Privacy Policy
Last updated: 13 Aug 2025
This Privacy Policy explains how Listzon (https://listzon.com) collects, uses, and protects information. We are a review and comparison website — we do not sell products or take orders on our site. Some links are affiliate links; purchases (if any) happen on third-party stores under their own policies.
Controller (GDPR)
listzon – Ing. Vojtěch Kuthejl (the “Controller”)
ICO: 76672476 · VAT: CZ8003311646
Privacy contact: [email protected]
For full company details, see our Contact Us page.
What we collect (minimal necessary)
- Contact (when you email us or submit a form): name, email, message content.
- Newsletter (if you subscribe): email address and consent preferences (via Ecomail).
- Browsing/technical data (automatic): IP address, device/browser info, pages viewed, timestamps, and cookies necessary for security, performance, analytics, and affiliate attribution.
- Comments (only if enabled): data in the comment form, IP and user-agent for spam prevention. An anonymized email hash may be sent to Gravatar to display an avatar (see their policy).
We do not create checkout accounts and do not process payments on Listzon.
Cookies & tracking
We use cookies and similar technologies for:
- Essential operations & security (e.g., CDN, firewall, caching).
- Analytics (under consent) to improve content (aggregated stats).
- Affiliate attribution so partners can credit a sale to our link (under consent where cookies apply).
- Embedded content (e.g., videos) which may set their own cookies.
You can manage your preferences any time at /cookie-settings/. See details in our Cookie Policy.
Legal bases (GDPR)
- Consent for analytics/marketing cookies and newsletter subscriptions.
- Legitimate interest for essential site operations, security/fraud prevention, first-party attribution, and measuring interest in our content.
- Legal obligation where applicable (e.g., responding to rights requests).
You can withdraw consent at any time (e.g., via /cookie-settings/ or email unsubscribe).
How we use information
- Operate, secure, and improve the website.
- Respond to inquiries and provide support.
- Measure content performance (aggregated analytics).
- Enable affiliate links and attribution.
- Comply with applicable laws.
We do not sell your personal data.
Service providers & partners we use
Some providers may process data outside your country (including EU/EEA & US). Where required, we rely on safeguards such as Standard Contractual Clauses (SCCs) or equivalent mechanisms.
Security, hosting & performance
Cloudflare (CDN / DNS / DDoS / WAF).
Purpose: secure and fast delivery; protect against abuse.
Data: IP address, request headers, device/browser info, security events; essential cookies.
Legal basis: Legitimate interest (security & reliability).
Retention: As per Cloudflare’s security logs; we keep only what’s necessary for troubleshooting.
Analytics
Google Analytics 4 (GA4).
Purpose: aggregated usage stats to improve content (no checkout/payment data).
Data: device/browser identifiers, events, pages; IP processed per GA4 settings.
Legal basis: Consent (analytics cookies).
Retention: typically up to 14 months (GA4 setting).
Controls: Opt out via /cookie-settings/.
Email / newsletters
Ecomail.
Purpose: manage subscriptions and send emails; deliverability metrics (opens/clicks).
Data: email address, consent status; engagement metrics (aggregated).
Legal basis: Consent (subscription).
Retention: until you unsubscribe or request deletion.
Affiliate programs & attribution
Amazon Associates.
Purpose: attribute clicks/purchases from our Amazon links.
Data: referral tags/click identifiers; purchases occur on Amazon under their policy.
Legal basis: Legitimate interest (attribution) + consent where cookies apply.
Retention: as per Amazon’s cookie window (varies by region).
CJ.com (Commission Junction).
Purpose: attribute clicks/purchases across participating advertisers.
Data: click IDs, pseudonymous identifiers, referral info.
Legal basis: Legitimate interest + consent where cookies apply.
Retention: set by advertiser/network (commonly 1–90 days).
AnyTrack (first-party attribution).
Purpose: first-party click/conversion attribution; optional relay of pseudonymous events to ad platforms (no PII).
Data: first-party identifiers, click IDs, events (page views, outbound clicks).
Legal basis: Legitimate interest (attribution) + consent for analytics/marketing where applicable.
Retention: within standard attribution windows configured in the platform.
Consent management & SEO
Real Cookie Banner (CMP).
Purpose: capture and honor your cookie consent; store a consent record.
Data: consent choices and a pseudonymous consent ID saved via a consent cookie and in our site database.
Legal basis: Legal obligation (GDPR consent) & legitimate interest (proof of consent).
Retention: typically up to 12 months (then re-asked).
Rank Math (SEO).
Purpose: SEO metadata, schema, sitemaps.
Data: no visitor PII collected on the frontend by default (operates on site content).
Legal basis: Legitimate interest (discoverability).
Retention: N/A for visitor PII.
We also link to and embed third-party content (e.g., videos). Those services may set their own cookies under their own policies.
Data sharing
We share data with the above providers as processors (under contracts and confidentiality). We may disclose information if required by law or to protect our rights, users, or the public. We do not sell personal data.
International transfers
Where data is transferred outside the EU/EEA, we rely on appropriate safeguards such as SCCs or equivalent mechanisms where required.
Retention
- Contact messages: up to 24 months (or less once resolved).
- Newsletter data (Ecomail): until you unsubscribe or request deletion.
- GA4 analytics: up to 14 months.
- Affiliate cookies (Amazon/CJ): per partner window (commonly 1–90 days).
- Consent records (Real Cookie Banner): up to 12 months.
- Security logs (Cloudflare/host): minimal period necessary for security and troubleshooting.
Your rights (EU/UK GDPR)
You may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interest. You can withdraw consent at any time (e.g., cookies, newsletter).
To exercise your rights, email [email protected]. You may also lodge a complaint with your local authority (CZ: ÚOOÚ).
California & certain U.S. state rights (CCPA/CPRA etc.)
Residents of certain U.S. states (e.g., California) may have rights to access, delete, correct, and opt-out of the “sale” or “sharing” of personal information as defined by law. While we do not “sell” data in the common sense, some analytics/advertising technologies could be treated as “sharing.” Use /privacy-choices/ or email [email protected].
Children’s privacy
Listzon is not intended for children under 13 (or the applicable age in your region). We do not knowingly collect data from children.
Security
We use reasonable technical and organizational safeguards (HTTPS, least-privilege access, monitoring). No method is 100% secure, but we work to protect your data.
Changes
We may update this Privacy Policy. The “Last updated” date reflects the latest version. Significant changes will be highlighted on this page.
Contact
For privacy inquiries or to exercise your rights: [email protected].
For full company details, see our Contact Us page.