Privacy Policy
1. Introduction
This Privacy Policy describes how Dmitrii Sharonov ("we," "us," or "our") collects, uses, discloses, and protects personal data when you visit our website at thezerofog.com (the "Site", which includes its subdomains such as platform.thezerofog.com, where the course itself is hosted), register for webinars, subscribe to our newsletter, purchase or use our digital products, or otherwise interact with our services (collectively, the "Services").
We are committed to protecting your privacy and processing your personal data in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the California Consumer Privacy Act ("CCPA") as amended by the California Privacy Rights Act ("CPRA"), the CAN-SPAM Act, and other applicable data protection laws.
2. Data Controller
For the purposes of GDPR, the data controller is:
Entity: Dmitrii Sharonov
Tax ID (NIF): Y9674448H
Registered as: autónomo in Spain
Address: Calle Floridablanca, 66-68, Local 9F, 08015 Barcelona, España
Email: privacy@thezerofog.com
Website: thezerofog.com
3. Data We Collect
3.1 Data You Provide Directly
- Email address - when you register for a webinar or subscribe to our newsletter through the Site
- Name - if you voluntarily provide it when registering for a workshop
- Name and email address - when you purchase the Course or create an account on Systeme.io
- Payment information - processed exclusively by Stripe, our payment processor; we do not receive or store your credit card number, bank details, or other payment credentials
- Toolkit data - if you use the Toolkit application at thezerofog.com/app/, we collect and store the data you enter there: Sleep Diary entries, Sleep Assessment answers and scores, your Protocol Card settings, and your Recovery tracker progress, linked to your account email. If you used the free Recovery tracker on this site before purchasing, the data saved on your device is imported into your account once, at your first sign-in, so you don't have to re-enter it
- Support communications - emails, messages, or other correspondence you send to us
- Refund request data - whatever you choose to share when you ask for a refund. Sharing anything at all is optional and never affects the outcome, and we never ask for your free-text diary notes
3.2 Data Collected Automatically
- Device and browser information - IP address, browser type and version, operating system, device type
- Usage data - pages visited, time on page, click patterns, referring URL, exit pages. Collected in part through PostHog analytics, which may also record session replays of how you interact with our pages (scrolling, clicks, mouse movement); text you type into forms is masked and not recorded. Whether PostHog is on by default or requires your prior consent depends on your region - see Section 9.2
- Cookies and similar technologies - see Section 9 (Cookie Policy) below
- Advertising data - data collected by advertising platforms (Meta Pixel, Google Ads) when you interact with our ads or visit our Site after clicking an ad
- Lead tracking identifiers - we may assign a unique identifier to track your journey through our marketing funnel (from webinar registration through purchase) for the purposes of analytics and service improvement. This identifier is linked to your email address and is not shared with third parties beyond those listed in Section 6.
3.3 Data from Third Parties
- Payment data from Stripe - transaction confirmation, purchase amount, payment status, and country of purchase. Stripe acts as an independent data controller for certain payment data it processes; see Stripe's Privacy Policy at https://stripe.com/privacy
- Advertising platforms - aggregated and anonymized campaign performance data from Meta and Google
4. How We Use Your Data
We use your personal data for the following purposes:
- To deliver the Services - register you for workshops (on our own site), process your purchase (via Stripe), provide Course access (via Systeme.io), and send workshop links and reminders (via MailerLite)
- To communicate with you - send transactional emails (purchase confirmations, access credentials), webinar-related emails, and newsletter content you opted in to receive, all delivered through MailerLite
- To process refunds - evaluate refund requests according to our Refund Policy
- To improve our Services - analyze usage patterns, optimize the Site and Course content, conduct A/B testing, and analyze funnel performance using lead tracking identifiers
- To run advertising - use cookies and pixels for ad targeting, retargeting, conversion tracking, and audience building on Meta and Google platforms
- To comply with legal obligations - tax reporting, fraud prevention, responding to lawful requests
- To protect our rights - enforce our Terms of Service, prevent unauthorized access, protect intellectual property
5. Legal Basis for Processing (GDPR)
Under GDPR, we process your personal data based on the following legal grounds:
- Contract performance (Art. 6(1)(b)) - processing necessary to deliver the webinar you registered for, the Course you purchased, provide account access, and communicate about your order
- Consent (Art. 6(1)(a)) - when you opt in to our newsletter or register for a webinar, you consent to receive email communications from us
- Legitimate interests (Art. 6(1)(f)) - website analytics, advertising (cookies and pixels), lead tracking, fraud prevention, service improvement, and direct marketing to existing customers (with opt-out)
- Legal obligation (Art. 6(1)(c)) - tax and financial reporting requirements
You may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
6. Data Sharing and Disclosure
We do not sell your personal data to third parties. We may share your data with the following service providers, each acting as a data processor (unless otherwise noted):
- Stripe (payment processor) - processes payments and issues receipts on our behalf. Stripe acts as an independent data controller for certain payment transaction data. Stripe's Privacy Policy: https://stripe.com/privacy
- Systeme.io - hosts and delivers the Course content, manages student accounts and course progress. Systeme.io Terms: https://systeme.io/terms-and-conditions
- MailerLite - manages our email marketing subscriber list and delivers email communications to our subscribers. MailerLite is a third-party provider which may process your data using industry standard technologies to help us monitor and improve our communications. MailerLite's Privacy Policy: https://www.mailerlite.com/legal/privacy-policy. You can unsubscribe from our emails by clicking the unsubscribe link provided at the end of each message.
