Privacy Policy
Version 1.2 · Last updated 4 October 2026 · Written to meet the New Zealand Privacy Act 2020
1. Who we are
AuraPier Tech (“we”, “us”) runs this website and Client Hub. We are responsible for the personal information described below. Our privacy contact is the contact in the footer of this page; send privacy questions, access, correction or deletion requests there.
2. Two kinds of people this covers
- Our customers (people with a Client Hub account) and people who contact us through the website.
- Our customers’ own clients and contacts. Customers store details about their clients in Client Hub. For that information the customer decides why and how it is used; we only store and process it on the customer’s behalf, to provide the Service. If you are on a business’s client list and want your details corrected, removed or not to be emailed, ask that business first. Every email sent through Client Hub has an unsubscribe link, and if you cannot reach the business you can contact us and we will help.
3. What we collect and why
| Information | Why |
|---|---|
| Account: email, optional name, a salted hash of your password (never the password), the time and version of Terms you accepted | To create and secure your account and keep a record of your agreement |
| Licence key and its dates | To provide and enforce your licence |
| Your clients’ details and notes that you enter | To provide the Service to you |
| Calendar events you create (title, times, location, notes, optional linked client), if the calendar is enabled for you | To provide the calendar feature |
| Jobs, quotes and invoices you create (customer, address, line items, amounts, GST, notes), and the business details you enter for them (business name, GST number, address, phone, email and bank account number), if UteWise (our quotes and invoices tool) is enabled for you | To provide UteWise |
| When one of your customers opens or answers a quote or invoice link: the name they type to accept, the time, and (briefly, for rate limiting) their IP address | To record acceptance, show the right document and protect the links from abuse |
| Notification settings: your browser’s push address (an endpoint URL) for each device where you turn reminders on, your time zone, and the reminders queued for you | To deliver event reminders to your devices |
| Linked email connection (an app password or access token, stored encrypted) and your email address | To send the messages you tell us to send |
| Send log: recipient address, time, success or failure (not message content) | To apply sending limits, prevent abuse and show you counts |
| Contact-form messages: name, email, message | To reply to your enquiry |
| Unsubscribe records | To stop emailing people who have opted out |
| Technical data: a sign-in cookie, and your IP address held briefly in memory for rate limiting; standard server logs | To keep you signed in and protect the Service from abuse |
We collect this directly from you (or, for client details, from our customers). We do not buy personal information, sell it, use it for advertising, or build profiles.
4. Email access
A linked email account is used only to send messages you explicitly choose to send. We do not read, scan or download your inbox. You can unlink at any time in Settings, which deletes the stored credentials (and revokes access with Google where applicable). We also recommend revoking the app password with your email provider.
5. Who we share it with
- Your email provider (for example Google, Microsoft, Yahoo, Apple or your own mail server) receives the messages you send, under its own privacy policy.
- Our hosting provider stores the data on our behalf (see section 6). It may not use it for its own purposes.
- Browser notification services (if you turn on reminders): reminders are delivered through your browser maker’s push service (for example Google, Apple or Mozilla). We send it a short content-free signal addressed to your device. The reminder text itself is fetched by your device directly from us, so the push service never sees your events. You can turn this off at any time in Settings, which deletes the device address from our records.
- Payments (Stripe): if you buy a plan, you pay on a page run by Stripe Payments, not by us. Stripe collects your card details, name and email and sends us confirmation that you paid (we never see or store your full card number). Stripe is an independent payment provider and may handle your information in other countries under its own privacy policy. We match your payment to your account by the email you used.
- Maps (calendar feature): when you use “Find address”, the address text you type is sent from our server to OpenStreetMap’s search service (Nominatim) to find its location. When you open an event that has a map, your browser loads a small map from openstreetmap.org, which will see your IP address. Clicking “Start directions” opens Google Maps (or Apple Maps on iPhone) with the destination, under their privacy policies. No map or address service is contacted unless you use those features.
- Your customers (UteWise quotes and invoices): a quote or invoice you send shows your business details (on invoices, including the bank account number you entered) and your customer’s name to anyone who has that document’s private link. Links use a long random key, are not indexed by search engines, and stop working if you delete the quote or your account.
- Our website administrators can see account emails, licence status, usage counts and contact-form messages. The admin tools do not display your clients’ details or notes.
- We disclose information if the law requires it or to protect people from serious harm.
Our pages load no third-party scripts, fonts or trackers; all code is served from our own server. The only third-party content is the optional map shown on a calendar event, described in section 5.
6. Where your information is stored
Our servers are hosted by Vultr in Sydney, Australia, so your information is stored outside New Zealand. We take reasonable steps to make sure it is protected with safeguards comparable to the Privacy Act. Messages you send are delivered by your own email provider, which may process them in other countries.
7. How long we keep it
- Quotes, invoices, jobs and business details: while your account exists, or until you delete them (sent invoices can be voided but not deleted). We are not a long-term archive, so download any records you must keep for tax purposes.
- Account, clients, notes and licence details: while your account exists. You can delete clients or notes yourself at any time, and delete your whole account in Settings (or ask us to).
- Send log: 90 days. Website enquiries: 24 months, then deleted. Sessions: expire after 14 days.
- Unsubscribe records stay with the client record so opted-out people are not emailed again; they are deleted with it.
- After you delete your account we remove your account data and linked mail connection. Routine server backups, if any, are overwritten on a rolling basis.
8. Security
Passwords are hashed, sessions use secure cookies, stored mail credentials are encrypted at rest, accounts are isolated from each other, traffic uses HTTPS and sign-in attempts are rate-limited. No system is perfectly secure, so please use a strong, unique password. If a privacy breach is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and the people affected as the Privacy Act requires.
9. Your rights
You can ask for a copy of the personal information we hold about you and ask us to correct it. Account holders can download their data and delete their account in Settings; otherwise contact us and we will respond within 20 working days. If you are in the EU or UK you may have additional rights (for example erasure and portability) and we will honour them. If you are unhappy with how we handle your information, please contact us first; you can also complain to the Office of the Privacy Commissioner (privacy.org.nz).
10. Children
The Service is for businesses and adults. It is not directed at anyone under 18 and we do not knowingly collect their information.
11. Cookies
We use one essential cookie (“sid”) to keep you signed in. We use no advertising or analytics cookies, so there is no cookie banner to dismiss.
12. Changes
If we make a material change to this policy we will tell account holders by email or in the app before it takes effect. The date above shows the latest version.