Legal
Privacy Policy
How Zero2Sales LLC processes information about website visitors, customers, and people acting in a professional capacity for organisations. Version 2026-10-03. Last updated 3 October 2026.
1. Who we are
Zero2Sales is operated by Zero2Sales LLC. Privacy and legal contact: privacy@zero2sales.biz. We have not published a public street address and do not invent one here. This policy covers the Zero2Sales website and application.
2. Data roles
Zero2Sales LLC is the controller for customer and service account data, and for independently discovered organisation intelligence and independently discovered professional B2B intelligence. Customers are generally independent controllers for their use of prospect information and for sales communications they send. Zero2Sales may act as a processor in narrower cases where customer-supplied information is processed solely on the Customer’s instructions. Zero2Sales is not merely a processor for the intelligence platform.
3. Visitors
The public website can be read without an account. A visitor may
build an anonymous Market Potential before signing
in. For that we set an opaque cookie named z2s_anon
(HttpOnly, SameSite=Lax, Path=/, maximum age 7 days; Secure when
the site is served over HTTPS). The server stores a hash of that
cookie and one Market Potential snapshot. The snapshot lasts 7 days
from creation and is not extended by later saves. Expired
snapshots are not used. That 7-day window is enforced in the
Service.
We do not currently set advertising or analytics cookies, and we do not load Google Fonts or similar font-tracking CDNs.
4. Customers and users
When you register or sign in we process name, organisation name, email, password (stored as a hash), organisation records, authentication sessions, product and website inputs, Market Potential, Business Islands, Sales Pipeline configuration, Sales Agent configuration, Gmail mailbox connection metadata needed to operate mail, sales communications sent or received through the Service, wallet and billing records, and operational or security information needed to run the Service.
Sign-in uses an opaque cookie named z2s_session
(HttpOnly, SameSite=Lax, Path=/, maximum age 7 days or until you
sign out; Secure when served over HTTPS). The server stores a
hash of the session token. Expired or revoked sessions are
rejected. That session window is enforced in the Service.
The browser may also keep localStorage drafts (for example organisation or campaign drafts on this device) and short-lived sessionStorage values (for example continuing Market Potential after sign-in). Those are device-side stores, not advertising cookies.
5. Professional B2B contacts
Zero2Sales processes information about people acting in an official or professional capacity representing organisations — not private-person dossiers. Typical data includes name, organisation or employer, professional role or title, professional profile or source, business contact information, provenance and evidence, and business or buying-role context.
Organisation and professional intelligence may be obtained from publicly available business, organisation, government, register, website, and similar professional sources. We record source and provenance so we can explain, where possible, where a fact was observed. Zero2Sales is not designed to create private-life profiles or to use sensitive categories (such as health, religion, political beliefs, sexual orientation, biometrics, criminal history, or private financial information) for sales targeting.
Outreach may be held or blocked when a recipient is unresolved, not eligible as a business/official recipient, suppressed, or otherwise gated. A marketing objection is recorded as a durable suppression so we can avoid future contact.
6. Providers and sources
- Google / Gmail — mailbox connection and email operations when a Customer connects a mailbox.
- Stripe — hosted payment and prepaid credit. Zero2Sales does not store card numbers.
- DuckDuckGo — discovery and search queries used in organisation research.
- Public websites, directories, and registers — business and organisation intelligence sources.
- AI / model infrastructure — analysis of the offer and relevant business information. Processing may run on infrastructure we operate or on third-party model providers. We do not claim that all model processing is permanently local.
- Hosting and database infrastructure — application hosting and PostgreSQL storage.
7. Cookies and similar storage
z2s_session and z2s_anon are necessary
for sign-in and anonymous Market Potential. We do not show a
cookie banner solely for these service cookies. See sections 3
and 4 for lifetime and HttpOnly / SameSite behaviour.
8. Retention
The following are Zero2Sales V1 retention policies. Only the 7-day anonymous Market Potential window and the 7-day (or revoked) auth-session window are automatically enforced in software today. Other periods are policy. This policy does not claim automatic deletion where the product does not yet purge the data.
- Anonymous Market Potential: 7 days (enforced on access; expired snapshots are not used).
- Auth sessions: 7 days or until revoked (enforced on access; sign-out revokes the session).
- Active customer and organisation data: while the account or service remains active (policy).
- Closed account or service configuration: 90 days, then delete or anonymize unless needed for legal, security, or financial reasons (policy).
- Mail content and replies: 12 months after the relevant pipeline or activity ends (policy).
- Professional B2B intelligence and provenance: 24 months since last verification or use, then reverify or remove (policy).
- Suppression and marketing-objection records: retain the minimum information needed to prevent future contact, with no routine expiry while needed for that purpose (no automatic expiry is applied).
- Billing, ledger, and transaction records: 7 years as Zero2Sales retention policy, subject to longer or shorter retention where law requires (policy).
- Ordinary operational and security logs: 90 days, longer where needed to investigate security, abuse, or legal issues (policy).
9. Your rights
Depending on applicable law, you may request access, correction, deletion, objection to direct marketing, information about source or provenance, or other privacy rights that apply to you. Email privacy@zero2sales.biz. We do not currently offer self-service export or deletion in the product. Direct-marketing objections are recorded as durable suppressions and are not treated as a routine expiring preference.
10. Changes
We may update this policy. The version identifier shown above is the current published version. New registrations must acknowledge the current Privacy Policy together with the Terms of Service.
Operator: Zero2Sales LLC. privacy@zero2sales.biz.