Privacy policy
In short
We keep only what we need to show you the course and to write to you: your email address, your progress and the certificates you receive. We don’t use advertising or tracking cookies and we don’t sell data.
Who is responsible for your data
The data controller is Andrei Stici, who provides the Zero2App service. For any request about your data: contact@zero2app.com.
What data we keep and why
The waiting list. Your email address, language and sign-up date. We use them to let you know about the launch and to send you the launch price. The legal basis is your consent, which you can withdraw at any time.
Your account. Your email address, the date the account was created and your password. We keep the password only as a cryptographic fingerprint: not even we can read it. To choose or change your password, we email you a link that is valid for 60 minutes and can be used only once; the link in invitations we send is valid for 7 days. While you’re signed in, your browser keeps a session cookie (“z2a-sesiune”) for 30 days. The legal basis is the contract: without them we can’t give you access to the course.
How you heard about us. On your account page we may ask you, optionally, how you heard about Zero2App (for example TikTok, Google or from a friend). If you answer, we keep the answer in your account, so we know where it’s worth talking about the course. The legal basis is your consent: you can choose “I’d rather not say”, and the answer is deleted together with the account.
Two-step verification. If you turn it on, we keep the key from which your authenticator app makes the 6-digit codes, and the backup codes, also as fingerprints. We delete them when you turn it off.
Your progress. The lessons you’ve read, your points (XP), your streak of days and your test results. They’re kept in your browser and, if you have an account, in your account, so you can see them on any device. For the refund rule, the server also records when you first opened each paid lesson and which tests you passed.
Certificates. When you pass a module’s test and ask for the certificate, we keep the name you type, the module, the date and a code. Anyone with the certificate’s link can see this data, so they can check that it’s genuine; certificate pages don’t appear in search engines. The legal basis is the legitimate interest, yours and that of the people you show the certificate to, that it can be verified.
Payments. Payments are processed by Paddle.com, our online reseller (Merchant of Record). Paddle receives the payment and billing details; we don’t see your card details. From Paddle we learn what you bought, your email address, your country and the amount, so we can unlock your modules.
Technical data. Your IP address is used momentarily to limit repeated sign-in attempts (protection against abuse). The servers keep ordinary technical logs for security. When you open the home page, we read your browser’s language to show you the site in Romanian or English; we don’t store it.
Cookies and browser storage
- We use two cookies, both strictly necessary: the session cookie, so you stay signed in, and “z2a-lang”, which remembers the language you chose with the RO/EN switch, for one year (only if you use the switch).
- Your progress and your chosen theme (light or dark) are kept in your browser (localStorage).
- We don’t use analytics, advertising or social media cookies.
- We count visits with Cloudflare Web Analytics, without cookies and without recognizing you from one visit to the next. We only see which pages are opened, from which country, on what kind of device and from which site people came.
- The links in our social media profiles (for example zero2app.com/tiktok) only count how many clicks each network gets, per day, with nothing about who clicked and without saving anything in your browser.
Who helps us process the data
- Cloudflare: hosting the site, the database (located in Europe) and the visit statistics.
- Resend: sending emails.
- Paddle: payments, invoices and refunds.
Some of these providers may also process data outside the European Union, with the safeguards required by the GDPR.
How long we keep the data
- Your address on the waiting list: until you unsubscribe or ask us to delete it.
- Your account and progress: until you delete the account. You can do this at any time, from your account page; deletion is immediate and permanent.
- Certificates: they remain after the account is deleted, with only the name, module, date and code, unlinked from the account, so the verification links keep working. When you delete your account you can tick “delete the certificates too”, or you can write to us at any time to delete them.
- Payment data: as long as the law requires, at Paddle.
Your rights
You have the right to ask for access to your data, to have it corrected or deleted, or to get a copy of it, to object to its processing and to withdraw your consent. Write to us at contact@zero2app.com and we’ll reply within 30 days at most.
You also have the right to lodge a complaint with a data protection authority, in particular the one in the country where you live: in Romania, ANSPDCP; in the Republic of Moldova, the National Center for Personal Data Protection.
Age
Zero2App is not intended for people under 16.
Changes
We may update this policy. We announce important changes by email to everyone who has an account.