Zaply
Privacy Policy
Last updated 7 August 2026
Zaply is a platform for building cash-on-delivery online stores in Algeria. Two different groups of people appear in this policy: merchants, who create an account and run a store, and their customers, who place orders on a merchant's storefront. What we hold about each is different, and so is who controls it.
Who controls what
For merchant accounts, Zaply is the data controller. For the order data a customer submits on a storefront, the merchant is the controller and Zaply is a processor acting on their instructions — we store and display it so they can fulfil the order, and we do not sell it, rent it, or use it to build profiles.
What we collect from merchants
| What | Why |
|---|---|
| Email address and name | Signing in, and contacting you about your account. |
| Store content | Products, prices, images, landing pages and delivery rates you create. |
| Integration credentials | Access tokens for delivery carriers and, if you connect one, your Meta ad account. Stored encrypted at rest and never shown to anyone but the store owner. |
| Usage records | Which features were used and when, so we can operate and support the service. |
What we collect from customers who place an order
This information is entered by the customer on a merchant's storefront, or recorded automatically at checkout.
| What | Why |
|---|---|
| Name, phone number, wilaya, commune, address | Required to confirm the order by phone and deliver the parcel. |
| Order contents and totals | The order itself, and the merchant's record of the sale. |
| IP address and country | Fraud and spam prevention. A merchant can block an address that is abusing their store. |
| Browser user-agent | Distinguishes a real checkout from an automated submission. |
| Advertising identifiers in the link | If the customer arrived from an ad, the ad's identifiers are recorded so the merchant can see which ad produced the order. These identify the ad, not the person. |
A customer who wants their order data corrected or removed should contact the merchant they ordered from, since it is their record. If that is not possible, write to us at the address below and we will pass the request on or act on it directly.
Advertising and analytics on storefronts
A merchant can connect a Meta (Facebook/Instagram) or TikTok pixel to their store. When they do, those platforms receive events about page views and completed orders, including a hashed phone number and name, plus the IP address and user-agent, so the platform can measure its own advertising. Hashing is one-way — the platform cannot read the original values from it. If a merchant has connected no pixel, nothing is sent.
Merchants may also connect their Meta ad account so Zaply can read advertising performance. In that case we request ads_read and nothing more: we can read spend and results, and we cannot create, change or stop ads, or post anything. We store the access token, the ad account's id, and a cache of spend figures and ad thumbnails. See data deletion for how to disconnect it.
Who else processes this data
We use a small number of providers to run the service. They process data on our behalf, under their own security commitments.
- Supabase — database, authentication and file storage.
- Vercel — hosting and content delivery.
- Delivery carriers (Yalidine, ZR Express, Ecotrack, Noest, Maystro and similar) — only the order details needed to ship a parcel, and only for orders a merchant chooses to dispatch.
- Meta and TikTok — only where a merchant has connected a pixel or an ad account, as described above.
- AI providers — text and images a merchant asks Zaply to generate for their own store. Customer order data is never sent.
How long we keep it
Merchant accounts and store content are kept while the account is open. Orders are kept as the merchant's business record, since they are needed for delivery, returns and accounting. Deleting a store deletes its products, landing pages, orders and connected credentials.
Security
Access is enforced in the database itself, not only in the application: a merchant can only read rows belonging to their own store, and integration tokens are readable only by the store owner — not by team members they invite. Traffic is encrypted in transit.
No system is perfect. If you believe you have found a vulnerability, please write to us before disclosing it publicly.
Your rights
You can ask for a copy of the data we hold about you, ask for it to be corrected, or ask for it to be deleted. Merchants can do most of this from the dashboard directly; anything else, write to us and we will respond.
Changes
If this policy changes materially, we will update the date at the top of this page and notify merchants in the dashboard.
Contact
Questions about this policy, or any request about your data: haydaaymen@gmail.com.