Privacy policy

ZWIM Privacy Policy

Last updated: 8 June 2026
Effective date: 8 June 2026

This Privacy Policy explains how we collect, use, store, and share your personal data when you use the ZWIM website (zwim.com) or the ZWIM mobile app (iOS and Android). It also explains your rights and how to exercise them.

We have tried to write this in plain language. If anything is unclear, email us at privacy@zwim.com.

1. Who we are

ZWIM is a brand operated jointly by:

ZEN8 Sports Ltd
Company number: 12662386
7 Bell Yard, London WC2A 2JR, United Kingdom
UK VAT: GB 370 1354 26

ZEN8 Sports Portugal Lda
NIF: 518 164 330
Rua Professor Sousa da Câmara 207, 3E
1070-216 Lisboa, Portugal

Both entities are joint controllers under Article 26 of the UK and EU GDPR. This means we share responsibility for how your personal data is handled. Either entity can be your point of contact — the easiest way to reach us on any privacy matter is privacy@zwim.com.

2. Who this policy applies to

This policy applies to:

  • Anyone who visits or uses the ZWIM website (zwim.com), including the online shop
  • Anyone who creates a ZWIM account
  • Anyone who uses the ZWIM mobile app on iOS or Android
  • Anyone who connects ZWIM Smart Paddles or other devices to the app

You must be 18 years of age or older to use ZWIM products and services. We do not knowingly collect personal data from anyone under 18. If you believe we have done so inadvertently, please contact privacy@zwim.com and we will delete it promptly.

3. What data we collect

3.1 Data you give us directly

Account and waitlist. When you create a ZWIM account or join the waitlist, we collect your name, email address, country, and a hashed (encrypted) password. We may also collect referral information if you were referred by another user.

Profile information (optional). You can choose to add profile information such as your age, gender, height, weight, swimming ability, and training goals. This helps us tailor your experience. This information is optional — you can use ZWIM without providing it.

Order and payment data. When you place an order, we collect your delivery address, billing address, the items you purchased, the amount paid, the currency, and payment method details. We do not store full card numbers — payments are processed by our payment providers (see Section 6).

Communications. If you contact us, complete a survey, or take part in a research interview, we collect the content of your communications and any other information you choose to share.

3.2 Training and performance data (ZWIM app)

When you use the ZWIM app with Smart Paddles, we collect performance data generated by the paddles during your sessions, including:

  • Propulsive Watts
  • Stroke rate and stroke count
  • Left and right balance
  • Efficiency and wasted energy measurements
  • Session duration and pace
  • Calibration data

This is performance data, not health data. It tells us how effectively you are moving through your training — it does not tell us about your physical health or medical condition.

3.3 Third-party device data (ZWIM app)

If you connect a third-party heart rate monitor (such as a Garmin, Polar, or Wahoo device) to the ZWIM app via Bluetooth, we receive your heart rate data from that device and display it within the app during your session.

Heart rate data is health data under UK and EU law (special category data under Article 9 GDPR). We only receive and display this data with your explicit consent, which you give when you connect your heart rate monitor for the first time. We act as a conduit — the data originates from your third-party device and its manufacturer, not from ZWIM. We do not share your heart rate data with third parties for marketing purposes and do not use it to make automated decisions about you.

You can revoke consent at any time by disconnecting your heart rate monitor in the app settings. If you do, we will stop receiving and displaying that data.

3.4 Device and connectivity data (ZWIM app)

When you pair Smart Paddles or other Bluetooth devices with the ZWIM app, we collect:

  • Device identifier and pairing information
  • Firmware version
  • Calibration data
  • Connection logs

This data is used to ensure your paddles function correctly and to push firmware updates.

3.5 App permissions

Location (Android only). Android requires apps to have location permission enabled in order to scan for and discover Bluetooth devices nearby. We request this permission solely to allow the app to find and connect to your Smart Paddles. We do not collect, record, or use your geographic location for any other purpose — we do not know where you are, and we do not track your movements. If the purpose of this permission changes in the future, we will update this policy and ask for your consent again.

Bluetooth (iOS and Android). We use Bluetooth to connect to your Smart Paddles and any third-party heart rate monitors you choose to pair. This is core app functionality — without it, the paddles cannot connect.

