Privacy Policy of Zoga

This privacy policy describes how Zoga (the "App") collects, stores, and processes personal data. Unlike some of our other apps, Zoga does require an account and stores your data in the cloud in order to provide its team-challenge features.

Data Controller

Arpacore B.V. — Coolsingel 65, 3012 AC, Rotterdam, The Netherlands
Contact email: privacy@arpacore.com

What the App does

Zoga lets users at a company organize teams and participate in in-person sports challenges (such as foosball / biliardino matches) against teams from other companies. Because challenges are played in person, the App needs to store company information — including the company address — so that a team's administrator can decide whether to send or accept a challenge invitation based on geographic proximity.

To support these features, the App uses a cloud backend to store user accounts, company and team information, and challenge data.

What data we collect

When you create an account and use the App, the following data may be collected:

  • Authentication data: username and password (the password is stored in hashed form by our authentication provider and is never accessible to us in readable form).
  • Personal profile data (about you): first name, last name, and email address.
  • Company profile data (about the company you belong to, managed by the company administrator): company name, company address, company website URL, company phone number, company email, and team name.
  • Role data: which company you belong to, which team you belong to, and whether you are a company administrator.
  • Activity and challenge data: data related to challenges your team participates in.
  • Content you upload: any files or images you choose to upload to the App (for example, team or profile images).

The App does not contain analytics SDKs, advertising SDKs, or tracking technologies. We do not profile your behavior for advertising purposes.

Why we collect this data (purposes and legal basis)

We process your personal data for the following purposes:

  • Providing the service — creating and authenticating your account, maintaining your profile, allowing you to form or join teams, and running challenges. Legal basis: performance of a contract (Article 6(1)(b) GDPR).
  • Managing a company profile — when a user acts as the administrator for a company, that user manages the company profile (name, address, website, phone, email, team name) on behalf of the company. Legal basis: performance of a contract with the administrator and the company, and legitimate interests in making the service usable in a company context (Article 6(1)(b) and 6(1)(f) GDPR).
  • Publishing the company profile to enable inter-company challenges — only if the company administrator explicitly chooses to publish the company profile, it becomes visible to other companies using the App, so that they can see the company exists and can send or receive challenge invitations, including based on geographic distance. Legal basis: the administrator's consent, given on behalf of the company (Article 6(1)(a) GDPR). The administrator can un-publish the profile at any time to stop this sharing.
  • Security and abuse prevention — protecting accounts from unauthorized access. Legal basis: our legitimate interests (Article 6(1)(f) GDPR).

Visibility of your data

The App uses a role-based visibility model. Who can see what depends on the role of the user and on whether the company administrator has chosen to publish the company profile.

Your personal profile (first name, last name, email) is visible only to you. It is not shown to your teammates, to your company administrator, or to any other user. Only you can edit it.

The company profile (company name, address, website URL, phone, email, team name) is visible in the following way:

  • The company administrator can view and edit the company profile.
  • Other users belonging to the same company can view the company profile, but cannot edit it.
  • If the company administrator chooses to publish the company profile, it becomes visible to users of other companies, who can see that the company exists on the App and can use its address to decide whether to send a challenge invitation based on distance. The administrator can un-publish the company profile at any time.
  • If the company profile is not published, other companies cannot see it.

Because challenges take place in person, the company address is specifically used by other companies to estimate travel distance before sending or accepting an invitation. This is the reason the address is part of the published company profile when the administrator chooses to publish it.

Where your data is stored (Firebase)

The App uses Firebase, a platform provided by Google, as its backend. Specifically:

  • Firebase Authentication is used to manage user accounts and sign-in.
  • Cloud Firestore is used to store profile, company, team, and challenge data.
  • Firebase Storage is used to store files and images you upload.

Your data is stored in Firebase regions located within the European Union (europe-west). Google acts as our data processor and processes your data on our behalf in accordance with the Firebase Data Processing Terms. Although the storage region is in the EU, Google is a US-based company and, in limited circumstances (such as support operations), data may be accessed from outside the EU under appropriate safeguards, including the EU Standard Contractual Clauses.

Google's privacy practices are described in its own privacy policy at https://policies.google.com/privacy and the Firebase-specific information at https://firebase.google.com/support/privacy.

How long we keep your data

We retain your account and the associated data for as long as your account is active. If you delete your account, your profile and personal data are deleted from the active systems. Some data may be retained for a limited period in backups, after which it is also deleted. Challenge results that have been shared publicly within the App may be retained in aggregate or anonymized form after account deletion.

Your rights under the GDPR

You have the following rights regarding your personal data:

  • Access — you can request a copy of the personal data we hold about you.
  • Rectification — you can ask us to correct inaccurate or incomplete data. Most profile fields can be edited directly from within the App.
  • Erasure — you can delete your account from within the App, or request deletion by writing to privacy@arpacore.com.
  • Restriction — you can ask us to restrict processing in certain circumstances.
  • Portability — you can request a copy of your data in a structured, machine-readable format.
  • Withdraw consent — where processing is based on your consent (for example, participation in inter-company challenges), you can withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
  • Object — you can object to processing based on our legitimate interests.
  • Lodge a complaint — you can lodge a complaint with your national data protection authority.

To exercise these rights, contact us at privacy@arpacore.com. We will respond within one month as required by the GDPR.

Security

We rely on Firebase's security infrastructure, including encryption of data in transit (HTTPS) and at rest, and Firebase Authentication for account security. You are responsible for keeping your password confidential and for signing out on shared devices.

Apple services

The App is distributed through the Apple App Store. Apple may collect information related to your download and use of the App independently of us, in accordance with Apple's own privacy policy.

Children

The App is not directed to children under 16 and we do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us and we will delete it.

Changes to this policy

We may update this policy from time to time. Material changes will be notified within the App or via the email address associated with your account, where appropriate. The "last updated" date below reflects the most recent version.

Contact

For any questions about this policy or about the processing of your personal data, please contact us at privacy@arpacore.com.

Last updated: April 21, 2026