Legal

Terms & Privacy

Effective January 1, 2025 Last updated May 29, 2026

Plattr Limited · NZBN 9429053737694
53 Ngae Place, Mangere East, Auckland 2024, New Zealand
www.plattr.nz · hello@plattr.nz

Terms of Service

Effective January 1, 2025 · Last updated May 29, 2026

1. Introduction & Acceptance of Terms

1.1 These Terms of Service (“Terms”) govern your use of Plattr (“the Service”), a cloud-based operating system for food businesses including point-of-sale (POS), online ordering, delivery management, loyalty programs, and marketing automation, operated by Plattr Limited (NZBN 9429053737694) (“we,” “us,” “our,” or “Plattr”), a company incorporated in New Zealand with its registered office at 53 Ngae Place, Mangere East, Auckland 2024. Plattr is offered to businesses in New Zealand and internationally.

1.2 By accessing, browsing, or using Plattr (including our website, applications, APIs, and services), you agree to be bound by these Terms. If you do not agree to these Terms, do not use the Service.

1.3 Plattr is based in New Zealand and the Service is provided from New Zealand. These Terms are governed by New Zealand law, including the Consumer Guarantees Act 1993, the Fair Trading Act 1986, the Contract and Commercial Law Act 2017, and the Privacy Act 2020 (see Sections 6, 7, 9 and 13). Where you, your business, or your customers are located outside New Zealand, you are responsible for ensuring that your use of the Service — and your collection, use and handling of your customers’ information — complies with the laws that apply to you in those places.

1.4 If you are using Plattr on behalf of a business, organization, or entity, you represent and warrant that you have the authority to bind that entity to these Terms.

2. Definitions

  • “Account” means your Plattr account, including all data, settings, and configurations.
  • “Business Data” means all data you input into Plattr, including menu items, pricing, customer information, orders, loyalty data, and payment information.
  • “Confidential Information” means non-public information disclosed by either party to the other in connection with the Service.
  • “Customer or You” means the individual, business, or entity that uses Plattr.
  • “End Users” means your staff, customers, and any third parties who interact with your Plattr account or storefront.
  • “Fees” means subscription, transaction, and usage fees you agree to pay as described in your plan.
  • “Intellectual Property (IP)” means patents, trademarks, copyrights, trade secrets, and all other intellectual property rights.
  • “Service” means Plattr and all associated features, APIs, documentation, and support.
  • “Subscription Term” means the period for which you have subscribed to Plattr (e.g., monthly, yearly).

3. Subscription & Payment

3.1 Subscription Plans: Plattr offers tiered subscription plans (Basic, Standard, Plus) with varying features, locations, staff seats, and usage limits. Plans are offered on a monthly or annual basis.

3.2 Pricing & Fees:

  • (a) Prices shown to New Zealand customers include GST at the prevailing rate (currently 15%). For customers outside New Zealand, prices are exclusive of local taxes (such as VAT, GST, or sales tax), which we add or collect where we are required to do so. The tax applied to each payment is itemised on your invoice.
  • (b) Annual plans receive a discount compared to monthly equivalents. You agree to the annual billing cycle in advance.
  • (c) Promotional pricing or trial offers are limited in duration and non-refundable.
  • (d) We reserve the right to modify Fees with 30 days’ written notice. Changes take effect at the start of your next billing cycle.
  • (e) Additional fees may apply for overage usage (e.g., orders, email sends, SMS, storage), usage-based add-ons (domains, extended seats), and third-party integrations.

3.3 Payment Methods & Processing:

  • (a) Payments are collected via Stripe or other authorized payment processors.
  • (b) You authorize us to charge your payment method on a recurring basis for your Subscription Term.
  • (c) Payment card information is never stored on Plattr servers; all processing is PCI-DSS compliant and handled by third-party processors.
  • (d) Failed payments may result in account suspension. We will notify you of payment failures and provide a grace period before suspension.
  • (e) You are responsible for maintaining accurate payment information.

3.4 Invoicing: Invoices are sent electronically. You can download and print invoices from your Plattr dashboard at any time.

3.5 No Refunds: Subscription fees are non-refundable. Upon cancellation, you retain access to your Account through the end of your paid Subscription Term, and your data is retained for 30 days before permanent deletion.

4. Use License & Restrictions

4.1 Limited License: We grant you a non-exclusive, non-transferable, revocable license to use Plattr solely for operating your food business in accordance with these Terms and your subscription plan.

