ZILAL OneZILALOne
Legal

Privacy Policy

Last updated: April 1, 2026

Data Controller: Zilal Technology LLC — Muscat, Sultanate of Oman. For privacy questions, contact our Data Protection Officer at: privacy@zilalone.com

1. Information We Collect

We collect different types of information to provide and improve our services:

  • Account data: name, email, phone number, and login credentials
  • Device data: device type, operating system, app version, and device identifier
  • Children's digital activity data: app usage, browsing activity (blocked sites only), and screen time — collected only with parental consent
  • Location data: family location sharing for registered children's devices (with parental consent)
  • Payment data: processed exclusively by Paddle.com — we do not store any credit card information
  • Usage data: how you interact with the platform, to improve user experience

2. How We Use Your Information

We use your information for the following purposes only:

  • Providing family safety and parental control services
  • Sending security alerts and notifications related to your children's safety
  • Improving and developing our products and services
  • Communicating with you about your account and subscription
  • Complying with legal and regulatory requirements

3. Data Protection

We take data protection seriously and implement strict security measures:

  • AES-256 encryption for all stored and transmitted data
  • TLS 1.3 protocol for all communications
  • Servers hosted in ISO 27001 certified data centers
  • Regular security audits and penetration testing
  • Access controls following the principle of least privilege

4. Data Sharing

We never sell your personal data. We only share your data in the following cases:

  • Paddle.com Market Limited — as our Merchant of Record and payment processor, Paddle receives data necessary to process payments and billing
  • Cloud hosting providers — for secure data storage under strict data processing agreements
  • Legal authorities — only when required by court order or mandatory legal requirement
  • With your explicit consent — in any other case, we will not share your data without your permission

5. Children's Data — Special Commitment

We handle children's data with the highest level of responsibility and care. We commit to the following:

  • All children's data is collected only with the consent of the parent who created the account
  • The parent is the sole controller of their children's data — they can view or delete it at any time
  • We never use children's data for advertising or marketing purposes
  • We do not share children's data with any third party except to provide the core service
  • We comply with the Children's Online Privacy Protection Act (COPPA) and applicable standards
  • We comply with children's data protection requirements under GDPR Article 8
  • Children's data is automatically deleted when removed from the parent's account

6. Your Rights

We respect your full rights to control your personal data. You have the right to:

  • Access all your personal data stored with us
  • Correct any inaccurate or incomplete data
  • Delete your personal data (right to be forgotten)
  • Export your data in a machine-readable format (data portability)
  • Object to the processing of your data in certain cases
  • Withdraw your consent to data collection at any time

7. Cookies

We use only essential cookies to operate the website and provide a smooth user experience. We do not use advertising or third-party tracking cookies. You can control cookie settings through your browser. The cookies we use include: session cookies (for login), language preference cookies, and security cookies (CSRF protection).

8. Data Retention

We retain your personal data only as long as your account is active or as necessary to provide the service. After account cancellation, your personal data will be deleted within 30 days. We may retain certain data longer if legally required (such as billing records). Aggregated activity data (non-identifiable) may be kept for service improvement purposes.

9. Updates to This Policy

We may update this privacy policy from time to time. We will notify you of any material changes via email or in-app notification at least 30 days in advance. Last updated: April 1, 2026.

To exercise any of your rights or for any privacy policy inquiries, contact us at: privacy@zilalone.com