Legal document

Zaply.me Privacy Policy

Last updated: 29 September 2026

Introduction

Zaply.me is a browser service: a shop collects short customer video reviews, receives an edit with captions, and can send a discount code. The shop uses an account. The end customer opens an individual link and does not create a Zaply account.

This policy explains which data Piotr Feder processes as a controller and when he acts only as a processor. Using the site is not consent and is not a legal basis for processing. We will announce a material change to this policy on the site or through another usual channel.

Controller

Controller:
Piotr Feder, a sole trader operating as piotrfeder.pl and the Zaply.me service.
Address:
ul. Sowińskiego 13/9, 96-300 Żyrardów, Poland
Tax ID (NIP):
8381776640
Privacy and GDPR:
rodo@zaply.me
Service contact:
contact@zaply.me

Who is the controller

For an end-customer recording and for order data received from the shop, the shop is the controller. Piotr Feder is then the processor. The entrustment rules, the data categories and the subprocessors are in § 14 of the Terms (the Data Processing Agreement). The end customer receives the notice on the recording page. This policy does not replace that agreement.

Piotr Feder is the controller for the shop account, the billing profile stored in the application, the contact form, and cookies and analytics on zaply.me. Tpay and Paddle are separate controllers for the payment data they handle.

Data Processing Agreement in the Terms

Purpose and legal basis

  • Contract (GDPR Article 6(1)(b)): registration, login, the account, settings, generation packs and providing the service to the shop.
  • Legal obligation (GDPR Article 6(1)(c)): accounting and tax duties where the service provider issues the sales document (Tpay payments for Poland).
  • Consent (GDPR Article 6(1)(a)): Google analytics cookies if the user clicks “Accept analytics”. There is no separate Zaply marketing consent and we do not use advertising cookies.
  • Legitimate interest (GDPR Article 6(1)(f)): service security, abuse prevention, error diagnostics and replying to a contact-form message.

Using the service does not mean acceptance of this policy and is not a legal basis for processing.

What data we process

As controller we process data you provide or that arises when you use zaply.me:

  • account — email address, password hash, company name, settings and shop-integration data,
  • billing — billing-profile data (name, tax ID, address, email) and the payment identifier,
  • contact form — name, email address and message, encrypted in the database,
  • the site — session and language cookies, the banner choice, and, only after analytics is accepted, Google Analytics data.

An end-customer recording (image, voice, transcript, captions, usage scope and, for Shopify and Shoper, an encrypted email address and first name kept only until the discount code is sent) is created on the shop's instruction. Those data are described in the Data Processing Agreement, not as Zaply's own purposes.

Special categories of data: the service does not ask for GDPR Article 9 data and does not collect it on purpose. The shop should not ask for it. A statement in a recording may nevertheless contain a name, an address or health information, in particular for cosmetics and services. The transcription, captions and quality analysis are then ordinary text in the recording record; the email address is encrypted, not that text. If such information appears, the shop, as controller, should delete the recording.

How long we keep data

The period depends on the data. There is no single period for the whole account.

  • The account, company settings and the billing profile in the application are kept for the life of the account. After a deletion request in the dashboard, sign-in is disabled and deletion runs on the 31st calendar day in the Europe/Warsaw time zone. The request day counts as day 1. A later request does not move that date. Deletion removes the account, the company, recordings, the billing profile stored in the application, the recording files in Cloudflare R2, and the linked Shopify and Shoper shop rows.
  • Transaction data stay with Tpay or Paddle under those providers' rules. Where the service provider issues the sales document, accounting rules may require that document to be kept for five years from the end of the calendar year in which it was issued. The billing profile in the application is not kept after account deletion for that purpose.
  • The contact-form record is deleted from the database automatically on the 12-month anniversary of the Europe/Warsaw calendar day it was saved. That day starts the period. You can ask for earlier erasure at rodo@zaply.me.

Your rights

Where Piotr Feder is the controller, you can request access, rectification, erasure, restriction and portability, and you can object to processing based on legitimate interest. For end-customer data, send the request to the shop. If it reaches us and the shop can be identified, we pass it on to the shop.

  1. the right of access,
  2. the right to rectification,
  3. the right to erasure,
  4. the right to restriction of processing,
  5. the right to data portability,
  6. the right to object,
  7. the right to withdraw consent, without affecting the lawfulness of processing before withdrawal.

