1. Controller and scope of this notice
The controller of the Zsákmány service is Easynet Kft. (registered office: 1139 Budapest, Petneházy utca 37-47, staircase E, first floor, door 1, Hungary; company registration number: 01-09-682490; referred to below as “Zsákmány”, the “Controller”, “we” or “us”). We accept privacy questions and data subject requests at support@zsakmany.hu.
This notice applies to the zsakmany.hu website, the Zsákmány iOS and Android applications, their API, and both consumer and business accounts. Terms used here have the meaning set out in the Terms and Conditions available at https://zsakmany.hu/terms.
2. Roles, sources and principles
We receive data primarily from you when you create an account, complete a personal or business profile, make a reservation, publish content, send a message or contact support. Further data is generated when you use the service and may come from your device, your chosen Apple or Google sign-in provider, businesses, or reports and feedback submitted by other users.
We process only data needed for a stated purpose. Required fields are marked on the relevant screen; optional profile, location and media fields can be left blank. Zsákmány does not sell personal data and, in the current release, does not use third-party advertising trackers or advertising SDKs.
The business publishing an offer acts as an independent controller for an in-store purchase, payment, invoicing or receipt. Zsákmány has no online payment system, so we do not ask for or process bank card details, bank account details or payment credentials.
3. Account, sign-in and public profile
When you create and use an account, we may process your email address, the technical identifier supplied by your sign-in provider, one-time login codes, user ID, session and security data, and the name you provide. If you use Apple or Google sign-in, we receive only the data that provider shares in accordance with your choices.
Your public profile may include your display name, unique @handle, bio, profile image, level or badges and part of your public community activity. Your email address, login identifiers, hide and block lists and security data are not public.
We process these data to create, authenticate, operate and protect your account and to display your profile. The legal basis is entering into and performing our contract with you (Article 6(1)(b) GDPR), and our legitimate interest in account security and preventing abuse (Article 6(1)(f) GDPR).
4. Location and nearby search
With device permission, we may access your approximate or precise location to show nearby offers, businesses and community traces. We request location when you use a location-based feature; we do not continuously track your location in the background. You can enter a city or map point manually without sharing device location.
If you attach a place to a trace or other community content, the selected coordinates, place name and address fragment may be visible to others with that content. Saved or recent search locations may be associated partly with your account and partly only with local storage on your device.
We may use your selected distance and category, saved searches, follows and previous interactions to order results and the feed by relevance. This supports personalised performance of the service and does not produce decisions with legal effects. Profiling for marketing may take place only with separate consent.
Processing a nearby search you request is necessary to perform the service; device location is accessed only after operating-system permission. Optional location-based marketing notifications require separate consent. You can revoke device permission at any time in system settings.
5. Offers, reservations, QR codes and business accounts
When you reserve or redeem an offer, we process data including the offer and business identifiers, reserved quantity, price and discount snapshot, pickup window, reservation status, reservation and redemption timestamps, unique QR or human-readable code, and related points, savings and activity data.
The relevant business receives the data needed to identify and fulfil the reservation and send mandatory communications. Keep your reservation code confidential because presenting it is used to confirm pickup.
For business accounts we process owner and member account relationships, contact details, business name, category, description, address and coordinates, opening hours, contact channels, social links, verification and suspension status, offers, inventory and redemption data. A business's public contact details and address may be visible to anyone.
These data are processed to perform the marketplace, reservation and business services (Article 6(1)(b) GDPR). Fraud-prevention, evidence and service-security logs are processed on the basis of our legitimate interests and those of businesses and users (Article 6(1)(f) GDPR).
6. Community content and connections
When you use community features, we process the traces, hunt reports, ratings, comments, replies, confirmations, photographs, likes and follows you submit, their timestamps, associated offer or location, and technical data needed to display and rank them.
Published content, your display name, @handle, profile image and part of your activity may be public. Before uploading, check that an image or text does not contain unnecessary personal data about anyone else. Where supported by our processing pipeline, embedded location and other technical metadata are removed from uploaded images before storage.
The purpose is to provide the community service and publish content at your request; the legal basis is performance of our contract. Safety checks and protection of the community are based on our legitimate interests.
7. Chat, customer support and notifications
In reservation, business and support conversations, we process message text and images, sender and recipient, timestamps, delivery and read status, and the related reservation or business identifier. On the public contact form, we process your name, email address, selected subject and message, as well as your phone number if you choose to provide it. We use these data to answer your request, provide the help you asked for and prevent abuse.
