This Privacy Policy explains how Daryl van Sittert, trading as Zumino (a sole proprietorship, South Africa) ("Zumino", "we", "us") collects, uses, stores, and protects personal information when you use the Zumino platform (the "Service"). We are the "responsible party" for this processing under the Protection of Personal Information Act 4 of 2013 ("POPIA").
Information Officer: Daryl van Sittert, reachable at [email protected] (marked for the attention of the Information Officer), or by post at PO Box 327, Ilala Drive, Durban, 4021, South Africa.
1. Information we collect
Account information
When you sign in with Google we receive your name, email address, and profile picture, together with a unique identifier. We do not receive or store your Google password.
Content and project data
- The projects and websites you create, including source files, chat messages exchanged with the AI assistant, previews, and published output.
- Deployment and publishing history for your projects.
Billing information
- Your subscription plan, order and payment history, and AI-token usage.
- Payments are processed by Paystack; we never see or store your full card number. Paystack shares with us a customer reference, payment status, and card metadata (such as brand and last four digits) needed to manage your subscription. See Paystack's privacy policy for their processing.
Usage and technical information
- Logs of actions taken in the Service (an audit trail of activity such as sign-ins, project changes, and publishes) for security and support.
- Technical data such as IP address, browser type, and device information, collected when you use the Service.
- Operational telemetry (performance metrics, error traces) used to keep the Service reliable.
Moderation data
When you publish a site, its content is automatically reviewed for compliance with our Acceptable Use Policy. Review outcomes and related metadata are recorded for safety, audit, and legal purposes.
2. How we use your information
We process personal information to:
- Provide the Service: authenticate you, run editing sessions, store projects, build and host your sites.
- Operate AI features: your prompts and project content are sent to our AI model providers to generate responses. They are used to provide the feature, not sold.
- Process payments and manage subscriptions via Paystack.
- Moderate content for safety and legal compliance.
- Secure the Service: detect and prevent abuse, fraud, and unauthorised access.
- Communicate with you about the Service (service notices, billing, support).
- Comply with legal obligations.
Our legal bases under POPIA are: performance of our contract with you, compliance with legal obligations, your consent where required, and our legitimate interests in operating and protecting the Service.
3. Sharing and third-party processors
We do not sell personal information. We share it only with service providers ("operators" under POPIA) that help us run the Service, under appropriate safeguards:
| Provider | Purpose |
|---|---|
| Sign-in (OAuth) | |
| GitHub | Storage of project repositories; build and deployment automation; AI model access (GitHub Copilot) |
| Paystack | Payment processing and subscription billing |
| Cloudflare | Content delivery, DNS, and routing of published sites |
| Grafana Cloud | Operational telemetry (application logs, metrics, and traces), which may include user, project, and session identifiers |
| Hetzner | Server and database hosting |
We may also disclose information where required by law, to protect our rights or users' safety, or as part of a business transfer (with notice).
Some providers process data outside South Africa. Where personal information is transferred across borders we do so in accordance with POPIA section 72, relying on the recipient being subject to laws or binding agreements providing an adequate level of protection.
4. Published sites
Websites you publish are public. Anything you include in a published site — including any personal information — is visible to anyone on the internet. Visitors to your published sites are your responsibility; if you collect personal information from visitors you are the responsible party for that collection.
5. Retention
- Account, project, and billing data are kept for as long as your account is active.
- When you delete your account, your subscriptions are cancelled, your account is deactivated and can no longer be accessed, and your published sites are taken offline. Your account and project data are then retained in an archived state for a limited period before being permanently deleted or de-identified — within 90 days of deletion — except records we must keep for legal, accounting, audit, or fraud-prevention purposes (kept only as long as required).
- Audit and moderation records are retained for 12 months for security and legal purposes.
6. Security
We take reasonable technical and organisational measures to protect personal information, including encrypted transport (HTTPS), authenticated and authorisation-scoped access to data, sandboxed and isolated editing environments, and audit logging. No system is perfectly secure; if we become aware of a breach affecting your personal information we will notify you and the Information Regulator as required by POPIA.
7. Your rights
Under POPIA you may:
- Request access to the personal information we hold about you.
- Request correction or deletion of your personal information.
- Object to processing, or withdraw consent where processing is based on consent.
- Delete your account (available directly in the app).
- Lodge a complaint with the Information Regulator (South Africa): https://inforegulator.org.za, [email protected].
To exercise these rights, contact us via Contact Details. We may need to verify your identity before acting on a request.
8. Cookies and similar technologies
We use strictly necessary cookies to keep you signed in (an HttpOnly authentication cookie) and short-lived cookies to secure preview access to your in-progress sites. We do not use third-party advertising cookies. We use Cloudflare Web Analytics to understand aggregate site usage; it is privacy-friendly and does not set any cookies or track you across other sites.
9. Children
The Service is not directed at children and may not be used by anyone under 18. We do not knowingly collect personal information from children; if you believe a child has provided us personal information, contact us and we will delete it.
10. Changes to this policy
We may update this policy from time to time. For material changes we will give notice (for example by email or in-app notice) before the change takes effect. The "Last updated" date above reflects the current version.
11. Contact
Privacy questions and POPIA requests: see Contact Details, marked for the attention of the Information Officer.