Updated 20 September 2026
Security and privacy
This page explains the concrete security and privacy controls currently implemented in Zuno. It stays at the level of what the product actually does today.
How Zuno is structured
- Each practice has one account and one practice record. The database enforces this, so orders and settings are scoped to that practice.
- Practice details, orders, and credits are stored in a managed database, and the platform is served by a managed web host.
Access control
- Protected pages and actions check your signed-in session before loading or changing anything.
- Ownership is checked on every read and write, so one practice cannot see another practice's details, orders, or credits.
- Wholesalers' internal cost information is never available to practice accounts.
- Afridose staff tools, including order management and pricing, are limited to a short list of staff accounts.
Database protections
- Row Level Security is enabled on the practice, order, and credit tables. Policies are written around the signed-in owner.
- Sensitive fields, such as a practice's referral code and who referred it, cannot be edited from a practice account.
- Orders record the price at the time they were placed, and cannot be dispatched before they are marked paid.
Orders and payment
- Orders are confirmed by a person on WhatsApp. Cash is collected by the driver on delivery.
- Zuno takes no card details and stores no payment credentials.
- WhatsApp messages are handled by WhatsApp under its own terms.
Data protection
- Zuno is designed around data-protection principles such as purpose limitation and access control.
- We do not claim formal certification, regulator approval, or guaranteed legal compliance on this page.
- Practices should still review their own legal and professional obligations before using the service.