Privacy Policy
Last updated: July 2026
This is the privacy statement for Cirqon Technologies Limited (Cirqon Technologies or We). Cirqon Technologies Limited is a private company (company number 16192647) with its registered office at 22 Wadley Close, Gloucester, England, GL1 3FE.
For the purpose of the Data Protection Act 2018 and the General Data Protection Regulation 2016/679 the data controller is Cirqon Technologies Limited. Cirqon Technologies is registered at the ICO with number ZC010759.
Your privacy is our priority. This policy explains how Cirqon Technologies Limited ("Cirqon", "we", "us", or "our"), the operator of Zempto, collects, uses, and protects your personal information. We are committed to transparency and giving you control over your data.
This Privacy Policy applies globally to users accessing Zempto from any location. While Cirqon Technologies Limited is a UK-based company, we comply with major international privacy frameworks, including the UK GDPR, EU GDPR, California Consumer Privacy Act (CCPA), Canada's PIPEDA, and other regional data protection laws where applicable.
By using Zempto from outside the United Kingdom, you acknowledge that your personal information may be transferred, stored, and processed in the UK and other countries where our partners operate, in accordance with this Privacy Policy.
Information We Collect
Data Controller Information
Data Controller: Cirqon Technologies Limited is the data controller responsible for processing your personal data under this Privacy Policy.
Contact: business@zempto.com
Personal Information You Provide
- Account Information: Name, email address (via Google OAuth), profile photo, public username, and biographical information.
- Contact Details: Phone numbers for verification purposes (encrypted and stored securely).
- Payment Information: Billing details, payment method information (securely processed and stored by Stripe), and transaction history.
- Identity Verification: Government-issued ID documents for verification services (automatically deleted after 30 days of successful verification).
- User-Generated Content: Referral link descriptions, chat messages, dispute information, reviews, and ratings.
Information Collected Automatically
- Usage Analytics: Pages visited, features used, time spent on platform, search queries, and interaction patterns.
- Device Information: Device type, browser information, IP address, operating system, and mobile device identifiers.
- Location Data: General location information based on IP address for service customization and fraud prevention.
- Communication Metadata: Timestamps, delivery status, and read receipts for platform messages.
Information from Third Parties
- Social Login: Public profile information from Google when you sign in using social authentication.
- Payment Processors: Transaction status and payment verification data from Stripe.
- Fraud Prevention: Risk assessment data from security service providers.
Regional Data Collection Differences
Depending on your location, we may be required to collect additional information for identity verification or tax compliance (e.g., in the U.S. or EU).
For users in jurisdictions with specific privacy laws (such as California, Canada, Australia, or Singapore), we ensure collection and processing meet local requirements and user rights protections.
How We Use Your Information
Service Provision and Account Management
- Creating and maintaining your account, including authentication and profile management.
- Facilitating referral link sharing and request processing between users.
- Processing payments, calculating commissions, and generating invoices and transaction records.
- Providing customer support and responding to your inquiries through our help system.
Communication and Notifications
- Sending transactional emails about requests, approvals, payments, and account activities.
- Delivering in-app notifications about new messages, requests, and platform updates.
- Providing security alerts and important account information.
- Sending marketing communications (with your consent, and you can opt-out anytime).
Platform Safety and Security
- Verifying user identities through our optional verification system.
- Monitoring communications for policy violations and protecting against fraud.
- Conducting dispute resolution and investigating reported issues.
- Preventing unauthorized access and maintaining platform security.
Service Improvement and Analytics
- Analyzing usage patterns to improve features and user experience.
- Conducting research and analytics to enhance our matching algorithms.
- Testing new features and services with user feedback.
- Personalizing content and recommendations based on your preferences.
Legal Basis for Processing (GDPR/UK GDPR)
Cirqon Technologies Limited processes your personal data only when we have a valid legal basis to do so, including:
- Contractual necessity – to create and manage your account, process transactions, and provide our services.
- Consent – when you agree to receive marketing communications or enable optional features.
