Privacy Policy

Last updated: January 2025

This Privacy Policy explains how ZERO VARIANT LTD ("ZERO VARIANT", "we", "us", or "our") collects, uses, shares, and protects personal information when you use our website and web application (the "Service") available at https://zerovariant.co.uk.

If you do not agree with this Privacy Policy, please do not use the Service.

1. Who we are (data controller)

For the purposes of the UK GDPR and EU GDPR (where applicable), ZERO VARIANT LTD is the data controller of personal data processed through the Service.

Contact details:

2. Personal data we collect

2.1 Information you provide

Depending on how you use the Service, we may collect:

  • First and last name
  • Email address
  • Phone number (if provided)
  • Billing and/or delivery address (if applicable)
  • Account-related information (such as login credentials or identifiers)

2.2 Information collected automatically

When you access or use the Service, we automatically collect:

  • IP address (including during login)
  • Device and browser information (user agent)
  • Log data (timestamps, pages viewed, actions taken)
  • Approximate location derived from IP address

IP addresses and logs are collected for security, fraud prevention, abuse detection, troubleshooting, and auditing.

2.3 Analytics data

We use Google Analytics to understand how users interact with the Service. This may include:

  • Pages visited
  • Time spent on pages
  • Referring pages
  • Device and browser information
  • Approximate geographic location

Learn more about Google's data practices: https://policies.google.com/privacy

3. How we use personal data

We use personal data to:

  • Provide, operate, and maintain the Service
  • Create and manage user accounts
  • Process payments and transactions
  • Send service-related communications
  • Send newsletters and product updates where users have opted in
  • Improve functionality, performance, and user experience
  • Detect, prevent, and address security or technical issues
  • Comply with legal obligations

4. Legal bases for processing (UK GDPR / EU GDPR)

Where applicable, we rely on the following legal bases:

  • Contract – to provide the Service and fulfil our obligations
  • Legitimate interests – security, fraud prevention, service improvement
  • Consent – marketing emails and non-essential cookies
  • Legal obligation – compliance with applicable laws

You may withdraw consent at any time.

5. Cookies and similar technologies

We use cookies and similar technologies for:

  • Essential site functionality
  • Analytics via Google Analytics

Where required by law (UK/EU), analytics cookies are used only after user consent, or are restricted until consent is given.

You can manage cookies through your browser settings.

6. Emails and communications

We send emails for:

  • Account and security notifications
  • Transactional messages
  • Newsletters and product updates (opt-in only)

Emails are delivered using Postmark, an email delivery service operated by ActiveCampaign.

Postmark privacy policy: https://postmarkapp.com/privacy-policy

You may unsubscribe from marketing emails at any time using the unsubscribe link provided.

7. Payments

Payments are processed by third-party payment processors:

  • Stripe
  • PayPal

When paying with PayPal, users may be redirected to PayPal's platform to complete checkout.

ZERO VARIANT LTD does not store full payment card details.

Privacy policies:

8. Sharing of personal data

We share personal data only where necessary, including with:

  • Service providers and processors (email, analytics, payments)
  • Professional advisers where required
  • Authorities where legally required
  • Successors in the event of a merger, acquisition, or asset sale

We do not sell personal data and do not use data for third-party advertising or remarketing.

9. International data transfers

Some service providers may process data outside the UK or EEA. Where required, we rely on appropriate safeguards such as adequacy decisions or standard contractual clauses to protect personal data.

10. Your rights (UK/EU)

You have the right to:

  • Access your personal data
  • Request correction or deletion
  • Restrict or object to processing
  • Request data portability
  • Withdraw consent at any time
  • Lodge a complaint with a data protection authority

To exercise your rights, contact us at support@staging.zerovariant.co.uk. We may need to verify your identity.

UK supervisory authority: Information Commissioner's Office (ICO).

11. Data retention

We retain personal data only as long as necessary:

  • Account data: for the duration of the account and a reasonable period after closure
  • Transaction records: as required by accounting and legal obligations
  • Security logs and IP addresses: typically 90 days, unless longer retention is required for security or legal reasons
  • Newsletter data: until you unsubscribe (with minimal suppression records retained)

12. Security

We use appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit, and monitoring for security incidents.

13. Age requirement

The Service is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18.

14. Third-party links

Our Service may contain links to third-party websites or services. We are not responsible for their privacy practices.

15. Changes to this policy

We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised "Last updated" date.

16. Contact us

For privacy-related questions or requests: