Privacy policy
Privacy Policy
Last updated: May 2026
1. Who We Are
ZenVoraFit ("we", "us", "our") is a UK-based online retailer of wellness and recovery devices, operating at www.zenvorafit.com.
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, ZenVoraFit is the data controller responsible for your personal data.
Contact: support@zenvorafit.com
2. What Data We Collect
We may collect and process the following personal data:
a) Data you provide directly:
- Full name
- Email address
- Delivery and billing address
- Phone number (if provided)
- Payment information (processed securely — we do not store card details)
- Messages or enquiries sent to us
b) Data collected automatically:
- IP address
- Browser type and version
- Device type and operating system
- Pages visited and time spent on site
- Referring website or search term
- Cookie identifiers (see Section 8)
c) Data from third parties:
- Information from payment processors (e.g. transaction status)
- Information from analytics providers (e.g. Google Analytics)
3. Lawful Basis for Processing
We process your personal data on the following lawful bases under UK GDPR Article 6:
| Purpose | Lawful Basis |
|---|---|
| Processing and fulfilling your order | Contract (Article 6(1)(b)) |
| Sending order confirmations and updates | Contract (Article 6(1)(b)) |
| Responding to customer enquiries | Legitimate interests (Article 6(1)(f)) |
| Sending marketing emails (with your consent) | Consent (Article 6(1)(a)) |
| Fraud prevention and security | Legitimate interests (Article 6(1)(f)) |
| Complying with legal obligations (e.g. tax records) | Legal obligation (Article 6(1)(c)) |
| Improving our website and services | Legitimate interests (Article 6(1)(f)) |
4. How We Use Your Data
We use your personal data to:
- Process, fulfil and deliver your orders
- Communicate with you about your order status
- Handle returns, refunds and complaints
- Send you marketing communications (only with your consent — you may opt out at any time)
- Improve our website, products and customer experience
- Detect and prevent fraud or misuse of our services
- Comply with our legal and regulatory obligations
We will never sell your personal data to third parties.
5. Who We Share Your Data With
To operate our business, we share your data with trusted third parties only where necessary:
Fulfilment and shipping partners — your name, address and order details are shared with our logistics and supply partners to fulfil and deliver your order. Some of our fulfilment partners may be located outside the UK (see Section 7).
Payment processors — Shopify Payments, PayPal or other payment providers process your payment. We do not store or have access to your full card details.
Shopify Inc. — our store is built on Shopify. Shopify processes data on our behalf as a data processor. You can view Shopify's privacy policy at shopify.com/legal/privacy.
Email marketing platforms — if you subscribe to our newsletter, your email address may be stored with a third-party email platform (e.g. Klaviyo or Mailchimp).
Analytics providers — we use Google Analytics to understand how visitors use our website. This data is anonymised and aggregated where possible.
Legal authorities — we may disclose your data if required to do so by law, court order, or regulatory authority.
6. Data Retention
We retain your personal data only for as long as necessary for the purposes set out in this policy:
| Data type | Retention period |
|---|---|
| Order and transaction records | 7 years (UK tax law requirement) |
| Customer account data | Duration of account + 2 years after last activity |
| Marketing consent records | Until you withdraw consent + 1 year |
| Website analytics data | 26 months (Google Analytics default) |
| Customer service correspondence | 3 years |
When data is no longer required, we securely delete or anonymise it.
7. International Data Transfers
Some of our service providers and fulfilment partners operate outside the United Kingdom, including in countries that may not provide the same level of data protection as the UK.
Where we transfer personal data outside the UK, we ensure appropriate safeguards are in place in accordance with UK GDPR, including:
- Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office (ICO)
- Transfers to countries with an adequacy decision from the UK Government
For more information about the safeguards in place, please contact us at support@zenvorafit.com.
8. Cookies
Our website uses cookies — small text files stored on your device — to improve your experience and help us understand how our site is used.
Types of cookies we use:
| Cookie type | Purpose |
|---|---|
| Essential | Required for the website to function (e.g. shopping cart, login) |
| Analytics | Help us understand how visitors use the site (e.g. Google Analytics) |
| Marketing | Track visits to show relevant ads on other platforms (e.g. Meta Pixel) |
| Preferences | Remember your settings and preferences |
You can manage or withdraw your consent to non-essential cookies at any time via our cookie banner or your browser settings. Note that disabling certain cookies may affect the functionality of our website.
For more information, please see our Cookie Policy [link].
9. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
- Right of access — request a copy of the personal data we hold about you
- Right to rectification — request correction of inaccurate or incomplete data
- Right to erasure ("right to be forgotten") — request deletion of your data, subject to legal obligations
- Right to restriction — request that we limit how we process your data
- Right to data portability — receive your data in a structured, machine-readable format
- Right to object — object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing
To exercise any of these rights, please contact us at support@zenvorafit.com. We will respond within one calendar month.
We may need to verify your identity before fulfilling your request.
10. Marketing Communications
We will only send you marketing emails if you have given your explicit consent (e.g. by ticking an opt-in box at checkout or subscribing to our newsletter).
You can unsubscribe at any time by:
- Clicking the "Unsubscribe" link in any marketing email
- Emailing us at support@zenvorafit.com
Withdrawing consent does not affect the lawfulness of any marketing sent before you opted out.
11. Data Security
We take the security of your personal data seriously. We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, disclosure or alteration. These include:
- SSL/TLS encryption on all pages
- Secure payment processing via PCI-DSS compliant providers
- Access controls limiting who can view customer data internally
However, no method of transmission over the internet is completely secure. If you believe your data has been compromised, please contact us immediately.
12. Children's Privacy
Our website and services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
13. Links to Third-Party Websites
Our website may contain links to third-party sites. We are not responsible for the privacy practices of those sites and encourage you to read their privacy policies independently.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. When we do, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.
For significant changes, we will notify you by email or by a prominent notice on our website.
15. How to Complain
If you have concerns about how we handle your personal data and are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Website: ico.org.uk Phone: 0303 123 1113 Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would always appreciate the opportunity to resolve your concern directly before you contact the ICO — please reach out to us first at support@zenvorafit.com.
16. Contact Us
For any questions, requests or concerns regarding this Privacy Policy or your personal data:
Email: support@zenvorafit.com Response time: Within 2 business days
ZenVoraFit — United Kingdom