- Legitimate interests – to improve our services, prevent fraud, ensure security, and personalize your experience (without overriding your rights).
- Legal obligations – to comply with financial, tax, anti-fraud, and regulatory requirements.
Regional Legal Basis
For users outside the UK and EU, processing is based on either:
- Consent – where required by laws such as the CCPA (California), PIPEDA (Canada), or LGPD (Brazil); and
- Legitimate business interest – to provide secure, personalized, and reliable global services.
Users can withdraw consent or object to processing at any time via their account settings or by emailing business@zempto.com.
Legal Basis Summary Table
| Purpose | Data Processed | Legal Basis |
|---|---|---|
| Account creation and login | Name, email, Google OAuth data | Contractual necessity |
| Payments and transactions | Payment info, billing details | Contractual necessity / Legal obligation |
| Marketing communications | Email, preferences | Consent |
| Fraud prevention and security | IP, device data, location | Legitimate interests |
| Analytics and improvements | Usage and performance data | Legitimate interests |
| Identity verification | ID documents, photos | Consent / Legal obligation |
| Session recording (Microsoft Clarity) | Clicks, scrolling, navigation patterns | Legitimate interests |
Information Sharing and Disclosure
With Other Users (Controlled Sharing)
- Public Profile Information: Your chosen username, profile photo, ratings, and public bio are visible to other users.
- Referral Listings: Information about links you share, including descriptions and terms, is visible to potential requesters.
- Transaction History: Limited information about successful transactions for reputation building (no personal financial details).
- Verification Status: Display of verification badges you've earned through our identity or safety verification processes.
With Service Providers and Partners
- Payment Processing: Stripe handles all payment transactions and stores payment method information securely.
- Email Services: Transactional email providers for delivering notifications and communications.
- Cloud Infrastructure: Secure hosting providers for data storage and platform operations.
- Analytics Services: We use third-party services including Google Analytics and Microsoft Clarity for anonymized usage statistics and session recording.
- Session Recording (Microsoft Clarity): Microsoft Corporation (Clarity) may receive interaction data such as mouse movements, clicks, and scrolling behaviour. Sensitive fields (passwords, payment details) are masked automatically and never captured. Microsoft's privacy statement is available at privacy.microsoft.com.
Legal and Safety Requirements
- When required by law, regulation, or court order.
- To protect our rights, property, or safety, or that of our users or others.
- In connection with legal proceedings, investigations, or regulatory inquiries.
- To prevent or address fraud, security breaches, or technical issues.
Law Enforcement Requests
We may disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. Any such disclosures will be limited to what is legally required and handled with transparency where permitted by law.
We Never Sell Your Personal Data
Cirqon Technologies Limited does not sell, rent, or lease your personal information to third parties for their marketing purposes. Your data is only used to provide and improve our service.
International Data Sharing
Zempto may share personal information with affiliates or service providers located in countries outside your own. In all cases, we ensure equivalent protection through Standard Contractual Clauses or other approved safeguards.
For users in the United States, Canada, or Australia, we limit data disclosure to purposes directly related to the provision and improvement of Zempto services, consistent with local privacy laws.
Third-Party Links and External Services
Third-Party Links and External Services
Our platform may contain links to third-party websites, referral programs, or external services. We are not responsible for the privacy practices, content, or security of these third-party services. We encourage you to review their privacy policies before providing any personal data.
When you click on a referral link shared through Zempto, you will be directed to an external website operated by that company. Your interactions with that site, including any data you provide, are governed by their privacy policy and terms of service, not ours.
Data Security and Protection
Technical Safeguards
- Encryption: All sensitive data is encrypted both in transit (TLS/SSL) and at rest using industry-standard algorithms.
- Access Controls: Strict employee access controls with multi-factor authentication and regular access reviews.
- Infrastructure Security: Secure cloud hosting with regular security updates, monitoring, and vulnerability assessments.
- Payment Security: PCI DSS compliant payment processing through Stripe with tokenized card storage.
