Privacy Policy
of the autonomous store "Zero Shop" and the mobile application "Zero Shop App"
Effective as of 10 October 2026
This English version is a translation provided for convenience. In the event of any discrepancy, the Bulgarian version prevails.
This Privacy Policy (the "Policy") constitutes an information document in accordance with the requirements of the General Data Protection Regulation (the "GDPR") and contains detailed information about the manner in which Your personal data are processed when You visit and use the autonomous store "Zero Shop" (the "Store" or the "Stores") and the mobile application "Zero Shop App" (the "App").
This Policy forms an integral part of the Terms and Conditions for the use of the autonomous store "Zero Shop" and the mobile application "Zero Shop App" (the "Terms") of ZERO SHOP OOD – the owner and operator of the autonomous stores operating under the trade name "Zero Shop" and of the mobile application "Zero Shop App", and applies on an equal footing with those Terms. All terms used in this Policy have the meaning given to them in the Terms and, where no such meaning is given, the meaning given to them in the GDPR and the applicable European and national legislation, including the legislation on the protection of personal data ("Applicable Law").
The Policy may be updated from time to time and as necessary, and You will be notified of this in a timely manner.
I. Controller of personal data
The controller of personal data under this Policy is ZERO SHOP OOD, UIC 203681730, with its registered office and address of management at: 49A Bulgaria Blvd., floor 1, commercial unit 7, Triaditsa district, Sofia, Bulgaria (the "Company", "We"). You can contact Us at this address, through the ZeroShop contact form or by e-mail at: tech@zeroshop.bg.
II. To whom does this Policy apply?
This Policy is intended for and applies to the following data subjects ("Data Subjects" or "You"):
- natural persons – Users of the App and of the Store, as well as Companions of a User;
- natural persons – Legal Entity Representatives;
- persons whose data have been provided to Us in connection with the use of the App and of the Store, including in breach of the Terms and/or this Policy.
III. What data do We collect and for what purpose?
Registration and use of the services are at Your option. The telephone number, the e-mail address and the data necessary for registering a payment instrument and for processing purchases are necessary for the respective services. Mandatory fields are marked in the App. The first name and surname are entered at Your discretion. Age verification via Didit is necessary only if You wish to access the alcohol cabinet; You can register and shop for the other Goods without it.
The personal data that We collect and process may include:
1. Information that You provide when creating and personalising Your Account
When an Account is registered, We process Your active telephone number, a valid e-mail address and the data necessary for authenticating access to the Account. The telephone number is confirmed by means of a one-time code sent via Twilio Verify. The e-mail address is mandatory as a second channel of communication and is used for messages concerning the Account and for password recovery. Confirmation of the e-mail address is not required in order to complete the registration. The first name and surname are processed if You have entered them. For bank cards, We process the tokens received from the Payment Provider and the information under Section V.
When completing the profile, You may provide details of a legal entity for the issuance of an invoice, contact details and other information that You enter through the available functionalities. We also process the selection of an active bank card and Your communication preferences. During the pilot phase, there is no active loyalty programme, and there are no subscription services or individual prices and personalised promotions.
If You choose age verification, Didit processes data from Your identity document, images of the document and of Your face, and data from the matching check and the liveness check. In ZeroShop's own platform, We retain from the KYC check the date of birth and sex, which We use for the age check. The documents and images from the check may be stored in Didit and may be accessible to authorised employees of the Company through Our business account. This processing is described in item 7 below and in Section VII.
We carry out the processing of the above categories of data for the following purposes:
- Creating, maintaining and personalising a user Account in the App; identifying the User; storing and managing the information, settings and preferences provided by the User.
- Providing access to the Store and the possibility of using the services offered; linking visits, purchases and other actions in the Store to a specific user Account; correctly recording and charging for the goods purchased.
- Enabling the registration and management of a payment instrument, as well as the processing of payments, refunds and other operations related to purchases made.
- Communicating with Users in connection with the use of the App and the Store; sending notifications, as well as information about the Account, purchases and the services provided, in accordance with the selected preferences.