4.2 Permitted Uses:

  • (a) Operating your point-of-sale system, accepting orders, and managing customer data
  • (b) Managing menus, inventory, staff, and locations
  • (c) Running loyalty programs, email campaigns, and SMS promotions
  • (d) Integrating with third-party services (e.g., Stripe, Instagram, Mailchimp)
  • (e) Customizing your storefront, website, and branding

4.3 Prohibited Uses: You may not:

  • (a) Use Plattr for any unlawful purpose or in violation of applicable laws
  • (b) Reverse-engineer, decompile, or attempt to derive the source code or algorithms
  • (c) Circumvent security measures, access unauthorized areas, or exploit vulnerabilities
  • (d) Scrape, crawl, or automate access without prior written consent
  • (e) Transmit malware, viruses, worms, or any code of malicious intent
  • (f) Spam, phish, or send unsolicited communications outside of lawful marketing using Plattr features
  • (g) Impersonate any person or entity, or misrepresent your identity
  • (h) Sell, resell, or distribute Plattr to third parties without express written permission
  • (i) Use Plattr to collect or process payments illegally or fraudulently
  • (j) Harass, defame, or violate the rights of others
  • (k) Violate the Acceptable Use Policy or any additional terms published on our website

4.4 Consequences of Violation: Violations may result in immediate account suspension or termination without refund, legal action, and liability for damages.

5. Intellectual Property Rights

5.1 Plattr IP: All content, features, functionality, code, and design of Plattr are owned by Plattr Limited or its licensors. This includes but is not limited to software, documentation, trademarks, logos, and compilation of information.

5.2 Your IP Rights: You retain all rights to your Business Data and customer content (e.g., menu photos, descriptions, customer reviews). You grant us a limited license to use, reproduce, and display your data solely to provide the Service and improve our features.

5.3 Feedback License: Any feedback, suggestions, or ideas you provide to us become our property without compensation or obligation.

5.4 Third-Party Content: Some content in Plattr (fonts, icons, images) may be licensed from third parties. Your use is subject to those third-party licences.

5.5 Copyright complaints: We respect copyright and comply with the Copyright Act 1994. If you believe material on the Service infringes your copyright, email hello@plattr.nz with enough detail to identify the material, your contact details, and a statement of your rights, and we will investigate and, where appropriate, remove the material.

6. Warranties & Disclaimers

6.1 Limited Warranty: We warrant that Plattr will substantially conform to its published specifications and that we will provide the Service in a professional manner consistent with industry standards.

6.2 Service Availability: Plattr aims for 99.5% uptime (excluding scheduled maintenance). We make no guarantee regarding availability, and we reserve the right to perform maintenance without advance notice. Planned maintenance windows are typically announced 48 hours in advance.

6.3 DISCLAIMER: EXCEPT AS EXPRESSLY PROVIDED ABOVE, PLATTR IS PROVIDED “AS IS” AND “AS AVAILABLE” WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED. 6.4 WE DISCLAIM ALL IMPLIED WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, AND TITLE.

6.5 We do not warrant that:

  • (a) The Service will be uninterrupted, error-free, or free from malware
  • (b) Any defects will be corrected within a specified time
  • (c) Third-party integrations will function perfectly at all times
  • (d) Your data will never be lost or corrupted

6.6 Consumer Guarantees Act 1993 & Fair Trading Act 1986 (New Zealand):

  • (a) Where you acquire the Service for the purposes of a business, you agree that the guarantees and remedies in the Consumer Guarantees Act 1993 do not apply, to the maximum extent permitted by section 43 of that Act, and that sections 9, 12A, 13 and 14(1) of the Fair Trading Act 1986 do not apply, to the maximum extent permitted by section 5D of that Act. You confirm that it is fair and reasonable for those provisions not to apply, given the nature of the Service and its price.
  • (b) Nothing in these Terms excludes, restricts or modifies any guarantee, right or remedy you may have under the Consumer Guarantees Act 1993, the Fair Trading Act 1986, or any other New Zealand law, where doing so cannot lawfully be excluded, restricted or modified. Where a guarantee cannot be excluded but our liability for a failure to comply with it can be limited, our liability is limited as set out in Section 7.

6.7 Consumers in Australia and other countries:

  • (a) Australia. Nothing in these Terms excludes, restricts or modifies any consumer guarantee, right or remedy under the Australian Consumer Law (Schedule 2 to the Competition and Consumer Act 2010 (Cth)) or any similar law that cannot lawfully be excluded. Where the Australian Consumer Law applies and permits us to limit our liability for failing to comply with a guarantee (other than one that cannot be so limited), our liability is limited, at our option, to resupplying the Service or paying the cost of having it resupplied.
  • (b) Everywhere else. If you acquire the Service as a consumer under the mandatory law of your country of residence, you keep the benefit of any consumer rights and remedies that law gives you and that cannot lawfully be excluded. The disclaimers in this Section 6 and the limits in Section 7 apply only to the extent that law allows.

