#Privacy Policy
The DTC Aperitivo, dtcaperitivo.com
Zipchat Inc. 407 E Ayre St #1207 Wilmington, Delaware DE 19804 United States
Contact for privacy matters: privacy@dtcaperitivo.com
Effective date: 8 September 2026 Version: 1.6
#1. Who is responsible for your data
Zipchat Inc. ("Zipchat", "we", "us") is the controller of the personal data described in this policy. Zipchat organises The DTC Aperitivo, a series of evening networking events held alongside ecommerce industry conferences, and operates the website at dtcaperitivo.com and the co-host portal on it.
The co-hosts of the edition you register for also receive your business contact details, because that is how the event is paid for and how it works. Each of those co-hosts is an independent controller of what it receives. From that point they decide how they use it and they answer to you directly for it. We tell you who they are on the registration form and on the edition page, before you register, and we name them in Section 6. If you would rather they did not have your details, tell us and we will remove you. Section 5.3 explains this in full.
#2. What this policy covers
This policy covers:
- the website dtcaperitivo.com, including the guest registration form
- the invite-only co-host portal on the same domain
- the emails we send about an event
- the running of the events themselves
It does not cover what a co-host does with your details once it has them, or what any other website you reach from ours does. It also does not cover Zipchat's own products at zipchat.ai, which have their own privacy policy.
#3. What we collect
#3.1 If you register for an event as a guest
- your full name
- your work email address
- your phone number for WhatsApp
- your company name
- your company website, which is required
- what you do, chosen from a short list of categories, plus a short description if you pick "Other"
- which co-host invited you, chosen from the list of that edition's co-hosts
- whether you are bringing a plus one, and if so their name
- the date and time of your registration, which edition you registered for, and the version of this policy and of the terms in force when you registered
- whether you have asked us not to pass your details to the co-hosts, and when
#3.2 If you are a co-host
- your name and email address, and the account you use to sign in
- your company name, tagline, description, website and logo, which you upload yourself and which appear publicly on the edition page
- the amount agreed for your slot, its payment status, and any note we record against it
- a log of when you or your colleagues opened or exported a guest list, and how many records were in it
We never see or store your password. Authentication is handled by our authentication provider, which stores only a cryptographic hash.
#3.3 Technical data
- your IP address, which we hash and use only to rate limit the public registration form against abuse. We do not store the address itself.
- your browser type and the time of the request, in short lived server logs
We do not run advertising pixels, we do not use third party analytics, and we do not set any cookie that is not strictly necessary to make the site and the sign in work. This is why you do not see a cookie banner: there is nothing optional to consent to.
Our server logs record error codes only. They do not contain names, email addresses or the text of anything you wrote.
#3.4 Sensitive information
We do not ask for and do not want special category data, which includes health, religion, ethnicity, political opinions or sexual orientation.
The registration form has no free text field, by design, so there is nowhere for you to volunteer this kind of information to us by accident. If you email us separately about an allergy, a dietary requirement or an accessibility need, we use what you tell us for the single purpose of accommodating you at the event, we do not share it with any co-host, and we delete it once the edition has taken place.
#3.5 Why we ask for a phone number
The venue is confirmed late and evening events move. A phone number lets us reach you on the day if the bar changes, if the door needs a name, or if we are running behind, which email does not do at 6pm while you are on a train. We use it for that, and the co-hosts of your edition receive it only after the evening, under the timing rule in Section 5.3. If you would rather we did not hold a number at all, write to privacy@dtcaperitivo.com and we will delete it and keep your place.
#3.6 If you bring a plus one
If you tell us you are bringing someone, we collect their name and nothing else. We use it only for the door list and to size the room, we delete it after the edition, and we do not pass it to the co-hosts. Please tell your plus one that you have given us their name and point them at this page. If they would rather we did not hold it, either of you can write to privacy@dtcaperitivo.com and we will remove it.
#3.7 Children
The events serve alcohol and are for business professionals. The site and the events are not intended for anyone under 18, and we do not knowingly collect data from anyone under 18. If you believe we have, write to privacy@dtcaperitivo.com and we will delete it.
#4. Registration is a request, not a confirmed place
When you register you are asking for a place. Places are limited by the capacity of the venue, and we curate the room so that it is useful: the events are built for ecommerce brands, agencies, and ecommerce software and app teams.
We may decline a registration. A decision to decline is made by a person, not by an automated system, and it is not a decision that produces legal effects for you within the meaning of Article 22 of the GDPR.
