Privacy policy
This privacy policy explains how Zenarion (Riya Thai Massage by Kusnirik, the "data controller") handles personal data of website visitors and registered users. It is based on the revised Swiss Federal Act on Data Protection (revFADP, in force since 1 September 2023) and — where applicable — on the EU General Data Protection Regulation (GDPR).
1. Data controller
Riya Thai Massage by Kusnirik
Schaffhauserstrasse 453, 8052 Zürich, Switzerland
Contact: [email protected]
2. What data we process
- Technical access data: IP address (anonymised), user agent, requested URL, timestamp — solely for operation and abuse detection.
- Audience measurement: aggregate page-view counts via Plausible Analytics. Plausible uses no cookies and collects no personal data.
- Salon directory data: business name, address, phone, website, opening hours, photos, Google reviews — sourced from the Google Places API or entered manually by us or by the salon owner.
- Booking requests: first and last name (plaintext), email and phone (encrypted — see §4), requested date and time, duration, massage type, optional note. See §4.
- Native reviews: display name, review text, star rating, verified phone number (via Twilio Verify — see §7), optional visit date. Display name shown publicly only as "First L." (revFADP data minimisation).
- Account data (Auth.js): email, language preference, optional display name and profile picture for Google sign-in. For OAuth sign-in we store the tokens Google issues (access token, refresh token) for session management.
- Salon claim submissions (SalonClaim): listing ID, submitted message, decision and (where applicable) rejection reason.
- Messages to salons (email relay): if you contact a salon through its contact form or its Zenarion email address (…@mail.zenarion.ch), we store the sender name, subject and message text in the salon's Zenarion inbox. Your email address is stored encrypted (see §4); the message is forwarded to the salon's own email address. Replies travel through masked reply addresses, so both sides stay reachable without exposing email addresses. To route replies we additionally store the technical Message-ID of each email we send, linked to the respective conversation or booking; beyond this ID, no content is stored for that purpose.
- Billing data (paid plans): to invoice paid plans we process the business or owner name, billing address, plan, invoice number, amount and payment status. The legal basis is performance of the contract; retention follows Swiss commercial and tax record-keeping duties (10 years).
- Gift card purchases:when a gift card is ordered via a salon page we process the buyer's name, email address (stored encrypted — see §4), amount, recipient name, personal message and the code's redemption balance — to issue, deliver and validate the respective salon's gift cards.
3. Purpose & legal basis
- Operating the directory: legitimate interest (art. 31 par. 2 lit. d revFADP / art. 6 par. 1 lit. f GDPR).
- Showing public business data about salons: legitimate interest; data already publicly available.
- Facilitating booking requests: contract performance or pre-contractual steps (art. 31 par. 1 revFADP / art. 6 par. 1 lit. b GDPR).
- Audience measurement: legitimate interest in aggregate usage data to improve the service.
- Review verification: legitimate interest in authentic reviews and abuse prevention.
- Salon offers to existing guests:salons may occasionally send offers or news via Zenarion to their own past guests (Art. 3 para. 1 lit. o Swiss UCA — advertising one's own similar services to existing customers). Every such email contains a working unsubscribe link; an unsubscribe is honoured permanently. Unsubscribes are enforced via a suppression list that stores a hash of your email address plus the optional reason or feedback you provide; every such email also supports one-click unsubscribe per RFC 8058. As proof of compliance we keep a per-recipient send log. Booking confirmations and appointment reminders are unaffected.
4. Booking requests
When you submit a booking request via a salon's booking form, we collect and store the following data in our database (hosted by Railway, EU-West (Amsterdam, Netherlands)):
- Plaintext: first and last name, requested date and time, massage type, duration and your optional note to the salon.
- Encrypted: your email address and phone number. Both fields are encrypted at rest with AES-256-GCM (256-bit symmetric encryption) and decrypted only when we deliver an email to you or the salon, or when you access your inbox via magic link.
- Pseudonymous hashes: we compute an HMAC-SHA-256 hash of your email and phone with a secret pepper so we can detect duplicates and respond to requests without decrypting the originals.
Phone masking: until a salon explicitly confirms your request, the salon sees your phone number only in masked form (e.g. +41 *********67). The full number is revealed in the salon's inbox only after confirmation.
Unclaimed salons: salons without a registered account on Zenarion can also receive requests. These are stored in a demand pool and only become accessible once the salon claims its listing. Until then no automated notification is sent to the salon.
Cancellation: you may cancel your request at any time via the magic link in the confirmation email in your inbox. Confirmed bookings can be cancelled up to 24 hours before the appointment.
