Version 0.9 · Effective 2026-08-09

Zarkili Privacy Policy

Version 0.9 — 2026-08-09 Last updated: 2026-08-09

By using Zarkili after the effective date of any update to this Policy, you accept the changes described in it. Material changes will be highlighted, and where required by law, re-acceptance will be requested.

1. Who we are

Zarkili is operated by Mogy LLC, a United States entity ("Zarkili," "we," "us," "our"). Mogy LLC is the data controller for the categories of personal data described in Section 3 as belonging to salon owners/admins and to our own platform staff (super admins). For salon clients' personal data, Zarkili acts as a data processor on behalf of the salon, which is the data controller — see Section 6 for a full explanation of this relationship.

EU Representative: Pursuant to Article 27 of the General Data Protection Regulation, Zarkili has appointed Mobendo d.o.o., a company organized in Croatia, as its representative in the European Union for data protection matters. You may contact our EU representative using the contact details in Section 15.


2. The three kinds of people whose data we handle

Zarkili is a multi-tenant platform used by independent nail salons ("Salons") to manage bookings, loyalty programs, and communication with their own clients ("Salon Clients"). Three distinct groups have personal data in our systems, and our role is different for each:

  1. Salon owners/admins — the businesses that subscribe to and pay for Zarkili. We are the data controller for this group's account and billing data.
  2. Salon clients — the people who book appointments with a Salon through the app. The Salon, not Zarkili, decides what to collect about its own clients and why (this is a normal customer-relationship-management function of running their business). Zarkili is the data processor that operates the underlying infrastructure. See Section 6.
  3. Zarkili platform staff (super admins) — our own personnel who operate the administrative console. We are the data controller for this small, internal group.

This Policy describes all three. If you are a Salon Client, your Salon's own privacy practices (which may be described to you separately by the Salon) also apply to how that Salon uses your data; this Policy describes how Zarkili, as the Salon's processor, handles it on the Salon's behalf and the rights you can exercise directly with Zarkili regardless.


3. What data we collect

3.1 Salon owners/admins

Collected at registration or entered later in the admin app:

3.2 Salon clients

If you are a Salon Client, we (on the Salon's instructions, as processor) hold:

3.3 Zarkili platform staff (super admins)

If you are Zarkili operational staff with administrative-console access: your user ID, email, name, role designation, and account creation/last-login timestamps. Every administrative action a super admin takes (creating a salon, suspending one, granting or revoking another super admin's access) is recorded in a permanent, tamper-evident audit log that not even the acting super admin can edit or delete.

3.4 Data we derive automatically


4. How and why we process data

4.1 Purposes

Data Used for
Client profile (name/email/phone/DOB) Identifying you to your Salon; date of birth (if provided) drives an automated birthday-greeting notification.
Booking records Core scheduling: creating, confirming, reminding, rescheduling, cancelling appointments.
Reference photos, gallery images Visual reference for a requested service, or the Salon's own portfolio.
Messages and attachments Direct communication between you and your Salon.
Loyalty data Running the rewards program your Salon has configured: automatic point awards, tier changes, referral and birthday bonuses.
Push token / notification preferences Delivering the notifications you and/or your Salon have enabled (booking updates, reminders, messages, birthday greetings, waitlist openings).
Salon subscription data Determining what features your Salon's account can access, per its billing status with us.
Salon booking/client history (aggregated) Business analytics and reporting, visible only to that Salon's own admin.

4.2 Automated processing — loyalty and analytics

Loyalty engine: points, tier progression, streaks, referral bonuses, and birthday bonuses are awarded automatically by our systems, following rules your Salon configures (e.g., point values, tier thresholds, reward catalog). Every change is recorded permanently in a transaction ledger.

