1. About this policy
- 1.1
This policy explains what personal information [COMPANY NAME], NZBN [NZBN], of [REGISTERED ADDRESS] (MoveMate, we, us, our) collects about you, why we collect it, who else sees it, and what you can do about it.
- 1.2
It applies to the MoveMate website and any related service we provide (the Platform), and to everyone who uses it — whether you are posting a job, bidding for one, or just browsing.
- 1.3
We are an agency for the purposes of the Privacy Act 2020, and we handle personal information in accordance with it. Nothing in this policy limits or excludes any right you have under that Act.
- 1.4
This policy sits alongside our Terms of Use. Where the two deal with the same subject, this policy governs how we handle personal information and the Terms of Use govern everything else.
- 1.5
MoveMate is a marketplace. We introduce customers to transporters; we do not carry anything ourselves. That shapes this whole document, because the most significant thing that happens to your information is that some of it is shown to the other member you are dealing with.
2. What we collect
- 2.1
Information you give us directly:
- (a)Your email address and a password when you create an account. We store the password only as a cryptographic hash and cannot read it.
- (b)Your name, and your phone number when you add one.
- (c)A company name, if you set yourself up to carry jobs as a business.
- (d)For each job you post: a title, a description, the suburb, city or region for pick-up and delivery, the dates you want, notes about access at each end, and the size of the item.
- (e)Photos and documents you upload to a job or a dispute.
- (f)For each bid you make: the amount, the dates you expect, and any message you write.
- (g)Messages you send to the other member once a booking is under way.
- (h)Reviews you write, and the reasons and evidence you provide if you open a dispute.
- (i)The version of our Terms of Use you accepted, and when you accepted it. We record this when you create your account.
- 2.2
A street address, but only if you add one. When you post a job we ask only for a suburb, city or region — we do not ask for a street address, and none is recorded. A street address is stored only where you go back and add one by editing the job. Please read clause 5.1 before you add one for an address that is not your own.
- 2.3
Information we collect indirectly, meaning from someone other than you:
- (a)What another member writes about you in a review, a message, or a dispute.
- (b)A street address that a customer supplies for a delivery to you — see section 5.
- (c)That you have opened a booking's messages, and when. We record this so the other member can see whether their message has been read.
- 2.4
Information collected automatically when you use the Platform: your IP address, your browser type, the pages you request and when, recorded in our hosting and database logs, and a cookie that keeps you signed in. Section 10 covers the cookie.
- 2.5
What we do not collect, because members sometimes assume otherwise:
- (a)Your card details. Payments are handled entirely by Stripe and we never receive or store a card number.
- (b)Driver licences, vehicle documents, insurance certificates or proof of identity. Our Terms of Use require transporters to hold these, but we do not collect them and we do not check them.
- (c)Your location. We do not use GPS, we do not track where you or your vehicle are, and we do not derive your location from your IP address.
- (d)Anything from advertising networks, data brokers or social media platforms.
- 2.6
Information we generate about you: notes our administrators record about a listing or a booking. The reason a listing was closed is shown to you on the listing itself. Our other notes, including the reason a booking was cancelled, are internal and are visible only to our administrators. Where support cancels a booking we tell you that support did it, but not the reason.
3. Why we collect it
- 3.1
To run the marketplace: to create and secure your account, to publish the jobs you post, to show your bids to the customer, and to let you both see who you are dealing with.
- 3.2
To take the deposit when a bid is accepted, and to keep a record of that payment.
- 3.3
To let two matched members contact each other, once the deposit has been paid, so the job can actually happen.
- 3.4
To publish reviews, so other members can judge who they are dealing with. Reviews are the main protection members have on this Platform, and they only work if they are attached to a real account.
- 3.5
To handle disputes, including by looking at the messages, photos and records attached to the booking in question.
- 3.6
To meet our legal obligations, including keeping business records for the periods the law requires.
- 3.7
To keep the Platform safe: to investigate misuse, to enforce our Terms of Use, and to suspend accounts where we need to.
- 3.8
We do not use your information to build a profile of you for advertising, and we do not use it for any purpose that is unrelated to running this Platform.
4. What other members can see, and when
- 4.1
This is the part of this policy most worth reading, because on a marketplace the other member is the person most likely to see your information. What they see is not the same in both directions.
