ziply
Privacy Policy Delete account Terms Support Contact
PRIVACY POLICY

Privacy Policy

Last updated: 29 August 2026

This Privacy Policy applies to Ziply Business OS, including the Android application published on Google Play as Ziply Business OS (package name my.ziply.pos), the Ziply website at ziply.my, and related Ziply platform services.

Developer / controller: Ziply (“Ziply”, “we”, “us”, or “our”).

App: Ziply Business OS.

Google Play package name: my.ziply.pos.

Privacy contact: support@ziply.app or the Ziply contact page.

This Privacy Policy explains how Ziply accesses, collects, uses, stores, shares and deletes information when you use Ziply Business OS or our websites. It is intended to satisfy Google Play’s User Data policy together with the in-app disclosures and the Data safety section in Play Console. It covers personal data of account holders and, where we act as a processor, business records that a customer organization stores in Ziply.

1. Scope and roles

Ziply Business OS is a business operations application for merchants and their staff. It is not directed to children. A customer organization (the business that creates a Ziply tenant) generally decides why and how its customer, employee and transaction data is processed. In that case Ziply processes that data on the organization’s instructions. Ziply is the controller for account data we collect to provide the Ziply service itself, such as owner registration details, authentication, billing contact information, device identifiers used for session security, and support communications sent directly to Ziply.

2. Information we collect in Ziply Business OS

Depending on how you use the app and which features the business enables, Ziply Business OS may collect the following categories of information:

Account and profile information

  • Name, work email address, password (stored as a hash), optional business phone number, business name, industry and country.
  • Role, tenant/workspace identifiers, and consent records for terms and this Privacy Policy.

Business operations data

  • Orders, invoices, payments metadata, inventory actions, bookings, loyalty activity, customer records entered by the business, and related workflow history.
  • Full payment-card numbers are not intended to be stored by Ziply. Card payments are processed by certified payment providers when that feature is used.

Device, app and security information

  • Device or installation identifiers, session identifiers, app version, and diagnostic or crash information needed to keep the app signed in, synchronized and secure.
  • Internet access is required to authenticate, sync and load business data.

Camera

  • Ziply Business OS may request camera permission only when you use in-app barcode or QR scanning (for example Sell > Scan).
  • Camera frames are used locally on the device to decode a code. The scanner does not persistently store photos or videos of the camera feed. You can refuse camera access and still use the rest of the app.

Messages and support content

  • If the business uses inbox, messaging or support features, conversation content that staff send or receive through those features is stored for the business.
  • Support requests you send to Ziply, including the contact details you provide.

AI and automated processing logs

  • If AI features are enabled for the tenant, prompts, tool calls, permissions context and outcomes may be logged for security, quality and governance within that tenant’s boundaries.

We do not collect precise location, contacts, SMS, microphone audio, advertising ID, or photos from the device gallery unless a future feature requests that permission and this policy is updated first. The current Android app declares Internet and optional Camera permissions.

3. How we use information

We use information to:

  • Create and authenticate accounts, keep sessions secure, and synchronize business records.
  • Provide POS, commerce, bookings, inbox, reporting and other subscribed features.
  • Process authorized business actions and maintain audit trails.
  • Provide customer support and service communications.
  • Prevent fraud, abuse and unauthorized access.
  • Improve reliability, diagnose crashes and meet legal obligations.

We do not sell personal data. We do not use Ziply Business OS data for third-party advertising. We do not use an advertising ID.

4. Sharing and subprocessors

Information may be shared only as needed to operate the service:

  • Infrastructure, hosting, email/communications, identity, analytics/diagnostics, and payment providers contracted by Ziply.
  • Customer-selected integrations (for example a payment, messaging or telephony provider the business connects). Those providers receive data according to the permissions the business grants and their own policies.
  • Professional advisers or authorities where required by law, a valid legal request, or to protect Ziply, users or the public.
  • A successor in a merger, acquisition or asset transfer, subject to this policy or equivalent protection.

Staff of a Ziply tenant can see business records according to the roles that tenant administrators assign.

5. Permissions used by the Android app

  • Internet: required to sign in, sync data and use online features.
  • Camera (optional): barcode and QR scanning. Denied permission does not block sign-in or core POS flows that do not scan.

6. International transfers and retention

Data may be processed in Malaysia and in other countries where Ziply or its service providers operate, using contractual and technical safeguards. We keep information only as long as needed to provide the service, keep it secure, meet accounting, tax, audit, fraud-prevention and legal duties, then delete or anonymize it. Backup copies expire through the encrypted backup lifecycle.

7. Security

Ziply uses HTTPS/TLS in transit, tenant isolation, access controls, encrypted local storage for authentication secrets and offline records on the Android app, logging, monitoring and incident procedures. Android backup/transfer excludes sessions, the encrypted local database and queued transactions. No system is completely secure. Customers must protect credentials, configure staff permissions and manage connected providers.

8. Your choices and rights

Depending on your location and relationship with Ziply, you may request access, correction, deletion, restriction or export of personal data, or object to certain processing. Staff and end customers of a business should first contact that organization, because it controls most operational records. Account holders can also email support@ziply.app.

9. Account and data deletion

To request deletion of a Ziply Business OS account or specified personal data:

  1. Email support@ziply.app or open the contact page and choose the privacy or account-access topic.
  2. Include the email address used for the Ziply account and the business or tenant name.
  3. State whether you want the complete account deleted or only specified personal data removed.
  4. Do not send a password, payment-card number, API key or other secret.

We may verify the request with you or with the organization that controls the tenant. After verification, active credentials, profile details, device registrations and customer-controlled content associated with the request are deleted or anonymized. Transaction, invoice, tax, security, fraud-prevention, consent and audit records may be retained only where required by law, contract or legitimate security obligations, with access restricted for that period. We will tell you when the request is completed or if a legally required record must be kept.

You can also request deletion at https://ziply.my/delete-account. Tenant administrators can remove staff users and operational records subject to legal retention.

10. Children

Ziply Business OS is for business operators aged 18 and older. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact support@ziply.app and we will delete it.

11. Changes

We may update this Privacy Policy. The “Last updated” date at the top will change. Material changes will be posted on this page. Continued use of Ziply Business OS after an update means the revised policy applies to later use.

12. Contact

Privacy questions, data requests and concerns:

  • Email: support@ziply.app
  • Web: https://ziply.my/contact
  • Account deletion: https://ziply.my/delete-account
  • Support: https://ziply.my/support
  • App: Ziply Business OS (my.ziply.pos)
ziply

Ziply Business OS privacy and legal information.

Legal Privacy Policy Account deletion Terms & conditions Support
© 2026 Ziply. All rights reserved.Ziply Business OS · my.ziply.pos