How Zerro. handles personal data, under the Swiss Federal Act on Data Protection (FADP/nDSG).
Enquiries about your data: hello@my-zerro.ch
Zerro. operates in Switzerland, and the processing described here is governed by the Swiss Federal Act on Data Protection (FADP, revised nDSG). Where a visitor is in the EU or EEA, the GDPR may additionally apply to their data; the rights described below are granted in either case.
At signup, through the form on this website:
Once the subscription is running, additionally:
Separately from the above, and not connected to any person: each time a page on this website is opened, we record which page it was and — if you arrived by a link or QR code that carries one — the campaign or building tag contained in that link. These entries hold no cookie, no name, no IP address and no identifier of any kind, so they cannot be traced back to you or joined up with your other visits. They exist only so that we can count how often a page is read and which flyer or link brought people to it.
To perform the subscription contract: scheduling and carrying out the cleans, identifying the right vehicle in the right garage, contacting you about your visits, issuing invoices and recording payment. Vehicle photographs exist to document condition before a clean, which protects both sides if damage is disputed.
We do not sell personal data, and we do not use it for advertising or profiling.
Third parties that process data on our behalf. Each is bound to process it only for the purpose described.
| Provider | Purpose | Data location |
|---|---|---|
| Supabase | Database, sign-in, and storage of inspection photographs | European Union — Stockholm, Sweden |
| Resend | Sending service emails, such as payment reminders | United States — covered by Standard Contractual Clauses |
| Cloudflare | Hosting this website, and the server functions that process payments, send reminders and notifications | Not pinned to a region — covered by the Data Privacy Framework |
| Google Workspace | The hello@my-zerro.ch mailbox and correspondence held in it | Not pinned to a region — covered by Standard Contractual Clauses |
| Payrexx | Taking the subscription payment and the monthly debits that follow it | Switzerland — Thun |
Loading this website also contacts Google Fonts (fonts.googleapis.com, fonts.gstatic.com) and the jsDelivr and unpkg script networks, which receive your IP address in order to serve those files. They are not sent any of the data listed above.
At the payment step only, and only after you have completed a signup, two further files are loaded: the payment window from Payrexx (media.payrexx.com) and the script library it needs from the cdnjs network. Both receive your IP address in order to serve those files.
If you enable browser notifications, messages are delivered through the push service your browser vendor operates (for example Google, Mozilla or Apple). That service sees the technical identifier for your browser and the encrypted message, not your account.
Subscription payments are handled by Payrexx AG, Burgstrasse 20, 3600 Thun, Switzerland. At the end of the signup form a Payrexx payment window opens over this site. Your card or TWINT details are entered into that window and go to Payrexx directly: Zerro. does not receive, process or store them at any point, and cannot see them.
So that Payrexx can take the payment and address the receipt, we pass it your name, your email address, the monthly amount and a reference number identifying your signup. Payrexx tells us in return whether a payment succeeded or failed, and the identifier of the resulting subscription — never your payment details.
Your subscription then runs as a standing monthly debit at Payrexx until it is cancelled. The payment window is only loaded once you have completed a signup and are about to pay; simply reading this website contacts no payment provider.
Subscriber data is stored by Supabase in the European Union (Stockholm, Sweden). Switzerland recognises the EU as providing an adequate level of data protection, so this transfer requires no additional safeguard beyond that recognition and our agreement with the provider.
Service emails are sent through Resend, which processes data in the United States; no European processing region is offered. The transfer rests on the Standard Contractual Clauses incorporated into Resend's data processing agreement, modified for Swiss law so that the Federal Data Protection and Information Commissioner is the competent supervisory authority for data transferred from Switzerland. Resend is additionally certified under the EU-U.S. Data Privacy Framework, including its UK Extension.
Our hosting provider, Cloudflare, runs the server functions that send payment reminders and notifications. Those functions process a subscriber's name, email address, building address, billing status, payment identifiers and notification identifiers. Cloudflare is certified under the EU-U.S. Data Privacy Framework, including its UK Extension, and under the Swiss-U.S. Data Privacy Framework, which is the primary basis for this transfer. Where that framework does not apply, the transfer falls back to the Standard Contractual Clauses in Cloudflare's data processing agreement, which are adapted for Swiss law — naming the Federal Data Protection and Information Commissioner as supervisory authority and substituting the Swiss FADP for references to the GDPR.
Correspondence held in the hello@my-zerro.ch mailbox is processed by Google Workspace. That mailbox is not pinned to a particular storage region, so the data may be processed outside Switzerland and outside the EU. The transfer is covered by the Standard Contractual Clauses, which are in force under Google's Cloud Data Processing Addendum and apply wherever the data is physically held.
Payments are processed by Payrexx AG in Thun, Switzerland. This is not a transfer abroad: the data stays in Switzerland, so no additional safeguard is engaged. Payrexx may in turn involve the card scheme or payment method you choose, which receives the payment details you enter directly into its window.
This website sets no advertising or analytics cookies, and uses no third-party tracking or analytics service. The anonymous page count described above under What we collect stores nothing in your browser at all. What this website does store there is functional only:
These are stored by your browser and can be cleared at any time through its settings.
Personal data is kept for as long as the subscription lasts, and afterwards for as long as statutory retention obligations require — in particular the ten-year retention period for business and accounting records under Swiss law. Data no longer needed for either purpose is deleted.
Under the Swiss FADP you may ask us for:
Write to hello@my-zerro.ch. We may ask you to confirm your identity before answering, so that data is not disclosed to the wrong person.
You may also lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern.
Data is held in access-controlled systems. Subscribers can see only their own records, and access to the internal dashboard is restricted to Zerro. staff. Transfers between your browser and our systems are encrypted.
Our email delivery provider, Resend, undergoes annual SOC 2 audits by an independent assessor.
This policy may be updated as the service changes. The version in force is the one published on this page.