Legal
Privacy policy
Last updated: August 12, 2026
1. Who we are
Zakazano ("we", "us", or "our") provides scheduling and messaging software for service businesses such as salons, spas, and studios. Our marketing site is available at zakazano.app and legenwaitforit.dev. Merchant workspaces run on subdomains of legenwaitforit.dev.
This Privacy Policy explains what personal data we process when you visit our websites, create a merchant Account, use the Merchant App, or connect messaging channels such as Instagram.
2. Scope
This policy covers data we process as a controller for our own websites, Account registration, billing-related contact details, and product analytics we run. When a merchant uses Zakazano to store client or conversation data, we process that data as a processor on the merchant’s instructions, except where we must process it to secure or operate the platform.
3. Information we collect
Account and profile data: name, email address, password (stored hashed), business name, subdomain/slug, locale, and optional business profile details (address, phone, social links).
Staff and access data: staff member profiles, roles, invite status, and Inbox access grants.
Client and appointment data that merchants enter or generate: client contact details, notes, appointment history, service snapshots, and related operational records.
Instagram and Meta messaging data when a merchant connects an Instagram professional account: Instagram-scoped user and account identifiers, usernames/display names, granted permissions/scopes, encrypted access tokens, connection health, and message content (inbound customer messages and outbound echoes) delivered through Meta webhooks for the shared Inbox.
Scheduling Assistant settings on the Account, including the timestamp of the AI processing acknowledgment when an Owner accepts AI processing of messages for scheduling.
Technical data: IP address, browser/user agent, timestamps, security logs, and cookies or similar technologies needed for authentication and session management.
4. How we use personal data
To create and secure Accounts, authenticate users, and operate the Merchant App (calendar, catalog, team, clients, Inbox, and settings).
To send transactional email such as invites, verification, and appointment-related notices when configured.
To connect and operate Instagram messaging for merchants who authorize Business Login for Instagram, including receiving webhooks, showing conversations in the Inbox, and sending replies the merchant chooses to send through Zakazano.
When the Scheduling Assistant is enabled and an AI processing acknowledgment exists on the Account: to understand scheduling requests, prepare replies, and propose or change appointments through service and availability tools.
To maintain security, prevent abuse, debug incidents, and comply with law.
We do not sell personal data. We do not use Instagram message content for advertising.
5. Meta / Instagram platform data
If you connect Instagram, Meta provides us with data according to the permissions you grant (for example instagram_business_basic and instagram_business_manage_messages). We use that data to provide the Inbox, related messaging features, and, when enabled, the Scheduling Assistant for your Account.
You can disconnect Instagram in Zakazano settings. Disconnecting stops new webhook processing for that channel; historical Inbox records may remain until you or we delete them under this policy.
Meta’s own processing is governed by Meta’s terms and privacy policy. Zakazano is not responsible for Meta’s independent processing.
6. Retention
We retain Inbox Messages and Conversation records for up to 24 months from receipt, unless a longer period is required by law or while a verified deletion request is pending.
We retain cached attachments (for example temporarily stored channel media) for up to 90 days, after which they are deleted or made inaccessible.
We retain Account and operational data for as long as the Account remains active and for a reasonable period afterward for backups, dispute resolution, and legal compliance. Instagram tokens are stored encrypted and are removed or invalidated when you disconnect or when tokens expire.
7. Deletion requests
To request deletion of customer personal data, use the form at /en/deletion-request (enter the business subdomain and email). We email a verification code when there is a match — without revealing whether data exists before verification. For merchant Account deletion, still email privacy@zakazano.app with the subject line “Deletion request”.
Merchants can archive or delete much of their client and channel data inside the product. End-customer requests should go to the merchant first; we assist when we act as processor.
8. Your rights
Depending on applicable law, you may have rights to access, correct, delete, or export personal data, and to object to or restrict certain processing. For privacy requests, email privacy@zakazano.app.
9. Sharing
We share data with infrastructure and service providers that help us run Zakazano (for example hosting, databases, email delivery, and error monitoring), under agreements that limit their use of the data.
We share messaging-related data with Meta as needed to authenticate, receive, and send Instagram messages you initiate or authorize.
When the Scheduling Assistant is enabled and an AI processing acknowledgment exists, Channel Message content and necessary conversation context may be sent to our model provider (currently Vertex Gemini in the europe-west1 region) solely for scheduling.
We may disclose data if required by law or to protect the rights, safety, and security of users and the service.
10. Cookies and similar technologies
We use essential cookies and local storage for sign-in sessions, CSRF/security, and basic product operation.
With your consent, PostHog Cloud EU may use cookies or similar identifiers for product analytics and, if you accept it, optional session replay on the marketing site. You can reject analytics or accept analytics without session replay.
We do not use third-party advertising cookies on the Merchant App.
11. Security
We use industry-standard measures including encrypted transport (HTTPS), encrypted storage of channel credentials, access controls, and least-privilege production access. No method of transmission or storage is completely secure.
12. Scheduling Assistant and AI processing
An Owner may enable the Scheduling Assistant (default Assistant display name Guzonja) to reply to scheduling-related messages on connected channels.
Before enablement, the Owner must record an AI processing acknowledgment on the Account: acceptance that customer Channel Messages may be processed by the Scheduling Assistant and its model provider (currently Vertex Gemini) for scheduling.
AI processing is used to understand requests, prepare replies, and use tools for services, availability, and appointments. Existing retention and deletion rules still apply. Disabling the assistant stops new automated AI replies; historical Inbox records remain under the same retention rules.
The AI processing acknowledgment is an Owner Account record. It is not a customer opt-in record and not a Staff Inbox permission.
13. Children
Zakazano is directed at businesses and adults. We do not knowingly collect personal data from children.
14. Changes
We may update this Privacy Policy from time to time. We will change the “Last updated” date above and, when changes are material, provide additional notice in the product or by email when appropriate.
15. Contact
Questions about privacy or this policy: privacy@zakazano.app.
This policy is provided for product and platform compliance (including Meta app Live settings). It is not a substitute for legal advice.