Reminder: for confirmed bookings we send you a single reminder email (via Resend) before the appointment, by default 24 hours in advance (the salon can adjust the lead time). The salon receives its own copy only if it has enabled that in its settings.
SMS notifications: if the salon has enabled SMS notifications, we send the booking confirmation and the reminder to the phone number you provided by SMS, in addition to or instead of the email. Delivery runs via Twilio (Twilio Ireland Ltd.); your phone number is transmitted to Twilio for this purpose. In our systems, SMS sends are logged only with a hash of the recipient number, never in plain text.
Bookings via AI assistants: guests may also submit booking requests through third-party AI assistants connected to our public booking interface. The assistant transmits your name, email address, phone number, requested slot and optional note on your behalf. The same encryption and phone masking described above apply. The provider of the AI assistant acts on your instruction and is not a sub-processor of Zenarion. Such bookings are rate-limited and marked internally as assistant bookings.
Staff-planning hint (form of address): from the first name of the person booking we derive a probable form of address — based on the public WGND name dictionary — shown to the salon solely for staff planning. This hint is computed on the fly each time it is displayed, never stored, never shown publicly and never shared with third parties. No inference is made beyond the first name.
Cancellations and no-shows: in its customer overview, booking notifications and customer export, the salon sees how many earlier bookings at that salon the person cancelled themselves (and how many of those less than 24 hours before the start) and how often they did not show up. Only bookings at that one salon are counted. The figures are computed from the existing booking records each time they are displayed, never shared between salons, never shown publicly and never used for any automated decision.
5. Public demand display
On the public detail page of salons that have not yet claimed their listing, we display up to five pending booking requests in an anonymous, shortened form. Publicly visible are only:
- The requested massage type and duration.
- The date and the start time rounded to the full hour (e.g. "Fri 12 Apr · 14:00") — without the exact minute.
Not public are and remain: your name (in any form), email, phone and optional note. The salon owner sees your name and contact details only through their private inbox after they claim the listing.
Purpose: this display signals real demand to the salon and encourages them to claim the listing so you can receive a response. You are notified of this display before submitting the form.
Right to object: you can withdraw your request at any time from your inbox — your card disappears immediately from the public demand display. As soon as the salon declines, the booking is cancelled or you withdraw it, the card is removed as well.
6. AI-generated photo captions
To make salon photos more discoverable in image search and to give screen-reader users a meaningful description, we generate short alt-text captions automatically using an AI model from OpenAI (model gpt-5.4-mini).
- What is sent: the public URL of the photo on our image server (
images.zenarion.ch) plus the salon name and city. - What is NOT sent: any customer data, booking data or identifying information about people viewing the photo.
- What is stored: only the generated caption (max. 120 characters) in the field
Photo.caption.
OpenAI is a sub-processor with EEA legal entity OpenAI Ireland Ltd. See §8.
7. Phone verification for native reviews
To ensure the authenticity of native reviews, we verify phone numbers before publication via a one-time SMS code. To do this we send your phone number to Twilio Verify (Twilio Ireland Ltd.).
- Twilio sends a one-time code to your number and checks your input.
- On successful verification we store your phone number (plaintext) on your user account (
User.phone) so we can recognise you for future reviews. - Your phone number is not displayed publicly.
8. Recipients (sub-processors)
- Railway — application and database hosting (EU-West (Amsterdam, Netherlands)). Privacy policy.
- Google Maps Platform (Places API) — Salon directory data, ratings, reviews, photos. Privacy policy.
- Google Identity (Sign in with Google) — Optional OAuth sign-in for users + salon owners. Privacy policy.
- Plausible Analytics — Privacy-friendly page-view analytics (no cookies). Privacy policy.
- Sentry (GmbH, Germany) — Server-side error tracking (no user-supplied PII captured). Privacy policy.
- OpenAI Ireland Ltd. — AI image captioning (public photo URLs only) + admin-side AI-assisted content generation. Privacy policy.
- Cloudflare R2 (Cloudflare Inc.) — Object storage for resized salon + city photos and 24-hour salon Stories, served via images.zenarion.ch. Privacy policy.
- Cloudflare Turnstile — Privacy-friendly bot protection on contact, booking and review forms (operated in Invisible mode — see Privacy §8). Privacy policy.
- Cloudflare CDN (visitor location headers) — Edge-level reverse proxy. Derives an approximate location (country, city, canton, latitude, longitude) from the visitor's IP address and forwards it as request headers so the homepage search can pre-select the nearest Swiss city. The IP itself is not exposed to our servers; the coordinates are read once per request and never stored.. Privacy policy.
- Resend (Resend, Inc.) — Transactional email delivery (magic links, booking proposals, confirmations, reminders, claim notifications). Privacy policy.
