Your data, explained clearly

Privacy Policy

This policy explains how personal data is handled across the ZEVLA website, platform and applications.

Last updated: 2026-07-29Version: 1.0

1. Who is responsible for your data

ZEVLA is an application, platform and commercial brand operated by MediaFlare Technologies. MediaFlare Technologies, established in Belgium, is the data controller for personal-data processing performed through ZEVLA, unless a specific tenant acts as an independent controller for its own legally defined activities.

Questions about privacy, data rights or account deletion can be sent to support@zevla.be.

2. Scope and people covered

This policy covers Customers, Drivers, Merchants, Tenant users, Support users and visitors to ZEVLA public websites.

  • Customers discover stores, place orders, request services and track deliveries.
  • Drivers manage availability, delivery missions, location sharing, proof of delivery and earnings information.
  • Merchants manage stores, products, availability, orders, promotions and settlements.
  • Tenants operate local networks, dispatch, billing and governance.
  • Support users handle authorized tickets and service communications.

3. Data we process

The exact data depends on the role and features used. We apply data minimisation and do not require every category from every user.

  • Identity and account data: name, email, telephone number, password hash, role, permissions, language and account status.
  • Profile and business data: profile images, merchant or tenant identity, store address, catalog and uploaded registration documents.
  • Customer data: delivery addresses, saved location, cart, order history, notes, support conversations, ratings and reviews.
  • Driver data: operational profile, availability, assigned missions, live location during an active delivery, delivery proof and payout records.
  • Operational data: order items, status history, dispatch events, delivery tracking, proof photos and signatures.
  • Financial data: prices, payment method and status, invoices, payouts, settlements and accounting metadata. Full card credentials are handled by an enabled payment provider and are not intended to be stored by ZEVLA.
  • Technical data: push tokens, device platform, app version, security events and limited request information needed for security and abuse prevention.

4. Location and live delivery tracking

Customer location is used when requested to resolve an address, show relevant local services or support delivery. Driver precise location is collected and shared only when required for an active delivery workflow and permitted by the device.

Assigned Customers and authorized operational users may see the delivery position needed to follow an active mission. ZEVLA does not present invented GPS, routes or arrival times as live truth.

5. Why we use personal data

  • Create, secure and administer accounts and role permissions.
  • Provide browsing, checkout, ordering, dispatch, delivery, proof, billing and support services.
  • Send transactional, security and service notifications in the recipient's selected language.
  • Prevent fraud, misuse, duplicate submissions and unauthorized cross-tenant access.
  • Maintain accounting, tax, payment, dispute and audit records where required.
  • Improve reliability using aggregated operational measurements without inventing user activity.

7. Service providers

ZEVLA uses processors only for services that are actually configured. Current technical categories include hosting and deployment, PostgreSQL database and object storage, transactional email, push delivery, mapping/location services, and Expo/EAS mobile build services.

  • Vercel for Platform hosting and deployment.
  • Supabase/PostgreSQL and Supabase Storage for production data and authorized files.
  • Firebase Cloud Messaging for Android push delivery; Firebase Authentication is not used as the primary ZEVLA account identity service.
  • Google Maps Platform for configured mobile mapping and location presentation.
  • Expo/EAS for mobile project and build infrastructure.
  • Postmark for configured transactional email delivery.
  • A tenant-selected payment provider only when that provider is enabled for the relevant checkout.

8. Sharing and international transfers

Data is shared only with authorized participants and processors needed to provide the service. Drivers receive the operational Customer information needed for an assigned delivery, not unrestricted account data. Tenants and Merchants see only records within their authorized scope.

Some processors may handle data outside Belgium or the European Economic Area. Where applicable, appropriate contractual and legal transfer safeguards must be used.

9. Retention and account deletion

We retain personal data only for as long as needed for the purposes described, security, disputes and applicable legal obligations. Operational account data is removed or anonymised after a valid deletion request when it is no longer necessary.

Invoices, payouts, settlements, tax, accounting, anti-fraud and essential audit records may be retained in minimised form for the period required by law or a live dispute. Retained records cannot be used to reactivate a deleted account.

10. Security

ZEVLA uses role checks, tenant isolation, hashed passwords and verification tokens, signed access tokens, restricted storage, rate limits, audit events and transport encryption. No service can guarantee absolute security, so users should protect their credentials and report suspected misuse promptly.

11. Your data-protection rights

Subject to applicable law, you may request access, correction, deletion, restriction, objection or portability, and may withdraw consent where processing relies on consent. Requests are assessed against identity, security, operational and lawful-retention requirements.

  • Use the in-app Account & Data area or the public account-deletion page.
  • Contact support@zevla.be for privacy and data-protection requests.
  • You may lodge a complaint with the competent data-protection authority, including the Belgian Data Protection Authority where applicable.

12. Children

ZEVLA accounts are intended for people legally able to use the relevant service or acting with valid authorization. We do not knowingly invite children to create operational Merchant, Driver, Tenant or Support accounts.

13. Changes and contact

We may update this policy when the service, legal requirements or providers change. Material updates will show a new version and effective date and, where required, an in-app acknowledgement.

Verified contact details

Brand
ZEVLA
Operated by
MediaFlare Technologies
ZEVLA support
support@zevla.be
Corporate email
info@mediaflare.be
Address
Rue de Boutonville 8/D 6464 Chimay Belgium
    Privacy Policy | ZEVLA