Please read this part carefully. If we decline your registration, or if you register and do not attend, we do not delete your record. We keep your contact details and may use them for our own marketing about future editions and about Zipchat, as described in Section 5.2, until you tell us to stop. You can tell us to stop at any time and we will act on it. Your details are also passed to the co-hosts of that edition as described in Section 5.3, whether or not you are admitted, unless you object first.
#5. Why we use your data, and our lawful basis
#5.1 To run the event
Managing the guest list, deciding admissions, sizing and booking the venue, emailing you the address once it is confirmed, and sending you practical updates about the evening.
Lawful basis: performance of our arrangement with you at your request, and our legitimate interest in running an event we have invited you to. These emails are transactional. They are not marketing and you cannot unsubscribe from the ones that carry the address and the timing of an event you are registered for, although you can ask us to cancel your registration entirely.
#5.2 For our own marketing
Telling you about future editions of The DTC Aperitivo, and about Zipchat's own products and services, by email.
Lawful basis: our legitimate interest in marketing business to business to a professional contact who came to us through an event registration, balanced against your interests. Where the law of your country requires consent for this instead, we rely on consent and we ask for it separately.
You can object at any time, with no reason and no consequence for your place at the event. Every marketing email carries an unsubscribe link, our identity and our postal address.
#5.3 Sharing your details with the co-hosts of an edition
This is the part to read before you register, so we have put it in plain terms.
Each edition is paid for by a small number of co-host companies. They fund the bar, they invite their own contacts, and in return they get to know who was in the room. That exchange is what makes the evening free for you. So the co-hosts of the edition you register for receive:
- your full name
- your company name
- your company website
- the category of what you do
- which co-host invited you
- your work email address and your phone number, but not until three hours after the evening ends
That is the complete list. We do not pass on your plus one's name, and we do not pass on anything else.
The timing is deliberate. From the moment you register the co-hosts can see who is coming, because that is the point of sponsoring the room. They cannot see how to reach you until three hours after the evening has finished, and under section 5.7 of our Terms and Conditions they are not allowed to contact you about their own products or services before the event at all. We built it that way so that registering for a free drink does not turn into four sponsors emailing you the following morning. The release time is enforced by the system, not by good intentions: before it passes, the contact fields are not in the data the portal can read.
Lawful basis: our legitimate interests, and the legitimate interests of the co-hosts, in running a sponsored business networking event and in following up with the professionals who chose to attend it. We are not relying on consent for this, so you will not find a tick box for it. Instead we tell you plainly, on the form itself and here, before you give us anything.
Why we think that balance is fair:
- The form asks for your work email and your company, not personal contact details. You are giving us a professional identity, in a professional context, to attend a professional event.
- The co-hosts are named on the registration form and on the edition page before you register, so there is no surprise about who receives it.
- Following up after an industry event is the ordinary, expected use of a business card, and this is the digital version of the same thing.
- What the co-hosts may do with it is contractually restricted. Section 5.7 of our Terms and Conditions holds them to three things: no contact about their own products before the event, an obligation to tell you they co-hosted The DTC Aperitivo the first time they get in touch so you always know where your details came from, and use for marketing their own products and services only, never selling or passing them outside their own company. It also requires them to honour an opt-out within five working days. If a co-host breaks any of that we terminate their slot and exclude them from future editions.
- Every time a co-host opens or exports a guest list we log which account did it, when, and how many records were involved.
You can object, and it is easy. Reply to any email from us, click the objection link in your confirmation email, or write to privacy@dtcaperitivo.com. We will remove you from the list the co-hosts can see, and we will tell any co-host who already has your details to delete them. There is no cost to you and it does not affect your place at the event. Because this is legitimate interests and not consent, objecting is an absolute right for direct marketing purposes and we will always honour it.
If a co-host joins after you registered they get access to the list from that point, and their name appears on the edition page. If you would rather that did not happen, object using any of the routes above.
Anything already transferred. If a co-host received your details before you objected, we will pass your objection on and give you their contact details so you can enforce your rights directly against them. This is why we name them up front.
Co-hosts are bound by our terms to use what they receive only to market their own products and services, to comply with the privacy and marketing laws that apply to you, to honour any opt-out you send them, never to pass the data to anyone else, never to load it into an advertising platform without their own lawful basis, and to delete it within twelve months of the edition. Those obligations are in Section 5.7 of our Terms and Conditions. If a co-host breaks them we exclude them and they lose their fee, and we will tell you what happened if you ask.