Operational Safeguards
- Regular security audits and penetration testing by third-party experts.
- Employee training on data protection and privacy best practices.
- Incident response procedures for potential security breaches.
- Data backup and recovery systems to ensure service continuity.
Identity Document Security
Government ID documents uploaded for verification are processed using secure, encrypted systems and are automatically purged from our servers 30 days after successful verification. This ensures your sensitive documents are not stored longer than necessary.
Global Security Standards
Our data protection and cybersecurity measures align with internationally recognized standards, including ISO/IEC 27001 and NIST frameworks, ensuring consistent protection across all regions where we operate.
Cookies and Tracking Technologies
Types of Cookies We Use
- Essential Cookies: Required for basic platform functionality, including authentication and security features.
- Performance Cookies: Help us understand how users interact with our platform to improve performance and user experience.
- Preference Cookies: Remember your settings, language preferences, and customization choices.
- Analytics Cookies: Provide insights into platform usage patterns and help us optimize our services.
Microsoft Clarity – Session Recording
We use Microsoft Clarity, a behavioural analytics tool operated by Microsoft Corporation, to help us understand how users interact with Zempto. Clarity may record:
- Mouse movements, clicks, and scrolling behaviour.
- Pages visited and navigation patterns.
- General device and browser information.
What Clarity does NOT capture: Sensitive input fields such as passwords, payment card numbers, and personal identification fields are automatically masked and are never transmitted to Microsoft.
The legal basis for this processing is our legitimate interest in improving usability and diagnosing technical issues. Data collected by Clarity is processed by Microsoft in accordance with the Microsoft Privacy Statement. You may opt out of Clarity tracking at any time by enabling a "Do Not Track" signal in your browser or by contacting us at business@zempto.com.
Managing Your Cookie Preferences
You can control cookie settings through your browser preferences. Note that disabling certain cookies may impact platform functionality. We respect Do Not Track signals and provide cookie consent options where required by law.
Regional Cookie Compliance
For users in the EU, UK, and similar jurisdictions, we use a cookie consent banner in compliance with the ePrivacy Directive (Cookie Law).
For users in other regions, cookie use follows local digital advertising and tracking laws (e.g., CCPA and CPRA in California). Users can withdraw or modify consent at any time via the in-app cookie settings.
International Data Transfers
Cirqon Technologies Limited operates globally and may transfer your personal data to countries outside your residence, including the United States and European Union. We ensure all international transfers comply with applicable data protection laws through:
- Standard Contractual Clauses approved by the European Commission.
- Adequacy decisions for transfers to countries with adequate protection levels.
- Binding corporate rules and other legally recognized transfer mechanisms.
- Ensuring our service providers maintain equivalent data protection standards.
For UK users, we rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses where required.
Legal Basis for International Transfers to the U.S.
For transfers to the United States, we rely on the EU-U.S. Data Privacy Framework and UK Extension (where applicable) or Standard Contractual Clauses to ensure adequate data protection. These mechanisms have been approved by the European Commission and UK Information Commissioner's Office as providing appropriate safeguards for international data transfers.
We also comply with equivalent international transfer mechanisms where applicable, including Canada's PIPEDA cross-border rules, Brazil's LGPD adequacy standards, and emerging regional frameworks such as India's Digital Personal Data Protection Act 2023.
Data Retention
Account and Profile Data
- Active Accounts: Retained for as long as your account remains active or as needed to provide services.
- Closed Accounts: Most personal data deleted within 90 days of account closure, except where legal retention is required.
- Deactivated Accounts: Data retained but made invisible; you can reactivate or permanently delete at any time.
Transaction and Communication Data
- Transaction Records: Retained for 7 years for legal, tax, and dispute resolution purposes.
- Chat Messages: Retained until either party deletes their account or requests deletion.
- Dispute Records: Retained for 5 years for potential legal proceedings and pattern analysis.
Verification and Security Data
- Identity Documents: Automatically deleted 30 days after successful verification.