- Supabase, Inc. - hosts the Toolkit application database (account profile, purchase status, Sleep Diary, Sleep Assessment, and Protocol Card data). Supabase Privacy Policy: https://supabase.com/privacy
- PostHog, Inc. - website and funnel analytics (page views, clicks, session replays with typed input masked), used to understand and improve how our pages work. Consent and opt-out rules are described in Section 9.2. PostHog Privacy Policy: https://posthog.com/privacy
- Crisp IM SAS - live chat support for customers, both in the course area and in the Toolkit application. When you use the chat, Crisp processes the messages you send, the name and email associated with your account, and technical data needed to run the chat widget. We use it solely to answer your support questions. The widget loads under the regional consent rules described in Section 9.2. Crisp Privacy Policy: https://crisp.chat/en/privacy/
- monday.com Ltd. - internal operations board where we record purchases, refunds and support notes so a paid order is never lost. It stores your name, email and the status of your purchase. monday.com Privacy Policy: https://monday.com/l/privacy/privacy-policy/
- Google Analytics - website analytics. Data is collected in aggregated form.
- Meta (Facebook) and Google Ads - advertising platforms for ad delivery and performance measurement via pixels/tags
- Legal authorities - when required by law, court order, or to protect our legal rights
All third-party service providers are contractually obligated to process your data only as necessary to provide their services and in compliance with applicable data protection laws.
7. International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States (where MailerLite, Supabase, PostHog, Meta, and Google operate) and Israel (where monday.com operates). When such transfers occur, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions by the European Commission
- EU-U.S. Data Privacy Framework certification (where applicable)
- Other legally recognized transfer mechanisms
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Account and Course data (on Systeme.io) - for the duration of your account plus 3 years, or as required by law
- Toolkit data (Sleep Diary, Sleep Assessment, Protocol Card) - for as long as your account is active. You can download all of it at any time from the app, with "Download my data" at the bottom of the Sleep Diary, and you can delete it yourself with "Delete my data", the button beside it. That button removes your app account, your Toolkit data, your workshop registration and your address from our mailing list, in one step. If you bought a course, two things are deliberately kept: your access to that course, because it is what you paid for, and the payment record, because tax law requires it. Write to privacy@thezerofog.com if you want your course access closed as well, or if you would rather we did the whole deletion for you
- Service discontinuation - if we ever discontinue the Services, we will give at least 60 days' notice by email, during which you can export your data; after that, remaining personal data is deleted except records we are required to keep by law (e.g., tax records)
- Email subscriber data (in MailerLite) - until you unsubscribe, plus up to 30 days for processing
- Transaction records (from Stripe) - as required by applicable tax and commercial law (typically 5-10 years in the EU)
- Operations board records (on monday.com) - the purchase, refund and support history of an order, kept for as long as we must keep the payment record itself under tax and commercial law. Support notes that are no longer needed to resolve an order are deleted earlier
- Refund documentation - deleted once the refund is resolved. We do not keep diary entries, screenshots, or notes shared during a refund; only the fact and date of the refund remain, in the payment record
- Lead tracking data - for the duration of your engagement with the funnel plus 12 months
- Analytics data - in aggregated/anonymized form, retained indefinitely
- Advertising audience data - managed by Meta and Google per their respective policies
9. Cookie Policy
9.1 What Are Cookies
Cookies are small text files placed on your device when you visit a website. They help the site function, improve user experience, and provide information to website operators.
9.2 Cookies We Use
Strictly Necessary Cookies - Essential for the Site to function. These include session cookies, security cookies, and load-balancing cookies. They cannot be disabled.
Analytics Cookies - We use PostHog and Google Analytics to understand how visitors interact with the Site, including the number of visitors, pages visited, traffic sources, and click patterns. PostHog may also record session replays of page interactions; text you type into forms is masked and not recorded.
Functional Cookies (Support Chat) - The customer course area and the Toolkit application use Crisp live chat. Crisp sets cookies needed to keep your chat session and conversation history working. The chat widget follows the same regional consent rules as analytics cookies.
