Ziningi™ Privacy at Ziningi

Privacy Policy

Last updated: 28 August 2026

Information processed

Ziningi processes business settings and services; Owner/Staff names, emails, roles and account state; customer names and mobile/WhatsApp numbers; job references, pair count, service, price, dates, notes, status and collection history; additive payment/reversal records; tracking-token records; device and synchronization metadata; audit/security logs; and support communications. Ziningi does not collect customer card credentials or bank-login details.

Purpose

Information is used to operate the counter workflow, authenticate users, enforce roles and tenant boundaries, synchronize offline work, calculate balances, provide limited tracking, open WhatsApp at a user's direction, secure and monitor the service, support users, investigate incidents, back up and restore records, and improve reliability.

Access

Authorized Owners and Staff access their business's data according to role. Ziningi support and technical personnel use least-privilege access when necessary. Hosting, transactional-email, domain and infrastructure providers process limited data required to deliver their services. Ziningi does not sell personal information.

Hosting geography and backups

The pilot application and PostgreSQL database are hosted in the European Union (Germany). Protected backups may be held in a separate failure domain. Email and DNS providers may process delivery metadata in their own regions.

Retention, anonymisation and deletion

Active records are kept while needed to provide the service. Payment, status and audit histories remain append-only. Pilot public tracking expires 90 days after canonical collection or cancellation. Counter devices retain recently completed data for seven days only after complete server confirmation and synchronization. Information no longer needed may be deleted, anonymised or replaced with a tombstone while required history remains truthful. Backups age out through rotation.

Public tracking boundary

A high-entropy QR/token may reveal only the sneaker cleaner's name, human-readable reference, pair count, safe status, relevant expected/ready date and generic contact guidance. It does not reveal customer identity, phone, payments, balances, staff, internal IDs, audit or sync details. Anyone holding the link can see that limited status until expiry or revocation.

Security

High-level controls include HTTPS, protected credentials and backups, private PostgreSQL, key-only administration, Owner/Staff permissions, tenant enforcement and forced RLS, opaque tracking credentials, secure sessions, audit history, device controls, monitoring and restore testing. No system can promise absolute security or uninterrupted recovery.

Privacy questions and requests

Account users should first contact their business Owner. Customers should direct requests about cleaner-entered information to that sneaker-cleaning business. Email Ziningi privacy questions to support@ziningiapp.co.za with “Privacy” in the subject. Never send passwords, PINs, security codes or complete secure links.

Privacy· Terms· Support

Ziningi™ · A Silabela Technologies product