Privacy policy
Zoop ISP Management app
In short
- The app is a secure way for ISP and LCO staff to sign in to their Zoop Radius panel from a phone.
- It has no advertising, no analytics and no third-party trackers.
- It does not read your location, contacts, messages, call logs or microphone.
- Your fingerprint never leaves your phone; the app never sees it.
- We do not sell personal data.
Who this policy covers
Zoop ISP Management is a business tool for people who work for an internet service provider (ISP) or a local cable operator (LCO) that uses the Zoop Radius ISP management system. You need an account issued by that ISP to use it. It is not meant for the ISP's broadband customers, and it is not meant for anyone under 18.
"We" and "us" mean Zoop Radius, the provider of the app and the system behind it.
What the app collects, and why
| Data | Why it is needed | Where it goes |
|---|---|---|
| Username and password | To sign you in to your Zoop Radius account. | Sent to the Zoop Radius server over an encrypted (HTTPS) connection. The app does not keep your password on the phone. |
| Device sign-in key | So you can open the app with your fingerprint instead of typing your password each time. | Stored on your phone in encrypted form, together with your username, and unlocked only by your fingerprint through Android's secure key storage. The server keeps only a scrambled (hashed) copy of the key. |
| Device details | So your ISP's administrator can see which phones are enrolled on an account and remove one that is lost. | Stored on the Zoop Radius server: an install ID generated by the app, a device label, the app version, the platform, the browser identifier, the IP address, and when the device was enrolled and last used. |
| Session cookies | To keep you signed in while you use the app. | Stored inside the app on your phone. |
| Photos and files you choose | To attach a document to a customer's account, or to scan a router's serial number, when you choose to do so. | Uploaded to your ISP's Zoop Radius account. Nothing is uploaded unless you select or capture it. |
Permissions the app asks for
- Camera — used only while you scan a barcode or serial number, or take a photo of a document to upload. The app does not use the camera in the background.
- Fingerprint / biometrics — used to unlock the app. The check is done by Android on your phone. The app is told only whether it succeeded; it never receives or stores your fingerprint.
- Internet and network state — to reach the Zoop Radius server and to tell you when you are offline.
Files you download in the app, such as invoices, are saved to your phone's Downloads folder.
The business data you see in the app
Inside the app you work with your ISP's records: its broadband customers' names, contact details, addresses, connection details, invoices, payments and documents. That information belongs to the ISP, which decides what is collected and how it is used. We store and process it on the ISP's behalf so that the system can work. If you are a broadband customer and have a question about your own data, please contact your ISP.
Who we share data with
We do not sell personal data, and we do not share it for advertising. Data is disclosed only:
- to the companies that host and operate our servers, under our instructions;
- to services your ISP has chosen to connect, such as a WhatsApp messaging provider or a payment gateway, and only the details needed for that message or payment;
- when the law requires it.
How it is protected
- All communication between the app and the server is encrypted with HTTPS.
- The device sign-in key is held in Android's secure key storage and cannot be used without your fingerprint or screen lock.
- Passwords and device keys are stored on the server only in hashed form.
- An administrator can remove an enrolled device at any time, which stops it signing in.
- Each ISP's data is kept separate from every other ISP's.
No system can be guaranteed to be perfectly secure. If you lose your phone, ask your ISP's administrator to remove the device straight away.
How long data is kept
Device details are kept while the device stays enrolled on your account, and a record that it was enrolled may be kept afterwards for security auditing. Account and business records are kept for as long as your ISP uses Zoop Radius, or as long as the law requires.
Your choices, and how to delete your data
- Remove this phone: uninstalling the app, or clearing its data, deletes the sign-in key and cookies from the phone.
- Remove the device record: ask your ISP's administrator to remove the device from the Devices page, or ask us.
- Delete your account: accounts are created and removed by your ISP. Ask your ISP's administrator, or contact us on the number below and we will pass the request on and confirm when it is done.
- See or correct your details: ask your ISP's administrator, or contact us.
- Camera and fingerprint: you can withdraw either permission at any time in Android Settings. You can then still sign in with your password, but scanning and photo upload will not work without the camera.
Changes to this policy
If the app starts handling data differently, we will update this page and change the effective date at the top before the change takes effect.
Contact
For any question about this policy or a request about your data, call or message us on 8451 8451 89 (WhatsApp).