- Carrying out age verification for the purchase of Restricted Goods; preventing abuse and ensuring the security of the App and the Store; complying with the applicable legal and regulatory requirements.
2. Information related to visiting and/or shopping in the Store
Upon a visit to the Store, We process the Account and Session identifiers, the time of entry and exit, access by means of a QR code and information about the Companions within the Session. Information about the movement of visitors and their interactions with the Goods, which is necessary for distinguishing between the individual Sessions and for compiling the basket, is processed by means of Trigo's technology.
We process the actions involving the Goods, the recorded pick-ups and returns, the contents of the final basket and the list of Goods to be charged. When a beverage is successfully prepared by the coffee machine, the type of beverage and the time of its preparation are processed so that it can be linked to the relevant Session. We also process events related to violations, incidents and complaints.
We process information about the pre-authorisation hold and the release of the deposit, payment transactions, amounts due, successful and unsuccessful payments and repeated charging attempts. In the event of an unpaid purchase, data are processed concerning the notification of the User, the restriction of subsequent entry and the subsequent settlement of the obligation through the App. We process the information contained in receipts and invoices. The sale is processed through Barsy, and the electronic receipt is provided in the App.
Finally, We may also process information related to the use of the panic button, including the time of activation, the reason for its use, the consequences of the activation and the measures taken in connection with it.
We carry out the processing of the above categories of data for the following purposes:
- Providing access to the Store and managing user Sessions; tracking entries into and exits from the Store, the method of access and the use of the services within a specific Session.
- Identifying the Goods selected and purchased; compiling the user's basket; determining the Goods to be charged and completing the purchase.
- Enabling the processing and administration of payments; issuing receipts and invoices; taking action in the event of an unsuccessful payment, including collecting amounts due and temporarily restricting access to the Store where there are outstanding obligations.
- Ensuring the security of the Store, its visitors and the services offered; detecting, investigating and preventing abuse and breaches of the Terms or of Applicable Law; handling reports and incidents, including in the event of use of the panic button, and taking the necessary follow-up action.
3. Data related to video surveillance
CCTV video surveillance is carried out in the Store and in its immediate vicinity for the security of visitors and property, the prevention and investigation of incidents and abuse, and the handling of complaints. Images of the persons who fall within the range of the cameras, their actions, and the place and time of recording are processed. There is an information sign at the entrance. The CCTV cameras are separate from the AI cameras for autonomous shopping. Recordings from the AI cameras are not stored. CCTV recordings are kept for up to 60 days, unless a specific recording is needed for the investigation of an incident, a complaint or a legal claim, in accordance with Section VII.
4. Information and data related to complaints
In connection with the right of Users who qualify as consumers within the meaning of the Consumer Protection Act to file complaints, We may process the following types of data: the subject matter of the complaint, the consumer's specific request (repair, replacement, price reduction, termination of the contract, refund), identification of the Session/purchase (date, time, Store) and contact details, evidence.
We carry out this processing for the purposes of accepting, examining and resolving complaints, as well as for compliance with the applicable legal requirements relating to consumer protection and the right to file complaints.
5. Information related to the use of the App
5.1. Information related to the use of the App's functionalities by Users
During the pilot phase, We process the data necessary for managing the profile and the cards, access by means of a QR code, the purchase history, receipts, invoice requests, and reports and complaints. The planned shopping list will contain the items that the User adds. When this functionality is introduced, the processing related to it will be described before it is used.
5.2. System information generated or collected automatically when using the App
In connection with the use of the App, We process the following system information, which is generated or collected automatically:
- Logs of the time, IP address and content of the actions relating to registration, acceptance of the Terms, acknowledgement of the Privacy Policy, giving or withdrawing consent to age verification or to marketing communications, and other electronic statements in the App. We process this information in order to prove the actions performed and to comply with the applicable legal obligations.
- Logs and other information for ensuring the security and reliable use of the App: Account login logs, server logs and security protection logs, data on Your behaviour/use of the App, for the purpose of detecting and resolving technical problems with the App, as well as for ensuring the security of the App and protecting it against denial-of-service attacks (DDoS attacks) and other malicious actions.
- Information about the IP address, basic technical data about the device and the operating system, Account and Session identifiers, and tokens for delivering push notifications. These data are necessary for the functioning of the App, the authentication of access, security and the delivery of notifications.
- The App uses local storage and similar technologies necessary for authenticating access, maintaining the user session and saving settings. Firebase Cloud Messaging is used to deliver push notifications. Permission to display push notifications is managed through the phone's operating system. Where optional analytical or other technologies for which the law requires consent are used, such consent is requested separately before the relevant processing.
We carry out the processing of the above categories of data for the following purposes:
- Providing and managing the available functionalities: profile, bank cards and active card, QR access, purchase history, electronic receipts, invoice requests, reports and complaints.
- Maintaining user settings and communication preferences. When new functionalities requiring the processing of additional personal data are introduced, the Policy is updated and Users are notified in advance.
- Maintaining evidence of electronic statements made and complying with the legal obligations to retain the relevant logs.
- Ensuring the normal functioning, security and reliability of the App; preventing, detecting and remedying technical problems, abuse and malicious actions.
- Analysing and improving the quality, security and user experience in the use of the App, including through the use of cookies or similar technologies.
6. Information contained in communication with Us by e-mail, telephone or through the App
When You contact Us for any reason, including in order to submit enquiries, reports, grievances, complaints or other requests to Us, to inform Us of an irregularity, to ask a question, to give Us feedback, to answer questions in user surveys or to seek assistance from Us, We will process Your identification data and contact details – first name and surname, electronic mail address (e-mail), telephone number, as well as the unstructured information that You provide to Us in the course of communication with Us.
We carry out this processing for the purpose of establishing and maintaining communication with You, examining and responding to enquiries, reports, grievances, complaints and other requests, as well as for the purpose of improving the quality of service and processing feedback provided by Users.
7. Age verification and Biometric Data
The check via Didit is at Your option and is carried out once, upon registration or at a later stage, if You request access to the alcohol cabinet. On subsequent visits, ZeroShop uses the stored date of birth to establish whether You have reached the age of 18, without a new KYC check for the same User.
Didit carries out the verification of the document, a comparison of the facial image with the photograph in the document and a liveness check. The data processed may include the data extracted from the document, the images of the document and of the face, Biometric Data and the results of the checks. In ZeroShop's own system, the date of birth and sex are retained from the KYC data. The other data may remain stored and accessible in Didit in accordance with the settings of the procedure. Authorised employees of the Company may have access to them through the platform where a check is necessary.
Before the procedure begins, You are provided with information about the processing, and separate explicit consent is required for the Biometric Data. The mere acceptance of the Terms or acknowledgement of this Policy does not replace that consent. The check is automated; You may request a review of the result via the contact details in Section I. You may withdraw Your consent at any time, without this affecting the lawfulness of the processing before the withdrawal. After withdrawal, access to the alcohol cabinet is not granted, but You may shop for the other Goods.
The Company has disabled the possibility for Didit to use the verification data for training or improving models.
8. Marketing communications
Subject to separately given consent, We may send marketing communications and information about general promotions by push notifications or by e-mail. For this purpose, the e-mail address or the push notification token and data on the consent given and the channels selected are processed. During the pilot phase, there are no individual prices or personalised promotions.
Disabling push notifications through the phone's settings does not constitute consent to marketing e-mails. Such e-mails are sent only if You have given consent for this channel. You may opt out using the unsubscribe mechanism in the message or via the contact details in Section I. Service messages concerning registration, security, purchases, payments and obligations are processed separately on the relevant legal basis.