#5.4 To operate the co-host portal
Giving co-hosts an account, showing them their own listing, their own amount due, and the guest list they are entitled to, and logging who looked at it and when.
Lawful basis: performance of our contract with the co-host, and our legitimate interest in keeping an audit trail of who accessed personal data.
#5.5 Security and abuse prevention
Rate limiting the public form, detecting automated abuse, keeping the portal locked down.
Lawful basis: our legitimate interest in the security of the service.
#5.6 Legal and accounting
Keeping records of payments, dealing with a legal claim, responding to a lawful request from an authority.
Lawful basis: legal obligation, and our legitimate interest in establishing or defending legal claims.
#6. Who we share your data with
#6.1 Co-hosts of the edition you registered for
As described in Section 5.3, and only the fields listed there. Each co-host is an independent controller of what it receives, is bound by the restrictions in Section 5.7 of our Terms and Conditions, and where it is established outside the European Economic Area or the United Kingdom it is also bound by Standard Contractual Clauses with us.
The current co-hosts of each edition are named on that edition's page on dtcaperitivo.com and on the registration form itself. Zipchat is the host of every edition. As at the effective date of this policy, the co-hosts of the London edition of 23 September 2026 are Zipchat and ABsolutely, and further slots are open.
Access is inside a password protected portal. A co-host can only ever reach the edition they are a co-host of, cannot see any other co-host's records, and every time a guest list is opened or exported we log which account did it, when, and how many records were involved.
#6.2 Service providers acting on our instructions
- our website and application platform
- our database, file storage and authentication provider
- our transactional email provider
These act as processors under a written agreement, may only use the data to provide the service to us, and may not use it for their own purposes. We will tell you the current names on request at privacy@dtcaperitivo.com.
#6.3 The venue
Once a venue is booked we give it the expected headcount and, if the venue requires it for door management, a guest list. We keep this to the minimum the venue insists on and we will name the venue on the event page once it is confirmed.
#6.4 Others
Our professional advisers where they need it, a buyer or successor if the business or the event series is sold, and any authority or court where we are legally required to disclose.
#6.5 What we do not do
We do not sell your personal data for money. We do not share it with data brokers. We do not share it with any company other than the co-hosts of your own edition and the providers above.
Do Not Sell or Share My Personal Information. Note for California residents: giving your details to the co-hosts of an edition so that they can market their own products to you may count as "sharing" under California law even though no money changes hands. You have the right to opt out of it. To do so, click the objection link in your confirmation email or write to privacy@dtcaperitivo.com with the words "do not share", and we will stop. We will not treat you any differently for asking. See Section 10.2.
#7. Where your data goes
Zipchat Inc. is a United States company and our providers are largely in the United States, so if you are in the European Economic Area, the United Kingdom or Switzerland, your data is transferred outside your country.
For transfers to our processors we rely on the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum where the UK GDPR applies, together with the additional safeguards those clauses require.
For a transfer of your data to a co-host established outside the EEA or the UK, we put Standard Contractual Clauses in place with that co-host before it is given access, as part of the data sharing terms every co-host has to accept. If you do not want your details passed to the co-hosts at all, object using any of the routes in Section 5.3.
You can ask us for a copy of the relevant transfer mechanism at privacy@dtcaperitivo.com.
#8. How long we keep it
| What | How long |
|---|---|
| Guest registration record and the operational fields, including the phone number and the plus one's name | Until 3 months after the edition, then the phone number, the plus one's name and the operational fields are deleted |
| Guest name, email, company and category, for our own marketing | Until you object or ask for deletion. We review and delete contacts with no engagement after 24 months |
| Record of your acceptance of the terms and this policy, and of any objection you make under Section 5.3 | 6 years, because it is our evidence of what you were told and of what you asked us to do |
| Co-host account and listing | For the duration of the relationship, then deleted |
| Co-host commercial records, fees, payment status, invoices | 6 years from the end of the relationship, for tax, accounting and limitation periods |
| Guest list access and export log | 24 months |
| Hashed IP rate limiting records | 30 days |
#9. How we protect it
- Every table in our database is protected by row level security, so an authenticated co-host can only read their own record and the guest list of their own edition. This is enforced by the database itself, not by the interface.
