The Nullware Standard0 trackers on this page
The Nullware Standard · version 1.0 · full text

Every rule, numbered.

The Standard page says it plainly. This is the same Standard written so reviewers, members and contracts can cite it. Where the two ever differ, this page wins.

Version 1.0Draft for pilot members · September 2026Next review September 2027
The rule
Customer data goes only to people working for you. Never to anyone who uses it for themselves or for advertising, whatever the route and whatever the customer clicked.
01Reading guide

How to read it

“Must” and “must not” are requirements. “May” is a permission. Every clause has an ID, the evidence we check and a severity.

Verified tier
The rule and the data map
Clauses NFS-1 to NFS-6. Checked with evidence at review, and scanned every week while a member is certified.
Pledged tier
Five public pledges
Pricing, leaving, minimisation, every channel, incidents. Signed by a director, published on the record, acted on when a concern is reported.
Rulings
Grey areas, decided
Each answer to a grey-area question gets a number and a date, and binds every future review.
Read more
02Definitions

Definitions

Customer
Anyone the member deals with, or who interacts with it: website and app visitors, prospects, newsletter subscribers, buyers and former buyers.
Customer data
Any information about a customer. Names, emails, phone numbers, addresses, IP addresses, device and advertising IDs, cookie IDs and ad click IDs, in plain, hashed, encrypted or tokenised form.
Processor
A service that handles customer data only on the member’s documented instructions, and is barred by contract from using it for itself.
Own use
Anything that serves the recipient rather than the member: building profiles, improving its products across clients, reselling.
Advertising use
Targeting, audience building, lookalikes, suppression lists, attribution, conversion measurement, bid optimisation, or training models for any of these.
Agent
An agency, contractor or freelancer acting for the member, including anyone with access to its ad accounts.
Scope
The legal entity, brands, domains, apps and countries listed on the member record. Everything in scope is certified. Nothing outside it is.
Verified
Checked at review with evidence, and scanned every week while certified.
Pledged
Signed by a director and published on the member record. Acted on when a concern is reported.
03Verified tier

Verified tier: the clauses

Evidence is screenshots or a screen-share. We never ask for passwords.

1 · Where customer data goes
ID
Requirement
Evidence we check
Severity
NFS-1.1
The member must not disclose customer data to any recipient for own use or advertising use.
Signed declaration; scans; ad account settings
Critical
NFS-1.2
The route does not matter. NFS-1.1 covers pixels, tags, SDKs, server-side APIs, list uploads, offline conversion imports, enhanced conversions, clean rooms and partner integrations.
Conversion settings; audience lists (must be empty); integration list
Critical
NFS-1.3
Consent does not cure a breach. NFS-1.1 applies even when the customer has agreed.
Consent tool configuration
Critical
NFS-1.4
The member may disclose customer data to processors, under a written contract that bars own use and advertising use, with every feature that allows either switched off.
Contract sample; screenshots of switched-off features
Major
NFS-1.5
Where the customer chooses a third party themselves, such as a payment method, a messaging app or a marketplace, the member may pass what that interaction needs and nothing more.
Integration list; checkout walkthrough
Major
NFS-1.6
The member must not buy, rent or receive customer data from data brokers, or enrich its records with third-party data.
Declaration; vendor list
Critical
NFS-1.7
The member is responsible for its agents, and must instruct each of them in writing to follow the Standard.
Written instruction to each agent
Critical
NFS-1.8
The member may share customer data with fraud and security services, for fraud prevention and security only.
Vendor terms; category on the data map
Major
2 · Measurement
ID
Requirement
Evidence we check
Severity
NFS-2.1
Visitor analytics must be aggregate. No identifier may link a person across days or sites, and IP addresses must be discarded after processing.
Scans; analytics configuration
Major
NFS-2.2
The member must not keep per-person email open or click logs. Aggregate counts are fine.
Email tool settings
Major
NFS-2.3
Pages must not load anything from an advertising company before the visitor acts: video, map and social embeds, fonts, captchas, social login. Self-host or click-to-load.
Scans with and without consent
Major
3 · Using your own data
ID
Requirement
Evidence we check
Severity
NFS-3.1
The member may personalise with its own customer data inside its own systems and processors: order history, recommendations, basket reminders. It must say so in its privacy notice, and must not build on sensitive inferences such as health, sex life, religion, politics, ethnicity, financial distress, pregnancy or children.
Privacy notice; sample of segments
Major
4 · The data map
ID
Requirement
Evidence we check
Severity
NFS-4.1
The member must publish a data map listing every recipient of customer data: what it gets, why, its role and its country. Fraud and security vendors may be listed by category, with names given to the reviewer.
Data map on the member record
Major
NFS-4.2
The member must update the data map within 30 days of any change.
Change log
Minor
5 · Declarations and audit
ID
Requirement
Evidence we check
Severity
NFS-5.1
A director must sign the declaration on application, at every annual review and after any material change.
Signed declaration
Critical
NFS-5.2
The member must tell Nullware Project within 30 days of adding a domain, app, brand or agent.
Notification record
Minor
NFS-5.3
The member must allow an audit on 14 days’ notice, including a read-only look inside its ad accounts.
Membership terms
Critical
6 · AI services
ID
Requirement
Evidence we check
Severity
NFS-6.1
Customer data may go only to AI services whose terms bar training on it.
Provider terms; account type
Critical
NFS-6.2
The data map must state each AI provider’s maximum retention period. Zero retention is not required.
Provider terms
Minor
NFS-6.3
Staff must use business accounts, never personal ones, for any task involving customer data, under a written staff AI-use policy.
Policy; account list
Major
04Pledged tier

Pledged tier: the five pledges

Each moves into the verified tier once we can check it at scale. A proven broken pledge is treated as a Major breach.

P-1 · Pricing
Your price never depends on your profile.
Prices and offers follow published rules, never a prediction of what you would pay.
Read more
P-2 · Leaving
Leaving takes two steps.
Cancel online from the account page, no call or chat, confirmation at once.
Read more
P-3 · Minimisation
A real retention schedule.
A period for every kind of data, deletion that actually runs, backups that age out.
Read more
P-4 · Every channel
Apps and inboxes count too.
The Standard follows the customer into apps, email, loyalty and in-store systems.
Read more
P-5 · Incidents
You hear it within 72 hours.
Unauthorised access to customer data is told to the people affected, and recorded publicly.
Read more
05Severity

Severity

01
Critical
A breach of the core rule. Suspension at once while we look into it. Removal if it isn’t fixed within 30 days, or if it was deliberate or hidden.
02
Major
Must be fixed within 30 days. If it isn’t, suspension, then removal.
03
Minor
Must be fixed before the next annual review.
06Versions

Versions and rulings

01
Six months to adapt
Every version has a number and a start date. Members get six months to meet a new one, and can leave in that time without it counting against them.
02
Rulings bind
A ruling applies to every future review. Only a later, published ruling can replace it.
03
Benefit of the doubt
Where the text is genuinely unclear, the member gets the benefit of the doubt until a ruling closes the gap. Nobody is removed for breaking a rule that wasn’t written down.
Ready to check yourself against it?

The self-check takes five minutes and tells you what, if anything, to change first.

Take the self-checkApply to join