Short version: We collect only what we need to run the platform. We never sell your data. Businesses control their own listing data. Customers can delete booking data by contacting us.
1. Who we are
Zotheka Network MW is an online business booking and discovery platform based in Malawi, operated by Kondwani Mlungu. We can be reached at +265 99 417 1869 (WhatsApp) or through our Help Center.
2. What data we collect
For businesses registering an account:
- Business name, owner name, email address, phone number
- Business category, location, description, services, and working hours
- Profile picture and cover photo (if uploaded)
- Payment history (plan activation dates, subscription status)
For customers making bookings:
- Name and phone number (required for the booking)
- Email address (optional)
- The service booked, date, time, and any notes provided
Automatically collected:
- Connection is (used for security rate-limiting only, not stored long-term)
- Basic usage data (which pages are visited no personal identifiers are attached)
3. How we use your data
- Businesses: To display your public listing, manage bookings and communications, process subscription payments, and send platform notifications
- Customers: To confirm and manage your bookings, allow businesses to contact you, and display your reviews on the platform
- Security: Connection data is used solely to protect your account from unauthorised access and is automatically discarded once no longer needed — it is never used for any activity
- Platform improvement: Aggregate, anonymised data may be used to understand how the platform is used and improve it
4. Who we share your data with
We do not sell, rent, or share your personal data with third parties for marketing purposes. Your data may be shared with:
- Cloudflare — data is stored securely by Cloudflare
- Paychangu (if you use card payments) — only the information necessary to process the transaction
- Law enforcement — if required by applicable Malawian law
Business listing information (name, description, location, services, hours) is publicly visible by design — that is the core purpose of being listed on the platform.
5. How long we keep your data
- Business accounts: Retained as long as the account is active. On deletion, we remove personal data within 30 days
- Booking records: Retained for 90 days from the booking date, then automatically deleted
- Reviews: Retained for 365 days
- Chat messages: Retained for 90 days
- Support tickets: Retained for 180 days after resolution
6. Your rights
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate data (businesses can do this directly in their dashboard)
- Delete your data — contact us and we will remove it within 30 days
- Withdraw consent for any optional data processing at any time
To exercise any of these rights, contact us via WhatsApp at +265 99 417 1869 or through the Help Center.
7. Security
We take security seriously. Measures in place include:
- Your account credentials are never stored in a readable format passwords go through an industry-standard cryptographic process before being saved, meaning even in the unlikely event of a data breach, your actual password cannot be recovered
- All communication between your device and our platform is encrypted in transit, so your information cannot be intercepted
- We have automatic safeguards in place to detect and block suspicious login behaviour before it can cause harm.
- Our administrative systems have additional layers of access control that go beyond a standard password.
- We do not store payment card details on our servers any card transactions are handled entirely by our licensed payment partner, Paychangu, which is independently certified for payment security.
We are committed to continuously improving our security as the platform grows and regularly review our protections to stay ahead of emerging threats. No platform can guarantee absolute security, and we believe in being honest about that. What we can guarantee is that we take every reasonable measure to protect your data and treat any security concern with the seriousness it deserves. If you ever notice anything unusual or believe you have found a problem, please contact us immediately and privately at +265 99 417 1869 we will respond promptly and with discretion.
8. Cookies and tracking
We believe your attention is yours, not ours to sell. Zotheka Network MW does not use advertising cookies, does not track you across other websites, and does not share your browsing behaviour with any third party for marketing purposes. We do not run third-party analytics tools that profile you or build advertising audiences from your activity on this platform.
The only data we store in your browser is a secure session token that keeps you signed into your business dashboard the equivalent of remembering you so you do not have to log in again every time you visit. This is stored locally on your device and is never shared. You can clear it at any time by signing out of your account.
What you do on Zotheka stays on Zotheka.
9. Changes to this policy
We may update this Privacy Policy from time to time. We will notify businesses of significant changes via the platform's notification system. Continued use of the platform constitutes acceptance of the updated policy.