Privacy policy
ZWIM Privacy Policy
Last updated: 8 June 2026
Effective date: 8 June 2026
This Privacy Policy explains how we collect, use, store, and share your personal data when you use the ZWIM website (zwim.com) or the ZWIM mobile app (iOS and Android). It also explains your rights and how to exercise them.
We have tried to write this in plain language. If anything is unclear, email us at privacy@zwim.com.
1. Who we are
ZWIM is a brand operated jointly by:
ZEN8 Sports Ltd
Company number: 12662386
7 Bell Yard, London WC2A 2JR, United Kingdom
UK VAT: GB 370 1354 26
ZEN8 Sports Portugal Lda
NIF: 518 164 330
Rua Professor Sousa da Câmara 207, 3E
1070-216 Lisboa, Portugal
Both entities are joint controllers under Article 26 of the UK and EU GDPR. This means we share responsibility for how your personal data is handled. Either entity can be your point of contact — the easiest way to reach us on any privacy matter is privacy@zwim.com.
2. Who this policy applies to
This policy applies to:
- Anyone who visits or uses the ZWIM website (zwim.com), including the online shop
- Anyone who creates a ZWIM account
- Anyone who uses the ZWIM mobile app on iOS or Android
- Anyone who connects ZWIM Smart Paddles or other devices to the app
You must be 18 years of age or older to use ZWIM products and services. We do not knowingly collect personal data from anyone under 18. If you believe we have done so inadvertently, please contact privacy@zwim.com and we will delete it promptly.
3. What data we collect
3.1 Data you give us directly
Account and waitlist. When you create a ZWIM account or join the waitlist, we collect your name, email address, country, and a hashed (encrypted) password. We may also collect referral information if you were referred by another user.
Profile information (optional). You can choose to add profile information such as your age, gender, height, weight, swimming ability, and training goals. This helps us tailor your experience. This information is optional — you can use ZWIM without providing it.
Order and payment data. When you place an order, we collect your delivery address, billing address, the items you purchased, the amount paid, the currency, and payment method details. We do not store full card numbers — payments are processed by our payment providers (see Section 6).
Communications. If you contact us, complete a survey, or take part in a research interview, we collect the content of your communications and any other information you choose to share.
3.2 Training and performance data (ZWIM app)
When you use the ZWIM app with Smart Paddles, we collect performance data generated by the paddles during your sessions, including:
- Propulsive Watts
- Stroke rate and stroke count
- Left and right balance
- Efficiency and wasted energy measurements
- Session duration and pace
- Calibration data
This is performance data, not health data. It tells us how effectively you are moving through your training — it does not tell us about your physical health or medical condition.
3.3 Third-party device data (ZWIM app)
If you connect a third-party heart rate monitor (such as a Garmin, Polar, or Wahoo device) to the ZWIM app via Bluetooth, we receive your heart rate data from that device and display it within the app during your session.
Heart rate data is health data under UK and EU law (special category data under Article 9 GDPR). We only receive and display this data with your explicit consent, which you give when you connect your heart rate monitor for the first time. We act as a conduit — the data originates from your third-party device and its manufacturer, not from ZWIM. We do not share your heart rate data with third parties for marketing purposes and do not use it to make automated decisions about you.
You can revoke consent at any time by disconnecting your heart rate monitor in the app settings. If you do, we will stop receiving and displaying that data.
3.4 Device and connectivity data (ZWIM app)
When you pair Smart Paddles or other Bluetooth devices with the ZWIM app, we collect:
- Device identifier and pairing information
- Firmware version
- Calibration data
- Connection logs
This data is used to ensure your paddles function correctly and to push firmware updates.
3.5 App permissions
Location (Android only). Android requires apps to have location permission enabled in order to scan for and discover Bluetooth devices nearby. We request this permission solely to allow the app to find and connect to your Smart Paddles. We do not collect, record, or use your geographic location for any other purpose — we do not know where you are, and we do not track your movements. If the purpose of this permission changes in the future, we will update this policy and ask for your consent again.
Bluetooth (iOS and Android). We use Bluetooth to connect to your Smart Paddles and any third-party heart rate monitors you choose to pair. This is core app functionality — without it, the paddles cannot connect.
Notifications (iOS and Android). We request permission to send you push notifications, such as session reminders and firmware update alerts. This is optional — you can decline at the OS prompt or change your preference at any time in your device settings.