For push notifications, we process the device token, platform, account notification settings and technical delivery data. Operating-system permission and the notification preferences stored on our server are separate controls.
Mandatory reservation, account-security and service notices are based on performance of the contract or our legitimate interests. The evening digest, saved-search offer alerts and other marketing messages are off by default and may be sent only with separate consent that you can withdraw at any time.
8. Reporting, hiding, blocking and moderation
To protect users and businesses, we process reports and their reason and description, a snapshot of the content, author, business and media at the time of reporting, moderation case and appeal data, hide and block relationships, restriction or suspension decisions, and abuse-prevention and audit logs.
We do not disclose the reporter's identity to the reported user or business. Evidence retained with a report may not be deleted immediately when the underlying content is deleted if it is still needed to investigate the complaint, decide an appeal, prevent fraud or establish, exercise or defend a legal claim.
Automated safety filters may review text and images, including Google Cloud Vision SafeSearch checks for images. A filter may reject content or hold it for review. If such a decision materially restricts you, you can appeal and request human review using the route shown in the service.
Moderation, community safety, fraud prevention and prevention of unlawful conduct are based on our legitimate interests and those of users and businesses (Article 6(1)(f) GDPR), or, where applicable, compliance with a legal obligation (Article 6(1)(c) GDPR).
9. Technical data, cookies and product analytics
To operate the service, we may process IP address, device and app version, operating system, browser, language setting, device and session identifiers, request and error timestamps and security log data. These data are used for authentication, troubleshooting, availability and abuse prevention.
The website uses cookies and similar local storage that are strictly necessary to provide the service without asking for consent. Without them, the requested function would not work or would not be secure. The main necessary storage currently comprises:
- zs_cookie_consent: records the cookie and analytics choice, its version and timestamp for up to 180 days and contains no user identifier;
- NEXT_LOCALE: remembers the selected language for up to 1 year;
- zsuser: an HTTP-only session cookie created only after sign-in, for up to 30 days or until sign-out;
- zsoauth: a short-lived HTTP-only nonce cookie that protects request-response correlation during Apple or Google sign-in, currently for up to 10 minutes;
- zsregistration: an encrypted HTTP-only pending-registration cookie used only to complete creation of a new account and retained no longer than the short-lived registration challenge;
- IndexedDB, sessionStorage or localStorage entries that provide stable reservation and account-deletion request identity, recovery of an unfinished business form or one-purpose secure recovery, only when the relevant feature is used and for as long as needed; the plaintext recovery secret is never placed in local storage, and only its SHA-256 fingerprint may bind the retry identity.
With separate convenience consent, the zsakmany_recent_locs local entry remembers up to 6 recent search locations in this browser. The history is deleted when consent is withdrawn or expires, or when browser data are cleared; refusing it does not limit search.
We send first-party product events - for example a screen view, search, reservation step or feature use - only after prior analytics consent. If enabled, zs_device_id is a random browser identifier, zs_session_id is a tab-scoped session identifier, and zs_attr, retained for up to 30 days, may store a campaign source or only the external referring domain; it never stores a full referring URL. We do not use these data for advertising profiles and currently have no advertising pixel or third-party advertising cookie.
On the first visit, “Necessary only” and “Allow optional storage” are offered at the same level; convenience and analytics purposes can be toggled separately in detailed settings. You can change the decision at any time through Cookie settings in the footer or under Account → Privacy & security → Cookie settings. Withdrawal deletes the related location history, optional attribution cookie and browser and session identifiers and stops future product-event transmission. Refusing does not limit core features. Security and operational logs remain separate and may be processed on the basis of legitimate interests.
10. Who may receive the data?
Personal data may be accessed only to the extent necessary by authorised Controller personnel and contracted processors. We may disclose data to the following categories of recipients:
- other users and the public in relation to your public profile and community content;
- the relevant business to the extent needed to fulfil and hand over a reservation and send related communications;
- IT infrastructure, database, email, push, mapping, image-processing and customer-support providers;
- Apple and Google when you use their sign-in, maps, app-store or notification infrastructure;
- legal, accounting and security advisers where needed to resolve a matter;
- courts, authorities or other competent bodies where disclosure is required by law or a binding order.
If you choose to open an external sharing link, that social or messaging provider's own privacy rules apply.
11. Main processors and international transfers
The current system's main providers are Google Cloud (application and API infrastructure), MongoDB Atlas (database), Mailgun (transactional email), Firebase Cloud Messaging and Apple Push Notification service (push delivery), Google and Apple (sign-in), Google Places and Apple MapKit (location and maps), Google Cloud Vision (image safety), and - where the feature uses it - Twilio Lookup (technical phone-number verification). You can request further information about the current provider and subprocessor chain at support@zsakmany.hu.