Withdrawal of consent

You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before the withdrawal.

Withdraw analytics consent in the cookie settings. The banner opens again and you can reject analytics. Send other requests to rodo@zaply.me.

Privacy contact: rodo@zaply.me

Security

We use measures appropriate to the risk: encryption in transit, encryption of selected database fields (AES-256-GCM), access control, input validation, abuse limits and error monitoring.

  • encryption in transit (SSL/TLS),
  • encryption of selected database fields (AES-256-GCM),
  • access control and authentication,
  • abuse limits,
  • error and security monitoring.

Recipients

We use the following providers to run the service. For end-customer data they act as the shop's subprocessors. For the account, billing, the contact form and analytics they act for the zaply.me controller.

  • DigitalOcean — hosting of the zaply.me application (frontend, backend, nginx) and Redis on the same server. Queue data are transient.
  • PostgreSQL database provider — application records. The database is not a Supabase service.
  • Cloudflare R2 — video files and account assets.
  • OpenAI — speech transcription (the audio recording is sent), content moderation and quality analysis (the transcript text is sent), when montage runs. The video file is not sent. According to OpenAI's documentation, API data are not used to train models unless that option is turned on; Zaply does not turn it on. Transcription and moderation are not, according to that documentation, retained for abuse monitoring. Quality-analysis text may be stored for up to 30 days for that purpose. Shorter retention requires a separate approval from OpenAI and does not follow from the service settings.
  • Postmark — the recording invitation and the discount code when Zaply sends those messages, in particular for Shopify. With WooCommerce the shop sends the message to the customer.
  • SMTP mail provider — account messages (registration, password reset) and the contact-form notification.
  • Amazon Web Services, region eu-central-1 — video-montage compute, when that variant is used.
  • Meta Platforms — only when the shop instructs publication of a recording to Facebook Reels or Instagram Reels. There is no Meta Pixel on zaply.me.
  • Google — Google Analytics, only after analytics is accepted. Advertising storage stays off.
  • Tpay and Paddle — payments, as separate controllers of the payment data. On the Tpay path the service provider issues the sales document. On the Paddle path Paddle issues the document to the buyer.

Data are processed mainly in the European Economic Area. OpenAI, Postmark, Cloudflare and Google may use infrastructure outside the EEA. We then use the mechanisms the GDPR requires, including standard contractual clauses where they are needed.

Cookies

The banner offers two choices: accept analytics or reject it. There is no separate choice for advertising cookies. After a choice the banner hides. You can open it again with “Cookie settings” in the footer, in the dashboard, or on this page.

  • Necessary cookies — the signed-in session: token (httpOnly, about 15 minutes) and refresh_token (httpOnly, 7 days).
  • Language cookie — zaply_locale, remembers the site language for one year.
  • Banner choice — stored in localStorage under cookie-consent. It is not an advertising cookie.
  • Analytics cookies — Google Analytics, only after “Accept analytics”. The gtag.js script is not loaded before that consent.

Google Analytics

After acceptance the browser loads the Google Analytics script and sends a page view. Without acceptance that script is not loaded.

Advertising storage (ad_storage, ad_user_data and ad_personalization) stays off even after analytics is accepted.

We do not mask the IP address in our own code before the browser contacts Google. After consent the browser connects to Google, and Google's policy describes what happens next.

Rejection, or a later withdrawal, turns analytics off. If Google cookies were already stored, the site tries to delete them.

Google's policy: policies.google.com/privacy.

You can also install the browser add-on from tools.google.com/dlpage/gaoptout.

Google may process analytics data outside the EEA, under the rules in its own policy.

Change the analytics setting with the button below or with “Cookie settings” in the footer. Browser settings can also delete cookies on your side.

Right to lodge a complaint

You may lodge a complaint with the President of the Personal Data Protection Office if you believe the processing breaches the GDPR.

Personal Data Protection Office: ul. Stawki 2 00-193 Warsaw, Poland phone: +48 22 531 03 00 email: kancelaria@uodo.gov.pl

Contact

For privacy, security and your rights, write to the controller at the privacy address. Service matters use a separate address.

Privacy: rodo@zaply.me

Service: contact@zaply.me

Changes to this policy

We will update the policy when the service, the providers, the law or the processing changes. We will announce a material change on the site or through another usual channel.

← Back to home