Privacy Policy
Effective date to be confirmed before launch.
This policy explains what personal data ZUPII Asian Online Marketplace processes when you shop, sell or deliver through the service, why we process it, and the rights you have under the EU General Data Protection Regulation (GDPR).
Operator details
Operator details must be completed before launch
The following legally required details have not been supplied. We do not display guessed or example values.
- Registered company name
- Finnish Business ID (Y-tunnus)
- Geographical address
- Customer support email
- Privacy request email
- Data Protection Officer contact (if appointed)
- Policy effective date
1. Who is responsible for your data
The operator of the ZUPII marketplace is the controller for the personal data described here. The operator's verified identity and contact details are shown in the operator details block above; where a field is still marked pending, that information has not yet been confirmed and must be completed before launch.
Independent grocery stores selling on ZUPII are separate businesses. In practice each store also processes information about the orders it receives in order to prepare them. The precise controller relationship between ZUPII and each store depends on the agreement in force between them; no definitive joint- or separate-controller conclusion is asserted here until those agreements are finalised.
2. What data we process
Depending on how you use ZUPII, we may process:
- Customer account data: email address, password credentials handled by our authentication provider, display name, phone number where you provide it, and language preference.
- Order data: basket contents, product names and prices, order number, order status, store, delivery date and time window, and any delivery instructions you write.
- Delivery data: delivery street address and postal code, the resolved delivery location used to route the rider, and delivery handover timestamps and handover code verification.
- Payment metadata: payment status, amounts, refund status and refunded amounts, and identifiers returned by the payment processor. Full card numbers are never received or stored by ZUPII.
- Support and complaint data: the issue type and description you submit about an order, any photo you choose to attach, and the resolution status and internal notes.
- Merchant data: store details, contact details of store staff, catalogue content, and payout onboarding status held by the payment processor.
- Rider data: application details you submit, contact details, verification status, roster status and delivery assignment records.
- Authentication and security data: sign-in events, session tokens, audit records of privileged actions such as approvals, and error and notification logs.
- Device and usage data: technical request data required to serve the site, and anonymous product analytics events (for example that a store page was viewed or an order was placed) recorded with a coarse context such as store or city and a timestamp, without names, emails, addresses or full postal codes.
3. Why we process it, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Creating and managing your account, taking and fulfilling orders, arranging delivery, and handling complaints, cancellations and refunds | Performance of a contract (GDPR Art. 6(1)(b)) |
| Accounting, tax and consumer-protection record keeping, and responding to lawful requests from authorities | Legal obligation (GDPR Art. 6(1)(c)) |
| Keeping the service secure, preventing abuse and fraud, maintaining audit records of privileged actions, resolving disputes, and improving the service using anonymous usage counts | Legitimate interests (GDPR Art. 6(1)(f)) |
| Approximate location detection in the browser, where you explicitly allow it | Consent (GDPR Art. 6(1)(a)), withdrawable at any time |
We do not send marketing messages on the basis of a bundled or pre-ticked checkbox. Where a purpose relies on legitimate interests, you may object as described below.
4. Who receives the data
- The independent store you order from receives the order details it needs to prepare and hand over your order.
- The delivery rider assigned to your order receives the delivery details needed to complete that delivery.
- Our hosting, database and authentication infrastructure provider processes the data that runs the service.
- Our payment processor (Stripe) processes payment and payout data where a store has card payment enabled.
- Our transactional email provider sends operational messages such as new-order and rider notifications.
- Professional advisers, and authorities or courts, where we are legally required or permitted to disclose.
We name only the providers that are confirmed in the running service. We do not sell personal data.
5. International transfers
Some providers may process data outside the European Economic Area. Where that happens, the transfer relies on a lawful transfer mechanism such as an adequacy decision or the European Commission's Standard Contractual Clauses, together with the provider's supplementary measures. We do not claim that all processing takes place exclusively inside the EU, because the hosting regions of every provider have not been independently verified for this statement.
6. How long we keep data
We keep personal data only as long as it is needed for the purpose it was collected for. Fixed retention periods have not been finally set for every category, so the criteria we apply are:
- Account data: kept while your account exists, and deleted or anonymised after closure unless a longer period is required below.
- Order, delivery and payment records: kept for the periods required by accounting and tax law, which in Finland is generally several years from the end of the accounting period.
- Complaint and support records, including any photo you attach: kept while the case is open and afterwards for as long as needed to evidence the outcome and to meet consumer-protection and limitation periods.
- Security, audit and notification logs: kept for a limited period appropriate to detecting and investigating misuse.
- Data relevant to an actual or reasonably anticipated dispute: kept until that dispute is finally resolved.
- Analytics events: retained in anonymous, aggregated form.
7. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you and receive a copy.
- Have inaccurate or incomplete data corrected.
- Have data erased where the legal conditions for erasure are met.
- Restrict processing in the situations set out in the GDPR.
- Receive data you provided to us in a portable, machine-readable format where the right applies.
- Object to processing based on legitimate interests, on grounds relating to your particular situation.
- Withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal.
Requests are made through the privacy contact shown in the operator details above. Because these rights concern your own data, we may need to verify your identity before acting — normally by confirming that the request comes from the account holder — and we will not ask for more information than that verification requires.
You can also lodge a complaint with the Finnish Data Protection Ombudsman.
8. Automated decision-making
ZUPII does not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing, and does not build marketing profiles about you. Delivery pricing is calculated automatically from the delivery distance and postal area, and order and stock rules are applied automatically, but these are contract calculations rather than decisions of that kind.
9. Security
We apply technical and organisational measures intended to protect personal data, including database row-level access rules that scope data to the account or store entitled to see it, server-side validation of prices, totals and order state changes, restricted access to precise delivery locations, hashed delivery handover codes, and audit records of privileged actions. No online service can be guaranteed to be completely secure, and we do not warrant absolute security.
10. Children
ZUPII is intended for people who can enter into a binding contract for a grocery order. A specific minimum age for using the service has not yet been established and confirmed for this statement; a verified age limit will be published here before launch. If you believe a child's data has been provided to us, contact us and we will review it.
11. Cookies and local storage
ZUPII uses strictly necessary browser storage that the service cannot work without: your signed-in session, your language choice, your basket, and the delivery location you enter or allow us to detect. These are used only to provide the service you asked for.
Implementation pending: ZUPII does not currently include a cookie consent manager. We therefore do not claim that optional or analytics storage is blocked until consent is given. Any optional cookies must be placed behind a consent tool before launch.
You can clear or block browser storage through your browser's own privacy settings, and you can withdraw browser location permission in the same settings at any time.