- Security Logs: Retained for 2 years for security monitoring and incident investigation.
- Payment Information: Managed by Stripe according to their retention policies and legal requirements.
Legal Retention and Tax Compliance
Certain transaction and financial records may be retained for up to seven (7) years as required by UK tax and accounting laws, even after account deletion. This includes invoice records, payment transaction history, and any documentation necessary for tax reporting and audit purposes.
Your Privacy Rights and Choices
Access and Portability
- Data Access: Request a copy of all personal data we hold about you in a structured, machine-readable format.
- Account Dashboard: View and manage your personal information through your account settings.
- Transaction History: Access your complete transaction and interaction history through our platform.
Correction and Deletion
- Profile Updates: Modify your profile information, preferences, and account settings at any time.
- Data Correction: Request correction of inaccurate or incomplete personal information.
- Account Deletion: Permanently delete your account and associated personal data (subject to legal retention requirements).
Communication Preferences
- Email Notifications: Customize which types of emails you receive through your notification settings.
- Marketing Communications: Opt-out of promotional emails while continuing to receive essential service communications.
- Push Notifications: Control mobile app notifications through your device settings.
Automated Decision-Making and Profiling
Zempto may use automated tools to detect fraudulent activity and to provide personalized recommendations. These processes do not have legal or similarly significant effects on you. If you wish to object to profiling or request human review of an automated decision, you may contact us at business@zempto.com.
Additional Rights for Non-UK Users
Depending on your location, you may have additional rights under local privacy laws, including:
- Right to Know / Access: What data we collect and how it's used (CCPA/CPRA).
- Right to Correction: To fix inaccurate or outdated information (LGPD, PIPEDA).
- Right to Deletion / Erasure: To request deletion of personal data, except where legally required to retain it.
- Right to Object / Restrict Processing: For marketing or profiling purposes.
- Right to Data Portability: To transfer your data to another service provider.
To exercise these rights, contact us at business@zempto.com with your region mentioned in the subject line (e.g., "Privacy Request – Canada"). We'll respond within the legally required timeframe.
Exercising Your Rights
To exercise any of these rights, contact us through the app's support system or email us directly at business@zempto.com. We'll respond to your request within 30 days and may require identity verification for security purposes.
Children's Privacy
Zempto is intended for users aged 18 and older. We do not knowingly collect personal information from anyone under 18 years of age. If we become aware that we have collected personal information from someone under 18, we will take immediate steps to delete such information. If you believe a child has provided us with personal information, please contact us immediately at business@zempto.com.
Changes to This Privacy Policy
Cirqon Technologies Limited may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Notify you via email or prominent notice in the app before the changes take effect.
- Update the "Last updated" date at the top of this policy.
- For significant changes, provide a summary of key updates and seek additional consent where required.
- Maintain previous versions for your reference and comparison.
Your continued use of Zempto after policy updates constitutes acceptance of the revised terms.
Regional Addenda
To reflect regional privacy requirements, Zempto provides additional notices or "addenda" for certain jurisdictions. These supplements clarify how specific laws apply:
- European Union and UK: GDPR/UK GDPR Addendum
- United States (California): CCPA/CPRA Addendum
- Canada: PIPEDA Addendum
- Australia: APP (Australian Privacy Principles) Addendum
- Brazil: LGPD Addendum
These regional notices are available on our website and form part of this Privacy Policy.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out to Cirqon Technologies Limited:
- Through the App: Use our in-app support system for the fastest response.
- Email: business@zempto.com for privacy-specific inquiries.
- General Support: Available through your account dashboard help section.
We aim to respond to all privacy-related inquiries within 24 hours during business days.
Data Controller Information
Company Name: Cirqon Technologies Limited
Trading As: Zempto
Registered in: United Kingdom
Contact Email: business@zempto.com
For global inquiries, Cirqon Technologies Limited may designate regional privacy representatives or data protection officers (DPOs) where required by local law. Details will be published on the Zempto website as regional operations expand.
