PRIVACY POLICY

Last updated: 18 September 2026

This Privacy Policy explains how ZeroMarket OÜ (“Zero Shop”, “we”, “us” or “our”) collects, uses, stores and protects personal data when you visit or use zero-shop.xyz, create an account, place an order, buy or use a gift card, receive or use Zero Shopping Points, subscribe to communications or contact us.

We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”), applicable Estonian data protection law and other applicable legislation.

1.1 Data controller

The controller is:

ZeroMarket OÜ

Registry code: 17576483

Registered address: Keskallee 7, Järve linnaosa, Kohtla-Järve linn, Ida-Viru maakond, 30322, Estonia

Email: support@zero-shop.xyz

Website: https://zero-shop.xyz

For privacy questions or requests concerning your personal data, contact us at support@zero-shop.xyz.

1.2 Personal data we collect

Depending on how you use Zero Shop, we may process the following categories of personal data.

Account and identity data

• name;

• email address and telephone number;

• username, customer number or account identifier;

• billing and delivery address;

• account preferences and settings;

• encrypted or hashed authentication data;

• login history and account activity.Passwords are not intended to be stored in readable form.

 Order and transaction data

• products or services ordered;

• order number, date, value, currency and status;

• discounts and promotional benefits applied;

• payment method, payment status and transaction reference;

• billing and delivery information;

• returns, cancellations, complaints and refunds;

• invoices and transaction history.

 Gift Card and Zero Shopping Points data

• Gift Card purchase, value, code or identifier and activation status;

• the Zero Shop account to which Zero Shopping Points are credited;

• points credited, used, restored, expired or cancelled;

• points balance and transaction timestamps;

• orders and discounts connected to points use;

• security, misuse and fraud-prevention information.

 Payment data

Payments may be processed by Stripe or another payment service provider shown at checkout. When card details are entered directly into a payment provider’s secure environment, we generally do not receive or store the full card number or card security code. We may receive the payer’s name, payment method type, limited card details such as brand and last digits, billing information, payment status, amount, currency, transaction identifier and information needed to reconcile, refund or investigate a payment. The payment provider also processes data under its own privacy notice and legal obligations.

Delivery data

For physical goods, we may process the recipient’s name, delivery address, telephone number, email address, delivery method, parcel identifier and tracking information. Necessary data may be shared with fulfilment, postal, courier and logistics providers.

 Communications and customer-support data

• messages, emails and support requests;

• information submitted through contact forms;• complaint, return and dispute correspondence;

• information you voluntarily provide to us.

 Marketing and preference data

• newsletter subscription and consent status;

• marketing preferences;

• campaign interactions, where permitted;

• consent and unsubscribe records.

 Technical and usage data

• IP address;

• browser, device and operating-system information;

• cookie and session identifiers;

• date, time and source of access;

• pages viewed, cart activity and referral information;

• diagnostic, security and fraud-prevention logs.

1.3 How we obtain personal data

 We obtain data:

• directly from you when you create an account, place an order,

 contact us or submit information;

• automatically from your browser or device through necessary

 cookies and, with consent where required, optional technologies;

• from payment, delivery, authentication and technical service

 providers;

• from a gift-card purchaser or sender where they provide recipient

 information;

• from public authorities or other parties where permitted or required

 by law.

 If you provide another person’s data, you must be entitled to do so and should ensure that the person receives relevant privacy information.

1.4 Purposes and legal bases

 We process personal data only where a lawful basis applies.

 Contract and steps before a contract — Article 6(1)(b) GDPRWe use necessary data to:

• create and administer accounts;

• display and maintain carts, wishlists and order history;

• process and deliver orders;

• process payments, cancellations, returns and refunds;

• sell, activate and administer Gift Cards;

• credit, record, apply and restore Zero Shopping Points;

• provide purchased services or digital content;

• communicate about transactions and provide customer support.

 If required data is not provided, we may be unable to create an account, accept an order, deliver products or provide the requested service.

 Legal obligations — Article 6(1)(c) GDPR

 We may process data to:

• comply with accounting, tax and consumer-protection duties;

• issue and retain invoices and transaction records;

• respond to lawful requests from authorities;

• comply with sanctions, anti-fraud or other mandatory requirements where applicable;

• document and respond to data-subject requests.

 Legitimate interests — Article 6(1)(f) GDPR

 Where our interests are not overridden by your rights, we may process data to:

• secure accounts and the website;

• prevent and investigate fraud, abuse and unauthorised activity;

• maintain transaction, diagnostic and security logs;

• establish, exercise or defend legal claims;

• improve service reliability, usability and customer support;

• understand aggregated service performance;

• protect our customers, business and systems.

 You may object to processing based on legitimate interests in accordance with section 1.11.

 Consent — Article 6(1)(a) GDPR

 Where required, we ask for consent before using optional analytics or marketing cookies or sending certain marketing communications. Youmay withdraw consent at any time without affecting processing carried out before withdrawal.

