Privacy Policy

How Zerano collects, uses, stores, and protects personal information across the store experience.

Last updated: March 11, 2026

SPYKO LIMITED, trading as Zerano ("Zerano", "we", "us", or "our"), operates this store and website, including all related information, content, features, tools, products, and services, in order to provide you, the customer, with a curated shopping experience (the "Services"). Zerano is powered by Shopify, which enables us to provide the Services to you. This Privacy Policy describes how we collect, use, and disclose your personal information when you visit, use, or make a purchase or other transaction using the Services, or otherwise communicate with us. If there is a conflict between our Terms of Service and this Privacy Policy, this Privacy Policy controls with respect to the collection, processing, and disclosure of your personal information.

Please read this Privacy Policy carefully. By using and accessing any of the Services, you acknowledge that you have read this Privacy Policy and understand the collection, use, and disclosure of your information as described in this Privacy Policy.

Personal Information We Collect or Process

When we use the term "personal information," we are referring to information that identifies you, relates to you, describes you, or can reasonably be linked to you or another person. Personal information does not include information collected anonymously or de-identified so that it cannot reasonably be linked to you. Depending on how you interact with the Services, where you live, and as permitted or required by applicable law, we may collect or process the following categories of personal information, including inferences drawn from this information:

  • Contact details, including your name, billing address, shipping address, phone number, and email address.
  • Financial information, including payment card information, payment confirmation details, transaction details, and limited payment-related information needed to process your order. Payment card processing is generally handled by our payment service providers.
  • Account information, including your username, password, preferences, and settings.
  • Transaction information, including the items you view, place in your cart, add to your wishlist, purchase, return, exchange, or cancel, as well as your order history.
  • Communications with us, including information you include in messages, emails, support requests, reviews, or other communications.
  • Device information, including information about your device, browser, network connection, IP address, and other identifiers associated with your use of the Services.
  • Usage information, including information about how and when you access, browse, interact with, or navigate the Services.

Personal Information Sources

We may collect personal information from the following sources:

  • Directly from you, including when you create an account, place an order, contact us, subscribe to marketing, submit a review, or otherwise provide your personal information to us.
  • Automatically through the Services, including through your device and through cookies and similar technologies when you browse or interact with our website.
  • From our service providers, including providers that support payments, fulfillment, shipping, customer support, analytics, fraud prevention, hosting, and other store operations.
  • From our partners or other third parties, including marketing, advertising, and social media partners, where permitted by applicable law.

How We Use Your Personal Information

Depending on how you interact with us or which Services you use, we may use personal information for the following purposes:

  • Provide, personalize, and improve the Services. We use your personal information to operate the store, process payments, fulfill orders, arrange shipping, manage returns and exchanges, create and maintain your account, remember your preferences, provide customer-facing features, and improve the performance, functionality, and user experience of the Services.
  • Marketing and advertising. We may use your personal information to send marketing communications by email, text message, or similar channels where permitted by law, and to show you advertisements for products or services on our Services or on other websites and platforms.
  • Security and fraud prevention. We use personal information to help verify accounts and transactions, protect the Services, detect and prevent fraud, abuse, or other unlawful activity, and maintain the safety and integrity of our store.
  • Communicating with you. We use personal information to respond to your inquiries, provide support, send service-related communications, and maintain our relationship with you.
  • Legal and compliance purposes. We may use personal information to comply with applicable law, regulations, legal process, lawful requests from public authorities, enforce our policies and terms, establish or defend legal claims, and protect our rights, users, and business.

Lawful Bases for Processing (EEA / UK)

If you are located in the European Economic Area or the United Kingdom, we process your personal information only where we have a valid legal basis to do so. Depending on the circumstances, these legal bases may include:

  • Performance of a contract, including to process your orders, take payment, deliver products, manage returns, and provide account-related services.
  • Compliance with legal obligations, including tax, accounting, fraud prevention, consumer protection, and responding to lawful requests or legal process.
  • Legitimate interests, including operating and improving our business and Services, preventing fraud, securing our store, understanding how customers use our Services, and providing responsive customer support, provided these interests are not overridden by your rights and freedoms.
  • Consent, where required by law, including for certain marketing communications and certain cookies or similar technologies used for analytics, personalization, or advertising. Where we rely on consent, you may withdraw it at any time.

Cookies and Similar Technologies

We and our partners may use cookies, pixels, tags, SDKs, and similar technologies to operate the Services, remember your preferences, understand how the Services are used, improve performance, measure campaign effectiveness, and support advertising and personalization.

Some of these technologies are necessary for the website to function properly, while others are optional and are used only where permitted by applicable law. Depending on where you live, you may be able to manage your preferences through our cookie banner or privacy tools on the Services. You can also manage certain cookie settings through your browser settings. Please note that disabling certain technologies may affect the functionality of the Services.

