Who we are
Zyfy is a UK data enrichment API operated as a sole trader in the United Kingdom.
For the purposes of UK GDPR, we are the data controller for personal data collected
through this website and API.
What data we collect
- Account data: your email address, hashed password, and any optional
contact name, business name, or website you provide at sign-up.
- API usage data: request counts, quota usage, and billing period dates.
This is used to enforce your plan limits and is visible to you in your dashboard.
- Billing data: Stripe customer ID, subscription status, and billing period.
We do not store card details — these are held by Stripe under their own privacy policy.
- API inputs: postcodes and vehicle registration plates submitted to the API.
These are processed to produce a response and are not retained as personal data.
We do not link API inputs to individual users.
- Request logs: your IP address and the API endpoint called are logged
with each request for security monitoring and abuse prevention. These logs are retained
for up to 90 days and are not linked to your specific API inputs.
- Contact submissions: email address and message content submitted via the
contact form.
How we use it
- To provide the API service and enforce quota and rate limits.
- To send transactional emails — account verification, password reset, and billing notifications.
- To manage billing and subscriptions via Stripe.
- To respond to contact form submissions.
- To monitor service health and detect abuse.
We do not use your data for advertising. We do not sell or share data with third parties for marketing purposes.
Legal basis (UK GDPR)
- Contract: processing necessary to deliver the service you signed up for.
- Legitimate interests: security monitoring, fraud prevention, and service reliability.
- Legal obligation: retaining billing records as required by UK tax law.
Data retention
- Account data: retained while your account is active. If you delete your account, account data is removed promptly, subject to legal retention requirements below.
- Billing records: retained for 7 years as required by HMRC.
- API inputs: postcodes and registration plates are not retained beyond the processing of a request.
How we protect your data
- Encryption in transit: all traffic to and from our API, dashboard, and Google Sheets add-on is encrypted using TLS/HTTPS. Any unencrypted (HTTP) request is automatically redirected to HTTPS — no data is transmitted or processed over an unencrypted connection.
- Encryption at rest: account data, API keys, and billing records are stored on infrastructure with disk-level encryption at rest.
- Password and key security: account passwords are hashed and never stored in plain text. API keys are shown in full only once, at creation — after that we display a masked prefix only.
- Access controls: production systems and databases are accessible only to the operator of Zyfy, over authenticated, key-based connections. We do not grant third parties access to production data.
- Google Sheets add-on: your Zyfy API key is stored using Google's own Properties Service, scoped to your Google account or the specific spreadsheet you choose — Zyfy never sees or stores your Google account credentials. The add-on reads only the specific cell values you select as formula input (a postcode or vehicle registration) and writes results back to the sheet; it does not read, store, or transmit the rest of your spreadsheet's contents.
- Least privilege: the add-on requests only the minimum Google API scopes needed to read your selected input cells, write results back, and display its sidebar — nothing broader.
Third parties
- Stripe: payment processing. Subject to Stripe's privacy policy.
- Email provider: transactional email delivery.
- Hosting provider: infrastructure hosted in the UK/EU.
We do not use analytics platforms, advertising networks, or tracking pixels of any kind.
Cookies
We use two HttpOnly session cookies: zyfy_auth (short-lived access token) and zyfy_refresh (refresh token, scoped to the authentication path). Both are strictly necessary for the authenticated
dashboard and do not require consent. We do not use tracking or analytics cookies.
Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your data, subject to legal retention requirements.
- Object to processing based on legitimate interests.
- Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
To exercise any of these rights, contact us.
Changes to this policy
We may update this policy from time to time. The date at the top of this page reflects the
most recent revision.