Privacy Policy
Last updated: pending review
This document is being finalized and is pending legal review. It accurately describes Zoulna's current practices but may be updated before launch.
Introduction
This Privacy Policy explains how Zoulna ("Zoulna", "we", "us", or "our") collects, uses, shares, and protects your personal information when you use the Zoulna platform — our mobile applications, websites, and related services (together, the "Service"). Zoulna is a food-delivery marketplace based in and serving Sudan, connecting customers, restaurants (merchants), and delivery riders.
Zoulna is governed by the laws of Sudan. Sudan does not currently have a comprehensive data-protection statute in force. In the absence of such a statute, Zoulna voluntarily commits to handling personal data in good faith and in line with widely recognized international data-protection best practices, including the principles of lawfulness, purpose limitation, data minimization, security, and respect for your rights as described in this Policy.
By using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with it, please do not use the Service.
Information We Collect
We collect only the information we need to operate the Service. Depending on whether you are a customer, a rider, or a merchant, this may include:
Account information (all users)
- Phone number (required — this is your unique primary identifier on Zoulna)
- Email address (optional)
- Name
- Password (stored only as a secure cryptographic hash; we never store your password in plain text)
- Your role (customer, rider, or merchant)
- Profile picture / avatar (optional)
Customer information
- Delivery addresses, including the street address and GPS coordinates (latitude and longitude) of the location
- Order history
- Favorite restaurants and items
- Reviews and ratings you submit
Rider information
- Identity-verification (KYC) documents: a photo of the front of your ID card, a photo of the back of your ID card, a selfie, and a photo of your vehicle
- Live GPS location (current latitude and longitude) while you are online and available to take deliveries
- Vehicle type and license-plate number
- Cash-settlement and earnings records
Merchant information
- Business and restaurant details
- Menu data
- Business-verification documents
Order information (for everyone involved in an order)
- Items ordered and amounts
- Delivery address
- Payment method. Zoulna currently supports cash, in-app wallet, and online payments through the Bravo payment provider. Card payments are planned but not yet active.
- Order status history
Technical information
- Device push-notification tokens (via Firebase Cloud Messaging) so we can send you notifications
- IP address and browser/device user-agent, captured in our security and audit logs
- App usage and error/diagnostic data
Marketing-website leads
If you contact us through our marketing website rather than as a registered user, we collect what you provide on the relevant form, together with the campaign information described under "Cookies and Marketing Measurement" below:
- Restaurant-partner application: restaurant name, contact person, phone number, city, and email
- Rider application: full name, phone number, city, vehicle type, and (optionally) email
- Contact-form message: name, email, and your message
- Customer waitlist: phone number, city, and (optionally) email
Phone verification
When you sign up, we send a one-time verification code (OTP) to your phone number via WhatsApp (operated by Meta) to confirm that the number belongs to you.
Cookies and Marketing Measurement
Our marketing website (zoulna.com) uses a small number of first-party cookies so that we can tell which of our advertisements and campaigns actually bring people to Zoulna. We do not use third-party advertising cookies, and we do not sell this information or share it with advertising networks.
The cookies we set
- z_id — a randomly generated visitor identifier that contains no personal information. Stored for up to two years.
- z_ft — the campaign details of your first visit, recorded once. Stored for up to two years.
- z_lt — the campaign details of your most recent visit. Stored for 30 days. That 30-day lifetime is also the window in which a visit can be credited to a campaign: once the cookie expires, the campaign is no longer credited.
All three are first-party cookies, set only on our own domain. They are marked HttpOnly (scripts running in your browser cannot read them) and SameSite=Lax, and no other website can read them.
What those cookies contain
- The campaign, creative, source, medium, content and term identifiers carried by the link you arrived on (for example utm_source, utm_campaign)
- Advertising click identifiers added by the advertising platform itself, where present (fbclid from Meta, ttclid from TikTok, gclid from Google)
- The path of the page you landed on, without its query string
- The host name of the site that referred you (for example instagram.com) — never the full referring address
- The time of the visit
They never contain your name, phone number, email address, or anything else you type into a form.
Short campaign links
Some of our advertisements and printed materials use short links of the form zoulna.com/go/.... When one is opened we record which link it was, the campaign it belongs to, the anonymous visitor identifier above, the broad family of browser used (for example "Chrome on Android"), the referring site's host name, and a salted, irreversible hash of your IP address. We do not store the IP address itself, and the salt changes every day, so the hash cannot be used to follow you from one day to the next.
If you submit a form
If you go on to submit one of our forms, the campaign details described above — together with the anonymous visitor identifier — are stored alongside your submission, so that we can tell which campaign led to it. The IP address hash is not attached to your form submission.
Visit measurement
Our website uses Vercel Web Analytics, provided by Vercel Inc., to produce aggregate page-view statistics. It does not set cookies and does not build a profile of you across websites.
Your choices
You can delete these cookies at any time from your browser settings, and you can block them entirely. Deleting or blocking them does not affect your ability to use the website or to submit any form. Zoulna's mobile apps and the signed-in Service do not use these marketing cookies.
How We Use Your Information
We use your information to:
- Operate the marketplace — place, dispatch, and deliver orders between customers, merchants, and riders
- Verify identity — confirm your phone number through the WhatsApp OTP, and verify riders and merchants through KYC documents
- Process payments — handle cash and wallet settlements and keep accurate earnings records
- Communicate with you — send order updates, account notifications, and service messages
- Provide support — respond to your questions and resolve issues
- Keep the Service secure — prevent fraud and abuse, enforce our terms, and maintain security and audit logs
- Improve the Service — understand how the Service is used and diagnose and fix errors
Data Retention
We keep personal data only for as long as we need it to provide the Service and to meet our legal and operational obligations. After that, we delete it or anonymize it.
In particular:
- Security and audit logs (including IP address and user-agent) are retained for approximately 365 days by default.
- Notifications are pruned automatically on a regular schedule.
- Marketing attribution cookies are stored on your device for 30 days (z_lt) or up to two years (z_id and z_ft), and you can delete them at any time from your browser.
- Campaign click records (short-link opens, including the daily IP address hash) are kept for campaign reporting and are then deleted or reduced to aggregate statistics.
- Accounts support soft-deletion: when an account is deleted, it is marked as deleted and removed from active use, and is then deleted or anonymized in line with our retention practices and any legal requirements.
Security
We take reasonable technical and organizational measures to protect your information, including:
- Passwords are stored only as secure cryptographic hashes (bcrypt) — never in plain text
- Sessions are managed using signed access tokens (JWT)
- Rate limiting to defend against abuse and brute-force attempts
- Role-based access controls limiting who can access what data
- KYC and verification documents are kept in private storage and are accessible only through signed, time-limited URLs
No method of transmission or storage is completely secure, but we work continuously to protect your information and to respond promptly to any incident.
Your Rights
You can ask us to:
- Access the personal data we hold about you
- Correct data that is inaccurate or out of date
- Delete your data
- Withdraw consent you have previously given
- Object or complain about how we handle your data
To exercise any of these rights, contact us through our WhatsApp support line (see "Contact Us" below). We may need to verify your identity before acting on a request.
Children
The Service is not directed to children under the age of 18, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, please contact us so we can remove it.
Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we do, we will revise the "Last updated" date at the top of this Policy and, where appropriate, notify you through the Service. Your continued use of the Service after an update means you accept the revised Policy.
Contact Us
If you have any questions about this Policy or wish to exercise your rights, you can reach us through our WhatsApp support line:
- WhatsApp: https://wa.me/393756199164