Legal

Privacy Policy

Last updated: April 2026  ·  Zanziholics Digital Agency  ·  Zanzibar, Tanzania

Summary: ZanziPOS collects only the data needed to operate your venue account. We do not sell your data. Card and payment data is handled entirely by Pesapal and never stored by us. Your venue data stays on servers in your region.

1. Who we are

ZanziPOS is a product of Zanziholics Digital Agency, a digital agency registered in Zanzibar, Tanzania. When this policy refers to "we", "us" or "ZanziPOS", it means Zanziholics Digital Agency.

Contact: build@zanzipos.app  ·  Fumba Town, Shehia ya Nyamanzi, Zanzibar, Tanzania

2. What data we collect

We collect the following categories of data depending on how you interact with ZanziPOS:

3. What we do not collect

4. How we use your data

5. Third-party services

ZanziPOS integrates with the following third-party services. Each has its own privacy policy:

Pesapal
Payment processing. Handles all card and mobile money transactions. PCI DSS compliant.
Google Analytics & GTM
Website usage analytics. Anonymised session and event tracking on the landing page.
Meta Pixel
Facebook and Instagram advertising measurement on the landing page.
TikTok Pixel
TikTok advertising measurement on the landing page.
Hotjar
User behaviour analytics (heatmaps, session recordings) on the landing page.
Google Fonts
Typography served from Google CDN. IP address may be logged by Google.
Google Sheets
Early access sign-up data is logged to a private Google Sheet via Apps Script.
Zanzibar Revenue Authority (ZRA)
Fiscal receipt data transmitted to ZRA API as required by Tanzanian tax law.
Anthropic Claude AI
AI assistant feature in the admin panel. Order data may be sent to Claude API for analysis and suggestions.

6. Data storage and security

Venue data is stored in isolated MariaDB databases on a Hetzner VPS server located in Europe. Each venue has its own database — tenant data is never mixed. Passwords are hashed using bcrypt and never stored in plain text.

We use SSL/TLS encryption on all connections. The server is maintained by Zanziholics with regular backups.

7. Data retention

We retain venue account and order data for as long as your subscription is active, plus 12 months after cancellation to comply with tax record-keeping requirements under Tanzanian law.

Early access sign-up data is retained until you request deletion.

Analytics data (Google Analytics, Hotjar) is retained according to those platforms own policies.

8. Cookies

The ZanziPOS landing page uses cookies from Google Analytics, Google Tag Manager, Meta Pixel, TikTok Pixel, and Hotjar for analytics and advertising measurement purposes.

The tenant POS application uses a session cookie to maintain staff login state. This cookie is essential for the system to function and does not track advertising activity.

9. Your rights

You have the right to request access to, correction of, or deletion of your personal data held by ZanziPOS. To exercise these rights, contact us at build@zanzipos.app. We will respond within 30 days.

Note that some data (ZRA fiscal receipt records) cannot be deleted as it is required to be retained under Tanzanian tax regulations.

10. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will always reflect the most recent version. Continued use of ZanziPOS after changes are posted constitutes acceptance of the revised policy.

Questions about your data?

We are based in Zanzibar and happy to answer any questions about how we handle your information.

Email: build@zanzipos.app

Address: Fumba Town, Shehia ya Nyamanzi, Zanzibar, Tanzania