Privacy Policy

Last updated 2 September 2026

Draft. This text is a working placeholder describing how the platform actually behaves. It has not been reviewed by legal counsel and must be replaced before launch.

What we collect

Account data: your name, work email address, phone number, job title and the organisation you belong to. This is provided by you or by your organisation's administrator when they invite you.

Usage data: your sign-ins. Each one is recorded with the time, the IP address the request came from and the browser or app that made it, and you can see your own on your profile. Attempts that failed are recorded the same way, at most one a minute per account, so that you and your administrator can tell when somebody has been trying an account that is not theirs.

Business data: the projects, tickets, documents, financial records and approvals your organisation creates in the platform. This belongs to your organisation, not to us.

How we use it

To operate the platform, authenticate you, apply your permissions and deliver the services your organisation has contracted.

To send transactional notifications — approval requests, ticket updates, contract reminders. You can control which of these reach you by email in your notification preferences; some, such as security notices, cannot be disabled.

We do not sell personal data, and we do not use your business data to train machine learning models.

Who can see your data

Data is isolated per organisation at the database level using row level security. A user in one customer organisation cannot read another organisation's records, regardless of how a request is constructed.

Zivara delivery staff can access customer organisations they are assigned to. Zivara administrators can access all customer organisations in order to operate the platform. All such access is recorded in an append-only audit log.

Delivery partners can access only the specific projects and tickets they have been assigned. They cannot see unrelated customer data, including financial records.

Storage and security

Documents are stored in private object storage and served only through short-lived signed URLs. Buckets holding confidential material are never publicly readable.

Passwords are hashed and never stored in plain text; authentication is handled by Supabase Auth. When you set one we check it against a public database of passwords exposed in known breaches, and refuse it if it appears there — only the first five characters of a one-way hash of the password leave our systems to do it, never the password. You can add a second factor from an authenticator app on your profile, and once you have, a password alone will not get you in. Enterprise single sign-on is not yet available.

Changes to the records that matter — customers, projects, tickets, approvals, contracts, documents, invoices, budgets, partners, memberships and entitlements — are recorded with the acting user, the timestamp and the before and after values. Document downloads are recorded too.

Retention and deletion

Important business records are soft-deleted so they can be recovered and so the audit trail remains intact. Hard deletion happens on contract termination, according to the retention period in your agreement.

You can request a copy of, or the deletion of, your personal data by contacting your organisation's administrator or Zivara directly.

Contact

For any question about this policy or about how your data is handled, contact Zivara LLC, Dubai, United Arab Emirates.