3.6 Technical and usage data
When you use the website or app, we automatically collect certain technical information, including:
- IP address
- Browser type and version
- Device model and operating system
- App version and language
- Timezone
- Pages or screens visited, features used, and session frequency
- Crash reports and diagnostic logs
This information helps us keep the service running, identify and fix problems, and improve the product.
3.7 Leaderboard and social features (ZWIM app)
The ZWIM leaderboard and social features are off by default. If you choose to enable them, your training performance data (such as Propulsive Watts rankings) may be visible to other users. You can turn this off at any time in your app settings and your data will be removed from public views.
3.8 Data from third-party sources
We may receive information about you from affiliates, social media platforms (for example if you sign up using a social login), and service providers. We handle this data in accordance with this policy.
3.9 Legacy ZEN8 customers
ZWIM is the successor brand to ZEN8. If you previously purchased from zen8swimtrainer.com or interacted with the ZEN8 brand before 2026, you are dealing with the same company — ZEN8 Sports Ltd — now trading as ZWIM. We are not transferring your data to a different company; we are continuing to hold it under the same controller and using it to support you under our new brand.
For legacy customers, we may continue to hold:
- contact details (name, email)
- purchase history (orders, items, fulfilment)
- support history
We use this data to:
- continue to support you on your existing ZEN8 hardware
- verify your eligibility for loyalty upgrades and Founder offers
- migrate your account to ZWIM if you choose to opt in
Marketing to legacy customers. Where the law allows it, we may send you product news about ZWIM as the successor product line, relying on our existing customer relationship ("soft opt-in" under PECR in the UK and equivalent rules in the EU) and on legitimate interests. Every email contains an unsubscribe link, and you can opt out at any time by clicking it or by emailing privacy@zwim.com. Once you opt out, we will stop sending marketing.
4. Why we use your data and our legal basis
| Data | Purpose | Lawful basis |
|---|---|---|
| Account data | Create and manage your account; verify your identity | Performance of contract |
| Optional profile data | Personalise your experience and recommendations | Consent |
| Order data | Fulfil your purchase; process payment; arrange delivery | Performance of contract |
| Tax and financial records | Meet legal accounting and tax obligations | Legal obligation |
| Training performance data | Deliver session summaries; power the in-app game; improve algorithms | Performance of contract; Legitimate interests |
| Heart rate data (external HRM) | Display heart rate in the app during your session | Explicit consent (Art. 9 GDPR) |
| BLE device data | Pair paddles; deliver firmware updates; diagnose connectivity issues | Performance of contract; Legitimate interests |
| Location (Android, BLE discovery) | Enable Bluetooth device discovery on Android | Consent |
| Notifications | Send session reminders and firmware alerts | Consent |
| Technical and usage data | Security; fraud prevention; product improvement; diagnostics | Legitimate interests |
| Marketing communications | Send news, offers, and updates (where you have opted in) | Consent |
| Support communications | Resolve your query | Legitimate interests |
| Survey and research data | Improve products and services | Consent |
| Cookie consent preferences | Record and apply your cookie choices | Legal obligation (ePrivacy / UK PECR) |
| Advertising measurement | Measure campaign conversions and support remarketing | Consent |
| Legacy ZEN8 customers | Where permitted by law, soft opt-in basis for marketing to existing customers who have not opted out | Legitimate interests (where applicable law permits) |
Legitimate interests: Where we rely on legitimate interests, we have weighed those interests against your rights. You can object to processing based on legitimate interests at any time — see Section 9.
5. How long we keep your data
| Data type | Retention period |
|---|---|
| Waitlist data | Until you unsubscribe, or 24 months of inactivity |
| Account and training data | While your account is active. After 24 months of inactivity we will contact you — if we hear nothing, we begin deletion |
| Order and financial records | 6 years (UK legal requirement) or 10 years (Portugal legal requirement) — whichever applies to the transaction |
| Marketing consent records | For the duration of your consent plus a reasonable period after withdrawal, to demonstrate compliance |
| Cookie consent records | 12 months from the date of consent |
| Support communications | 3 years from resolution |
| Heart rate data | Session display only. We do not retain heart rate data beyond the active session unless you explicitly save session data in the app |
| Technical/diagnostic logs | Up to 12 months |
When data is no longer needed, we delete or anonymise it securely.
