Privacy Policy
Last updated: July 29, 2026
Zigsa ("we", "our", or "us") operates the Zigsa business management platform, including waitlist, booking, customer management, communications and related services (the "Service"), available at zigsa.app and related domains. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our Service.
1. Information We Collect
- Account Information: Name, email address, phone number, and password when you create an account.
- Business Data: Information you enter to operate your business on the Service, such as locations, services, staff, schedules and appointments.
- End-Customer Data: Information that businesses using the Service store about their own customers (for example names, contact details, appointment history and, for businesses in regulated verticals such as healthcare, records those businesses choose to keep). Each business is responsible for the data it stores and for obtaining any consents required from its customers. Zigsa processes this data solely to provide the Service to that business.
- Payment Information: Payments are processed by Stripe. We do not store full card numbers on our servers.
- Usage Data: Log and device information such as IP address, browser type, pages visited and actions taken, used to operate and secure the Service.
2. How We Use Information
- To provide, operate, maintain and improve the Service.
- To send service notifications (for example appointment confirmations, reminders and staff alerts) through the channels the business configures.
- To process subscriptions and payments.
- To provide support and communicate with you about the Service.
- To protect the security and integrity of the Service.
We do not sell personal information, and we do not use it for third-party advertising.
3. Google User Data
If you choose to connect a Google account (for example to sync appointments to Google Calendar, create Google Meet links, or sign in with Google), the Service accesses the following Google user data with your explicit consent:
- Google Calendar (calendar, calendar.events): used exclusively to create, update and delete calendar events that correspond to appointments managed in the Service, and to attach Google Meet links to those events when enabled.
- Basic profile (email, profile): used to identify the connected Google account and display which account is linked.
How we handle this data:
- OAuth tokens are stored encrypted and are used only to perform the actions described above on your behalf.
- We do not read, store or analyze calendar events that were not created by the Service.
- Google user data is never sold, never used for advertising, and never shared with third parties, except as necessary to provide the features you enabled or as required by law.
- You can disconnect Google at any time from the integrations page in the Service, and additionally revoke access at myaccount.google.com/permissions. Upon disconnection, stored tokens are deactivated.
Limited Use disclosure: Zigsa's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. Sharing of Information
We share information only with service providers that are necessary to operate the Service (such as hosting, storage, email/SMS/WhatsApp delivery, payment processing and video calling providers), under agreements that limit their use of the data; or when required by law.
5. Data Retention
We retain data for as long as the account that owns it remains active or as needed to provide the Service. Businesses can delete their data from within the Service; upon verified request to the contact below we will delete account data, subject to legal retention obligations.
6. Security
We use administrative, technical and physical safeguards appropriate to the nature of the data, including encryption in transit (HTTPS), encrypted storage of credentials and tokens, access controls and audit logging. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. Children's Privacy
The Service is intended for businesses and their staff and is not directed to children under 13. We do not knowingly collect personal information from children.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and update the "Last updated" date above.
9. Contact
If you have questions about this Privacy Policy or want to exercise your data rights, contact us at info@zigsa.com.