Privacy Policy
This policy explains what personal information Zimun collects, why it is used, who it may be shared with, how long it is kept, and what rights are available to business users, staff members, and customers who use businesses powered by Zimun.
Last updated: June 14, 2026
1. Who we are and who this policy covers
Zimun is a SaaS platform for appointment-based businesses. It helps businesses manage appointments, customers, staff, services, availability, reminders, reporting, and public booking pages.
This policy applies to business owners, managers, staff members, platform users, end customers who book or manage appointments through a Zimun-powered booking portal, and anyone else who provides personal information while using Zimun.
If you book an appointment with a business that uses Zimun, that business may determine some of the purposes and means of using your information. Zimun provides the technology platform and processes information for that business, while also acting as an independent controller for platform accounts, security, operations, support, and legal compliance.
2. Privacy roles
- For user accounts, sign-in, permissions, security, support, platform operations, and abuse prevention, Zimun acts as the controller of personal information.
- For information a business enters, imports, or collects about its customers to manage appointments, the business is usually the controller and Zimun processes that information on behalf of the business according to its settings and instructions.
- A business using Zimun is responsible for making sure it has an appropriate legal basis for collecting and using its customers' information, including where the nature of the service may reveal sensitive information such as health, treatment, religious, or highly personal information.
- Zimun is not intended for collecting sensitive information that is not needed to manage an appointment. Users and businesses should avoid entering sensitive information in free-text fields unless it is necessary and permitted by applicable law.
- Businesses that need a data processing agreement or additional processing terms may contact privacy@zimun.app.
3. Personal information we collect
- Account and identity information: full name, email address, phone number, encrypted or hashed password, sign-in methods, two-factor authentication status, interface language, linked businesses, roles, and permissions.
- Business and operational information: business name, public slug, branches, addresses, staff members, services, prices, service durations, opening hours, availability, cancellation policy, message templates, and system settings.
- Customer and appointment information: customer name, phone number, email address, appointment, service, staff member, branch, time, appointment status, booking history, waiting list entries, notes entered by the business or customer, and cancellation or change requests.
- Communication information: verification messages, appointment confirmations, reminders, appointment updates or cancellations, delivery status, recipient email addresses or phone numbers, and operational records of message delivery.
- Technical and security information: IP address, user agent, session identifiers, cookies, browser and device data, sign-in events, failed sign-in attempts, authorization events, logs, errors, and information needed to protect the platform.
- Integration information: if a business or user connects an external service such as a calendar or identity provider, Zimun may store identifiers, permissions, tokens, or metadata needed to operate that connection.
- Support information: request content, contact details, screenshots, and any additional information voluntarily provided to help resolve a support request.
4. Sources of information
- Information you provide directly when registering, signing in, creating a business, managing the system, booking an appointment, or contacting support.
- Information provided or imported by the business about its customers, staff members, and services.
- Information generated automatically when the platform is used, such as logs, security events, cookies, session identifiers, and operational usage data.
- Information received from external providers that the user or business chose to connect to Zimun, such as identity providers, calendars, email, SMS, IVR, or infrastructure services.
5. Purposes and legal bases
- Creating accounts, signing in, managing permissions, and selecting an active business: performance of a contract or steps before entering into a contract.
- Providing appointment management, public booking pages, customer management, staff management, availability, reminders, and reporting: performance of the contract with the business or delivery of the requested service to the user or end customer.
- Processing business customer information according to the business's instructions: processing on behalf of the business, where the business is responsible for the legal basis toward its customers.
- Security, fraud prevention, abuse detection, troubleshooting, and system reliability: legitimate interests of Zimun, the businesses using the platform, and users.
- Sending operational messages such as OTPs, appointment confirmations, reminders, appointment updates, cancellations, and security alerts: performance of the service, legitimate interests, or legal obligations depending on the context.
- Keeping records needed for compliance, dispute handling, responding to authorities, or protecting legal rights: legal obligation or legitimate interests.
- Improving the product, measuring performance, and planning new capabilities: legitimate interests, with a preference for aggregated, minimized, or non-identifying data where possible.
- Actions based on a clear user choice, such as saving customer details on a device for future form filling or connecting a specific integration: consent or an affirmative user action that can be withdrawn or disconnected where supported by the platform.
- Product notices, service updates, or marketing communications, where sent: consent, legitimate interests, or another permitted legal basis, with an opt-out where required.
6. Cookies, local storage, and similar technologies
- Zimun uses cookies and local storage for sign-in, session refresh, CSRF protection, language preference, active business and branch selection, interface state, and normal platform functionality.
- Sign-in cookies may be kept for up to 7 days by default, or up to 30 days when the user selects remember me. A short-lived access token cookie is kept for only a few minutes according to the active session lifetime.
- On the public booking portal, if a customer chooses to remember their details, their name and phone number may be stored in a local cookie for up to 90 days to prefill future bookings. The customer can clear it through the portal flow or through browser settings.
- A portal session for viewing recent appointments may be kept for up to 12 hours, and limited local portal history may be kept for up to 30 days to provide convenient access to recent appointments on the same device.
- Zimun does not currently use targeted advertising cookies, sell personal information to third parties, or use customer appointment data to build external advertising profiles. If analytics or advertising tools are added, this policy will be updated and user choice will be provided where required.
7. Who information may be shared with
- The business where an appointment was booked or managed, and authorized staff members of that business according to their permissions.
- The end customer, when the information is needed to display, manage, cancel, or send messages about that customer's appointment.