Salon-facing reports: at your Salon admin's request, we compute (on demand, not continuously) business analytics from a Salon's own booking history: revenue and completion statistics, cancellation and lead-time patterns, and client-level classifications, including a "needs attention" flag applied to individual clients who have completed two or more appointments but have no booking of any status in the last 40 days. This is intended as a re-engagement/retention signal for the Salon's own marketing decisions — it does not, by itself, trigger any automated action against you (no automatic suspension, price change, or service denial results from it), and it is visible only to your own Salon's admin, never to Zarkili staff in the ordinary course of operating the platform, and never to any other Salon.

4.3 Legal bases for processing

Purpose Proposed legal basis (GDPR Art. 6)
Salon owner account creation and management Performance of a contract (the Zarkili subscription agreement)
Salon subscription billing Performance of a contract; and our legitimate interest in operating a functioning billing system
Operating the booking/messaging/loyalty service for Salon Clients, on the Salon's behalf Performed at the instruction of, and under the legal basis established by, the Salon as controller (see Section 6) — Zarkili's own basis for acting as processor is the performance of our contract with the Salon
Transactional notifications (booking confirmations, reminders) Performance of a contract / legitimate interest in providing the core service
Loyalty engine and salon-facing analytics Legitimate interest of the Salon (as controller) in operating its own loyalty program and business; performed by Zarkili as processor
Responding to GDPR access/erasure requests Legal obligation
Any future marketing communications from Zarkili itself (none currently exist — see Section 4.4) Not yet applicable

4.4 No Zarkili-run marketing or cross-tenant use

Zarkili does not currently use Salon Client data for its own marketing, does not aggregate data across Salons for any purpose, and does not sell personal data to anyone. Any marketing a Salon sends to its own clients (e.g., promotions) is that Salon's own activity as controller, undertaken through communication features Zarkili provides but does not initiate or control the content of.


5. Third parties and sub-processors

We do not have any analytics, advertising, or crash-reporting SDKs integrated into Zarkili as of this writing. The only outside parties that process personal data on our behalf are:

5.1 Google Cloud Platform / Firebase — infrastructure

Firebase (a Google Cloud product) is our infrastructure provider for: the database (Firestore), authentication (Firebase Authentication — holds your actual login credential), file storage (Cloud Storage — booking photos, message attachments, gallery images, profile photos, and temporary data-export archives), and our server-side application logic (Cloud Functions). See Section 8 for where this infrastructure is physically located.

5.2 Stripe — subscription billing (Salon owners only; no card data reaches us)

Salon subscription payments are handled entirely by Stripe. When a Salon subscribes, we send Stripe only the owner's email, the salon's business name, and an internal salon identifier — nothing else. The card-entry screen itself is Stripe's own hosted page; Zarkili's app has no card-input form anywhere, and payment/billing management (updating a card, viewing invoices, cancelling) also happens on Stripe's own hosted portal. Stripe sends us back only subscription lifecycle information (active/trialing/cancelled status, trial end date, billing period dates) — never card details. Zarkili's servers never receive, transmit, or store raw payment card data.

5.3 Resend — transactional email delivery

Transactional and scheduled emails (booking notifications, reminders, birthday greetings, waitlist alerts, and GDPR data-export download links) are sent through Resend, from a verified mail.zarkili.com sending domain. Resend receives the recipient's email address and the content of that specific email.

5.4 Expo Push Notification Service — push notification delivery

If you enable push notifications, your device's push token, the notification text, and a small structured payload (e.g., a booking reference) are sent to Expo's push delivery service to route the notification to your device.

5.5 No other third parties

No other outside service (no analytics platform, no advertising network, no additional data broker) receives personal data from Zarkili.


6. The Salon/Zarkili relationship for client data (controller/processor)

If you are a Salon Client, it is important to understand who is responsible for what:


7. How we protect your data


8. International data transfers

Production decision: all of Zarkili's production infrastructure — the Firestore database, Cloud Storage file buckets, AND Cloud Functions compute — will be provisioned in Google Cloud's europe-west3 region (Frankfurt, Germany). This means personal data is both stored and processed (not merely stored while being transiently processed elsewhere) within the European Union in production.