How We Disclose Personal Information

We may disclose personal information to third parties for the purposes described in this Privacy Policy, subject to applicable law. These circumstances may include:

  • Service providers and processors. We may disclose information to Shopify and to vendors and service providers who perform services on our behalf, such as website hosting, payment processing, data analytics, customer support, cloud storage, fraud prevention, fulfillment, and shipping.
  • Marketing and advertising partners. We may disclose information to business and marketing partners to help us market our products, measure advertising performance, and deliver relevant advertising, subject to applicable law and your available choices.
  • At your direction or with your consent. We may disclose information when you request or direct us to do so, or where you otherwise consent, including through social media features, integrations, or similar services.
  • Affiliates and corporate transactions. We may disclose information within our corporate group or in connection with a proposed or completed merger, acquisition, reorganization, financing, sale of assets, bankruptcy, or similar business transaction.
  • Legal and safety reasons. We may disclose information where necessary to comply with applicable law, regulations, legal process, lawful requests from authorities, enforce our terms or policies, or protect the rights, property, safety, and security of SPYKO LIMITED, Zerano, our users, or others.

Relationship with Shopify

The Services are hosted by Shopify, which provides the ecommerce platform we use to operate our store. Shopify may collect and process personal information about your access to and use of the Services in order to provide and improve the Services. Information you submit through the Services may be transmitted to and processed by Shopify and certain third parties that support Shopify's infrastructure and services.

We may also use certain Shopify features that help us operate, improve, protect, and grow our business. Depending on the feature used, Shopify may process certain personal information in accordance with its own privacy practices and responsibilities.

To learn more about how Shopify uses personal information, please review the Shopify Consumer Privacy Policy. To exercise certain privacy rights directly with Shopify where applicable, you may use the Shopify Privacy Portal.

Third Party Websites and Links

The Services may provide links to websites or other online platforms operated by third parties. If you follow links to websites not affiliated with or controlled by us, you should review their privacy policies, security practices, and terms independently. We are not responsible for the privacy, security, accuracy, or reliability of third-party websites, platforms, or services.

Children's Data

The Services are not intended for children, and we do not knowingly collect personal information from children under the age of majority in their jurisdiction. If you believe that a child has provided personal information to us, a parent or guardian may contact us using the details below to request deletion. As of the effective date of this Privacy Policy, we do not have actual knowledge that we "sell" or "share" (as those terms are defined in applicable law) the personal information of individuals under 16 years of age.

Security and Retention of Your Information

We use reasonable administrative, technical, and organizational measures designed to help protect personal information. However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. We recommend that you do not use unsecured channels to send sensitive or confidential information.

We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Services, maintain your account, complete transactions, handle returns, comply with tax, accounting, legal, and regulatory obligations, resolve disputes, prevent fraud, and enforce our agreements. Retention periods may vary depending on the type of information, the nature of our relationship with you, and applicable legal requirements.

Your Rights and Choices

Depending on where you live, you may have some or all of the following rights in relation to your personal information, subject to applicable law and any permitted exceptions:

  • Right to Access / Know. You may have the right to request access to personal information we hold about you.
  • Right to Delete. You may have the right to request that we delete personal information we maintain about you.
  • Right to Correct. You may have the right to request that we correct inaccurate personal information we maintain about you.
  • Right to Portability. You may have the right to receive a copy of certain personal information in a portable format and, in some cases, request that it be transmitted to another party.
  • Managing Communication Preferences. You may opt out of marketing emails at any time by using the unsubscribe link in those messages. Even if you opt out of marketing communications, we may still send you non-promotional communications, such as messages relating to your orders, account, transactions, or our ongoing business relationship with you.

If you reside in the UK or European Economic Area, and subject to applicable law, you may also have the following rights:

  • Objection to Processing and Restriction of Processing. You may have the right to object to certain processing activities or ask us to restrict the processing of your personal information in certain circumstances.
  • Withdrawal of Consent. Where we rely on your consent to process personal information, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

You may exercise any available rights by contacting us using the contact details below or, where available, through tools provided on the Services. We may need to verify your identity before processing your request, as permitted or required by applicable law. Where permitted by law, you may designate an authorized agent to submit a request on your behalf.

To learn more about how Shopify uses personal information and any rights you may have in relation to information processed by Shopify, please visit the Shopify Privacy Portal.

Complaints

If you have complaints about how we process your personal information, please contact us using the details below. Depending on where you live, you may also have the right to lodge a complaint with your local data protection or privacy authority. For the EEA, a list of data protection supervisory authorities is available here.

International Transfers

Your personal information may be transferred to, stored in, and processed in countries other than the country in which you live. These countries may have data protection laws that differ from those of your country.

Where required by applicable law, if we transfer personal information outside the European Economic Area or the United Kingdom, we will rely on an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or other recognized safeguard, unless the transfer is to a country or jurisdiction recognized as providing an adequate level of protection.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time, including to reflect changes to our practices or for operational, legal, or regulatory reasons. When we do, we will post the revised version on this page, update the "Last updated" date, and take any additional steps required by applicable law.

Contact

If you have any questions about this Privacy Policy, our privacy practices, or if you would like to exercise any rights available to you, please contact SPYKO LIMITED, trading as Zerano, at privacy@thezerano.com or by mail at 74-78 Stanley Street, Central, Hong Kong Island, Hong Kong SAR. Phone: +15126014131. Company number: 78962963. For the purposes of applicable data protection law, SPYKO LIMITED, trading as Zerano, is the data controller of your personal information unless otherwise stated.