Skip to content

Privacy Policy

Last updated:

This Privacy Policy explains how zovrā (“we”, “us”, “our”) collects, uses, and protects your personal information when you use our website and services. We are committed to transparency and to giving you meaningful control over your data.

We comply with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and the California Consumer Privacy Act (CCPA) where applicable.

1. Information we collect

1.1 Information you give us

  • Account data - email address (required), and any profile fields you choose to add (display name, preferred destinations, field of study). You provide this when you sign up or update your profile.
  • Search context - the citizenship, destination, purpose, and other filters you enter into our visa, school, scholarship, and job finders. We use these to return relevant results.
  • Saved items + recently viewed - when signed in, which results you save or view. Used only to populate your personal dashboard.
  • Email preferences - your opt-in choices for marketing emails and weekly digests. You can update these at any time in your account settings, or via the unsubscribe link in any marketing email.
  • Communications - if you email us, we keep a record of that correspondence to respond and follow up.

1.2 Information collected automatically

  • Usage data - pages you visit, features you use, interactions with our search and result pages. Used to improve the product and detect abuse.
  • Device + browser data - IP address (used for rate limiting and abuse detection), user agent, screen size, referrer URL.
  • Cookies + similar technologies - see our Cookies section below.

2. How we use your information

  • To provide and operate the zovrā service
  • To authenticate you and keep your account secure
  • To send transactional emails (password resets, security alerts, account confirmations)
  • To send marketing communications you have opted into (and never if you have not)
  • To analyse usage patterns and improve our product
  • To detect, prevent, and respond to abuse, fraud, or security incidents
  • To comply with legal obligations

3. Legal bases for processing (UK + EU users)

Under the UK GDPR and EU GDPR, we rely on the following legal bases:

  • Contract - to provide the service you signed up for (account, search results)
  • Legitimate interests - for analytics, product improvement, security, abuse detection
  • Consent - for marketing emails (you opt in; we never assume)
  • Legal obligation - when required by law to retain or disclose data

4. Who we share your data with

We do not sell your personal data. We share specific data with a small set of vetted third-party processors who help us run the service:

  • Database & authentication (EU/US regions) - stores your account, profile, and search data.
  • Hosting (EU/US regions) - serves the website and sees basic request metadata (IP address, user agent).
  • Transactional email (EU) - sends password resets, account confirmations, and any marketing emails you opt into.
  • Bot-protection (captcha) - shown on the sign-up and sign-in forms to block automated abuse.
  • Error monitoring - captures crash reports. We strip personally identifiable information from error payloads before they are sent.
  • Product analytics (EU) - aggregated usage events. We do not include personal data in event properties (enforced by code-level guards).

Each processor is bound by a data-processing agreement and only handles the data needed for its function. We can provide the names of our current processors on request - just contact us.

5. International transfers

Some of our processors operate in the United States. Where data leaves the UK or EU, we rely on appropriate safeguards - Standard Contractual Clauses (SCCs) or equivalent - to ensure your data is protected to the same standard as if it stayed in the UK/EU.

6. How long we keep your data

  • Account data - for as long as your account is active, plus 30 days after deletion to handle any rollback or dispute. After 30 days, data is permanently deleted.
  • Anonymised analytics - retained indefinitely for trend analysis. Cannot be linked back to you.
  • Error logs - 90 days, then automatically purged.
  • Email send logs - 12 months, for deliverability monitoring and compliance with anti-spam regulations.

7. Your rights

You have the following rights regarding your personal data:

  • Access - request a copy of the data we hold about you
  • Rectification - correct inaccurate or incomplete data
  • Erasure - delete your account and associated data. You can do this yourself in account settings (deletes within 30 days), or by emailing us
  • Portability - receive your data in a machine-readable format
  • Objection - object to processing based on legitimate interests (analytics, marketing)
  • Withdraw consent - opt out of marketing emails at any time via the unsubscribe link or account settings
  • CCPA-specific (California residents) - request to know what we collect, request deletion, opt out of any “sale” of data (we do not sell data), and not be discriminated against for exercising these rights

To exercise any of these rights, email privacy@zovra.me from the email address on your account. We respond within 30 days.

8. Cookies and similar technologies

We use a small set of cookies + localStorage entries:

  • Essential - auth session token (keeps you signed in), CSRF token, theme preference (dark/light)
  • Functional - recently-viewed items, welcome-back state, MFA-enrolment flow
  • Analytics - anonymous usage tracking. We do not use third-party advertising trackers.

We do not use behavioural advertising cookies or third-party ad-network trackers. See our Cookies page for the full list.

9. Children

zovrā is not directed at children under 16. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, please contact privacy@zovra.me and we will delete it promptly.

10. Security

We use industry-standard security practices: encrypted connections (TLS 1.3), encrypted-at-rest storage, modern password hashing (Argon2), breach-checking of new passwords against known-compromised databases on sign-up, multi-factor authentication (TOTP), row-level security on all database access, server-side rate limiting, captcha on auth flows, and content-security-policy headers.

No system is perfectly secure. If you believe your account has been compromised, email security@zovra.me immediately.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will post the new version with an updated “Last updated” date. For material changes, we will notify users via email or an in-product banner at least 14 days before the change takes effect.

12. Contact

Questions about this policy or about your personal data? Email privacy@zovra.me.

If you’re in the UK and unhappy with how we’ve handled your data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO). If you’re in the EU, you can contact your local Data Protection Authority.