Regional consent rules - If you are visiting from the European Union, EEA, United Kingdom, or Switzerland, analytics and advertising cookies load only after you give consent via our cookie banner ("Accept All"). For visitors from other regions, including the United States, these cookies are active by default and you can opt out at any time - with one click via "Opt out" in the cookie banner, via the "Cookie Settings" link in the footer, or as described in Section 11 (Do Not Sell or Share My Personal Information).
Marketing / Advertising Cookies - We use cookies from Meta (Facebook Pixel) and Google (Google Ads Tag) to deliver targeted ads, measure ad performance, and build retargeting audiences. These cookies may track your activity across other websites.
9.3 Managing Cookies
You can decline or switch off all analytics and advertising cookies with one click - "Essential Only" or "Opt out" in our cookie banner, or the "Cookie Settings" link in the footer at any time. You can also control and delete cookies through your browser settings. Most browsers allow you to refuse cookies or alert you when a cookie is being sent. Note that disabling certain cookies may affect the functionality of the Site.
To opt out of Google Analytics, install the Google Analytics Opt-Out Browser Add-on. To manage ad personalization preferences, visit Facebook's Ad Preferences (https://www.facebook.com/adpreferences) and Google's Ad Settings (https://adssettings.google.com).
For more information about cookies in general, visit www.allaboutcookies.org.
10. Your Rights
10.1 Rights Under GDPR (EEA Residents)
If you are a resident of the European Economic Area, you have the right to:
- Access - request a copy of the personal data we hold about you
- Rectification - request correction of inaccurate or incomplete data
- Erasure - request deletion of your data ("right to be forgotten")
- Restriction - request restriction of processing in certain circumstances
- Data portability - receive your data in a structured, commonly used, machine-readable format
- Object - object to processing based on legitimate interests, including direct marketing
- Withdraw consent - withdraw previously given consent at any time
To exercise any of these rights, contact us at privacy@thezerofog.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
10.2 Rights Under CCPA/CPRA (California Residents)
If you are a California resident, you have the following rights under the CCPA/CPRA:
- Right to know - request disclosure of the categories and specific pieces of personal information we have collected
- Right to delete - request deletion of personal information we have collected
- Right to correct - request correction of inaccurate personal information
- Right to opt out of sale/sharing - see Section 11 below
- Right to non-discrimination - we will not discriminate against you for exercising your CCPA rights
We do not knowingly sell or share the personal information of consumers under 16 years of age.
11. Do Not Sell or Share My Personal Information
We do not sell your personal information in exchange for monetary consideration.
However, under the CCPA/CPRA, the use of advertising cookies and pixels (such as the Meta Pixel and Google Ads Tag) may constitute "sharing" of personal information with third-party advertising platforms for the purpose of cross-context behavioral advertising.
You have the right to opt out of this sharing. To exercise this right, you may:
- Disable advertising/marketing cookies through your browser settings
- Use the opt-out tools provided by each advertising platform (Facebook Ad Preferences, Google Ad Settings)
- Send an opt-out request to privacy@thezerofog.com with the subject line "Do Not Sell or Share My Data"
Upon receiving a verified opt-out request, we will cease sharing your personal information with advertising platforms within 15 business days.
12. Children's Privacy
The Services are not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a person under 18, we will take steps to delete such data promptly.
13. Email Communications and CAN-SPAM Compliance
When you provide your email through our webinar registration or newsletter opt-in, you consent to receive email communications from us via MailerLite. All marketing emails include a clear unsubscribe mechanism. We honor unsubscribe requests within 10 business days, as required by the CAN-SPAM Act. Transactional emails (purchase confirmations, access credentials, refund communications) may still be sent as necessary for service delivery.
14. Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These include encrypted data transmission (TLS/SSL), secure hosting infrastructure, limited access controls, and regular security reviews. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
Access to your individual Toolkit entries (such as your Sleep Diary and Sleep Assessment) is limited to what is necessary to operate and support the Service. We do not review your individual entries except where you ask us to - for example, to help with a support request, or if you choose to share your entries with us when asking for a refund - or where necessary for security, fraud prevention, or legal compliance, or with your consent. Aggregated or anonymized analytics that do not identify your individual entries may be used to improve the Service.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will post the revised policy on the Site with an updated "Last Updated" date. We encourage you to review this policy periodically. Your continued use of the Services after changes are posted constitutes your acceptance of the updated policy.
16. Contact Us
For questions, requests, or complaints regarding this Privacy Policy or the processing of your personal data, please contact:
Entity: Dmitrii Sharonov
Tax ID (NIF): Y9674448H
Registered as: autónomo in Spain
Address: Calle Floridablanca, 66-68, Local 9F, 08015 Barcelona, España
Email: privacy@thezerofog.com
Website: thezerofog.com
For EU data protection inquiries, you may also contact your local supervisory authority. For Spain: Agencia Española de Protección de Datos (AEPD), https://www.aepd.es.