9. Your rights and how to exercise them

Right Status today How to exercise it
Access / obtain a copy of your data ✅ Self-service, fully built In the app, go to Profile → "Export My Data." We email you a secure, time-limited (approximately 7-day) download link to an archive containing your data in a readable format together with your uploaded photos and message attachments. Note: if your account has an unusually large number of uploaded files, a single export is capped for technical reasons; in that rare case the archive will include everything up to the cap plus a notice, and you can contact us (Section 15) for anything not included.
Erasure ("delete my account") ✅ Self-service, fully built In the app, go to Profile → "Delete Account" (requires re-entering your password). This clears your personal identifying fields, deletes your uploaded photos and attachments, and disables your login. Certain historical business records your Salon relies on (e.g., that an appointment happened, its price, and its date) are retained but de-identified — your name and contact details are removed from them, but the record itself is not deleted, consistent with standard business record-keeping practice. This is an anonymization of your identifying information, not a guarantee that every trace of your relationship with a Salon is erased.
Correction (rectification) ✅ Partially self-service You can edit your name, phone number, Instagram handle, date of birth, profile photo, language preference, and notification preferences directly in your Profile at any time. Your email address is tied to your login identity and is not currently self-editable in Profile — contact us (Section 15) to correct it or any other field you cannot change yourself.
Restriction of processing ❌ No dedicated in-app mechanism Contact us (Section 15).
Objection to processing ❌ No dedicated in-app mechanism Contact us (Section 15).
Data portability ✅ Partially covered by the export above The same export tool provides your data in a machine-readable format.
Lodge a complaint with a supervisory authority Available as a matter of law, independent of anything Zarkili builds You may contact the data protection authority in your country of residence, place of work, or where an alleged infringement occurred.

10. Data retention

If a defined retention schedule (e.g., "booking records are deleted N years after the appointment") is adopted as a business/legal policy going forward, this section must be updated to reflect it — and the corresponding deletion mechanism would need to be built, since no such mechanism exists in the product today. Until then, this section describes our actual current practice, not a future commitment.


11. Children and minors

Zarkili is not directed to children, and you must be at least 16 years old to create an account or use the Service, whether as a Salon owner/admin or as a Salon Client. This age aligns with the default digital-consent age under Article 8 of the GDPR; some individual EU member states set this age lower, down to 13, and where local law sets a lower age that applies to you, that age controls instead.

If you are a parent or guardian and believe a child under this age has provided us with personal data, contact us (Section 15) and we will take reasonable steps to delete it.


12. Cookies and tracking technologies

Zarkili does not currently use cookies, web analytics, advertising trackers, or any similar tracking technology. We store your language preference locally on your device (not shared with us or any third party for tracking purposes) so the app remembers your chosen language between sessions. If this changes in the future (for example, if analytics are added), this Policy will be updated first, and a consent mechanism will be added if legally required.


13. Automated notifications you cannot fully turn off

Most notifications (booking reminders, messages, birthday greetings, waitlist openings) respect both your Salon's own notification settings and your personal on/off preference toggle. Two narrow categories of transactional notification bypass some or all of these preferences because they relate directly to an action you just took or a status change you are actively waiting on: booking confirmation/rejection/cancellation/reschedule notices always reach you regardless of your Salon's own settings, and a notice that your account has been approved by a Salon reaches you regardless of either setting. These exist to make sure you always learn about the direct outcome of your own booking requests and account status.


14. Changes to this Policy

We may update this Policy from time to time. The "Last updated" date at the top will reflect the most recent revision. For material changes, we will provide notice and, where required by law, request renewed acceptance before the change takes effect.

15. Contact us

For any question about this Policy, or to exercise a right described in Section 9 that isn't yet self-service in the app, contact us at:

support@mobendo.com

You may also use this address to reach our Article 27 EU representative, Mobendo d.o.o.