Privacy Notice
How we collect, use and protect your personal data under the GDPR and the BDSG.
Last updated: 14 July 2026
1. Controller
The controller responsible for processing your personal data is:
- Entity
- The JCM Group GbR (trading as ZIPIEE)
- Address
- Hauptstraße 9, 49179 Ostercappeln, Germany
- Data protection contact
- gdpr@zipiee.io
We are not required to appoint a Data Protection Officer. All data protection enquiries are handled directly by the contact above.
2. What we collect
2.1 This website
We collect only what you choose to send us through our forms:
- Contact form: name, email address, business name (optional), enquiry type, your message and your consent.
- Pilot application: name, business name, location, number of stores, email address, phone number and your consent.
- Subscribe form: email address, town or postcode (optional), whether you are a shopper or a shop owner, and your consent.
When you visit this website, our hosting provider processes technical data such as your IP address, the pages requested, and the date and time of the request. This is necessary to deliver the site and to keep it secure and stable.
2.2 Cookies and tracking
This website does not set cookies, does not use analytics, and does not track you across sites. Our fonts are hosted on our own servers, so no data is sent to third-party font providers when you visit.
2.3 The ZIPIEE apps and display units
Where you use the ZIPIEE retailer or consumer apps, we process:
- Account and contact data: the details you provide when registering.
- Display content: the opening hours, offers and announcements you publish.
- Device and connectivity data: display unit identifiers, connection status and usage data, held in pseudonymised form.
- Integration credentials: the access tokens that allow ZIPIEE to update your Google Business Profile on your instruction. These are stored encrypted.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Responding to your enquiry or pilot application | Art. 6 (1) (b) GDPR (steps prior to a contract) and Art. 6 (1) (f) GDPR (our legitimate interest in answering you) |
| Sending you launch and product updates | Art. 6 (1) (a) GDPR (your consent, which you may withdraw at any time) |
| Providing the ZIPIEE apps and display service | Art. 6 (1) (b) GDPR (performance of our contract with you) |
| Publishing your content to your Google Business Profile | Art. 6 (1) (b) GDPR, on your instruction and authorisation |
| Keeping the website and service secure and stable | Art. 6 (1) (f) GDPR (our legitimate interest in security) |
We do not sell your personal data, and we do not use it for automated decision-making or profiling.
4. Recipients and processors
We share personal data only with service providers who process it on our behalf under a data processing agreement:
| Recipient | Role and location |
|---|---|
| Amazon Web Services EMEA SARL | Cloud hosting and infrastructure. Data is processed in the AWS Europe (Frankfurt) region, eu-central-1, within the EU. |
| Google LLC / Google Ireland Limited | Google Business Profile API, used only to publish the content you instruct us to publish. Google LLC is certified under the EU-US Data Privacy Framework. |
| Formspree Inc. | Processing and delivery of the forms on this website, being the contact, pilot application, subscribe and unsubscribe forms. Formspree processes submissions on infrastructure in the United States and acts on our instructions under a data processing agreement. |
We may also disclose data where we are legally required to do so. Where you publish content through the ZIPIEE retailer app that contains personal data of your own customers or staff, you are the controller for that data and we act as your processor under a separate data processing agreement.
5. International transfers
The ZIPIEE service is hosted inside the European Union, in the AWS Frankfurt region. Two of our processors involve a transfer of personal data to the United States, each with its own safeguard:
- Google LLC, for the Google Business Profile integration. Google LLC is certified under the EU-US Data Privacy Framework, which the European Commission has recognised in an adequacy decision as providing an adequate level of protection, so the transfer is made under Art. 45 GDPR.
- Formspree Inc., which processes the forms on this website. Formspree is not certified under the EU-US Data Privacy Framework, so this transfer is made under the European Commission's Standard Contractual Clauses in accordance with Art. 46 (2) (c) GDPR.
This means that when you send us a message through a form on this website, the details you enter are transmitted to Formspree in the United States before they reach us. If you would prefer not to use a form, you can email us directly at hello@zipiee.io.
6. Retention
| Data | Retention period |
|---|---|
| Website enquiries, pilot applications and contact details | 24 months after our last contact with you, then deleted |
| Subscription email address | Until you unsubscribe or withdraw consent |
| Display content and account data | For as long as your account is active, then deleted on closure |
| Device connectivity and usage data | A maximum of 90 days |
| Google integration access tokens | Until you revoke the authorisation |
We may retain data for longer where a statutory retention obligation applies, for example under commercial or tax law.
7. Your rights
Under the GDPR you have the right to:
- request access to the personal data we hold about you (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data deleted (Art. 17);
- restrict our processing of your data (Art. 18);
- receive your data in a portable format (Art. 20);
- object to processing based on our legitimate interests (Art. 21);
- withdraw your consent at any time, without affecting the lawfulness of processing before withdrawal (Art. 7 (3)).
To exercise any of these rights, write to gdpr@zipiee.io. To stop receiving our updates, use the unsubscribe link in any email we send, or the unsubscribe page.
8. How we protect your data
We apply technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, encrypted storage of integration credentials, role-based access control limited to the people who need it, pseudonymisation of device usage data, and logging of access to production systems. If a personal data breach occurs, we will notify affected controllers without undue delay and within 24 hours of becoming aware of it, and the supervisory authority where required by Art. 33 GDPR.
9. Supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5, 30159 Hannover, Germany
www.lfd.niedersachsen.de
10. Changes to this notice
We may update this notice to reflect changes to our service or to legal requirements. The current version is always available on this page.