Security in MYZAP is a shared responsibility: we protect the platform, and you protect your account and devices. This page explains both sides and how to report a problem.
1.What we do
ZAPMICRO applies reasonable technical and organisational measures designed to protect MYZAP and the data it holds, including:
- Encryption of data in transit (HTTPS/TLS)
- Passwords stored only in hashed form
- Row-level access controls so each shop sees only its own data
- Role-based permissions for owners, staff and delivery users
- Restricted administrative access and audit logging
- Managed cloud infrastructure with provider-level safeguards and backups
- Regular dependency and security reviews
No internet-connected system can be described as absolutely secure. We do not claim MYZAP is "100% secure", and account security depends significantly on the practices you follow.
2.Protect your MYZAP account
- Never share your password or OTP.
- Use separate accounts for staff members.
- Sign out from shared devices after use.
- Change your password periodically and immediately if compromise is suspected.
- Remove access for staff who no longer work with you.
- Keep your device, browser and operating system updated.
- Allow offline bills to sync before clearing app or browser data.
- Regularly retain or export important business records.
- Protect your device with a PIN, password or biometrics.
- Protect the email and mobile number registered to your account.
ZAPMICRO will never ask you to disclose your password.
Signing out at the end of the business day, particularly on shared devices, is good practice — but it does not by itself eliminate all security risk.
3.Staff accounts and access reviews
Create an individual account for every person who uses MYZAP instead of sharing one administrator login. This keeps activity traceable and lets you revoke access precisely.
- Review the team list in the app at regular intervals
- Give each person the lowest role that lets them do their job
- Remove access on the same day an employee leaves
- Reset shared or suspected credentials immediately
4.Offline data safety
Offline billing stores records on your device until they are synchronised. Before clearing browser or app data, uninstalling the MYZAP app, resetting the device or switching browsers, open the app while online and let synchronization finish. Otherwise unsynchronised bills and edits may be permanently lost.
5.Report unauthorized access
Tell us immediately if you notice any of the following:
- A login you do not recognise
- Credential theft or a phishing attempt using the MYZAP name
- Suspicious bills, refunds or stock changes
- Staff access you did not authorise
- Any suspected exposure of business or customer data
Change the affected passwords first, then contact us so we can investigate and assist.
6.Responsible vulnerability disclosure
If you believe you have found a security vulnerability, report it privately using the contacts below. Please do not access, modify or publish other users' data, and give us a reasonable opportunity to fix the issue. Testing must follow the Acceptable Use Policy.
7.Security contact
Related documents: Terms of Service · Privacy Policy
