Privacy Policy
Last updated 11 September 2026
This policy explains what personal data Zord (“Zord”, “we”, “us”) collects when you visit zord.app, join the waitlist, or use the Zord product, why we collect it, and the rights you have over it. It applies wherever you are, and is written to meet UK GDPR, EU GDPR, and US state privacy laws (such as the CCPA) where they apply to you.
Zord is early-stage software, currently in a waitlist / early-access phase. Some of the “when you use the product” sections below describe data handling for features that are in active development rather than fully live today — we've written them as the standard we're building to, and will update this page as each part ships.
1. Who we are and how to contact us
Zord is operated by the team behind zord.app. For anything relating to this policy — including exercising the rights described in section 7 — email hello@zord.app. We haven't completed company registration yet; once we have, we'll publish our registered company name, number, and address here and in the site footer.
2. Data we collect
2.1 When you join the waitlist
We collect:
- Email address — required, so we can contact you about early access.
- Name and company — collected in the hero sign-up form so we can personalise your invitation and, if you become a founding customer, engrave your physical badge. These are optional at the database level but requested as required fields on that form.
- Consent record — the timestamp and policy version you agreed to when you checked the consent box, so we can demonstrate consent was given (required under GDPR Article 7).
2.2 When you sign in
Zord uses passwordless sign-in (a six-digit emailed code). We collect your email address and, once verified, maintain a signed-in session using a cookie set by our authentication provider, Supabase. See our Cookie Policy for details.
2.3 When you connect a Salesforce org
If you connect a Salesforce org to Zord, we store the org's Salesforce ID, instance URL, and an OAuth refresh token — encrypted at rest — so Zord can reconnect to your org to run checks without you re-authenticating each time. Zord requests OAuth scopes designed to be read-only, and is built so its own code only ever issues read requests against the Salesforce APIs it uses (Metadata, Tooling, Limits) — see our Terms of Service for the full statement on this. We do not currently extract or store bulk records (such as your Contacts, Leads, or Opportunities) from your org; health-check results are metadata about your org's configuration (permission sets, Apex coverage, certificate expiry, and similar), not your customers' personal data. If that changes as the product develops, this policy — and, where legally required, a separate data processing agreement — will be updated before it does.
2.4 Technical data
Like most websites, our hosting provider (Vercel) automatically logs standard technical information for security and reliability — IP address, browser type, and request timestamps. We don't use this for analytics or tracking, and we don't run any analytics, advertising, or tracking scripts on zord.app today. See our Cookie Policy for what that means in practice.
3. Why we process your data
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Notify you when early access opens | Email, name, company, consent record | Consent |
| Engrave a founding-customer badge | Name, company | Consent / contract |
| Sign you in and keep you signed in | Email, session cookie | Contract (providing the service you asked for) |
| Run Salesforce org health checks | Salesforce org ID, instance URL, encrypted refresh token | Contract |
| Keep the service secure and working | Technical/log data | Legitimate interest |
4. Who we share data with
We don't sell your personal data, and we don't share it with third parties for their own marketing purposes. We use a small number of service providers (“ processors”) to run Zord, each of which only processes data on our instructions:
- Supabase — database, authentication, and session management.
- Resend — sending transactional emails (waitlist confirmation, sign-in codes).
- Vercel — application hosting.
These providers may process data outside your home country, including in the United States. Where that involves transferring personal data out of the UK or EEA, we rely on the providers' own GDPR-compliant safeguards (such as Standard Contractual Clauses). We may also disclose data if required by law, or to investigate fraud or abuse of the service.
5. How long we keep data
- Waitlist entries: kept until early access is offered and accepted or declined, or until you unsubscribe (see section 7).
- Account data: kept for as long as your account is active, plus a reasonable period afterwards for legal, tax, and security purposes.
- Salesforce connection data: deleted when you disconnect an org or close your account.
6. Security
We encrypt Salesforce refresh tokens at rest, use TLS in transit throughout, and use row-level security in our database so an account can only ever read its own data. No system is completely secure, and we can't guarantee the absolute security of information transmitted over the internet.
7. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your data (“right to be forgotten”).
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw consent at any time, without affecting processing that already happened.
Every waitlist email includes an unsubscribe link, which removes you immediately. For anything else — including a full deletion request — email hello@zord.app; we'll respond within 30 days. If you're in the UK or EU and unhappy with our response, you can complain to the UK Information Commissioner's Office or your local data protection authority.
If you're a California resident, you have rights under the CCPA/CPRA to know, delete, and correct your personal information, and to opt out of the “sale” or “sharing” of it — we don't sell or share personal information as those terms are defined by California law.
8. Children
Zord is a business tool and isn't directed at, or knowingly used by, children.
9. Changes to this policy
We'll update the date at the top of this page whenever we make a material change, and, where required by law, notify you directly.
10. Contact
Questions about this policy or your data: hello@zord.app.