This Privacy Policy explains how Zeevlo (“Zeevlo”, “we”, “us”, or “our”) collects, uses, stores, and shares information when you use the Zeevlo mobile application or website (collectively, “the Service”). By using Zeevlo you agree to the practices described here.
1. Who We Are
Zeevlo is a campus marketplace that allows enrolled college and university students in India to buy and sell pre-owned items within their student community. The platform operates at www.zeevlo.com and through the Zeevlo Android mobile application (package: com.zeevlo.zeevlo_mobile_app).
Google OAuth tokens during Google Sign-In — passed to Supabase to establish a session; not stored independently by Zeevlo.
Phone number submitted for Firebase phone OTP verification — processed by Firebase Authentication.
Local Device Storage (Mobile App)
Chat read timestamps and cleared-chat markers stored locally using shared_preferences. This data does not leave your device.
Analytics (Website Only)
The Zeevlo website uses @vercel/analytics and @vercel/speed-insights, which collect anonymised page-view and performance data. No personally identifiable information is linked to these events. The mobile app does not include this SDK.
What we do NOT collect: GPS location data, precise device hardware identifiers (IMEI, GAID, IDFA), financial or payment card information (Zeevlo does not process payments), camera or microphone recordings beyond photos you voluntarily upload, or browsing history from other apps or websites.
3. How We Collect Information
Information you provide directly during sign-up, profile setup, listing creation, messaging, and placing requests.
Information collected automatically — FCM device tokens are fetched on sign-in; timestamps are generated server-side; Vercel Analytics collects anonymised page views on the website.
Information from third-party sign-in — if you use Google Sign-In, we receive your name, email, and profile photo URL from Google.
4. How We Use Your Information
Operate the marketplace — display listings, match buyers with sellers, manage requests and orders.
Authenticate you — verify identity via email/password, OTP, or Google OAuth and maintain your session.
Campus scoping — filter listings using your university/college so you see campus-relevant content.
Enable messaging — facilitate real-time chat between buyers and sellers about a listing.
Send notifications — push and in-app notifications about purchase requests, listing moderation outcomes, messages, and announcements.
Moderation — review listings and wishlist requests before publication; enforce community guidelines.
Prevent abuse — enforce platform rules, restrict violating accounts, and limit daily chat creation to prevent spam.
Transactional email — send event-triggered emails (listing approvals, admin messages) to your registered email address.
Service improvement — use anonymised website analytics to understand usage and improve performance.
5. Information Visible to Other Zeevlo Users
Publicly visible (to all users)
Your name and profile photo — shown on your listings and in chat.
Your university / college name — shown alongside your listings.
Marketplace listings you publish — title, description, price, condition, category, images, and campus scope.
Wishlist requests you post — item name, price range, category, and campus scope.
Visible only to parties involved
Chat messages — visible only to you and the other party in a conversation.
Purchase request details — offer price, quantity, and note are visible to you and the listing seller.
Private (not visible to other users)
Phone number — stored in your profile but not displayed publicly. May be visible to Zeevlo administrators. You may choose to share it in a chat conversation.
Email address — not displayed publicly. Visible to Zeevlo administrators for moderation and support.
Authentication tokens, session data, FCM device tokens, and local device preferences.
6. Information We Share
We do not sell, rent, or trade your personal information to third parties for marketing. We share data only in the following limited circumstances:
Service providers — Supabase, Firebase, Vercel, and Gmail SMTP process your data as necessary to operate the platform. See Section 10.
Other platform users — published listings, name, and college are visible as described in Section 5.
Zeevlo administrators — can access profiles, listings, requests, orders, and conversations for moderation and support.
Legal requirements — when required by a valid legal process, court order, or applicable law.
7. Student Eligibility
Zeevlo is designed exclusively for enrolled students at recognised colleges and universities. You must provide your institution name during onboarding. Zeevlo does not currently perform automated document verification (e.g., student ID scans). You are responsible for providing accurate information. False eligibility information violates our Terms of Service.
Your university/college name is stored in your profile and visible on your public listings.