IV. On what grounds do We process Your personal data?
We process personal data for the performance of the contract under the Terms or in order to take steps at Your request prior to entering into it — Article 6(1)(b) of the GDPR. This includes creating and maintaining an Account, authenticating access, entry into the Store, managing Sessions, recording purchases, payments and the related communication. Without the necessary data, We cannot provide the relevant service. This basis relates to the applicable categories under Section III, items 1, 2 and 4–6.
We also process Your personal data on the basis of compliance with legal obligations which apply to Us (pursuant to Article 6(1)(c) of the GDPR). We carry out the processing of personal data in this context in order to be able to fulfil Our legal obligations relating to:
- the issuance, retention and provision of accounting documents, receipts, invoices and other documentation in accordance with tax and accounting legislation;
- the keeping and retention of information on payments, sales and commercial transactions carried out;
- age checks and the prevention of the sale of alcohol, energy drinks or other age-restricted goods to persons who do not meet the legal requirements;
- the examination and documentation of complaints, the exercise of consumer rights and compliance with the requirements of consumer protection legislation;
- the retention of electronic statements, logs and other records;
- the provision of information to competent state authorities, courts, law enforcement authorities or regulatory authorities in the cases provided for by law;
- the retention of documents and information for the statutory periods under tax, accounting, consumer and other Applicable Law.
On this basis, We process the data under Section III that are necessary for the relevant legal obligation. A legal necessity to check age does not replace the separate explicit consent to the processing of Biometric Data.
In addition, We also process data relating to You on the basis of the pursuit of Our legitimate interests or of the legitimate interests of third parties (pursuant to Article 6(1)(f) of the GDPR), for which the processing of Your personal data may be necessary. Such legitimate interests arise for Us or for third parties in connection with the need to:
- ensure the security of the systems, the App and the Store, including preventing, detecting and investigating abuse, unauthorised access and malicious actions;
- prevent and detect fraud, malicious actions or unlawful use of services;
- manage and protect Our commercial activity, including protecting property, goods, digital assets and infrastructure;
- improve the technical reliability, security and quality of the services through the necessary analysis of the operation of the systems;
- ensure effective communication with Users, including handling enquiries, reports and feedback, and sending notifications, system messages and information related to the provision and management of the services;
- establish, exercise and defend legal claims, including collecting unpaid obligations for purchases;
- carry out internal control and audit and ensure the quality of the services and processes;
- protect the rights and lawful interests of third parties, including other Users, partners and merchants.
On the basis of legitimate interest, We process only the necessary data, following an assessment of the interests and the fundamental rights and freedoms of the persons concerned. This basis also applies to the CCTV video surveillance under Section III, item 3.
On the basis of consent — Article 6(1)(a) of the GDPR — We process data for marketing communications and other optional activities for which You have made a separate choice. For Biometric Data in age verification, explicit consent under Article 9(2)(a) of the GDPR is also required. Consent to one purpose or channel does not constitute consent to all the others. You may withdraw it at any time.
V. With whom do We share personal data?
We may exchange personal data relating to You with third parties in the following cases:
Trigo Vision Ltd. (Trigo) is the technology partner for autonomous shopping. For this service, Session identifiers and data on movement and interactions with the Goods are processed, which enable the final basket to be compiled. The technology does not use facial recognition to establish the identity of visitors. ZeroShop links the relevant Session and purchase to the User's Account; therefore, the linked data are treated as personal data, regardless of the use of technical identifiers. Recordings from the AI cameras are not stored.
For the processing of card payments, We use DSK Bank AD, UIC 121830616 (the "Payment Provider"). The data necessary for the registration and use of the bank card, pre-authorisations, charging and refunds are transmitted to it. The bank also processes the data in order to fulfil its own legal obligations in accordance with the applicable privacy policy.
The full bank card data are processed by the Payment Provider. ZeroShop does not store the full card number or its security code. We process the tokens that enable the use of the registered card, as well as payment transaction identifiers, amounts, dates, statuses and payment results, which are necessary for purchases, refunds and the settlement of obligations.
The Payment Provider applies the security requirements for card payments and may act as an independent controller for the payment services it performs and its legal obligations. The exchange of data is limited to what is necessary for the relevant transaction.
