Privacy Policy
Last updated: July 22, 2026
This policy explains what personal data Zoaki collects, why, and what rights you have over it. Zoaki is a marketplace app that connects pet owners with pet sitters.
1. Who we are
Zoaki is operated by Konstantinos Trokanas, based in Greece. For the purposes of data protection law, Konstantinos Trokanas is the data controller for personal data processed through the Zoaki app and website.
2. What data we collect
- Account information: name, email address, password (stored as a salted hash — we never store or see your plain-text password), optional phone number, and profile photo.
- Location: if you use Zoaki to find a sitter, we ask your device for its location (with your permission) to show sitters near you. Sitters provide an address so we can determine their general service area; that exact address is only ever shared with an owner after a booking is accepted, and search results only ever show an approximate location, never a precise address.
- Pet information:if you add a pet, we store its name, species, breed, birth date, weight, spay/neuter status, photos, and any feeding, medical, or behavioral notes you choose to add, plus your vet's name and phone number if you provide one. This is shared with a sitter only in connection with a booking you make with them.
- Payment information: card details are collected and processed directly by our payment processor, Stripe. We never see or store your full card number. We store limited related metadata, such as a Stripe customer/account identifier, transaction amounts, and booking status.
- Identity verification (sitters): to help build trust in the marketplace, sitters complete an identity check through Stripe Identity, which may involve a government ID and a selfie. Those documents are collected and processed by Stripe directly — we only receive and store the result of that check (verified or not), never the documents or images themselves.
- Messages: in-app chat between an owner and a sitter about a booking, delivered through our real-time messaging provider, Pusher.
- Reviews: ratings and written reviews you leave for, or receive from, another user.
- Device and usage data: a push-notification token if you use the mobile app, basic device/session information for keeping you signed in, and technical logs (such as IP address and request timestamps) that we use briefly for security purposes like detecting abuse and rate-limiting login attempts.
3. How we use your data
- To operate the marketplace: creating your account, matching owners with sitters, and managing bookings.
- To process payments and sitter payouts, and to run identity verification for sitters.
- To enable messaging between an owner and a sitter about a shared booking.
- To send you transactional emails and notifications (booking updates, receipts, security alerts).
- To detect and prevent fraud, abuse, and unauthorized access.
- To comply with legal, tax, and accounting obligations.
- To maintain and improve the service.
4. Our legal bases for processing
Where GDPR applies, we rely on one or more of the following legal bases for each use above:
- Contract: processing needed to create your account and to arrange and pay for bookings.
- Legitimate interests: fraud prevention, platform security, and improving the service, balanced against your rights.
- Consent: for optional things like sharing your device location or sending promotional notifications, which you can withdraw at any time.
- Legal obligation: for record-keeping required by tax and financial regulations.
6. International data transfers
Some of the providers listed above may process data outside the European Economic Area. Where that happens, we rely on appropriate safeguards required by law, such as standard contractual clauses, to protect your data.
7. Data retention
We keep your personal data for as long as your account is active, plus any additional period required for legal, tax, or dispute-resolution purposes (for example, financial transaction records). When you delete your account, we delete or anonymize your personal data, other than what we're legally required to keep, within 30 days.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or receive a copy of your personal data, and to object to certain processing. To exercise any of these rights, contact us at privacy@zoaki.online. If you're in the EU/EEA, you also have the right to lodge a complaint with your local data protection authority — in Greece, this is the Hellenic Data Protection Authority.
9. Deleting your account
To delete your account, email us at privacy@zoaki.online from the address on your account. We'll delete your account and associated personal data within 30 days, other than what we're required to retain for legal or financial record-keeping.
10. Children
Zoaki is not directed at children, and you must be at least 18 years old to create an account.
11. Security
We use industry-standard measures to protect your data, including encrypted connections, hashed passwords, and rate limiting on authentication endpoints to slow down credential-stuffing and brute-force attempts. No method of transmission or storage is completely secure, so we can't guarantee absolute security.
13. Changes to this policy
We may update this policy from time to time. If we make a material change, we'll notify you through the app or by email before it takes effect.
14. Contact us
Questions about this policy or your data? Email privacy@zoaki.online. (This address may change as Zoaki grows — the current version of this page always has the right one.)