steps to require that such providers maintain a standard of data protection consistent with this Notice and applicable Indian law, including the DPDP Act's provisions governing cross-border transfer of personal data.
We retain Partner and Authorised User account information for as long as your Shop maintains an account with us, and for a reasonable period afterward to comply with legal, tax, accounting, and business-verification record-keeping obligations (financial and business-registration records are generally retained for up to eight years, consistent with the Income-tax Act, 1961, and the Central Goods and Services Tax Act, 2017). Customer information visible through the Services is retained for as long as your account remains active, so that queue history, appointment history, and chat history remain available to you for legitimate operational reference, unless you request earlier deletion of specific records and we are not otherwise required or permitted to retain them by law. When information is no longer needed for these purposes, we delete it or render it irrecoverable, except where retained in secure backups pending routine deletion.
We implement reasonable security practices and procedures as required under Section 43A of the Information Technology Act, 2000 and the rules made under it, and consistent with the DPDP Act, including encryption of data in transit (TLS), access-token–based authentication validated at our infrastructure gateway before any request reaches our application, hashed storage of passwords and arrival credentials, and role-based access controls limiting which of your staff can access which functions. No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security. You play a critical role in security by keeping your account credentials confidential and promptly reporting any suspected compromise to privacy@zapocuts.com.
In the event of a personal data breach that is likely to result in harm to affected individuals, we will notify the Data Protection Board of India and affected individuals as required under the DPDP Act and its rules.
The Services are intended solely for use by adults acting on behalf of a lawfully operating business. You must be at least 18 years old, and authorised to act for your Shop, to register for or use the Services. We do not knowingly collect personal information from, or direct the Services toward, individuals under 18. If we become aware that we have collected personal information from someone under 18 in connection with account registration, we will take reasonable steps to delete it and deactivate the associated account. If you believe a minor has provided us with personal information, please contact us at privacy@zapocuts.com.
Subject to applicable law, including the DPDP Act, you (and, in relation to information about them, your Authorised Users) may have the right to: obtain a summary of the personal data we hold and the processing activities carried out on it; request correction, completion, or updating of inaccurate or outdated personal data; request erasure of personal data that is no longer necessary for the purpose it was collected, subject to our legal retention obligations; withdraw consent previously given, without affecting the lawfulness of processing carried out before withdrawal; and register a grievance in the manner described in Section 15.
You may exercise these rights by emailing privacy@zapocuts.com or by submitting a request through our data-request portal at zapocuts.com/dsar. We will verify your identity and your authority to act for the Shop before actioning a request, and we will respond within the time limits required by applicable law. Some rights may be limited where processing is necessary for compliance with a legal obligation or the establishment, exercise, or defence of legal claims.
You may also withdraw or revoke camera, location, or notification permissions at any time through your device's operating-system settings; doing so will disable only the specific feature that relies on that permission.
The Services are a native mobile application and do not use browser cookies. Our analytics and diagnostics providers (Firebase and Mixpanel) use comparable device- and application-level identifiers (such as installation IDs and app-instance IDs) to associate events with a device or account for the purposes described in Section 6. These identifiers are not used for cross-app or cross-site advertising tracking.
The Services may contain links to third-party websites or services (for example, a service provider's own privacy notice, or Google Maps). We are not responsible for the privacy practices or content of any third party, and this Notice does not apply to information you provide to, or that is collected by, any third party. We encourage you to review the privacy notice of any third-party service before providing it with information.
We may update this Notice from time to time to reflect changes in our practices, the Services, or applicable law. The application checks a cryptographic version marker for this document and will prompt you to review material changes before you can continue using the Services. We encourage you to review this Notice periodically. The date at the top of this Notice indicates when it was last revised.
In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the DPDP Act, the Grievance Officer for the Services is:
Grievance Officer Zapocuts Private Limited 1, Hutum's Complex, Bishnu Rabha Path Guwahati, Assam 781040, India Email: privacy@zapocuts.com
The Grievance Officer will acknowledge a complaint within 24 hours of receipt and endeavour to resolve it within 15 days, or such other period as applicable law prescribes.
For all other questions or comments about this Notice, you may also contact us at business@zapocuts.com, contact@zapocuts.com, or by phone at +91 86387 26046, or by post at the address above.