Privacy
Privacy policy
Last updated: 21 August 2026
This policy explains how ZIZR AS processes personal data on zizr.com, in the free Zizr-ID service and when supporting online stores.
ZIZR AS is the controller for the public website, direct contact, Zizr-ID accounts and the Zizr newsletter. When Zizr processes pseudonymous store-customer data under a store’s instructions, the store is the controller and Zizr is its processor.
Controller and privacy contact
Controller: ZIZR AS, organisation number 922 796 556, c/o Kleins AS, Dronningens gate 38, 7011 Trondheim, Norway. Email: contact@zizr.id.
ZIZR AS has not appointed a data protection officer. Privacy requests are handled through the contact address above.
Public website and analytics
When you visit zizr.com, technical request data such as IP address, time, requested page and browser information is processed to deliver and secure the site. Cloudflare and Microsoft Azure provide infrastructure in the EU/EEA.
We use Plausible Analytics in its standard cookieless configuration. It does not set analytics cookies or use a persistent visitor identifier. We use aggregate statistics to understand page use and improve the website. The legal basis is our legitimate interest in operating, securing and improving the website (GDPR Article 6(1)(f)).
Contact requests
The contact form on zizr.com prepares an email in your own email application. The website does not upload the entered name, email address, subject or message before you choose to send it. Sent messages are processed in Microsoft 365.
We process contact data to answer requests, take steps before a possible agreement and document relevant business communication. The legal bases are GDPR Article 6(1)(b) and our legitimate interest under Article 6(1)(f). We retain correspondence only while needed to resolve the matter and meet applicable documentation or legal-claims requirements.
Zizr-ID accounts and size recommendations
To create a Zizr-ID account, first name, birth year and email address are required. Birth year is used for the minimum-age check, is stored with the account and can be deleted with the account. The minimum age is 16. Gender is optional and is used only to improve recommendations and avoid irrelevant Zizr newsletters; the service works without it and Zizr does not infer gender.
Purchase history is received directly from participating stores and can include brand, product, purchased size and return information. It is linked to the account using a hashed email address. This history is necessary to provide personal, product-level size recommendations. Core account processing is necessary to perform the free user agreement (GDPR Article 6(1)(b)). Google Firebase is used only for Authentication; Zizr does not receive the user’s password in readable form.
Where purchase data comes from
Purchase and return data comes from participating online stores, not directly from the user. This policy provides that information through the privacy link shown during registration. The data is used to provide recommendations and can be transformed into anonymised information for analysis and product development.
A size recommendation is advisory. The user can always choose another size, and the recommendation does not determine price, access or legal rights.
Newsletter and marketing
Zizr sends newsletters only when the user has selected a separate, optional box that is not preselected. The current signup uses a single confirmation rather than double opt-in. Consent can be withdrawn through account settings or the unsubscribe link in each email. Gender may be used to avoid sending an irrelevant newsletter. Zizr does not use the newsletter to advertise products that the user can buy from Zizr.
The legal basis is consent (GDPR Article 6(1)(a)). We retain the subscription while it is active and keep the information required to document consent and withdrawal for as long as needed to establish compliance.
Zizr Target and store-customer data
For Zizr Target, stores send a stable customer number together with transaction and return information. Zizr does not receive the customer’s name or contact details, but the information remains pseudonymous personal data because the store can reconnect the customer number to a person.
Zizr processes this data under a data processing agreement and the store’s instructions. Zizr Target generates segment rules and statistics; the store reviews the campaign and sends only to customers who have given marketing consent directly to the store. The store is responsible for its marketing recipients, legal basis and withdrawal handling.
Recipients and service providers
We use the following categories of processors under data protection terms. Access is limited to what each service needs.
| Provider | Purpose |
|---|---|
| Microsoft Azure | Application, backend and data infrastructure |
| Cloudflare | Delivery, network security and performance |
| Google Firebase Authentication | Account authentication |
| Microsoft 365 | Company email and contact correspondence |
| Plausible Analytics | Cookieless, aggregate website analytics |
| Participating online stores and Shopify | Purchase signals, integrations and store-side service delivery |
International transfers
Primary hosting and storage are configured in the EU/EEA. Some providers may use group companies or subprocessors outside the EEA for limited support or service functions. Where this constitutes a transfer, we require a lawful transfer mechanism such as an adequacy decision or the EU standard contractual clauses, together with supplementary measures where needed.
Retention and deletion
Zizr-ID account data and connected purchase history are retained while the account is active. When the user deletes the account, the account, profile and connected purchase history are deleted immediately from the active Zizr solution.
Store-customer data is retained and deleted under the relevant store’s instructions and data processing agreement. Technical logs are retained according to security need, incident investigation and technical lifecycle, then deleted or anonymised when no longer needed.
Your rights
Depending on the circumstances, you can request access, correction, deletion, restriction, portability or object to processing. You can withdraw consent at any time without affecting earlier lawful processing. Zizr-ID users can correct information and delete their account in the service; a copy of personal data can be requested from contact@zizr.id.
If your request concerns data controlled by an online store, we may refer the request to that store. You can complain to the Norwegian Data Protection Authority or the data protection authority where you live.
Security, children and changes
We use access controls, encryption in transit, processor agreements and other technical and organisational measures appropriate to the risk. Zizr-ID registration is limited to users aged 16 or older, and registration is blocked when the birth year indicates that the user is under 16.
We update this policy when services, vendors or processing change. If Plausible or another tool is changed to use optional cookies or persistent identifiers, we will update the information and request consent before activating that use where required.