Notifications (iOS and Android). We request permission to send you push notifications, such as session reminders and firmware update alerts. This is optional — you can decline at the OS prompt or change your preference at any time in your device settings.

3.6 Technical and usage data

When you use the website or app, we automatically collect certain technical information, including:

  • IP address
  • Browser type and version
  • Device model and operating system
  • App version and language
  • Timezone
  • Pages or screens visited, features used, and session frequency
  • Crash reports and diagnostic logs

This information helps us keep the service running, identify and fix problems, and improve the product.

3.7 Leaderboard and social features (ZWIM app)

The ZWIM leaderboard and social features are off by default. If you choose to enable them, your training performance data (such as Propulsive Watts rankings) may be visible to other users. You can turn this off at any time in your app settings and your data will be removed from public views.

3.8 Data from third-party sources

We may receive information about you from affiliates, social media platforms (for example if you sign up using a social login), and service providers. We handle this data in accordance with this policy.

3.9 Legacy ZEN8 customers

ZWIM is the successor brand to ZEN8. If you previously purchased from zen8swimtrainer.com or interacted with the ZEN8 brand before 2026, you are dealing with the same company — ZEN8 Sports Ltd — now trading as ZWIM. We are not transferring your data to a different company; we are continuing to hold it under the same controller and using it to support you under our new brand.

For legacy customers, we may continue to hold:

  • contact details (name, email)
  • purchase history (orders, items, fulfilment)
  • support history

We use this data to:

  • continue to support you on your existing ZEN8 hardware
  • verify your eligibility for loyalty upgrades and Founder offers
  • migrate your account to ZWIM if you choose to opt in

Marketing to legacy customers. Where the law allows it, we may send you product news about ZWIM as the successor product line, relying on our existing customer relationship ("soft opt-in" under PECR in the UK and equivalent rules in the EU) and on legitimate interests. Every email contains an unsubscribe link, and you can opt out at any time by clicking it or by emailing privacy@zwim.com. Once you opt out, we will stop sending marketing.

4. Why we use your data and our legal basis

Data Purpose Lawful basis
Account data Create and manage your account; verify your identity Performance of contract
Optional profile data Personalise your experience and recommendations Consent
Order data Fulfil your purchase; process payment; arrange delivery Performance of contract
Tax and financial records Meet legal accounting and tax obligations Legal obligation
Training performance data Deliver session summaries; power the in-app game; improve algorithms Performance of contract; Legitimate interests
Heart rate data (external HRM) Display heart rate in the app during your session Explicit consent (Art. 9 GDPR)
BLE device data Pair paddles; deliver firmware updates; diagnose connectivity issues Performance of contract; Legitimate interests
Location (Android, BLE discovery) Enable Bluetooth device discovery on Android Consent
Notifications Send session reminders and firmware alerts Consent
Technical and usage data Security; fraud prevention; product improvement; diagnostics Legitimate interests
Marketing communications Send news, offers, and updates (where you have opted in) Consent
Support communications Resolve your query Legitimate interests
Survey and research data Improve products and services Consent
Cookie consent preferences Record and apply your cookie choices Legal obligation (ePrivacy / UK PECR)
Advertising measurement Measure campaign conversions and support remarketing Consent
Legacy ZEN8 customers Where permitted by law, soft opt-in basis for marketing to existing customers who have not opted out Legitimate interests (where applicable law permits)

Legitimate interests: Where we rely on legitimate interests, we have weighed those interests against your rights. You can object to processing based on legitimate interests at any time — see Section 9.

5. How long we keep your data

Data type Retention period
Waitlist data Until you unsubscribe, or 24 months of inactivity
Account and training data While your account is active. After 24 months of inactivity we will contact you — if we hear nothing, we begin deletion
Order and financial records 6 years (UK legal requirement) or 10 years (Portugal legal requirement) — whichever applies to the transaction
Marketing consent records For the duration of your consent plus a reasonable period after withdrawal, to demonstrate compliance
Cookie consent records 12 months from the date of consent
Support communications 3 years from resolution
Heart rate data Session display only. We do not retain heart rate data beyond the active session unless you explicitly save session data in the app
Technical/diagnostic logs Up to 12 months

When data is no longer needed, we delete or anonymise it securely.