- Twilio Verify (Twilio Inc.) — Phone-number verification (one-time SMS code) for native review authentication. Privacy policy.
Hosting & CI: for automated deployment we use GitHub Actions (GitHub Inc.) (Post-deploy health watchdog (runs a Railway restart if the new container is unresponsive). Processes service metadata only — never user data.) Privacy policy.
Cloudflare Turnstile — Invisible Mode: when you submit a contact, booking or review form on this site, Cloudflare Turnstile runs a silent bot check in the background. There is no visible widget; the verification happens automatically. Cloudflare may collect technical information about your device and browser to perform the check, as described in the Cloudflare Privacy Policy. This processing is also subject to the Cloudflare Turnstile Privacy Addendum. By submitting the form you accept this processing.
Database backups: we create a full backup of our database every night and store it in a separate, non-publicly accessible bucket on Cloudflare R2 (encrypted at rest server-side there). The encrypted contact fields (see §4) are contained in the backup exclusively in their encrypted form. Every backup run is logged. Old backups are deleted automatically after 30 days; the seven most recent successful backups are always retained regardless of age.
9. International transfers
Some of our sub-processors are based outside Switzerland and the EU — notably Google (US), Sentry GmbH (Germany), OpenAI Ireland Ltd. (Ireland), Cloudflare Inc. (US), Resend Inc. (US) and Twilio Inc. (US, with EEA data-processing terms). Transfers outside the EEA rely on the EU Standard Contractual Clauses (SCCs) and additional technical and organisational safeguards. Further information on request.
10. Retention
- Server logs: 14 days.
- Salon directory data: for the lifetime of the directory.
- Booking requests: retained indefinitely for follow-up and complaint handling. On request we redact your personal data across all bookings within 14 days (see §11).
- Native reviews: while the salon is listed, unless you request deletion.
- Account data: for the duration of your active account; deleted within 30 days of account deletion.
- Stories: public for 24 hours, then the row and the R2 image objects are hard-deleted by an hourly job.
- Database backups: 30 days; the seven most recent successful backups are retained regardless of age, older ones are deleted automatically (see §8).
11. Your rights
Under revFADP (and, where applicable, GDPR) you have the right to:
- Information about the personal data we process about you.
- Rectification of inaccurate data.
- Erasure of your personal data (right to be forgotten).
- Objection to specific processing.
- Data portability for data you provided to us.
To exercise any of these rights, email [email protected] — using the email address you used with us. We respond within 30 days.
Right to be forgotten for bookings: on receiving an erasure request we redact the encrypted email and phone fields (customerEmailEnc, customerPhoneEnc), delete the corresponding hashes and replace your name in the affected conversations with "[redacted]". This operation runs through a protected admin interface, is audit-logged and is normally completed within 14 days.
Data export by salons: a salon that has claimed its listing can export the booking and contact data of its own guests as a CSV file to maintain its customer relationship independently of Zenarion. The salon is itself responsible for any subsequent processing of that data; Zenarion and the salon each remain responsible for their own processing.
12. Cookies
We use only essential cookies (sign-in session, theme preference, locale choice). No tracking cookies, no advertising cookies. Plausible Analytics operates entirely without cookies. We therefore deliberately do not display a cookie banner. Stories uses sessionStorage only to deduplicate view counting; sessionStorage is not a cookie and is not used for tracking.
13. Data Protection Officer (DPO)
We are not required to appoint a DPO under revFADP. For any data-protection questions, please contact [email protected].
14. Right to complain
You may file a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC): www.edoeb.admin.ch. For GDPR-relevant matters you may contact the data-protection authority in your country of residence.
15. Stories
Salon owners can publish ephemeral "Stories" — a portrait photo that is publicly visible and automatically expires after 24 hours. On expiry the story is hidden immediately, and an hourly background job then permanently deletes both the database row and the associated image files.
- Storage: the image is stored — like regular salon photos — as a resized WebP variant on Cloudflare R2 and served via our image server (
images.zenarion.ch). - Retention: public for 24 hours; hidden immediately at expiry; the hourly job then performs a hard delete of the database row and the image objects on Cloudflare R2.
- View counter: for each story we keep only an aggregate view count, shown to the salon as a simple number. The counter is incremented once per browser session (deduplicated via
sessionStorage). We store no viewer identity, no IP addresses and no event log. - Owner responsibility: salon owners are responsible for the rights and consent of any people depicted. Stories are published without prior moderation (with file type and size validation). You can report a story; we remove flagged content the same day. Reports to [email protected].
sessionStorage is not a cookie and is not used for tracking.
Last updated: 29 September 2026