Some providers may process data outside the European Economic Area, in particular in the United States. Such transfers may take place only with safeguards compliant with Chapter V GDPR: an applicable adequacy decision - including the EU-US Data Privacy Framework for participating US organisations - or, where it does not apply, the European Commission's standard contractual clauses and supplementary measures where needed. You may request a copy of the safeguards relevant to you, or further information, at support@zsakmany.hu.
12. Retention periods
We retain data only for as long as needed for the relevant purpose, obligation or legal claim. The main rules are:
- account, profile, reservation, business and community data generally remain active while the account exists or until the relevant content or business relationship is deleted;
- one-time sign-in codes and account-deletion confirmation codes used by legacy clients are short-lived and currently valid for no more than 10 minutes; the new self-service deletion does not request an email code; the web login cookie currently lasts up to 30 days and can be terminated by signing out;
- consent-based settings are retained until you withdraw consent or delete the account;
- first-party product analytics events are currently retained for no more than 180 days, and user-linked events are removed on account deletion;
- a formal consumer complaint and our substantive response are retained for 3 years under Hungarian consumer-protection law;
- a moderation case, report and evidence are kept until the case and appeal are resolved and then, with restricted access, only for as long as needed to prevent abuse or establish, exercise or defend legal claims;
- security, access and troubleshooting logs are kept for a limited period determined by risk and investigation needs;
- consent-based convenience settings and recent locations stored locally may remain until the end of the 180-day decision period, withdrawal of consent or clearing browser data;
- deleted data ages out of limited backup cycles and is not restored into normal production use.
Where law requires retention, or data are needed for pending litigation, fraud investigation, regulatory proceedings or unresolved business obligations, we may retain the relevant data separately with restricted access for the necessary period.
13. Account deletion
You can start account deletion through the self-service flow in the app or web account. After reviewing the consequences, one explicit confirmation starts deletion; the new flow does not require an email code or contacting support.
Confirmed deletion is immediate and permanent: the account, personal profile, profile image and other media, your public content, private support and transaction messages, sessions, push tokens, saved items, follows, likes, notifications and user-linked activity data are removed in the same deletion lifecycle. The @handle may then become available again.
Only a statistical, idempotency or audit receipt that contains no personal data and cannot resolve your identity may remain from a reservation or other operation. Where law, a binding authority request, a pending legal claim or necessary moderation evidence requires it, the relevant minimum data may be segregated with restricted access; it is not restored to ordinary service use.
An active business offer, reservation or other unresolved business obligation may temporarily prevent final deletion. If so, the service shows the steps required to resolve it.
14. Your rights
Subject to the GDPR, you may request information and access, rectification, erasure, restriction of processing and - for data processed by automated means on the basis of consent or contract - data portability. You may object to processing based on legitimate interests; you may object to direct marketing at any time without giving reasons.
You may withdraw consent at any time. Withdrawal does not affect the lawfulness of earlier processing and does not end processing that remains necessary on another legal basis. You can edit certain profile data directly and delete your account through the self-service flow.
Send requests to support@zsakmany.hu or the Controller's postal address. We may ask for reasonable verification to protect your identity. We will act without undue delay within the time limit set by the GDPR, or explain why we cannot grant the request.
15. Data security
We apply technical and organisational measures proportionate to the risk, including encrypted transport, access controls, logging, session and authorisation safeguards, restricted administrator access, backups and incident-response procedures. No information system can be made entirely risk-free; if a personal data breach occurs, we will meet the investigation and notification duties required by law.
16. Complaints, court remedies and changes
If you believe that processing of your personal data is unlawful, you may complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH): 1055 Budapest, Falk Miksa utca 9-11, Hungary; postal address: 1363 Budapest, P.O. Box 9; email: ugyfelszolgalat@naih.hu; phone: +36 1 391 1400; web: https://www.naih.hu. You also have the right to seek a judicial remedy, including before the competent court for your habitual residence.
We may amend this notice when the service or legal environment changes. We will give appropriate advance notice of material changes in the app, by email or on the website. The current version is available at https://zsakmany.hu/privacy.
Privacy questions and requests: support@zsakmany.hu. Postal address: Easynet Kft., 1139 Budapest, Petneházy utca 37-47, staircase E, first floor, door 1, Hungary.