- 4.2
Before a deposit is paid, a transporter looking at your job sees the job itself — its title, description, suburbs, dates, size, access notes and any photos — together with your username and your review score, or a note that you are a new customer. They do not see your name, your email address or your phone number.
- 4.3
Before a deposit is paid, a customer looking at bids on their job sees each transporter's username, their company name if they have one, their payment terms, their review score, and the message attached to the bid. They do not see the transporter's name, email or phone number.
- 4.4
Once the deposit is paid, and only between the two members on that booking, we release your names, your phone numbers and any street address recorded for the job. This is the point at which the two of you need to be able to find and contact each other. Before that point you are known to each other by your usernames.
- 4.5
If the deposit is later refunded, those details stay visible to both of you. Information that has already been exchanged cannot be un-exchanged, and cutting off contact in the middle of a dispute would make things worse rather than better.
- 4.6
Reviews are different. Once a review is published it is visible to anyone using the Platform, alongside the username on the account it is about. Section 8 explains why we do not remove published reviews on request.
- 4.7
No other member ever sees your email address, your password, or your payment records. Those are not shown anywhere on the Platform, in any state.
- 4.8
If you are not signed in you see very little. We do not publish a browsable list of open jobs, and job pages themselves are only available to signed-in members. Nothing that identifies you is shown to the public web.
5. Delivery recipients and other people's information
- 5.1
If you post a job that delivers to someone else — a relative, a buyer, a friend — and you add a street address for it, you are giving us information about that person. You should have their agreement before you do, and you should tell them that MoveMate holds their address and will pass it to the transporter you choose once the deposit is paid.
- 5.2
We hold that address for the same time as the rest of the job record. We release it to the transporter you are matched with once the deposit is paid, under the rule in clauses 4.4 and 4.5, and to no other member. Our administrators can see it in order to run the Platform, and we may have to disclose it in the limited circumstances set out in clause 6.3.
- 5.3
We usually have no way to contact a delivery recipient directly, because we do not collect their name, email address or phone number. That is why this obligation sits with you rather than with us — you are the one who knows who they are.
- 5.4
The same applies to anything else you type about another person. Descriptions, access notes, messages and dispute evidence are free text, and we cannot check what you put in them. Please do not include another person's contact details, and do not include information about anyone that they would not expect you to share.
- 5.5
If you are a delivery recipient and you want to know what we hold about you, or you want it removed, email [PRIVACY OFFICER EMAIL]. Tell us the delivery address and roughly when the delivery was arranged, and we will find the record. We will remove your address where we are not required to keep it, and we will tell you if we cannot. We do this by hand, so please allow us up to twenty working days.
7. Where your information is stored
- 7.1
Your personal information is stored in Australia. Our database and file storage are hosted by Supabase in its Sydney region.
- 7.2
Our website is served by Vercel, which operates a global network, so the servers handling your requests and their logs may be located outside New Zealand and outside Australia.
- 7.3
Stripe processes payments on its own infrastructure, which is located outside New Zealand, principally in the United States.
- 7.4
This means your personal information is held and processed outside New Zealand. We rely on our agreements with these providers to require them to protect it to a standard comparable to the safeguards in the Privacy Act 2020.
- 7.5
Information held overseas may be accessible to the courts, law enforcement and regulators of the country it is held in, under the laws of that country. We cannot prevent that.
8. How long we keep it
- 8.1
We keep your account information — your name, email address, phone number and company name — for as long as your account is open, and for two years after it is closed, so that we can deal with anything arising from jobs you were involved in.
- 8.2
We keep records of transactions, including bookings, deposits and payment references, for seven years. We are required to keep business records for that period under the Tax Administration Act 1994.
- 8.3
We keep job records, messages, photos and dispute material for as long as the booking they relate to may still give rise to a claim, and for two years after the job is completed or cancelled. Where a dispute is on foot, we keep everything relating to it until the dispute is resolved and any period for challenging that resolution has passed.
- 8.4
We keep published reviews indefinitely. A review is the record other members relied on when they decided whether to deal with someone, and removing it later would misrepresent that history. Clause 11.6 explains what we will and will not do about a review you disagree with.