6. Who we share your data with

We do not sell your personal data. We share it only with the service providers listed below, who act as our data processors and are contractually bound to handle it securely and only as we instruct.

Provider Purpose Location
Amazon Web Services (AWS) Hosting and infrastructure United States
Google Analytics 4 Website and app analytics United States
PostHog Product analytics United States
Microsoft Clarity Anonymised session replay and heatmaps to improve usability United States
Klaviyo Email marketing and communications United States
Shopify / Shopify International Ltd E-commerce platform, subscriptions, checkout Ireland / Canada
Shopify Payments Payment processing Ireland
Klarna Buy now, pay later Sweden
Gorgias Customer support ticketing United States
Intercom In-app support and chat United States
Apple Pay / Google Pay Payment processing United States
Pandectes Cookie consent management — records and applies your cookie preferences Ireland (EU)
Google Ads Conversion measurement and remarketing (only with your consent) United States

We may also share personal data with:

  • Law enforcement or regulatory authorities, where required by law
  • Professional advisers (lawyers, auditors) under confidentiality obligations
  • Acquirers, in the event of a merger, acquisition, or sale of assets, under appropriate confidentiality protections

We will always tell you about significant changes to how your data is shared.

7. International data transfers

Some of our service providers are based outside the UK and EU. Transferring personal data to these countries requires appropriate safeguards. We rely on the following:

Provider Transfer mechanism
Amazon Web Services Standard Contractual Clauses (EU SCCs 2021; UK IDTA)
Google Analytics 4 Standard Contractual Clauses (EU SCCs 2021; UK IDTA)
Google Ads Standard Contractual Clauses (EU SCCs 2021; UK IDTA)
PostHog Standard Contractual Clauses (EU SCCs 2021; UK IDTA)
Microsoft Clarity Standard Contractual Clauses (EU SCCs 2021; UK IDTA)
Klaviyo Standard Contractual Clauses (EU SCCs 2021; UK IDTA)
Gorgias Standard Contractual Clauses (EU SCCs 2021; UK IDTA)
Intercom Standard Contractual Clauses (EU SCCs 2021; UK IDTA)
Shopify / Shopify International Ltd Based in Ireland (EEA) — no transfer required for EU data; UK IDTA for UK data
Pandectes Based in Ireland (EEA) — no transfer required for EU data; UK IDTA for UK data

If you would like details of the specific safeguards in place for any particular transfer, email privacy@zwim.com.

8. Cookies and tracking technologies

We use cookies and similar technologies on the ZWIM website to make it work, to understand how it is used, and — with your consent — to deliver relevant marketing.

Our cookie consent tool is managed by Pandectes GDPR Compliance. When you first visit the website, you will be shown a consent banner where you can choose which categories of cookies to accept or decline. You can update your preferences at any time using the "Cookie preferences" link in the website footer.

For the full list of cookies we use, their purposes, durations, and providers, see our Cookie Policy.

The app does not use browser cookies. Any analytics in the app are governed by this policy (see Sections 3.6 and 6 above).

9. Your rights

Depending on where you live, you have the following rights over your personal data. You can exercise any of them by emailing privacy@zwim.com. We will respond within one calendar month (or sooner where required by law).

Right What it means
Access Request a copy of the personal data we hold about you
Rectification Ask us to correct inaccurate or incomplete data
Erasure Ask us to delete your data (subject to legal retention obligations)
Restriction Ask us to pause processing while a dispute is resolved
Portability Receive your data in a machine-readable format
Objection Object to processing based on legitimate interests, including direct marketing
Withdraw consent Where processing is based on consent, withdraw it at any time without affecting prior processing
Automated decisions Not be subject to solely automated decisions that have a significant effect on you

Marketing opt-out: You can unsubscribe from marketing emails at any time using the unsubscribe link in any email, or by emailing privacy@zwim.com.

Data subject requests are free of charge. We may ask you to verify your identity before processing a request.

10. Data security

We use appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include encryption of data in transit and at rest, access controls, and regular security reviews.

If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and we will notify you directly if the risk is high.

No method of transmission over the internet is completely secure. If you have concerns about the security of your account, please contact us immediately at privacy@zwim.com.