- The public website can read only two curated views that expose company name, tagline, logo and website of published co-hosts. It cannot read the guest list at all.
- Every view and every export of a guest list is written to an access log.
- The public registration form is rate limited and protected against automated abuse.
- Logo uploads accept raster images only. We refuse SVG files, which are executable markup, and we verify the real file type rather than trusting what the browser tells us.
- All traffic is encrypted in transit, and the site sends a strict content security policy.
- Sign in is invite only. Nobody can create an account without an invitation from us.
No system is perfect. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and tell you without undue delay where the law requires it.
#10. Your rights
#10.1 If the GDPR or the UK GDPR applies to you
You have the right to:
- access the personal data we hold about you, and get a copy
- rectify it if it is wrong or incomplete
- erase it, where one of the grounds in Article 17 applies
- restrict how we use it while a dispute is resolved
- portability, receiving the data you gave us in a machine readable format
- object to processing based on legitimate interests, including an absolute right to object to direct marketing, which we will always honour
- object to your details being passed to the co-hosts, at any time and with no reason needed, which is an absolute right where the purpose is direct marketing
- complain to a supervisory authority. In the United Kingdom that is the Information Commissioner's Office at ico.org.uk. In the EEA it is the authority in your country of residence or work. You can also complain to us first, and we would prefer that, but you do not have to.
To exercise any of these, write to privacy@dtcaperitivo.com. We will respond within one month and will tell you if we need longer, which we may for a complex request. We do not charge for this. We may ask you to confirm your identity, using the email address you registered with.
If you ask us to erase your data and we hold nothing else about you, we will do it. If a co-host already received your details, we will pass your request on and give you their contact details so you can enforce it directly against them.
#10.2 If you are a resident of California
Under the California Consumer Privacy Act as amended by the CPRA you have the right to know what we collect and why, to access it, to correct it, to delete it, to opt out of the sale or sharing of your personal information, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of these.
- The categories we collect are identifiers, professional and employment information, commercial information relating to your registration, and internet activity limited to the technical data in Section 3.3.
- We collect it from you directly.
- We disclose identifiers and professional information to the co-hosts of your edition, contact details only after the event. You may opt out at any time, and we will stop.
- We do not sell personal information for money, and we do not use or disclose sensitive personal information for anything other than the purpose you gave it for.
- We do not knowingly collect or sell the personal information of anyone under 16.
To exercise a right, write to privacy@dtcaperitivo.com. We will verify your request using the email address on your record and respond within 45 days, extendable once by a further 45 days. An authorised agent may act for you with written proof.
#10.3 If you are a resident of another US state with a privacy law
Residents of states including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana have comparable rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, and certain profiling. We honour those requests through the same address, privacy@dtcaperitivo.com, on the timescales the relevant law sets, and we will tell you how to appeal a refusal where your state gives you that right.
#10.4 Everyone else
Wherever you are, you can write to privacy@dtcaperitivo.com and ask us what we hold, ask us to correct it, ask us to delete it, or ask us to stop marketing to you. We will do it.
#11. Cookies and similar technologies
We use only what is strictly necessary:
- a session cookie so that a signed in co-host or administrator stays signed in
- local storage on your own device to remember interface preferences such as whether the sidebar is collapsed and which table columns you chose to show
We do not use advertising cookies, tracking pixels, session recording, heatmaps or third party analytics on dtcaperitivo.com. Nothing here requires your consent, which is why there is no banner. If that ever changes, we will ask you before setting anything.
The venue map. Once a venue is confirmed, the event page shows where it is on a map embedded from OpenStreetMap. Your browser loads that map directly from openstreetmap.org, so your IP address and the page you are looking at reach the OpenStreetMap Foundation, which handles them under its own privacy policy. We do not send them anything about you ourselves, we set no cookie of our own for the map, and the map appears only on the page where the address is published. The full address is written out next to the map, so nothing you need is hidden inside the embed.
Lawful basis: our legitimate interest in showing you how to find the evening.
#12. Changes to this policy
If we change this policy we will update the version and the effective date at the top. If a change materially affects how we use data we already hold, we will email registered guests and co-hosts before it takes effect. Continuing to use the site after a change means you accept the updated policy, except where the change concerns something that needs your consent, in which case we will ask again.
#13. How to contact us
Zipchat Inc. 407 E Ayre St #1207 Wilmington, Delaware DE 19804 United States
This policy is written in English. If we publish a translation and the two disagree, the English version governs.