Privacy Policy
Effective 16 August 2026 · Last updated 16 August 2026
How Spatial Regal Digital Ltd collects, uses, and shares personal data on Zipper.
1. Who we are
Spatial Regal Digital Ltd is the controller for account, billing, and website data. For customer traffic that transits The Crown, The Keep, and Portcullis, we act as a processor under the Data Processing Addendum.
Contact privacy at privacy@tinyzipper.com.
2. Data we collect
Account data: name, email, hashed password or SSO claims, workspace membership, plan, and payment tokens handled by our payment processor.
Service data: hostnames, DNS records, WAF rules, Portcullis site keys, and configuration you store in the dashboard.
Edge telemetry: request metadata (IP, user-agent, JA3/JA4-class fingerprints, path, status, cache outcome), Portcullis challenge outcomes, and security events. We do not store full origin response bodies in Watchtower by default.
Widget signals: timing, proof-of-work solution, and coarse interaction signals used only to issue or deny a Portcullis token.
3. Why we process it
To authenticate you, provision named services, deliver and protect customer sites, prevent abuse, bill plans, and improve reliability. Legal bases include contract, legitimate interests in securing a multi-tenant network, and consent where required for optional cookies.
4. Sharing
We share data with subprocessors listed at /legal/subprocessors, with authorities when legally compelled, and with you (the tenant) for your own logs. We do not sell personal data.
5. Retention and rights
Account data is kept for the life of the workspace plus 30 days. Security logs are kept 7–90 days depending on plan. You may request access, correction, deletion, or export via privacy@tinyzipper.com.
6. International transfers
Edge nodes may process request metadata in the region closest to the visitor. Account data for this deployment is stored in the Supabase region configured for the project. Transfers rely on contractual clauses in the DPA.