Privacy Policy

Last updated: 7 September 2026

1. Who we are

321ZERO is a carbon measurement and reporting platform built in Jersey, Channel Islands. This policy explains the information processed by the service. You can contact us through our privacy request form about this policy or a data rights request.

2. What data we collect

  • Account data: Your email address and account metadata, such as your company name and selected tier.
  • Emissions data: Energy, fuel, waste, travel and other activity figures you enter, together with calculated CO₂e values.
  • Optional cost data: Costs you choose to enter alongside consumption records.
  • Team and enquiry data: Invitation email addresses, membership records and the details you send through the contact form.
  • Published data: A company name and reviewed annual emissions summary when the company owner explicitly publishes a ticker.
  • Technical data: Hosting and authentication providers may process IP addresses, browser information, request timestamps and security logs when you access the service.

We do not currently operate a separate product analytics or behavioural tracking system. We do not collect data directly from utility providers.

3. How we use your data

  • To create and authenticate your account.
  • To calculate greenhouse gas emissions from information you provide.
  • To display dashboards, charts, summaries and exports on your device.
  • To generate reporting files for you to review and submit to the relevant organisation yourself.
  • To share company records with invited team members and display a public snapshot only when the company owner chooses to publish it.
  • To maintain service security, diagnose faults and respond to support or legal requests.

4. Where and how data is stored

For signed-in accounts, saved company profiles and emissions records are stored in Supabase. Database access rules restrict company records to the owner and authorised team members. An invited member can see and export the company's emissions, including costs and notes, and can add records and delete their own entries. Owners manage the team and all company entries.

The browser also keeps a local working copy of emissions, session information and preferences. Demo records and custom site or activity settings remain in browser storage. If a cloud save fails, a local fallback may be retained and the interface reports the problem. A local copy is not confirmation that a record reached your account.

Local copies are separated by account and company but can be accessed by someone with access to your unlocked browser profile. Logging out preserves local backups. Clearing site data removes local copies, not saved cloud records. Keep exports of information you need.

Netlify hosts the website and stores contact-form submissions for review by 321ZERO. Provider processing locations are described in the providers' own service and subprocessors documentation.

5. Processors and disclosures

We do not sell your personal data. We do share or make data available to service providers where necessary to run the platform:

  • Netlify: website hosting, content delivery and associated technical logs, contact-form storage and spam filtering.
  • Supabase: authentication, account services and relevant company emissions storage, team access and published snapshots.

These providers act as processors or subprocessors for relevant data. They may use their own subprocessors as described in their terms and privacy documentation.

We do not send your emissions data to the Government of Jersey, JFSC or another reporting body on your behalf unless a feature clearly asks for your authorisation. Reports generated for download or email remain your responsibility to review and submit.

A published ticker exposes the reviewed company name, reporting year, scope totals, record count, reporting-period coverage and publication date. It excludes individual entries, costs, notes and team contact details. Others may view, copy or index public snapshots. Future edits to company records do not change a snapshot until its owner publishes an update.

6. Legal grounds and international processing

Depending on the context, we process data to provide the service you request, to pursue legitimate interests such as security and support, to comply with legal obligations, or on the basis of consent for optional publication.

Where providers process data outside Jersey, including in the United Kingdom, we rely on the provider arrangements and applicable legal safeguards available for that processing.

7. Your data protection rights

Subject to applicable conditions and exemptions under Jersey law, you may have rights to:

  • Ask whether we process your personal data and request a copy.
  • Ask us to correct inaccurate or incomplete personal data.
  • Ask us to erase personal data we hold on the server.
  • Request restriction or object to certain processing.
  • Request portable data where the legal requirements apply.
  • Withdraw consent for optional processing, including publication.

You can export emissions and delete entries you are authorised to manage. Browser site-data controls remove local copies only. To exercise a right concerning server-side data, use the privacy request form. We may need to verify your identity before acting on a request.

8. Retention and deletion

Browser data remains in localStorage until you delete it, clear the browser's site data, or the browser removes it. Account and other server-side records are retained while needed to provide the service and for reasonable security, support or legal purposes.

For signed-in accounts, an emissions deletion is sent to Supabase before the active local copy is removed. If the server reports a failure, the interface reports it and retains the local copy. Deleting emissions does not delete your login, other team members or a previously published snapshot. Turn off public sharing separately to withdraw that snapshot. If you want confirmation that server-side data has been removed, contact us through the privacy request form. Removing a team member ends their company access, but does not recall exports or copies already held by that person. Limited records may be retained where required by law or necessary to resolve security and legal matters.

9. Security

Connections to the deployed service use HTTPS. Supabase Auth handles account authentication and password storage; 321ZERO does not receive or store your plain-text password. No internet or browser storage system is completely secure, so you should use a strong, unique password, protect access to your device and keep your own exports or backups where appropriate.

10. Changes to this policy

We may update this policy as the service and its providers change. The date at the top identifies the latest version. Material changes will be presented through the platform or another reasonable channel where practicable.

11. Contact

Questions or requests can be sent through the privacy request form.

321ZERO
Jersey, Channel Islands