Sweet as Goods – Privacy Policy
Last Updated: 02 July 2025
Governing Law: Privacy Act 2020 (NZ)
1. Information We Collect
We collect data to provide “sweet as service”:
- Personal Data: Name, email, shipping/billing address, phone number.
- Order Details: Products purchased, payment method (no card storage), GST invoices.
- Technical Data: IP address, browser type, cookies (for site functionality).
- Vendor Data: Business name, bank details (for payouts), product listings.
2. How We Use Your Data
Purpose
- Process orders & payments
- Ship products (Self & NZ Post)
- Send marketing emails
- Prevent fraud
- Improve website UX
Legal Basis
- Legal Basis
- Legitimate business interest
- Consent (opt-in required)
- Legal obligation
- Consent via cookie banner
3. Data Sharing & Third Parties
We only share when essential:
- Vendors: Shipping address for order fulfillment (vendors sign NDAs).
- Payment Processors: PayPal, Stripe (PCI-DSS compliant).
- Shipping Partners: Self Service, and NZ Post.
- Legal Compliance: If required by NZ courts or police.
We never sell your data.
4. Data Storage & Security
- Location: Encrypted servers in Australia/NZ (GoDaddy VPS Server).
- Retention:
- Order data: 1 year (NZ tax law).
- Inactive accounts: Deleted after 1 year
- Protection: SSL encryption, regular security audits, staff training
5. Your Rights (Privacy Act 2020)
You have the right to:
- Access: Request a copy of your data.
- Correct: Update inaccurate details (e.g., address).
- Delete: Ask for erasure (unless required for legal/tax purposes).
- Opt-Out: Unsubscribe from marketing (link in every email).
- Complain: Contact NZ Privacy Commissioner (privacy.org.nz).
6. Cookies & Tracking
- Essential Cookies: Cart functionality, login sessions (no consent needed).
- Analytics: Google Analytics (anonymized IPs). Opt-out via cookie banner.
- Marketing Cookies: Facebook Pixel – enabled only with consent.
- We do not target users under 16.
- Accounts for under-16s require parental consent.
- Data stays in NZ/AU unless you’re overseas (e.g., EU → GDPR-compliant partners).
9. Vendor Data Responsibilities
Vendors must:
- Use customer data only for order fulfillment.
- Delete shipping data after 90 days.
- Report breaches to us within 24 hours.
10. Policy Updates
We’ll notify users of changes via email or site banners.
11. Vendor Responsibilities
- Vendors must:
- Accurately describe products.
- Fulfill orders within 24 hours.
- Comply with NZ safety/labeling laws (e.g., fiber content tags).
12. Dispute Resolution
- Negotiation: Contact us at sweetasgoodsnz@gmail.com.
- Mediation: If unresolved, parties agree to NZ-based mediation.
- Courts: Claims may be filed in NZ courts
13. Amendments
We may update these Terms. Continued use = acceptance.
11. Contact Us
Privacy Officer: SHAHZADA SALEEM
Email: sweetasgoodsnz@gmail.com
Phone: 0274 775 816
Address: 19 Frost Road, Mount Roskill, 1041 Auckland, New Zealand
Key NZ Legal Safeguards
Business Protection
- Limits liability for vendor data breaches
- Allows data use for fraud prevention
- Retains order data for GST compliance
Customer
- Guarantees access/deletion rights (IPP 6 & 7)
- Requires explicit consent for marketing (IPP 4)
- Enforces data anonymization (IPP 12)