Skip to content

ZS-PP-001Version 1

Privacy Policy

Last updated:

1. Who we are

This Privacy Policy explains how Wonki Collective Ltd, trading as Zest (“Zest”, “we”, “us”) collects and uses personal data when you use the Zest Platform (the “Service”), a B2B platform for visualising food waste across manufacturing production lines.

For UK data protection law (the UK GDPR and the Data Protection Act 2018), the data controller is Wonki Collective Ltd, trading as Zest, 21 Albemarle Street, The Royal Institution, London, England, W1S 4BS. Contact us about privacy at hello@zestsolutions.io (privacy contact: Davina McGrath).

2. Scope & our role

The Zest Platform is sold to business customers (your employer or organisation). Our role under data protection law depends on the data:

Controller: for personal data relating to user accounts, authentication, support and product analytics (described below). This Policy covers that processing.

Processor: for the operational/manufacturing data a customer organisation uploads and visualises (production runs, lines, materials, waste metrics, costs). That data belongs to the customer; our processing of it is governed by our Data Processing Addendum (DPA) with the customer, not by this Policy. Operational data is largely non-personal, but where it contains personal data the customer is the controller.

3. Personal data we collect

Account & identity data

Authentication is provided by Google Cloud Identity Platform (Firebase). When an account is created or an invitation accepted, the following are processed: email address, display name, a unique user identifier, password (managed and stored by Google Identity Platform, never by us in plain text), and (if enabled) multi-factor authentication (TOTP) enrollment data. Where your organisation invites you to the Service, we receive your name and email address from your organisation rather than from you directly.

Usage & product-analytics data

We use Mixpanel to understand how the Service is used. This includes your user identifier, your organisation's identifier and name, and a defined (“allowlisted”) set of event properties such as the page/route viewed, sign-in method, and which filters, metrics and views you interact with.

Session recording & heatmaps

Mixpanel may, with your consent, record user sessions and capture interaction heatmaps within the Service. This can capture on-screen interactions during your use of the application. Session recording does not run unless you have given consent, all on-screen text is masked by default, and you may withdraw consent at any time (see section 5).

Technical, cookie & local-storage data

Authentication tokens and certain preferences are stored in your browser (see the table in section 5).

Support communications

If you contact us, we process the information you choose to provide.

What we do not do: our application servers do not store end-user personal data in our own database beyond per-organisation configuration; identity data is held in Google Identity Platform. Sensitive manufacturing and financial details (client, site, line and material names, costs and quantities) are deliberately excluded from analytics (including session recordings, where all on-screen text is masked) and masked in our application logs.

4. How and why we use personal data

  • Provide and secure the Service; authenticate users; multi-tenant access control.Data: account/identity, technical. Basis: performance of a contract; legitimate interests (security).
  • Understand and improve product usage. Data: usage/analytics. Basis: consent (see section 5).
  • Session recording & heatmaps. Data: session/interaction data. Basis: consent.
  • Respond to support requests. Data: support communications. Basis: legitimate interests; performance of a contract.
  • Comply with legal obligations. Data: as required. Basis: legal obligation.

5. Cookies & local storage

The Service uses the following browser storage. It does not use advertising or cross-site tracking cookies.

firebase_token (localStorage)
Authentication token that keeps you signed in.Duration: until sign-out.
last_activity (localStorage)
Inactivity-timeout tracking; auto sign-out after 5 days idle.Duration: rolling.
invite_email (localStorage)
Temporary, during invitation acceptance.Duration: transient.
theme (cookie)
Light/dark theme preference (SameSite=Lax).Duration: 1 year.
zest.analytics.optout.v1 (localStorage)
Records your analytics consent choice.Duration: persistent.
Mixpanel cookies/storage
Product analytics, session recording & heatmaps (secure cookie; not shared across sub-domains).Duration: 365 days.Set only with your consent.

Consent. Analytics (including session recording) does not initialise unless you have given consent through the in-product consent prompt. You can withdraw consent at any time within the Service; your choice is stored locally and analytics stops initialising from that point on. Strictly necessary storage (authentication, security and your saved preferences) does not require consent and is used in any event.

6. Who we share personal data with (sub-processors)

We use the following providers, sharing only the data needed for each purpose. We do not sell personal data. We may disclose data where required by law.

  • Google Cloud Identity Platform (Firebase): authentication & identity. Data: email, display name, user ID, password, MFA enrolment.
  • Google Cloud Platform: hosting, analytics data store, data ingestion. Data: operational/manufacturing data; limited technical data.
  • Mixpanel: product analytics, session recording & heatmaps. Data: pseudonymous user ID, organisation, usage events.

7. International transfers

Our infrastructure runs on Google Cloud Platform in the UK Region (europe-west2). Mixpanel is configured to use its EU endpoint (api-eu.mixpanel.com). Where personal data is transferred outside the UK, we rely on appropriate safeguards such as the UK International Data Transfer Agreement (IDTA), the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, or an applicable UK adequacy regulation (including the UK–US Data Bridge where the recipient is certified).

8. How long we keep personal data

We retain personal data only as long as necessary.

  • Account/identity data: retained for the life of your account, then deleted within 12 months of account closure.
  • Usage/analytics data: retained for the life of your account, then deleted within 12 months of account closure.
  • Operational data: governed by the customer contract/DPA.
  • Support communications: retained for the life of your account, then deleted within 12 months of account closure.

9. How we protect personal data

Security measures include strict multi-tenant isolation enforced on every request, optional multi-factor authentication, masking of sensitive fields in logs, short-lived signed tokens for embedded dashboards, and encryption of data in transit. No system is perfectly secure, but we work to protect your information.

10. Your rights

Under UK data protection law you have the right to access, rectify, erase, restrict, object to, and port your personal data, and to withdraw consent where processing relies on it. Because account identity is managed within your organisation's tenant, some requests may be directed to your organisation as controller. To exercise your rights, contact hello@zestsolutions.io. Where we rely on legitimate interests, you may object at any time. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.

You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

11. Children

The Service is a workplace B2B tool and is not directed at children.

12. Changes to this Policy

We may update this Policy from time to time. We will update the “Last updated” date and, where appropriate, notify you.

13. Contact

Wonki Collective Ltd, trading as Zest
21 Albemarle Street, The Royal Institution
London, England, W1S 4BS
Privacy enquiries: hello@zestsolutions.io

Contact us