Privacy Policy
The short version: to send you an alert we store your email address, the route and dates you asked about, and the IP address that asked. We don't sell it, we don't advertise, and there are no tracking cookies. Every alert email has a one-click cancel link.
1. Who we are
Ziri (ziri.app) is a small independent project run from the United Kingdom. For data protection purposes we are the controller of the personal data described here. Write to support@ziri.app, or by post:
Ziri17 Delta Building
London E14 9PP
United Kingdom
2. What we collect
When you create an alert
- Your email address. It is the only way to send you the alert, and the only thing that identifies you to us.
- The route and dates. Departure and destination airport, and the month or part-month you want to fly.
- Whether the route was already on sale when you asked, so a later "it just opened" is true rather than a guess.
- The IP address that submitted the form, to rate-limit abuse.
- A random alert token. This is the link in your email; it is the only credential the Service has.
When you ask us to cover an airport or an airline
- What you typed: the airport or city, or which airline you want and any note you add.
- Your email address, only if you give one. It is optional, and it is used once: to tell you when we start watching what you asked for.
- The IP address that submitted the form, to rate-limit abuse.
When you use the contact form
- Your name, email address, chosen subject and message, so we can reply.
Automatically
- Web server logs: IP address, time, page requested, browser user agent. Standard for any web server, used for troubleshooting and abuse.
We do not collect names, passwords, payment details, location, or any special category data. There are no accounts, so there is nothing else to collect.
3. Why we're allowed to hold it
- Performing what you asked for. You gave us an email address in order to receive one specific alert; we use it for that.
- Legitimate interests. Server logs, rate-limit records and abuse prevention, balanced against your privacy and kept to a minimum.
We never use your address for marketing, newsletters or anything you did not ask for.
4. Cookies
Ziri sets no cookies for browsing, searching a route or creating an alert. There is no advertising pixel and no cross-site tracking.
We do count visits, using Umami running on our own server. It sets no cookie and gives you no identifier that follows you between sites. It records the page, the referrer, and the country, screen size and browser your request arrived with. Your IP address is used to work out the country and is then discarded; it is never stored and never leaves our hardware.
It also counts one thing you do rather than one page you see: creating an alert. That count carries the route, the month and whether you asked for part of it, so we can see which routes people care about. It carries no email address and nothing that identifies you, and the route and month were already visible in the web address of the page you were on.
The contact form is the one exception: submitting it
sets a single session cookie (ZIRI_SESSION) so we can show you
the result and block cross-site request forgery. It holds no personal data
and expires when you close your browser.
5. Who else sees it
We do not sell, rent or trade personal data. It is shared only with the services needed to run Ziri:
- Resend delivers our email. Your address passes through them.
- Nobody, for the look of this page. The stylesheet and font used to come from jsDelivr and Google Fonts, which revealed your IP address to both. We now serve them ourselves, so loading a Ziri page contacts no one but Ziri.
- Airlines. We read their public availability. We never send them anything about you; a booking link is an ordinary link you choose to follow, and once you do, the airline's own privacy policy applies.
We will disclose data if the law requires it. If Ziri ever changes hands, we'll say so here before any data moves.
6. Where it lives, and how long
Data is stored on our own server in the United Kingdom. The database accepts no connections from the network, backups are readable only by the operator, and the site is served over HTTPS.
We keep an alert while it is live. Once it has fired or you have cancelled it, we keep the record so the same alert is not created again by accident; ask us and we delete it outright. Contact messages are kept while the conversation is useful. Server logs rotate within a few weeks.
Three things delete themselves, nightly and without being asked, all after 90 days: the IP address recorded against an alert, the IP address recorded against a request to cover an airport or airline, and our log of which addresses we have emailed, which exists only to stop one person flooding the mail relay.
An email address left on a coverage request is kept until we have answered it, because adding an airport can take longer than ninety days. Ask us and we delete it.
No system is perfectly secure. We hold as little as possible so that a breach would expose as little as possible.
7. Your rights
Under UK and EU data protection law you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct it if it's wrong;
- delete it;
- restrict or object to how we use it;
- send it to you in a portable format.
Email support@ziri.app from the address concerned and we'll act within one month, free of charge. To stop an alert immediately you don't need to write at all: use the cancel link in the email.
If you think we've handled your data badly, you can complain to the UK Information Commissioner's Office at ico.org.uk, or to your national supervisory authority in the EU.
8. Children
Ziri is not aimed at children and we don't knowingly collect data from anyone under 16. If you believe a child has given us an email address, tell us and we'll remove it.
9. Changes
If this policy changes we'll update the date at the top. If a change materially affects how we use data you have already given us, we'll email the people affected before it takes effect.
Contact
Privacy questions: support@ziri.app, or use the contact form. See also our terms of service.