We may entrust the processing of personal data to providers of IT support, cloud infrastructure, communication, accounting and other support services. Where they act as processors on Our behalf, they process the data for the service entrusted to them in accordance with the applicable contractual terms and the requirements of the GDPR. Access by employees and providers is restricted according to business need. Organisational and technical measures are applied to protect the data against unauthorised access, loss, alteration and disclosure.
The services used include Didit for the one-time age verification; Twilio Verify for the one-time codes for confirming the telephone number; Google/Firebase, including Firebase Cloud Messaging, for cloud services and push notifications; and DigitalOcean for cloud infrastructure. The data processed by each service depend on the function assigned to it. Barsy is used for sales, receipts and invoices. Didit processes the age verification data on Our behalf; the details are set out in Section III, item 7 and Section VII.
We may provide the necessary data to competent state and judicial authorities where required by law, as well as to lawyers, notaries and debt collection agencies in the establishment, exercise or defence of legal claims. In the collection of an unpaid purchase, this may include the identification data and contact details provided, information about the specific purchase, the amount due, the payment results and the communication conducted. The data are provided only to the extent necessary and where there is an applicable legal basis.
VI. Transfer to countries outside the EU/EEA
When technology, communication and cloud services are used, data may be processed or accessed outside the EU/EEA depending on the location and organisation of the relevant provider. This also applies to providers or their subcontractors established outside the EU/EEA, including in Israel and the USA. Trigo is established in Israel.
The transfer is carried out where an applicable mechanism under Chapter V of the GDPR is in place — a decision of the European Commission on an adequate level of protection, within its scope, or appropriate safeguards, including standard contractual clauses and, where necessary, supplementary measures. You may request information about the applicable safeguards and a copy of them via the contact details in Section I. The information is provided subject to the protection of the rights of third parties and of confidential contractual data.
VII. Retention periods
When processing Your personal data, We strive to retain them for no longer than is necessary to fulfil the purposes for which We process them. In this regard, and in view of the periods introduced by Applicable Law, We have determined the following data retention periods:
- Account data and user settings — for as long as the Account is maintained. After its deletion, only the data necessary for legal obligations, for proving actions performed or for legal claims are retained, for up to 5 years, unless the law requires a different period for a particular document. This does not mean that all optional profile data are retained for that period.
- Date of birth, sex and information about the age verification performed, used in ZeroShop — for as long as the Account and the authorised access to the alcohol cabinet are maintained. After their termination, only the information necessary to prove consent or for defence in respect of a specific claim is retained within the applicable period, up to 5 years. The primary KYC data in Didit, including the images of the document and of the face and the related results, are stored for 30 days from the performance of the check, after which they are deleted automatically. Their deletion from Didit is carried out separately from the deletion of the data in ZeroShop.
- Necessary data on Sessions, purchases, final baskets and the settlement of obligations — up to 5 years from the relevant Session, for proving the purchases made and for the defence of legal claims. This period does not apply to video recordings from the AI cameras, which are not stored.
- Accounting documents and information to which the statutory retention period applies — 10 years, starting from the beginning of the year following the relevant reporting period. Other payment information is retained for the necessary period according to its purpose and the applicable legal obligations.
- CCTV video recordings — up to 60 days from their creation. A specific recording needed for an incident, complaint, dispute or request by a competent authority may be retained until the completion of the relevant investigation or proceedings and the lapse of the grounds for its retention.
- Logs of electronic statements – for the period of validity of the act for which the electronic statement was made and up to 5 (five) years after its termination.
- Other system logs – up to 1 (one) year.
- IP address and data about Your device and other system data collected in connection with the security of the App: for the duration of Your Session or for the technical time necessary to perform the relevant functionality.
- Data for marketing communications — until consent is withdrawn or an objection to direct marketing is made. The necessary record of consent given and withdrawn is kept in accordance with the rule for electronic statements. Minimal data on an opt-out from communications may be retained so that the opt-out is respected.
