Privacy Policy
1. Data Controller Information
The data controller responsible for the processing of your personal data is:
Zephyroxttdrex
1000 Market St, San Francisco, CA 94102, United States
Email: touch@zephyroxttdrex.world
Website: https://zephyroxttdrex.world
2. Scope of This Policy
This Privacy Policy describes how Zephyroxttdrex ("we," "us," or "our") collects, uses, stores, and shares your personal data when you visit our website at zephyroxttdrex.world, place an order, or otherwise interact with our services.
This policy applies to all individuals located in the European Economic Area (EEA), the United Kingdom, and the United States. Where applicable, it complies with the General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA), and other relevant data protection laws.
3. Data We Collect
3.1 Data You Provide Directly
- Contact details: full name, email address, and phone number (optional) submitted via our order form.
- Order information: notes, special requirements, or questions submitted with your order.
- Communication records: emails or messages you send to our support team.
3.2 Data Collected Automatically
- Technical data: IP address, browser type and version, operating system, device type, and screen resolution.
- Usage data: pages visited, time spent on pages, links clicked, referral source, and navigation paths.
- Cookie data: session identifiers and consent preference records stored locally (see our Cookie Policy).
4. Purposes and Legal Basis for Processing
| Purpose | Data Used | Legal Basis (GDPR) |
|---|---|---|
| Processing and fulfilling your order | Name, email, phone, order notes | Contract performance (Art. 6(1)(b)) |
| Sending order confirmation and shipping notifications | Email address | Contract performance (Art. 6(1)(b)) |
| Responding to support enquiries | Name, email, communication content | Legitimate interests (Art. 6(1)(f)) |
| Website analytics and performance improvement | Technical data, usage data | Consent (Art. 6(1)(a)) |
| Legal compliance and record-keeping | Order data, communication records | Legal obligation (Art. 6(1)(c)) |
| Fraud prevention and security | IP address, device data | Legitimate interests (Art. 6(1)(f)) |
5. Cookies and Similar Technologies
We use cookies and similar technologies to operate our website and, with your consent, to analyze traffic. Cookie consent preferences are stored locally in your browser's localStorage. For full details on how we use cookies and how to manage your preferences, please see our Cookie Policy.
6. How We Share Your Data
We do not sell, rent, or trade your personal data to third parties. We may share your data with:
- Fulfilment and logistics partners: shipping and order processing services required to deliver your order.
- Payment processors: if applicable, secure payment service providers processing your transaction.
- IT service providers: hosting, email delivery, and technology infrastructure providers bound by data processing agreements.
- Analytics providers: only if you have consented via our cookie banner (aggregated, anonymized data).
- Legal authorities: where required by law, regulation, or valid legal process.
All third-party processors are required by contract to process your data only for specified purposes and to maintain appropriate security standards.
7. International Data Transfers
We are based in the United States. If you are located in the EEA or UK, your data may be transferred to and processed in the United States. Such transfers are carried out in accordance with applicable data protection law, using appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission, or other lawful transfer mechanisms.
8. Data Retention
- Order data: retained for 7 years to comply with financial and tax record-keeping obligations.
- Support communications: retained for 3 years from last contact, then deleted.
- Analytics data: retained in aggregated, anonymized form; identifiable data deleted within 26 months.
- Cookie consent records: retained for 13 months from the date of consent.
9. Your Rights
Depending on your location, you have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): request deletion of your personal data where there is no compelling reason for its continued processing.
- Right to restriction of processing: request that we limit how we use your data.
- Right to data portability: receive your data in a machine-readable format to transfer to another controller.
- Right to object: object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent: where processing is based on consent, you may withdraw at any time without affecting the lawfulness of prior processing.
- Rights under CCPA (California residents): right to know what personal information is collected, used, or disclosed; right to opt out of sale; right to non-discrimination for exercising rights.
To exercise any of these rights, contact us at: touch@zephyroxttdrex.world. We will respond within 30 days (GDPR) or 45 days (CCPA).
10. Data Security
We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, loss, or destruction. These include encrypted data transmission (HTTPS/TLS), access controls, and regular security assessments.
While we take all reasonable precautions, no method of transmission over the internet is completely secure. We encourage you to use strong, unique passwords and to contact us immediately if you suspect unauthorized access to your account.
11. Children's Privacy
Our website and products are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that a child under 18 has provided personal data, we will take steps to delete that information promptly.
12. Links to Third-Party Sites
Our website may contain links to external websites not operated by us. We have no control over the content or privacy practices of those sites and are not responsible for their privacy policies. We encourage you to review the privacy policy of any third-party site you visit.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Updated versions will be published on this page with a revised "Last updated" date. For significant changes, we will notify you by email or a prominent notice on our homepage.
14. How to Complain
If you believe we have not handled your personal data appropriately, you have the right to lodge a complaint with your local supervisory authority:
- EEA residents: contact your national data protection authority (a full list is available at edpb.europa.eu).
- UK residents: Information Commissioner's Office (ICO) — ico.org.uk
- California residents: California Attorney General — oag.ca.gov
We would appreciate the opportunity to address your concerns first. Please contact us at touch@zephyroxttdrex.world before filing a complaint.
15. Contact Us
For any questions, requests, or concerns regarding this Privacy Policy or our data practices:
Zephyroxttdrex
1000 Market St, San Francisco, CA 94102, United States
Email: touch@zephyroxttdrex.world