11. Changes to this policy

We may update this policy from time to time. When we do, we will update the date at the top and, for material changes, notify you by email or via an in-app notice. Your continued use of ZWIM products and services after a change takes effect means you have seen and understood the updated policy.

12. How to contact us and how to complain

For any privacy-related question or request:

Email: privacy@zwim.com

Post:
ZEN8 Sports Ltd (data protection)
7 Bell Yard, London WC2A 2JR, United Kingdom

ZEN8 Sports Portugal Lda (data protection)
NIF: 518 164 330
Rua Professor Sousa da Câmara 207, 3E, 1070-216 Lisboa, Portugal

If you are not satisfied with our response, you have the right to complain to your local supervisory authority:

Supplement A — UK GDPR

This supplement applies to residents of the United Kingdom.

The UK GDPR (retained in UK law by the Data Protection Act 2018) gives you the rights set out in Section 9 above. The supervisory authority is the Information Commissioner's Office (ICO).

ZEN8 Sports Ltd (7 Bell Yard, London WC2A 2JR) is your UK data controller.

You have the right to lodge a complaint with the ICO at ico.org.uk or by calling 0303 123 1113.

Where we transfer personal data from the UK to countries outside the UK, we use UK International Data Transfer Agreements (IDTAs) or the UK Addendum to the EU SCCs, as appropriate.

Supplement B — EU GDPR

This supplement applies to residents of the European Union and European Economic Area.

The EU GDPR gives you the rights set out in Section 9 above. ZEN8 Sports Portugal Lda (Rua Professor Sousa da Câmara 207, 3E, 1070-216 Lisboa, Portugal) is your EU data controller and point of contact.

You have the right to lodge a complaint with the CNPD (cnpd.pt) or with the data protection authority of the EU member state where you live or work.

Where we transfer personal data from the EEA to third countries, we rely on the European Commission's Standard Contractual Clauses (2021) or other valid transfer mechanisms.

Supplement C — US State Privacy Rights

This supplement applies to residents of US states with applicable privacy laws, including California, Virginia, Colorado, Connecticut, Texas, Utah, Oregon, Florida, and Montana.

Categories of personal information collected

We collect the following categories of personal information as defined under applicable US state law:

  • Identifiers: name, email address, IP address, device identifiers
  • Customer records: billing and delivery address, payment information
  • Commercial information: purchase history, subscription status
  • Internet or other electronic network activity: usage data, app interactions, diagnostic logs
  • Geolocation data (Android only): approximate device location used solely for Bluetooth device discovery — not used to determine your geographic location
  • Sensory / biometric data: heart rate data from third-party devices (collected only with explicit consent)
  • Inferences: training performance trends derived from session data
  • Sensitive personal information: health-related data (heart rate from third-party HRM devices)

Sale and sharing of personal information

We do not sell your personal information for money. However, certain analytics and advertising tools we use (such as Google Analytics 4 and Google Ads) may constitute "sharing" of personal information under California law (CCPA/CPRA). You can opt out of this sharing using the "Do Not Sell or Share My Personal Information" link in the website footer, or by enabling Global Privacy Control (GPC) in your browser — we honour GPC signals.

Sensitive personal information

We use sensitive personal information only for the purposes described in this policy (displaying heart rate data in the app with your consent). We do not use it for inferring characteristics about you or for targeted advertising. You can limit the use of your sensitive personal information using the "Limit the Use of My Sensitive Personal Information" link in the website footer.

Your state privacy rights

Depending on which state you live in, you may have the right to:

  • Know what personal information we collect, use, disclose, and sell or share
  • Access a copy of your personal information
  • Correct inaccurate personal information
  • Delete your personal information (subject to certain exceptions)
  • Opt out of the sale or sharing of your personal information
  • Limit the use of sensitive personal information
  • Non-discrimination for exercising your rights

How to exercise your rights: Email privacy@zwim.com with the subject "US Privacy Rights Request" and tell us which right you want to exercise. We will acknowledge your request within 10 business days and respond substantively within 45 calendar days (extendable by a further 45 days where necessary, with notice).

We will not discriminate against you for exercising your privacy rights.


This policy should be read alongside our Terms of Service, Refund and Returns Policy, and Purchase Options Cancellation Policy.