Privacy policy

Draft — under owner review.

This policy explains how NewCo collects, uses, stores, and shares personal information when you apply for a website or work with us. For information collected through this site, NewCo is the agency under the Privacy Act 2020.

Information we collect

Our application form may collect:

  • your name, business name, email address, mobile number, and region;
  • whether you consent to marketing;
  • the services you select and any free-text project context you provide;
  • your contact preference and preferred callback times;
  • UTM campaign parameters and the referring page; and
  • a salted hash derived from your IP address for abuse prevention. We do not store the raw IP address in the application row.

Please do not put passwords, access keys, payment information, or other sensitive credentials in the free-text field. If a project proceeds, we will request necessary access through a separate secure channel and keep client credentials isolated from other client work.

Why we collect and use it

We use application information to assess and process your application, contact you about it, prepare the scoping-call agenda, deliver requested services, maintain business records, attribute campaigns, understand funnel performance, and prevent spam or excessive submissions. Providing the required contact details is necessary for us to process the application; optional selections and project context help us prepare.

We send service messages about your application because they are needed to respond to your request. We send separate marketing messages only where we have a defensible consent basis under the Unsolicited Electronic Messages Act 2007. Marketing messages will identify NewCo accurately and include a working unsubscribe method. You can withdraw marketing consent at any time by using that method or contacting us. Withdrawal does not affect application-related messages already required to handle your request.

Storage, processors, and safeguards

Application data is stored in a dedicated Supabase database protected by deny-all row-level security and accessed only by authorised server-side services. Supabase and other service providers may process information outside New Zealand. The planned production database region is Sydney, Australia; the owner must confirm the final region before launch. We use reasonable technical and organisational safeguards and limit provider access to what is needed to supply the service.

If a privacy breach occurs, we will contain and assess it, keep the records required by law, and notify the Office of the Privacy Commissioner and affected people when the Privacy Act 2020 requires us to do so.

Retention, deletion, and export

We keep personal information only for as long as it is needed for the purposes above or to meet legal obligations. As a draft operating schedule, unprogressed partial applications are deleted after 90 days, other application records after 24 months from the last interaction, and contractual or tax records for the period required by New Zealand law. The owner must approve this schedule before launch. We then securely delete or de-identify information unless continued retention is required.

At the end of a client engagement, customer data is included in the agreed export where applicable and is deleted from systems we control after the handover and any legally required retention period. Third-party processors may retain backups for their documented backup cycles.

Your access and correction rights

You may ask for access to personal information we hold about you and ask us to correct it. You may also request deletion where we have no lawful reason to keep it. We may need to verify your identity and may withhold information only where the Privacy Act 2020 permits.

Client websites and analytics

For a client website, the contract will define whether the client or NewCo is responsible for particular information. Analytics and tracking defaults are decided and documented for each site. Routing data through a first-party domain does not itself create permission to collect or use it.

Contact

To withdraw marketing consent or request access, correction, deletion, or an export, use the contact page — or the three-minute application, noting your request in the form. A verified contact address will be published here before launch.