Privacy information
Your business data should remain understandable and controlled.
This page explains the information used by Zarak Client Portal client accounts and Zarak’s owner workspace. Client access is linked to the services agreed with Zarak.
Website requests and photographs
Your messages, request history, photo-review decisions and website-preview approvals are stored with your project. Photographs are held in private Cloudflare R2 storage and are available only to the authorised client and linked Zarak team through authenticated routes. Photos are resized and saved as JPEG; location and other application metadata is removed. Keep original files separately. Uploading or approving a photograph does not automatically publish it, send it to AI, or copy it to Google Drive or OneDrive. Zarak may download approved photographs to prepare your agreed website changes. Contact lenin@zarakmarketing.com to request removal of uploaded materials, subject to necessary project and legal records.
Website projects and deposits
Private project records contain the agreed scope, terms, deposit amount, invoice reference, delivery updates and Revolut-hosted payment link. We record who accepted the project and when Zarak manually confirmed receipt, with an internal receipt reference. These records are restricted to Zarak and the designated linked client account. Revolut handles payment details on its own page; Zarak Client Portal does not store raw card or bank details. Where integrated Revolut checkout is used, the server verifies payment status with Revolut and records provider references. Optional recurring care requires separate card authorisation; existing saved agreements retain their terms.
Who is responsible
Zarak Marketing Ltd operates Zarak Client Portal. The registered office is 18 Albert Gate, Middlesbrough, North Yorkshire, TS5 6JA. Privacy questions can be sent to lenin@zarakmarketing.com.
Information used
Depending on the features you use, this may include account identity, business and website details, enquiries, messages, uploaded photographs, approvals, audit records and payment references. Owner reporting separately uses authorised Google metrics. Beta issue reports also record the page, browser/device description and viewport size you submit so faults can be reproduced.
Connected services
Clients do not need to connect Google or social accounts to use the portal. Zarak Client Portal uses Cloudflare for protected storage and hosting. Owner-only services are not made available to client workspaces. Zarak does not ask you to hand over a provider password.
Owner-only Google reporting
The Zarak owner may separately authorise selected Google Analytics and Search Console sources for read-only website reports. These connections and reports are not available to client workspaces. The website assistant and its inbox, calendar and vault access are retired. Access can be revoked with Google; authorisation alone does not confirm that a report update succeeded.
Why information is used
Information is used to provide the workspace, provide authorised owner website reports, manage approved work, maintain security and audit records, support billing, and respond to requests. Marketing use requires an appropriate basis and choice.
Stored records
The website assistant has been removed and its retired task and chat records have been deleted. Client account, project, photograph, payment and necessary security records remain protected. No new assistant requests are processed. Automated account deletion and export are not currently available; contact Zarak for help.
Control and security
Client workspaces have separate access permissions from the Zarak owner workspace. Connection tokens are encrypted at rest. Client accounts can access only their authorised projects, messages and materials. Owner reporting does not publish content or change Google accounts.
Your choices
You can ask about access, correction, deletion, restriction, objection, portability or provider disconnection where applicable. Email lenin@zarakmarketing.com without including secrets. We may need to verify your identity. Deletion is not automatic and some records may need to be retained for legal obligations or claims. You can also raise a data-protection concern with the Information Commissioner’s Office.
Earlier pilot records
The existing commitment for beta feedback and its diagnostic device/browser metadata remains: deletion within 90 days after the beta closes, unless a shorter deletion request applies or a longer period is required for a documented security or legal reason. Product records and uploads are not automatically erased by signing out or disconnecting a provider. Contact Zarak about retention or deletion of your account records.
Cookies and tracking
Necessary storage supports secure sign-in, authorisation and saved privacy choices. If Google Analytics 4 is configured, it remains unloaded until you allow Analytics and is limited to public product pages. No advertising tracker is currently active. See the cookie information and use the persistent control to change or withdraw optional choices.