Legal
Security at Zziffy
Last updated: 30 May 2026
Your business runs on Zziffy. We take that responsibility seriously. This page describes how we protect your data and what to do if you find a security issue.
1. Data residency
Zziffy's databases run on India-region infrastructure. Backups are encrypted and stored in the same region.
2. Encryption
- In transit: all traffic between your browser, the staff PWA, and our API is encrypted using TLS 1.2+ (HTTPS).
- At rest: the database, file storage, and backups are encrypted at rest using industry-standard AES-256.
- Passwords: stored as one-way bcrypt hashes. We cannot read your password — even with database access.
3. Access control
- Tenant isolation: every database query is scoped to your tenant. No cross-tenant data access is possible by design.
- Role-based access within a tenant: owners see everything for their business; managers see only their assigned outlets; employees see only their own data.
- Staff access: a small, vetted group of authorised Zziffy staff can access your data when needed for support — these accesses are logged in an audit trail.
- JWT-based authentication with short-lived access tokens and rotated refresh tokens.
4. Selfies and location
Selfies and GPS pings captured at clock-in are scoped to your business — only the owner (you) and the employee themselves can see them. They are stored in the same encrypted-at-rest storage as the rest of your data, and retained for 12 months from the date of capture.
5. Payment data
Zziffy does not store credit card numbers, debit card numbers, or bank account numbers used for payments. All payment processing is handled by Razorpay (PCI-DSS Level 1 certified). We store only the Razorpay payment identifier and the amount.
6. Vendor security
We use a small set of named vendors, each contractually bound to process data only on our instructions: Supabase (database + storage), Railway (API hosting), Cloudflare (web hosting and DNS), Razorpay (payments), Anthropic (AI assistant), Google Fonts. Vendor list is updated as the architecture evolves; the current list is also in our Privacy Policy.
7. Breach notification
If we detect a personal data breach, we will notify affected users by email and the Data Protection Board of India as required by the Digital Personal Data Protection Act, 2023.
8. Responsible disclosure
If you find a security issue, please email [email protected] with the subject line "Security Disclosure" and a description of the issue. We acknowledge within 2 working days and aim to fix critical issues within 7 working days. We will publicly credit researchers who report valid issues, with their permission.
9. Updates
Material changes to our security posture will be reflected here with the "Last updated" date.