- 8.5
We keep our hosting and database logs for as long as our providers retain them. These periods are set by Supabase and Vercel rather than by us.
- 8.6
You can ask us to delete your information at any time by emailing [PRIVACY OFFICER EMAIL]. We will delete what we are not required to keep, and we will tell you what we have kept and why. We do this by hand rather than through a button in the Platform, so please allow us up to twenty working days.
- 8.7
These are the periods we work to, not periods enforced by software. We have no automatic deletion job: information stays in our systems until we remove it by hand, which in practice means when you ask us under clause 8.6, or when we do a periodic clear-out. We would rather tell you that than imply a tidiness we do not have.
9. Keeping it safe
- 9.1
Your information is protected in transit by encryption, and it is encrypted at rest by our database and storage providers.
- 9.2
Access to each record is enforced in the database itself, not merely in the website. Our tables carry row-level security rules that decide who may read each row, and where a row must stay readable for other reasons, the sensitive columns are withheld at the grant level instead. Either way a member cannot reach another member's information by going around the website.
- 9.3
The release of contact details and street addresses described in section 4 is enforced in the database too. Those columns are not readable by members at all; they are served only through views that apply the deposit test in SQL. It is a database rule tied to the deposit being paid, not a display setting.
- 9.4
Only people who need access in order to operate the Platform have it, and administrative access is limited to that purpose.
- 9.5
We are not certified against any information security standard and we have not been independently audited. We would rather say so than imply otherwise. No system is completely secure, and we cannot guarantee that your information will never be accessed by someone who should not have it.
- 9.6
If a privacy breach happens that could cause you serious harm, we will notify you and the Office of the Privacy Commissioner, as Part 6 of the Privacy Act 2020 requires.
11. Getting a copy, and correcting it
- 11.1
You have the right to ask us for the personal information we hold about you, and the right to ask us to correct it if it is wrong. These rights come from the Privacy Act 2020 and this policy does not limit them.
- 11.2
Most of what we hold is already visible to you when you are signed in: your account details, your jobs, your bids, your bookings and your messages. If you want the rest, or you want it in one place, email [PRIVACY OFFICER EMAIL].
- 11.3
We will respond within twenty working days, as the Act requires. If we need longer we will tell you why, and when to expect an answer.
- 11.4
We will not charge you for a reasonable request. If a request is unusually large or repetitive we may charge for the extra work, and we will tell you what it will cost before we do anything.
- 11.5
There are circumstances in which the Act allows us to refuse. The most likely one here is that the information is also about another member — their messages, their review of you, their side of a dispute — and releasing it would breach their privacy. Where we refuse, we will tell you which ground we are relying on, and you can complain about that decision.
- 11.6
You can correct your name, phone number and company name yourself in your account. For anything else, email us and we will correct it. If we disagree that something is wrong, you can ask us to attach a statement of your view to the record, and we will.
12. Complaints
- 12.1
If you think we have mishandled your personal information, tell us first. Email [PRIVACY OFFICER EMAIL] with what happened, and we will investigate and respond within twenty working days.
- 12.2
If you are not satisfied with our response, or you would rather not come to us at all, you can complain to the Office of the Privacy Commissioner. You do not need our permission and you do not need to complain to us first.
- 12.3
The Office of the Privacy Commissioner can be reached at privacy.org.nz, by email at enquiries@privacy.org.nz, or by phone on 0800 803 909.
13. Changes to this policy
- 13.1
We will update this policy when what we do with personal information changes. The version number and the date at the top of the page tell you which version you are reading.
- 13.2
Where a change materially affects how we handle your information, we will give you notice on the Platform before it takes effect. We do not currently send email notifications of any kind.
- 13.3
If you keep using the Platform after a change takes effect, that is how we will treat you as having accepted it. If you do not accept it, you can ask us to close your account and delete what we are not required to keep.
14. Contact us
- 14.1
Our privacy officer is responsible for how we handle personal information, and is the person to contact about anything in this policy. Email [PRIVACY OFFICER EMAIL].
- 14.2
For anything else, including questions about a job or a booking, email [CONTACT EMAIL].
- 14.3
Our postal address is [REGISTERED ADDRESS].