6. Who we share your data with
We do not sell your personal data. We share it only with the service providers listed below, who act as our data processors and are contractually bound to handle it securely and only as we instruct.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Hosting and infrastructure | United States |
| Google Analytics 4 | Website and app analytics | United States |
| PostHog | Product analytics | United States |
| Microsoft Clarity | Anonymised session replay and heatmaps to improve usability | United States |
| Klaviyo | Email marketing and communications | United States |
| Shopify / Shopify International Ltd | E-commerce platform, subscriptions, checkout | Ireland / Canada |
| Shopify Payments | Payment processing | Ireland |
| Klarna | Buy now, pay later | Sweden |
| Gorgias | Customer support ticketing | United States |
| Intercom | In-app support and chat | United States |
| Apple Pay / Google Pay | Payment processing | United States |
| Pandectes | Cookie consent management — records and applies your cookie preferences | Ireland (EU) |
| Google Ads | Conversion measurement and remarketing (only with your consent) | United States |
We may also share personal data with:
- Law enforcement or regulatory authorities, where required by law
- Professional advisers (lawyers, auditors) under confidentiality obligations
- Acquirers, in the event of a merger, acquisition, or sale of assets, under appropriate confidentiality protections
We will always tell you about significant changes to how your data is shared.
7. International data transfers
Some of our service providers are based outside the UK and EU. Transferring personal data to these countries requires appropriate safeguards. We rely on the following:
| Provider | Transfer mechanism |
|---|---|
| Amazon Web Services | Standard Contractual Clauses (EU SCCs 2021; UK IDTA) |
| Google Analytics 4 | Standard Contractual Clauses (EU SCCs 2021; UK IDTA) |
| Google Ads | Standard Contractual Clauses (EU SCCs 2021; UK IDTA) |
| PostHog | Standard Contractual Clauses (EU SCCs 2021; UK IDTA) |
| Microsoft Clarity | Standard Contractual Clauses (EU SCCs 2021; UK IDTA) |
| Klaviyo | Standard Contractual Clauses (EU SCCs 2021; UK IDTA) |
| Gorgias | Standard Contractual Clauses (EU SCCs 2021; UK IDTA) |
| Intercom | Standard Contractual Clauses (EU SCCs 2021; UK IDTA) |
| Shopify / Shopify International Ltd | Based in Ireland (EEA) — no transfer required for EU data; UK IDTA for UK data |
| Pandectes | Based in Ireland (EEA) — no transfer required for EU data; UK IDTA for UK data |
If you would like details of the specific safeguards in place for any particular transfer, email privacy@zwim.com.
8. Cookies and tracking technologies
We use cookies and similar technologies on the ZWIM website to make it work, to understand how it is used, and — with your consent — to deliver relevant marketing.
Our cookie consent tool is managed by Pandectes GDPR Compliance. When you first visit the website, you will be shown a consent banner where you can choose which categories of cookies to accept or decline. You can update your preferences at any time using the "Cookie preferences" link in the website footer.
For the full list of cookies we use, their purposes, durations, and providers, see our Cookie Policy.
The app does not use browser cookies. Any analytics in the app are governed by this policy (see Sections 3.6 and 6 above).
9. Your rights
Depending on where you live, you have the following rights over your personal data. You can exercise any of them by emailing privacy@zwim.com. We will respond within one calendar month (or sooner where required by law).
| Right | What it means |
|---|---|
| Access | Request a copy of the personal data we hold about you |
| Rectification | Ask us to correct inaccurate or incomplete data |
| Erasure | Ask us to delete your data (subject to legal retention obligations) |
| Restriction | Ask us to pause processing while a dispute is resolved |
| Portability | Receive your data in a machine-readable format |
| Objection | Object to processing based on legitimate interests, including direct marketing |
| Withdraw consent | Where processing is based on consent, withdraw it at any time without affecting prior processing |
| Automated decisions | Not be subject to solely automated decisions that have a significant effect on you |
Marketing opt-out: You can unsubscribe from marketing emails at any time using the unsubscribe link in any email, or by emailing privacy@zwim.com.
Data subject requests are free of charge. We may ask you to verify your identity before processing a request.
10. Data security
We use appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include encryption of data in transit and at rest, access controls, and regular security reviews.
If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and we will notify you directly if the risk is high.
No method of transmission over the internet is completely secure. If you have concerns about the security of your account, please contact us immediately at privacy@zwim.com.
