We keep your list, not your life.
When does this apply from?
This policy took effect on October 7, 2026, and that is also the date it was last changed. It covers zavtilo.com and every inquiry, chat and email that reaches us through it.
Who is on the other end?
Zavtilo, trading at zavtilo.com. We are a small parts counter selling fasteners and saw-cut blanks on an inquiry-only basis. For privacy law purposes we are the business that decides what happens to your data, the controller.
Postal address: 46 Market Street, Büro 5, Austin, Texas 82389, United States. Email [email protected], phone +1 (536) 555-1163.
What do you keep?
Only what you send and what the server records when you send it. There are no accounts here, no passwords, no payment and no card data. Nothing is sold on this site and no payment is taken.
- The inquiry form. Your name, phone, email, delivery address, the kind of inquiry, your message, the specification you asked for, and the consent tick.
- Recorded with the form. Your IP address, the browser's user-agent string, the referring URL, the moment the form was rendered and the moment it was sent.
- The support chat. The conversation itself, plus any name, phone or email you choose to give. A token is kept in your browser under
zavtilo_chatso you can come back to the same conversation. - Server logs. Standard access logs: IP address, time, page requested, user-agent.
- Your consent choice. Stored in your browser under
site_consent_v2. Nothing else on this site persists a choice. - Advertising click identifiers. When you arrive from an ad, the link carries a gclid, msclkid or fbclid. With your consent, the platform's tag reads it to count that click as a visit or an inquiry.
What do you do with it?
Your inquiry is used to check the shelf, write you a reply with stock, price basis and lead time, and fill the order if you confirm it. Contact details are used to send that reply and to answer follow-up questions about the same order. We do not put you on a mailing list.
The technical data on a form submission is there to stop spam and to sort out a dispute about what was sent and when. Server logs keep the site running and help us find abuse. Chat transcripts let us answer you and pick up where we left off.
Click identifiers and the ad tags, only when you allow them, tell us which ad brought a visitor and whether that visit ended in an inquiry. That is how we decide which ads to keep paying for.
What gives you the right?
| Purpose | Data | Legal basis |
|---|---|---|
| Answering an inquiry | Form fields | Steps at your request before a contract, then the contract itself |
| Storing the inquiry | Form fields, consent tick | Your consent, given with the tick |
| Spam and dispute records | IP, user-agent, referrer, timestamps | Legitimate interest in a working, abuse-free form |
| Support chat | Transcript, token, optional contact | Your request, and consent where you give contact details |
| Server logs | IP, time, page, user-agent | Legitimate interest in security and operation |
| Ad measurement | gclid, msclkid, fbclid, ad cookies | Consent only, through the cookie choice |
Do you run ads, and what do they track?
Yes. Google Ads, Microsoft Advertising and Meta Ads send paid clicks to this site today. Each one adds its own identifier to the link you click:
- Google Ads adds
gclid. - Microsoft Advertising adds
msclkid. - Meta Ads adds
fbclid, where a campaign runs there.
The identifier is a random string tying your click to the ad. It does not carry your name. If you allow storage, the platform's tag keeps it in a cookie and reports back when that visit becomes an inquiry. If you do not, the identifier sits in the address bar and nothing reads it. No platform has reviewed or vouched for this site; the ads are simply bought.
What happens before I click Allow?
Nothing that stores advertising or analytics data. We use Google Consent Mode v2, and before you choose, all four signals are set to denied: ad_storage, ad_user_data, ad_personalization and analytics_storage.
Clicking Allow sets them to granted. Clicking Decline, or withdrawing later through Cookie settings in the footer, sets them back to denied the moment you do it. While they are denied, ad tags may send cookieless pings that carry no identifier, and no ad or analytics cookie is written. Details of every key are on the cookie policy.
Who else sees it?
- Google Ireland Ltd / Google LLC, for Google Ads. Receives the gclid and the consent signals.
- Microsoft Ireland Operations Ltd, for Microsoft Advertising. Receives the msclkid. Its own handling is set out in the Microsoft privacy statement at privacy.microsoft.com.
- Meta Platforms Ireland Ltd, for Meta Ads. Receives the fbclid where a campaign runs there.
- Our hosting provider, which serves this site and stores the inquiry database and chat transcripts.
- Our mail provider, which carries the notification of your inquiry to our inbox and our reply back to you.
Nobody else. We do not sell your data, and we do not hand inquiry contents to the ad platforms.
Does it leave the country?
We are in the United States and the data is held here. If you write from Europe, your inquiry travels to the United States so we can answer it, which is necessary to deal with your request. The ad platforms move data between their Irish entities and the United States under the EU Standard Contractual Clauses and, where they participate, the EU-U.S. Data Privacy Framework.
How long do you hold on to it?
| Record | Kept for |
|---|---|
| Inquiries and their email copies | 24 months |
| Chat transcripts | 12 months |
| Server and access logs | 30 days |
| Record of a consent choice | 12 months |
After that it is deleted. Ad platforms keep their own data under their own policies.
How is it protected?
The site runs over HTTPS only. The inquiry database and chat store sit outside the public web folder and are reached only through a password-protected operator panel. Access is limited to the counter crew who answer inquiries. Forms carry spam traps and rate limits. No system is perfect; if we find a breach that puts you at risk, we tell you.
I'm in Europe. What can I ask for?
Under the GDPR you have the right to:
- access a copy of what we hold on you;
- rectification of anything wrong;
- erasure of your data;
- restriction of how we use it while a question is settled;
- portability, a copy in a common machine-readable format;
- objection to processing based on legitimate interest;
- withdraw consent at any time, without affecting what was done before.
I'm in California, or another US state?
Under the CCPA as amended by the CPRA, and the other state privacy laws now in force, you can ask to know what we collect and why, get a copy, correct it, delete it, and opt out of the sale or sharing of personal information for cross-context behavioral advertising. We do not sell personal information. Ad cookies set with your consent can count as sharing, so Decline, or Cookie settings in the footer, is your opt-out. We will not treat you differently for using any of these rights.
Do you respect Global Privacy Control?
Yes. If your browser sends the Global Privacy Control signal (the Sec-GPC header), we treat it as an opt-out of sale and sharing. The four Consent Mode signals stay denied and the banner does not ask you. If you later click Allow in Cookie settings, only analytics storage switches on; ad_storage, ad_user_data and ad_personalization stay denied for as long as the signal is sent.
Is this site for children?
No. It sells industrial fasteners to trades and businesses. We do not knowingly take data from anyone under 16. If a child has sent us something, write in and we delete it.
How do I get it deleted?
Use the data request page, or email [email protected], or write to Zavtilo, 46 Market Street, Büro 5, Austin, Texas 82389, United States. Say what you want: a copy, a correction, deletion. Give the email or phone you used so we can find it.
We answer within 5 days. If we need to confirm it is you, we ask once, using the contact detail already on the inquiry.
Who do I complain to?
Tell us first and we will try to fix it. You can also complain to your state Attorney General, and in California to the California Privacy Protection Agency. If you are in the EU or UK, you can go to the data protection authority where you live.
What if this policy changes?
The new version goes up on this page with a new effective date at the top. If the change affects how we use data you already gave us, we email you at the address on your inquiry before it applies. If it changes what the ad tags do, the cookie banner asks you again.
Who do I ask about this?
The same counter that answers parts inquiries. Email [email protected] or call +1 (536) 555-1163. Post goes to 46 Market Street, Büro 5, Austin, Texas 82389, United States. Also see the terms and the cookie policy.