Privacy Policy

Privacy Policy

Effective Date: 14 June 2025
Business Name: Zach & Grace Ltd
Company Number: 14341735
Registered in: England & Wales

This Privacy Policy explains how Zach & Grace Ltd (“we”, “our”, or “us”) collects, uses, and protects your personal information when you visit our website, purchase digital products, or access our online courses.

For more information about how we use cookies, please see our Cookie Policy.


1. Who We Are

Zach & Grace Ltd is a UK-based creative business offering digital products and online education for photographers and creatives worldwide.

Our services are delivered via platforms including:

  • Shopify (online store)

  • Kajabi (course delivery)

  • Squarespace (content pages)

For the purposes of UK GDPR, we are the Data Controller.


2. What Information We Collect

When you interact with our website or purchase from us, we may collect:

Personal Information

  • Name

  • Email address

  • Billing address

  • Business details (if provided)

  • Purchase history

  • Account login data (for course access)

Payment Information

Payments are processed securely via third-party processors (e.g., Stripe, PayPal, Shop Pay).
We do not store full credit card details.

Technical & Usage Data

  • IP address

  • Browser type

  • Device information

  • Website behaviour

  • Course login activity

  • Access timestamps

Marketing Data

  • Email subscription status

  • Engagement with marketing emails

  • Advertising interaction (Meta, Google)


3. How We Use Your Information

We process personal data for the following purposes:

  • To fulfil digital product orders

  • To provide access to online courses

  • To deliver customer support

  • To manage accounts and prevent unauthorised access

  • To analyse website and course usage

  • To run advertising and retargeting campaigns

  • To comply with legal, tax, and accounting obligations


4. Lawful Basis for Processing (UK & EU Users)

Under UK GDPR, we process your data under the following lawful bases:

  • Contractual necessity – to deliver purchased products and services

  • Legitimate interests – to improve our services and prevent fraud

  • Consent – for marketing communications

  • Legal obligation – for accounting and compliance

You may withdraw marketing consent at any time.


5. Marketing & Communication

If you subscribe to our email list or purchase from us, you may receive marketing communications.

You can unsubscribe at any time using the link in our emails.

We do not sell, rent, or trade your personal data.


6. Cookies & Analytics

We use cookies and tracking technologies including:

  • Google Analytics

  • Meta (Facebook/Instagram) Pixel

  • Shopify analytics

  • Kajabi analytics

These tools help us:

  • Measure website performance

  • Analyse ad effectiveness

  • Improve user experience

  • Retarget visitors

You may manage cookies via your browser settings.


7. Online Course Data (Kajabi)

When accessing our courses via Kajabi, we may collect:

  • Login activity

  • Course progress

  • Video engagement

  • IP address

  • Access timestamps

This data may be used for:

  • Platform functionality

  • Customer support

  • Preventing account sharing

  • Fraud and chargeback defence


8. Data Retention

We retain personal data only as long as necessary to:

  • Deliver services

  • Maintain accounting records

  • Resolve disputes

  • Comply with legal obligations

Purchase records may be retained for up to 6 years to comply with UK tax regulations.

Course access data may be retained for platform administration and fraud prevention.


9. Third-Party Services

We use third-party service providers who process data on our behalf, including:

  • Shopify (ecommerce)

  • Kajabi (course hosting)

  • Stripe / PayPal (payment processing)

  • Squarespace (content hosting)

  • Meta Ads

  • Google Analytics

  • Email marketing providers

Each provider processes data in accordance with its own privacy policy and relevant data protection laws.


10. International Transfers

Your information may be transferred and stored outside the UK or EU.

Where this occurs, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses

  • GDPR-compliant processing agreements


11. Your Data Rights (UK & EU)

If you are located in the UK or EU, you have the right to:

  • Access your personal data

  • Correct inaccurate data

  • Request deletion

  • Restrict processing

  • Object to processing

  • Withdraw consent

To exercise your rights, contact:
hello@zachandgrace.co


12. Data Security

We implement appropriate technical and organisational measures to protect personal data from:

  • Unauthorised access

  • Loss or misuse

  • Disclosure or alteration

However, no online transmission can be guaranteed to be completely secure.


13. Contact

If you have questions about this Privacy Policy or your personal data, contact:

Zach & Grace Ltd
Email: hello@zachandgrace.co
Website: zachandgrace.co/contact