The Nullware Standard0 trackers on this page
The Nullware Standard · version 1.0

The line, written down.

Understanding your customers is fine. Handing them to someone else’s marketing machine isn’t. In one line: customer data goes only to people working for you, never to anyone who uses it for themselves or for advertising, whatever the route and whatever the customer clicked.

Version 1.0Draft for pilot members · September 2026Next review September 2027
Verified20 clauses, checked with evidence
1Where customer data goes
1.1No disclosure for own use or advertising
1.2The route doesn’t matter
1.3Consent doesn’t cure a breach
1.4Processors only under contract
1.5What the customer chose, and no more
1.6No brokers, no enrichment
1.7Agents instructed in writing
1.8Fraud and security, for that only
2Measurement
2.1Analytics that count, not follow
2.2No per-person open or click logs
2.3Nothing loads before the visitor acts
3Using your own data
3.1Personalise, never on sensitive guesses
4The data map
4.1Every recipient, published
4.2Updated within 30 days
5Declarations and audit
5.1A director signs, every year
5.2Additions reported within 30 days
5.3Audit on 14 days’ notice
6AI services
6.1AI that doesn’t train on it
6.2AI retention, stated on the data map
6.3Business AI accounts, never personal
Pledged5 pledges, signed by a director
P-1Your price never depends on your profileP-2Leaving takes two stepsP-3A real retention scheduleP-4Apps and inboxes count tooP-5You hear it within 72 hours

One mark for each clause, heavier where a breach is Critical, and a ring for each pledge. A review walks the line from the top, every year.

01Definitions

Three ideas we use carefully

Customer data
Anything about a customer, and customers include visitors, subscribers and prospects. Names, emails, phone numbers, addresses, IP addresses, device IDs, ad click IDs. Hashed or not.
Working for you
A service that handles customer data only on your instructions and is barred by contract from using it for itself. Payments, delivery, email, hosting. Anyone else is outside the line, whoever they are.
Counting, not following
Visitor numbers in aggregate, and personalisation inside your own tools. Nothing that follows a person across days or sites.
02The rule in practice

Fine and never

Fineinside the line
A newsletter the customer asked for, sent through the company’s own email service.
Counting visitors, and which pages they read, in aggregate.
Order, payment, delivery and support details needed to serve the customer.
Fraud prevention, security, and records the law requires.
Buying ads on any platform, with any targeting it offers, as long as nothing flows back to it.
Personalising with your own data, inside your own tools: order history, recommendations, basket reminders.
Neveroutside it
Customer data sent to an ad platform: by pixel, tag, server or upload, hashed or not.
Selling, renting or swapping customer data, or buying it from data brokers.
Ad pixels and conversion tags, even ones that carry no names.
Retargeting, lookalikes and fingerprinting: anything that follows a person across days or sites.
Customer data given to AI services that train on it, or to any tool that uses it for itself.
Asking customers to “accept” being handed over. Consent doesn’t make it fine.
03Rulings

Grey areas, answered

The questions every applicant asks. The full list is in the rulings register, and every answer binds future reviews.

Our data is hashed before upload. Is that allowed?
No. Hashing hides an address in transit, but the platform matches it against its own users, so the person is identified anyway. Hashed identifiers count exactly like plain ones. (R-005)
Not allowed
What about server-side tracking or a conversions API?
The route doesn’t matter. If personal data reaches a marketing platform, from a browser or from a server, it’s outside the Standard. (R-004)
Not allowed
Can we use campaign links and promo codes?
Yes. Tagged links, discount codes and “how did you hear about us?” questions measure marketing inside your own business, without sending anyone anywhere.
Allowed
Can we still run ads on Google or social platforms?
Yes. Buy ads on any platform and use any targeting it offers from its own data. What you can’t do is feed it your customers: no pixels, no uploads, no sales sent back. (R-001)
Allowed
Do newsletter open and click tracking count?
Counts, yes. Logs, no. Aggregate open and click numbers are fine. Per-person open and click records aren’t. Our own newsletter works this way. (NFS-2.2, R-008)
Aggregate only
See all 21 rulings
04Two tiers

One verified rule, five public pledges

The rule and the data map are checked at every review. The five pledges are signed by a director and published on every member’s record.

Verified · Where data goes
Checked at every review, scanned every week
Nobody knows where their data ends up. Our members publish it.
Read the rule
Pledged
Signed by a director, published on the record
Pledge 01 · PricingYour price never depends on your profile.Pledge 02 · LeavingLeaving takes two steps.Pledge 03 · Data minimisationWe keep only what we need.Pledge 04 · Every channelApps and inboxes count too.Pledge 05 · HonestyIf something goes wrong, you hear it from us first.
05Enforcement

How it’s enforced

How reviews and removals work
One certificate
12 months
52 weekly scans, then a new review
01Automatic expiryCertification lasts 12 months. The badge shows the date it runs out, and the register flips to Lapsed on its own.
02Weekly scansEvery member’s site, every week, from more than one country, with and without consent. The last clean scan is on their record.
03ReportsAnyone can report a member, with or without proof. Staff and agency workers get a confidential channel.
04Due processNotice, 30 days to fix it, a right of reply and an appeal. Only then is a removal published, for 24 months.
06Versions

Changelog

Every change to the Standard is versioned and explained.

1.0September 2026First draft, for pilot members.
RulingsSeptember 2026R-001 to R-021 published with version 1.0, including email open and click tracking.