- Infrastructure and processing providers acting for Zimun, such as hosting, databases, monitoring, security, email, SMS, IVR, identity providers, calendar services, and support tools.
- Providers the user or business chose to connect, such as Google or another calendar provider, according to the permissions granted and that provider's own policy.
- Authorities, courts, professional advisers, or other parties where required by law, to enforce terms, handle a security incident, prevent fraud, or protect rights.
- As part of a corporate transaction, merger, acquisition, or transfer of activity, subject to the information continuing to be protected under this policy or a replacement policy provided where required.
- Businesses may request current subprocessor information by contacting privacy@zimun.app.
8. International transfers
Zimun is intended to serve businesses and customers in Israel and may use providers that store or process information in Israel, the European Union, the United States, or other countries. The processing location depends on the deployment environment and the infrastructure and communications providers selected.
Where personal information is transferred outside the user's country or outside the European Economic Area, Zimun will seek to use appropriate safeguards where required, such as data processing agreements, confidentiality commitments, contractual security measures, Standard Contractual Clauses, or other recognized transfer mechanisms under applicable law.
9. Retention and deletion
- Account information is kept while the account is active and then for the period needed for security, fraud prevention, dispute handling, backup recovery, and legal compliance.
- Business, staff, service, availability, and appointment information is kept while the business uses the platform or while it is needed to operate the service, maintain operational records, respond to requests, exercise rights, or comply with law.
- Business customer information is kept according to the business's settings and appointment-management needs. A business may request deletion or anonymization of a customer where supported by the platform and subject to exceptions such as security records, backups, disputes, or legal obligations.
- Sign-in, authorization, and security events, including auth_events records, may be retained after account or business erasure because they are needed to detect attacks, investigate incidents, prevent repeat abuse, protect users, and prove the integrity of actions in the system. They are access-limited and are not used for marketing.
- Temporary holds for unfinished bookings are kept briefly, usually up to 5 minutes. Live IVR phone sessions, where enabled, are usually kept for up to 30 minutes to complete the call flow.
- IVR call audit records, where the IVR service is enabled, are usually retained for up to 60 days for troubleshooting, call-flow review, abuse prevention, and operational audit.
- Backups and technical logs are deleted or overwritten according to backup and operational cycles. Deletion from active systems may not immediately remove information from every existing backup, but backups are access-limited and kept for recovery purposes only.
- When information is deleted or anonymized, non-identifying records or minimal records may remain where needed to document the action, prevent abuse, troubleshoot issues, or comply with law.
- When a business deletes appointment history through a dedicated deletion tool, appointments and related operational records are deleted from active systems where supported by the product, but an aggregate audit event for the deletion may remain and information may also remain in backups or technical logs according to retention cycles.
10. Security
- Zimun applies organizational and technical measures designed to reduce unauthorized access, misuse, alteration, disclosure, or loss of personal information.
- Measures may include tenant separation, role-based permissions, encrypted or hashed passwords, secure cookie attributes, two-factor authentication where enabled, security event logging, rate limiting, error monitoring, and restricted access to administrative environments.
- No system is completely secure. If Zimun becomes aware of a security incident affecting personal information, it will investigate, contain the impact, document the response, and notify users, businesses, or authorities where required by law.
11. Rights over personal information
- Subject to applicable law, you may have the right to access personal information, receive a copy, correct inaccurate information, delete information, restrict processing, object to processing, receive information in a portable format, or withdraw consent.
- Where a request concerns a business customer's information, Zimun may forward the request to the relevant business or act according to that business's instructions because the business is the controller for that customer information.
- To protect privacy and security, Zimun may ask for additional details to verify identity or authority before handling a request.
- There may be situations where a request cannot be fully fulfilled, for example where information must be retained, is needed for security, relates to an open dispute, is stored in backups, or affects another person's rights. In that case, an explanation will be provided as required by law.
- In the European Union and other regions, you may have the right to complain to a competent data protection authority. In Israel, you may contact the Privacy Protection Authority at the Ministry of Justice.
12. Minors and sensitive information
- Zimun is not intended for independent use by children under 16 or the applicable age of digital consent, and does not knowingly seek to collect information from children without involvement of a parent, guardian, or authorized business.
- If a business uses Zimun to manage appointments for minors, the business is responsible for making sure the collection and use of information complies with applicable law and required consents.
- Information about service type, notes, or timing may sometimes reveal sensitive information. Businesses and users should avoid entering sensitive information that is not necessary and should use limited, professional wording where such information is needed to operate the service.
13. Automated decision-making
Zimun may use business rules, availability checks, permissions, rate limits, and operational filtering to allow or prevent certain actions, such as showing available appointment times or blocking suspicious requests. These actions are used to operate and secure the service.
Zimun does not currently make automated decisions that have legal or similarly significant effects on users in the usual meaning of data protection laws. If such a capability is added in the future, this policy will be updated accordingly.
14. Changes to this policy
Zimun may update this policy from time to time to reflect changes in the product, infrastructure, providers, legal requirements, or the way information is processed. The last updated date will appear at the top of the policy.
Where a material change significantly affects rights or the way personal information is used, Zimun will provide appropriate notice in the product, by email, or by another suitable method.
15. Contact
Zimun, the operator of the service, can be contacted for privacy questions, deletion requests, access requests, or security concerns at: privacy@zimun.app.
If you are a customer of a business using Zimun, you should also contact the business where the appointment was booked because that business may determine the purposes for using your information.