Privacy Policy
Last updated: September 1, 2026
This Privacy Policy explains how Zaifay OÜ ("Zaifay", "we", "us", or "our") collects, uses, discloses, and protects your personal information when you use our websites (zaifay.com, goeven.app), mobile applications, and related services (collectively, the "Services").
Zaifay OÜ is the data controller for the purposes of the EU General Data Protection Regulation (GDPR). Our registered address is Harju maakond, Tallinn, Kesklinna linnaosa, Tartu mnt 67/1-13b, 10115, Estonia.
1. Information We Collect
1.1 Information You Provide
When you create an account, make a purchase, or contact us, we may collect:
- Name and email address
- Account credentials (passwords are hashed and never stored in plaintext)
- Profile information (display name, profile picture)
- Expense data and financial transaction records within GoEven
- Messages sent through in-app group chat
- Contact form submissions and correspondence
- Shipping addresses for retail orders
- Payment information (processed through secure third-party payment processors)
1.2 Information Collected Automatically
When you use our Services, certain information is collected automatically:
- Device information (type, operating system, unique identifiers)
- Usage data (features accessed, actions taken, timestamps)
- IP address and approximate geolocation (country/region level)
- App crash reports and performance diagnostics
1.3 Information from Third Parties
If you sign in using a third-party service (such as Google or Apple), we receive basic profile information as permitted by your account settings with that service.
2. How We Use Your Information
We use your information for the following purposes:
- Provide and operate our Services: Process transactions, manage expenses, facilitate group communications, fulfil retail orders
- Account management: Create and maintain your account, authenticate your identity
- Communication: Respond to inquiries, send service notifications, provide customer support
- Improvement: Analyse usage patterns to improve our products and user experience
- Security: Detect and prevent fraud, abuse, and security incidents
- Legal compliance: Comply with applicable laws, regulations, and legal processes
3. What We Do NOT Do
We are committed to protecting your privacy. We explicitly do not:
- Sell, rent, or trade your personal data to third parties
- Display advertisements in our applications
- Monetise your data through profiling or targeted advertising
- Share your expense data or financial information with marketing companies
- Use your data for purposes unrelated to providing our Services
4. Data Sharing and Disclosure
We may share your information only in the following limited circumstances:
- With other users: Expense data is shared with members of your groups and friends list within GoEven, as this is essential for the core functionality of the service
- Service providers: We use trusted third-party services for hosting (cloud infrastructure), crash reporting (Firebase Crashlytics), push notifications, and payment processing. These providers are contractually bound to protect your data
- Legal requirements: If required by law, legal process, or governmental request
- Business transfers: In connection with a merger, acquisition, or sale of assets (with appropriate user notification)
5. Data Security
We implement appropriate technical and organisational measures to protect your data, including:
- TLS/SSL encryption for all data in transit
- Encrypted storage for sensitive data at rest
- Password hashing using industry-standard algorithms
- Regular security assessments and code reviews
- Access controls and audit logging for internal systems
6. Data Retention
We retain your personal data only for as long as necessary to provide our Services and fulfil the purposes described in this policy. When you delete your account, we will delete or anonymise your personal data within 30 days, except where retention is required by law.
7. Your Rights (GDPR)
Under the GDPR, you have the following rights regarding your personal data:
- Right of access: Request a copy of the personal data we hold about you
- Right to rectification: Request correction of inaccurate personal data
- Right to erasure: Request deletion of your personal data ("right to be forgotten")
- Right to restrict processing: Request limitation of how we use your data
- Right to data portability: Receive your data in a structured, machine-readable format
- Right to object: Object to processing of your data for specific purposes
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, please contact us at sales@zaifay.com.
8. International Data Transfers
Your data may be processed in countries outside the European Economic Area (EEA). When this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
9. Children's Privacy
Our Services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that a child under 16 has provided us with personal data, we will delete it promptly.
10. Cookies and Tracking
Our website (zaifay.com) may use essential cookies to enable core functionality. We do not use advertising or tracking cookies. Our mobile applications do not use cookies.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through our Services or via email. Continued use of our Services after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us:
- Email: sales@zaifay.com
- Address: Zaifay OÜ, Harju maakond, Tallinn, Kesklinna linnaosa, Tartu mnt 67/1-13b, 10115, Estonia
You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local supervisory authority.