Privacy Policy

Version 2026-08-18b · Last updated: 18 August 2026

This policy describes what Zuca Snacks collects when you join our waitlist, why we collect it, our legal basis for doing so, who else sees it, how long we keep it, and what you can require us to do about it. It is written to describe what our systems actually do. If something here does not match your experience, tell us — that is a bug and we will fix it.

This policy is written around the GDPR, which sets the strongest standard of the ones that apply to us — and everyone gets that standard, wherever they live. Where California law (CCPA/CPRA) adds something different, it is in section 9.

We do it that way because running one standard is how you avoid the mistake of applying the wrong one to somebody. It also means you do not have to work out which rules cover you: the answer is the strict ones.

  1. Who we are
  2. What we collect
  3. Health-related information
  4. Our legal basis
  5. What we do not do
  6. Who else sees it
  7. Sending data outside the EEA
  8. How long we keep it
  9. Your rights, and how to use them
  10. California residents
  11. Emails from us
  12. Security

1. Who we are

Zuca Snacks (“Zuca”, “we”) is a food company based in California, USA. We are the data controller for the personal data described below — we decide why and how it is processed.

Privacy questions and rights requests: privacy@zucasnacks.com. Anything else: emil@zucasnacks.com.

2. What we collect

Everything below is given to us by you, through one form on this website. We do not buy personal data and we do not obtain it from data brokers or scraped lists. Only your email address and your consent are required. Every other field is optional, and leaving one blank has no effect on your place in line.

WhatWhy
Email address (required)To tell you when pre-orders open. The only thing we genuinely need.
First name (optional)So our emails address you rather than your inbox.
Phone number (optional)Stored only if you tick the text-message box. Give us a number without ticking it and the number is discarded on our server and never written down. We use it to text you about your order and about launch — nothing else — and you can stop it any time by replying STOP.
Postal address (optional)Stored only if you tick the post box. Same rule: no tick, no storage. We use it to post you samples and product news. It is the most identifying thing on this form, which is why it sits behind its own separate opt-in rather than being bundled with the rest.
Company name and rough size (optional)Only if you tell us you are interested in Zuca for an office. It helps us work out whether an office offering is worth building, and at what size.
How many you would buy, and where you would buy it (optional)Rough bands, not an order. They tell us how much to make and where to sell it.
Dietary needs (optional)Treated as health information — an allergy is a health fact. Stored under the same separate opt-in as your reason for interest, and covered by the same wording. See section 3.
Whether you'd give us 15 minutes of feedback (optional)A preference about email we already have your permission to send. It narrows what we send you rather than widening it, so it needs no extra opt-in.
Whether you confirmed your email, and whenWe email you a confirmation link when you sign up. Clicking it is what puts you on the send list. If you never click, we keep your signup but do not email you again — see section 8 for how long.
“Other” free-text answers (optional)Three questions let you type your own answer instead of picking from the list: how you heard about us, where you would buy, and any dietary need. We store what you typed. There is deliberately no free-text box beside the question about why fiber matters to you — that one is a fixed list, because an open box invites people to write far more about their health than we have any reason to hold.
ZIP code (optional, US only)To work out which regions to ship to first. Used at regional level only. We do not currently ask for postal codes outside the US.
Reason for interest (optional)Treated differently — see section 3.
Purchase intent, price expectation, flavor preference (optional)To decide how much to make, at what price, in which flavor.
Whether you are a clinician (optional)Clinicians receive more technical updates. Nothing else differs.
How you heard about us (optional)To know which of our efforts are worth repeating.
Campaign tags in the link you arrived on, and the page you signed up fromSame reason. Taken from the URL you clicked — not from tracking you across the web.
Your country, worked out from your IP addressWe never ask you for this. Your country determines which privacy law protects you, and we would rather derive it than get it wrong — it is the difference between treating you correctly and treating you as though you lived somewhere else. We store the two-letter country code only. Not your city, not your coordinates, not your full IP.
Consent record: the date and time you opted in, the exact wording you were shown, a shortened form of your IP address, and your browser's user-agent stringGDPR Art 7(1) requires us to be able to prove you consented, and the honest version of that proof is a copy of the sentence you actually read — not a reference number. The timestamp is taken from our server, not your device. Your IP address is shortened before storage (for example 203.0.113.0) so it identifies a network rather than a device — enough to corroborate the record, no more.