- Data from local storage, authentication and similar technologies — for the time necessary for the relevant function, the active user session or the use of the Account. Optional data are deleted or anonymised when the purpose of or the basis for their processing ceases to exist.
We may also retain data for longer than the periods specified above in the event of a legal dispute or a request from a competent state authority requiring the retention of the data, as well as in the event of changes in Applicable Law requiring such longer retention.
VIII. What rights do You have in relation to the processing of Your personal data?
1. Right to be informed
This Policy is intended to inform You in detail about the processing of Your personal data in the context of access to and use of the Store and the App.
2. Right of access
You have the right to obtain confirmation as to whether Your personal data are being processed, and access to those data and to information about their processing and Your rights in that regard.
3. Right to rectification
You have the right to the rectification of Your personal data where they are incomplete or inaccurate. In this regard, You may independently correct/supplement Your personal data through the functionalities of Your Account.
4. Right to erasure
You have the right to request the erasure of Your personal data under the conditions of the GDPR. You may submit a request for deletion of an Account through the ZeroShop contact form, including the form accessible through the App, or via the contact details in Section I. Where there are data that must be retained for a legal obligation or for the establishment, exercise or defence of a legal claim, only the data necessary for that purpose are retained, and the basis and the applicable period are stated. An unpaid obligation does not cancel Your other rights under the GDPR. Requests relating to the KYC data in Didit are also addressed to the Company as controller.
5. Right to restriction of data processing
You have the right to request the restriction of the processing of Your personal data if the grounds for this are present.
6. Right to have third parties notified
Where applicable, You have the right to request that We notify the third parties to whom We have provided Your personal data of any rectification, erasure or restriction of the processing of Your personal data, unless this proves impossible or requires disproportionate effort on Our part.
7. Right to data portability
You have the right, under certain conditions, to receive Your personal data in a structured, commonly used and machine-readable format. Where technically feasible, You have the right to have Your personal data transmitted directly from Us to another controller.
8. Right not to be subject to a decision based solely on automated processing
Your personal data under this Policy will not be used for decisions based solely on automated processing, including profiling, which produce legal effects concerning You or similarly significantly affect You, unless the grounds for this provided for in Applicable Law are present and appropriate safeguards for the protection of Your rights, freedoms and legitimate interests are in place.
For the avoidance of doubt, automated technological means are used in the course of service in the Store to track Users' interactions with the Goods and to compile the list of Goods to be charged. These processes are based on information about the User's actions in the Store and are used solely for the purposes of completing the purchase and correctly determining the price payable for the selected Goods.
In the event of a dispute concerning an automatically recorded purchase, You may file a complaint through the App or contact Us for a check by an employee and a correction, where applicable. In the same way, You may request a review of, and contest, a result of the age verification or a restriction of access. The exercise of these rights does not guarantee a positive outcome of the check or authorised access to Restricted Goods.
9. Right to withdraw consent
You have the right to withdraw Your consent to the processing of Your personal data at any time where such processing is carried out on the basis of consent. Such withdrawal does not affect the lawfulness of the processing carried out before the consent was withdrawn.
10. Right to object
You have the right to object to processing based on legitimate interest on grounds relating to Your particular situation. You may object to processing for direct marketing purposes at any time, without giving reasons; following the objection, Your data will not be used for that purpose.
11. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a supervisory authority if You consider that the processing of Your personal data infringes the Applicable Law on the protection of personal data. The supervisory authority in the Republic of Bulgaria is the Commission for Personal Data Protection, address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, e-mail address: kzld@cpdp.bg, website: www.cpdp.bg.
You may exercise Your rights through the ZeroShop contact form or via the contact details in Section I. Where necessary, We may request additional information to confirm Your identity, limited to what is necessary for the request. We respond without undue delay and within one month of receipt of the request. In the event of complexity or a large number of requests, the period may be extended by a further two months, in which case We will notify You of the extension and the reasons for it within the first month.
This Privacy Policy is in force as of 10 October 2026.