8. Marketplace Listings & Images
Content you submit for a listing or wishlist request is stored in our database and displayed on the marketplace. Images are stored in Supabase Storage and served via public URLs. Do not upload images containing sensitive personal information.
All new listings go through a moderation review before publication. When you delete a listing, the database record is removed. Associated images in Supabase Storage are completely purged by our automated cleanup jobs.
9. Authentication & Account Information
Zeevlo supports the following sign-in methods:
Email + Password — passwords are never stored in plain text; managed by Supabase Authentication.
Email OTP — a time-limited code sent to your email; managed by Supabase Authentication.
Google OAuth — Google shares your name, email, and profile photo URL with Zeevlo via Supabase.
Phone OTP (SMS) — a one-time SMS code handled by Firebase Authentication.
JWT session tokens are managed by Supabase, stored securely on your device, and invalidated when you sign out.
10. Third-Party Services
Supabase
Our primary backend: PostgreSQL database, authentication, Supabase Storage (listing and profile images), real-time WebSocket data, and Edge Functions (including account deletion). Hosted on AWS in the ap-south-1 (Asia Pacific — Mumbai) region. supabase.com/privacy
Firebase (Google)
Used for (1) Firebase Cloud Messaging (FCM) to deliver push notifications — your FCM device token is stored in our database and sent to Firebase to dispatch messages; and (2) Firebase Authentication for phone number OTP verification. firebase.google.com/support/privacy
Google Sign-In
If you use Google Sign-In, Google processes your authentication and shares your name, email, and profile photo URL with Zeevlo. policies.google.com/privacy
Vercel (Website only)
The Zeevlo website is hosted on Vercel. Vercel Analytics and Speed Insights collect anonymised page-view and performance metrics. Vercel may log standard server access logs as part of normal hosting. This does not apply to the mobile app. vercel.com/legal/privacy-policy
Gmail SMTP (Transactional Email)
Zeevlo uses Gmail SMTP to send transactional emails triggered by in-app events (listing approvals, admin messages). These are not marketing emails.
11. Data Storage & Security
HTTPS/TLS — all communication between the app/website and our servers is encrypted in transit.
Supabase Authentication — passwords are hashed; sessions use industry-standard JWT tokens.
Row Level Security (RLS) — Supabase RLS policies ensure users can only access records they are authorised to read or modify.
Server-side authorisation — the account deletion Edge Function verifies the caller's JWT before using privileged service-role credentials.
Supabase Storage access policies — file uploads are governed by storage access policies.
FCM token deactivation on sign-out — your device push token is deactivated in our database when you sign out.
While we apply reasonable technical and organisational security measures, no system connected to the internet can guarantee absolute security.
12. Data Retention
While your account is active — your profile, listings, requests, orders, messages, and device tokens are retained.
When a listing is deleted — the database record is removed. Listing images in Supabase Storage are not automatically purged (operational gap under review).
When you delete your account — a database cleanup procedure removes your profile and associated records, followed by deletion of your authentication identity. See Section 13.
Local device data — chat timestamps stored by shared_preferences remain on your device until you uninstall the app or clear app data.
13. Account & Data Deletion
You can permanently delete your Zeevlo account and data at any time:
In the mobile app — go to Settings → Account & Security → Delete Account. Type “DELETE” to confirm.
What happens immediately: Your authentication session is revoked, device push tokens are removed, and your public profile and listings are hidden from all other users.
The 15-Day Retention Period: For safety and fraud prevention, we retain your data in an inactive state for 15 days. After this period, an automated scheduled job permanently anonymizes all your personal information in our database and permanently purges all images you uploaded to our servers.
14. Your Privacy Choices
Access and update your information — edit your name, phone, college, and profile photo from your profile in the app or website.
Delete your listings — remove any listing you have created from your profile.
Delete your account — as described in Section 13.
Notification preferences — manage push notification permissions through your device's system settings.
Zeevlo is intended for use by enrolled college and university students. To be eligible you must be a student at a recognised higher-education institution. Zeevlo is not designed for or directed at children. If we become aware that an ineligible account has been created, we will take appropriate steps to remove it and associated data.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes we will update the “Last updated” date above. Continued use of Zeevlo after any change constitutes acceptance of the updated policy.