3. Health-related information

If we ask why you are interested in a high-fiber food, some answers — digestion, gut health, a doctor's suggestion — say something about your health. Under GDPR Article 9 that is a special category of personal data, and processing it is prohibited unless you give explicit consent. That is a higher bar than ordinary consent, and we treat it as one.

We store this only if you tick the separate box next to that question. Ticking the general email box is not enough and does not count. If you select an answer but do not tick that box, your selection is discarded on our server and never written down — this is enforced in code, not by policy.

Dietary needs are covered by this same opt-in. A nut allergy is a health fact exactly as a digestive complaint is, and the consent wording names both — one explicit box rather than two, because two boxes would be friction without extra protection.

We do not infer anything about you beyond what you told us. We never send this to an analytics service, an advertiser, or anyone else. You can withdraw this consent on its own, while staying on the waitlist.

4. Our legal basis

What we doLegal basis (GDPR)
Store your email address and send you launch updates Consent — Art 6(1)(a). Also required by Norway's Marketing Control Act § 15, which prohibits marketing by email to individuals without prior consent.
Store your reason for interest Explicit consent — Art 9(2)(a), given separately from the above.
Store your phone number and text you Consent — Art 6(1)(a), separate again. Also required by Norway's Marketing Control Act § 15, which covers text messages as well as email, and by the US TCPA.
Store your postal address and post to you Consent — Art 6(1)(a), its own separate opt-in.
Store the optional product-preference answers Consent — Art 6(1)(a), given at the same time and for the stated purpose.
Keep the consent record itself (time, the wording you were shown, country, shortened IP, user-agent) Legal obligation — Art 6(1)(c), read with Art 7(1), which requires us to be able to demonstrate consent.
Work out your country from your IP address Legal obligation — Art 6(1)(c). We have to know which privacy regime applies to you in order to comply with it. We keep the country code and discard the rest.
Rate limiting and anti-spam on the signup form Legitimate interests — Art 6(1)(f): keeping our own waitlist accurate and our systems available. This processing is transient and does not build a profile of you.
Keep a one-way hash of your address after you unsubscribe Legitimate interests — Art 6(1)(f). It exists solely so we can honor your objection. It cannot be turned back into your address.

Consent is never a condition of anything. You are not buying, and refusing any optional item costs you nothing. You can withdraw consent at any time, and withdrawing is as easy as giving it — see section 9. Withdrawal does not affect the lawfulness of what we did before you withdrew.

5. What we do not do

Fonts

This site currently loads its typefaces from Google's font service, which means Google receives your IP address and browser type when the page loads. Nothing you type is involved. We are moving these fonts onto our own servers to remove that request entirely, and this notice will be updated when that ships.

6. Who else sees it

A short list, because the system is small. Each of these is a processor: they act only on our written instructions, under a data processing agreement, and may not use your data for their own purposes.

ProcessorWhat they holdWhere
Google (Workspace & Sheets)The waitlist itselfUSA
VercelWebsite hosting and short-lived server logsUSA
UpstashAnti-spam counters and a one-way hash of your email — no readable addressEEA
An email service providerName and emailNamed here once chosen

Beyond these, we disclose personal data only where the law requires it, and we will tell you if that happens unless we are legally barred from doing so.

7. Sending data outside the EEA

Zuca is a US company and our waitlist is stored in Google Sheets on US infrastructure. If you are in the EEA, your personal data is transferred to the United States. You are entitled to know how that transfer is made lawful, so:

Both Google LLC and Vercel, Inc. are certified under the EU–US Data Privacy Framework. On 10 July 2023 the European Commission decided that the US provides an adequate level of protection for personal data transferred to organizations on that list, and that decision expressly covers transfers from Norway, Iceland and Liechtenstein as well as from EU member states. Transfers to a certified organization therefore need no additional safeguard. Where a processor is not certified, we rely on the European Commission's Standard Contractual Clauses instead.

You can check any organization's current status yourself at dataprivacyframework.gov/list.

You should also know the limitation: the adequacy decision has been challenged before — the two arrangements that preceded it, Safe Harbor and Privacy Shield, were both struck down by the Court of Justice. If this one is annulled, we will move to Standard Contractual Clauses and tell you. As an EEA resident you have the right to obtain a copy of the safeguards that apply to you; email us and we will send them.