11. Changes to this policy
We may update this policy from time to time. When we do, we will update the date at the top and, for material changes, notify you by email or via an in-app notice. Your continued use of ZWIM products and services after a change takes effect means you have seen and understood the updated policy.
12. How to contact us and how to complain
For any privacy-related question or request:
Email: privacy@zwim.com
Post:
ZEN8 Sports Ltd (data protection)
7 Bell Yard, London WC2A 2JR, United Kingdom
ZEN8 Sports Portugal Lda (data protection)
NIF: 518 164 330
Rua Professor Sousa da Câmara 207, 3E, 1070-216 Lisboa, Portugal
If you are not satisfied with our response, you have the right to complain to your local supervisory authority:
- UK: Information Commissioner's Office (ICO) — ico.org.uk
- Portugal / EU: Comissão Nacional de Proteção de Dados (CNPD) — cnpd.pt, or your local EU data protection authority
- Other EU: Your national data protection authority — edpb.europa.eu/about-edpb/about-edpb/members_en
Supplement A — UK GDPR
This supplement applies to residents of the United Kingdom.
The UK GDPR (retained in UK law by the Data Protection Act 2018) gives you the rights set out in Section 9 above. The supervisory authority is the Information Commissioner's Office (ICO).
ZEN8 Sports Ltd (7 Bell Yard, London WC2A 2JR) is your UK data controller.
You have the right to lodge a complaint with the ICO at ico.org.uk or by calling 0303 123 1113.
Where we transfer personal data from the UK to countries outside the UK, we use UK International Data Transfer Agreements (IDTAs) or the UK Addendum to the EU SCCs, as appropriate.
Supplement B — EU GDPR
This supplement applies to residents of the European Union and European Economic Area.
The EU GDPR gives you the rights set out in Section 9 above. ZEN8 Sports Portugal Lda (Rua Professor Sousa da Câmara 207, 3E, 1070-216 Lisboa, Portugal) is your EU data controller and point of contact.
You have the right to lodge a complaint with the CNPD (cnpd.pt) or with the data protection authority of the EU member state where you live or work.
Where we transfer personal data from the EEA to third countries, we rely on the European Commission's Standard Contractual Clauses (2021) or other valid transfer mechanisms.
Supplement C — US State Privacy Rights
This supplement applies to residents of US states with applicable privacy laws, including California, Virginia, Colorado, Connecticut, Texas, Utah, Oregon, Florida, and Montana.
Categories of personal information collected
We collect the following categories of personal information as defined under applicable US state law:
- Identifiers: name, email address, IP address, device identifiers
- Customer records: billing and delivery address, payment information
- Commercial information: purchase history, subscription status
- Internet or other electronic network activity: usage data, app interactions, diagnostic logs
- Geolocation data (Android only): approximate device location used solely for Bluetooth device discovery — not used to determine your geographic location
- Sensory / biometric data: heart rate data from third-party devices (collected only with explicit consent)
- Inferences: training performance trends derived from session data
- Sensitive personal information: health-related data (heart rate from third-party HRM devices)
Sale and sharing of personal information
We do not sell your personal information for money. However, certain analytics and advertising tools we use (such as Google Analytics 4 and Google Ads) may constitute "sharing" of personal information under California law (CCPA/CPRA). You can opt out of this sharing using the "Do Not Sell or Share My Personal Information" link in the website footer, or by enabling Global Privacy Control (GPC) in your browser — we honour GPC signals.
Sensitive personal information
We use sensitive personal information only for the purposes described in this policy (displaying heart rate data in the app with your consent). We do not use it for inferring characteristics about you or for targeted advertising. You can limit the use of your sensitive personal information using the "Limit the Use of My Sensitive Personal Information" link in the website footer.
Your state privacy rights
Depending on which state you live in, you may have the right to:
- Know what personal information we collect, use, disclose, and sell or share
- Access a copy of your personal information
- Correct inaccurate personal information
- Delete your personal information (subject to certain exceptions)
- Opt out of the sale or sharing of your personal information
- Limit the use of sensitive personal information
- Non-discrimination for exercising your rights
How to exercise your rights: Email privacy@zwim.com with the subject "US Privacy Rights Request" and tell us which right you want to exercise. We will acknowledge your request within 10 business days and respond substantively within 45 calendar days (extendable by a further 45 days where necessary, with notice).
We will not discriminate against you for exercising your privacy rights.
This policy should be read alongside our Terms of Service, Refund and Returns Policy, and Purchase Options Cancellation Policy.