Back to Zziffy

Legal

Security at Zziffy

Last updated: 30 May 2026

Your business runs on Zziffy. We take that responsibility seriously. This page describes how we protect your data and what to do if you find a security issue.

1. Data residency

Zziffy's databases run on India-region infrastructure. Backups are encrypted and stored in the same region.

2. Encryption

  • In transit: all traffic between your browser, the staff PWA, and our API is encrypted using TLS 1.2+ (HTTPS).
  • At rest: the database, file storage, and backups are encrypted at rest using industry-standard AES-256.
  • Passwords: stored as one-way bcrypt hashes. We cannot read your password — even with database access.

3. Access control

  • Tenant isolation: every database query is scoped to your tenant. No cross-tenant data access is possible by design.
  • Role-based access within a tenant: owners see everything for their business; managers see only their assigned outlets; employees see only their own data.
  • Staff access: a small, vetted group of authorised Zziffy staff can access your data when needed for support — these accesses are logged in an audit trail.
  • JWT-based authentication with short-lived access tokens and rotated refresh tokens.

4. Selfies and location

Selfies and GPS pings captured at clock-in are scoped to your business — only the owner (you) and the employee themselves can see them. They are stored in the same encrypted-at-rest storage as the rest of your data, and retained for 12 months from the date of capture.

5. Payment data

Zziffy does not store credit card numbers, debit card numbers, or bank account numbers used for payments. All payment processing is handled by Razorpay (PCI-DSS Level 1 certified). We store only the Razorpay payment identifier and the amount.

6. Vendor security

We use a small set of named vendors, each contractually bound to process data only on our instructions: Supabase (database + storage), Railway (API hosting), Cloudflare (web hosting and DNS), Razorpay (payments), Anthropic (AI assistant), Google Fonts. Vendor list is updated as the architecture evolves; the current list is also in our Privacy Policy.

7. Breach notification

If we detect a personal data breach, we will notify affected users by email and the Data Protection Board of India as required by the Digital Personal Data Protection Act, 2023.

8. Responsible disclosure

If you find a security issue, please email [email protected] with the subject line "Security Disclosure" and a description of the issue. We acknowledge within 2 working days and aim to fix critical issues within 7 working days. We will publicly credit researchers who report valid issues, with their permission.

9. Updates

Material changes to our security posture will be reflected here with the "Last updated" date.