8. How long we keep it

GDPR Art 5(1)(e) does not permit us to keep personal data indefinitely, so we do not. Each period below has a reason attached, because a retention period without a reason is not a retention period.

DataKept forWhy that long
Waitlist record (email and any optional fields) 24 months from your last interaction with us, or until you ask us to delete it — whichever comes first A food product goes from pre-order to shelf over roughly one to two years. Beyond 24 months of silence, consent is stale and the record is no use to either of us.
Phone number and postal address 24 months, or until you withdraw that specific consent Tied to the consent that permits them. Withdraw the text or post opt-in and they are deleted, even if you stay on the email list.
Reason for interest (health-related) 12 months, or until you withdraw that specific consent Deliberately shorter than the rest. It is the most sensitive thing we hold and the least necessary to keep.
Consent record As long as the waitlist record, then 12 months after deletion It is the evidence that the earlier processing was lawful, and it needs to outlive the data it justifies.
Server logs 30 days Long enough to investigate a fault or an attack. They contain no email addresses — only a short one-way hash.
Unsubscribe suppression list (one-way hash only) Indefinitely The one deliberate exception. It is the only way to guarantee we never email you again, so deleting it would defeat your own objection. It holds no readable address and is used for nothing else.
If Zuca never launches Everything deleted within 90 days of us abandoning the product The purpose you consented to would no longer exist.

9. Your rights, and how to use them

If you are in the EEA or the UK, the GDPR gives you the rights below. We extend all of them to everyone who writes to us, regardless of where you live.

How to exercise them

Email privacy@zucasnacks.com from the address you signed up with and say what you want. That is the whole process. Or use the unsubscribe link in any email, which removes you immediately and needs no reply from us.

We answer within one month, as GDPR Art 12(3) requires. If a request is genuinely complex we may extend by up to two further months, and we will tell you why within the first month. It is free; we will not charge you a fee.

To confirm it is you, we reply to the address on file and ask you to confirm. We will never ask for an ID document, an account, or any information we do not already hold. Collecting new personal data in order to process a deletion request would defeat the point of it.

One limitation, stated plainly

An earlier version of this site saved a copy of your submission in your own browser's local storage, on your own device. We have removed that, but we cannot reach a copy already sitting in your browser — only you can, by clearing this site's data. Nothing else has access to it and it goes no further than the device it is on. We mention it because an erasure request should tell you the truth about what erasure can and cannot reach.

10. California residents

Under the CCPA as amended by the CPRA you have the rights to know, access, delete, correct, limit the use of sensitive personal information, opt out of sale or sharing, and not be discriminated against for exercising any of them. The GDPR rights above already meet or exceed each of these, and the same email address serves all of them.

Two California-specific points. We do not sell or share personal information as those terms are defined by the CPRA, including for cross-context behavioral advertising, so there is no “Do Not Sell or Share My Personal Information” link — if that changes, one will appear before it does, not after. And California gives you 45 days where the GDPR gives one month; we work to the shorter of the two for everyone.

11. Emails from us

We email you only if you asked us to. Every email carries a working one-click unsubscribe link and our physical postal address. Unsubscribing takes effect immediately — US law would allow us ten business days and we do not use them. Our subject lines describe what is actually in the email.

If you ever receive email from us that you did not ask for, or that has no unsubscribe link, please forward it to privacy@zucasnacks.com. We would much rather hear it from you than from a spam filter or a regulator.

12. Security

Everything travels over HTTPS. The signup endpoint validates and rate-limits every submission and accepts requests only from this site. Data is encrypted at rest by our storage provider and access to the list is limited to the people who need it. No system is perfect, and we would rather describe what we do than promise what nobody can deliver.

If a breach puts your rights at risk we will notify our supervisory authority within 72 hours as GDPR Art 33 requires, and tell you directly where Art 34 requires it.

Found a vulnerability? Email privacy@zucasnacks.com. We will not pursue anyone who reports a genuine issue in good faith.

Changes

If we change this policy materially we will update the version above and email everyone on the waitlist before the change takes effect. Where a change would widen what we do with data you already gave us, we will ask for fresh consent rather than assume the old one still covers it.