 1.5 Automated checks

 We may use automated indicators to identify unusual account, order or payment activity and to protect the service from fraud or misuse. A transaction may be held for manual review or additional verification. We do not intend to make decisions based solely on automated processing that produce legal or similarly significant effects unless permitted by law and accompanied by required safeguards.

 1.6 Recipients of personal data

 We do not sell personal data.

 Where necessary and lawful, we may share limited data with:

• payment service providers, including Stripe where used at checkout;

• banks and financial institutions;

• hosting, cloud, website, e-commerce and IT service providers;

• email, newsletter and communication providers;

• authentication, cybersecurity and fraud-prevention providers;

• fulfilment centres, suppliers, postal operators and couriers;

• accountants, auditors, insurers, legal advisers and other professional advisers;

• a specifically identified third-party seller, where the product page and checkout clearly state that the third party is the contracting seller;

• public authorities, courts, regulators or law-enforcement bodies where legally required;

• a buyer, investor or successor in connection with a genuine corporate transaction, subject to appropriate safeguards.

 Processors acting for us may use data only under our instructions and applicable data-protection obligations. Independent controllers, such as payment providers or delivery operators, may process data under their own legal duties and privacy notices.

1.7 International transfers

 Some providers may process personal data outside Estonia or the

 European Economic Area (EEA). Where data is transferred outside the EEA,we use a lawful transfer mechanism, such as an adequacy decision, European Commission Standard Contractual Clauses or another recognised safeguard, and supplementary measures where appropriate.

 You may contact us for further information about safeguards relevant to your data.

1.8 Retention

 We retain personal data only for as long as necessary for the stated purpose and applicable legal requirements. As a general guide:

• account data is retained while the account is active and normally for up to 3 years after closure, unless earlier deletion is appropriate or longer retention is necessary;

• order, invoice, payment and accounting records are generally retained for 7 years as required by Estonian accounting law;

• Gift Card and Zero Shopping Points records are retained while a balance or related obligation remains and afterwards for the applicable accounting, limitation and dispute periods;

• customer-support, return and complaint records are normally retained for up to 3 years after the matter is closed, and longer where a dispute or legal claim is pending;

• marketing data is retained until consent is withdrawn, an objection is made or the data is no longer needed; evidence of consent or objection may be retained for the relevant limitation period;

• security and diagnostic logs are normally retained for up to 12 months, unless an incident or investigation requires longer retention;

• cookie lifetimes are described in the Cookie Policy or cookie settings interface.

 When data is no longer required, we delete, anonymise or securely dispose of it.

 1.9 Security

 We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, disclosure or access. Measures may include access controls, authentication, encryption where appropriate, backups, monitoring, staff confidentiality and restricted administrative access.No internet-based service can guarantee absolute security. You are responsible for keeping your login credentials confidential and notifying us promptly of suspected unauthorised account use.

 1.10 Cookies

 We use necessary cookies for functions such as login, shopping cart, checkout, security, session management and preferences. Optional analytics, advertising or similar cookies are used only where a valid legal basis exists and consent is obtained when required. See the Cookie Policy and the website’s cookie settings for details.

 1.11 Your rights

 Subject to the GDPR and applicable limitations, you may have the right to:

• receive confirmation whether we process your data and obtain access to it;

• correct inaccurate or incomplete data;

• request deletion;

• restrict processing;

• object to processing based on legitimate interests;

• object at any time to direct marketing;

• receive certain data in a structured, commonly used and machine- readable format and transmit it to another controller;

• withdraw consent at any time;

• obtain safeguards relating to certain international transfers;

• not be subject to qualifying solely automated decisions without applicable safeguards;

• lodge a complaint with a supervisory authority.

 To exercise a right, email support@zero-shop.xyz. We may request information reasonably necessary to verify identity. We normally respond within one month; the period may be extended where permitted by the

 GDPR.

 1.12 Complaints

 You may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or the data-protection authority in your habitual EU/EEA residence, workplace or place of the alleged infringement.Estonian Data Protection Inspectorate: https://www.aki.ee/en

 1.13 Children

 Zero Shop is not directed at children who cannot lawfully enter into the relevant transaction or provide valid consent. If a child uses the service, a parent or guardian may need to act on the child’s behalf. If we learn that data has been collected without a valid legal basis, we will take appropriate steps to delete or restrict it.

 1.14 Third-party links

 Our website may link to independent third-party services. We are not responsible for their privacy practices. Review their privacy notices before providing personal data.

 1.15 Changes to this policy

 We may update this Privacy Policy to reflect changes in our services, technology or legal obligations. The latest version will be published on the website with its updated date. Where required, we will provide additional notice of material changes.

 1.16 Contact

 ZeroMarket OÜ

 Registry code: 17576483

 Keskallee 7, Järve linnaosa, Kohtla-Järve linn, Ida-Viru maakond, 30322,

 Estonia

 support@zero-shop.xyz