7. Limitation of Liability

7.1 TO THE MAXIMUM EXTENT PERMITTED BY LAW, PLATTR SHALL NOT BE LIABLE FOR: (a) ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, OR PUNITIVE DAMAGES; (b) LOST PROFITS, REVENUE, DATA, OR BUSINESS INTERRUPTION; (c) COST OF SUBSTITUTE GOODS OR SERVICES; (d) ANY CLAIMS ARISING FROM THIRD-PARTY SERVICES OR INTEGRATIONS; (e) EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

7.2 Cap on Liability: Subject to Section 7.4 and to any mandatory consumer-protection law that applies to you, and except for indemnification obligations or breaches of confidentiality, Plattr’s total aggregate liability shall not exceed the fees you paid in the 12 months immediately preceding the claim.

7.3 Essential Basis: You acknowledge that these limitations are essential to Plattr’s pricing model and are a fundamental part of our agreement.

7.4 Exceptions: Nothing in these Terms limits liability for: (a) death or personal injury caused by negligence, (b) fraud or fraudulent misrepresentation, (c) statutory rights that cannot be excluded or limited under applicable law, or (d) indemnification obligations set out in Section 8.

8. Indemnification

8.1 You agree to defend, indemnify, and hold harmless Plattr and its officers, directors, employees, and agents from and against any and all claims, losses, liabilities, damages, costs, and expenses (including reasonable legal costs on a solicitor-and-own-client basis) arising from or related to:

  • (a) Your use or misuse of Plattr
  • (b) Your violation of these Terms or applicable laws
  • (c) Your infringement of third-party intellectual property rights
  • (d) Your Business Data, customer data, or content uploaded to Plattr
  • (e) Unlawful activities, fraud, or misconduct by you or your staff
  • (f) Claims from your customers or third parties related to your business operations
  • (g) Non-compliance with laws including payment processing, employment, and consumer protection laws

8.2 Plattr reserves the right to assume sole control of the defence at your expense. You agree to cooperate fully with our defence.

9. Data Protection & Security

9.1 Data Responsibility: You are the data controller for all personal data you process through Plattr. You are responsible for ensuring your use of Plattr complies with all privacy and data protection laws that apply to you — in particular the Privacy Act 2020, and, where your customers are located outside New Zealand, any privacy or data protection laws that apply to them.

9.2 Data Processing Agreement: Under the Privacy Act 2020 you are the agency responsible for the personal information you collect, and we handle it on your behalf as your service provider. If you require a written data processing agreement — for example because you also serve customers in the EU or UK — a standard DPA is available on request at hello@plattr.nz.

9.3 Security Measures: We implement industry-standard security measures including encryption (TLS 1.2+, AES-256), access controls, regular backups, and security audits. However, no system is 100% secure.

9.4 Your Responsibility: You are responsible for:

  • (a) Maintaining secure account credentials and not sharing passwords
  • (b) Enabling two-factor authentication (2FA) where available
  • (c) Promptly reporting any unauthorized access to hello@plattr.nz
  • (d) Complying with all applicable privacy laws for your end users and customers
  • (e) Training your staff on appropriate use and security practices

9.5 Privacy Breach Notification: We will notify you as soon as practicable after we become aware of any confirmed unauthorized access to your data. Where the breach is one that has caused, or is likely to cause, serious harm, we will assist you to meet your obligations under Part 6 of the Privacy Act 2020, including notifying the Office of the Privacy Commissioner and affected individuals. You remain responsible for notifying your own customers and any regulators that apply to them.

9.6 Data Retention: Upon account termination, we retain your data for 30 days, during which you may export it. After 30 days, data is permanently deleted. You are responsible for backing up your data before termination.

10. Termination & Suspension

10.1 Termination by You: You may terminate your subscription at any time through your account settings or by contacting support. Termination is effective at the end of your current billing cycle. No refunds are issued for the remaining portion of the cycle.

10.2 Termination by Plattr: We may terminate your account immediately and without liability if:

  • (a) You materially violate these Terms and fail to remedy the breach within 14 days of notice
  • (b) Payment fails and remains unpaid after a 30-day grace period
  • (c) Your account is used for unlawful, fraudulent, or abusive purposes
  • (d) We reasonably determine that your account poses a security risk to Plattr or other customers
  • (e) We cease offering the Service (with 30 days’ advance notice where reasonably practicable)

10.3 Suspension: We may suspend your account without notice if your account presents an immediate security risk, is subject to a legal order or regulatory requirement, or involves suspected payment processing violations. We will notify you promptly after any suspension and provide an opportunity to respond.

10.4 Effect of Termination: Upon termination, your right to access Plattr ceases immediately. Your data is deleted after 30 days per Section 9.6. Termination does not relieve you of any payment obligations that accrued prior to termination.

11. Modifications to Terms

11.1 We may modify these Terms at any time. Non-material changes take effect immediately upon posting to our website. Material changes (including changes to pricing, liability, or your legal rights) will be announced at least 30 days in advance via email or in-app notification.

11.2 Your continued use of Plattr following the effective date of any modification constitutes acceptance of the updated Terms.

11.3 We may modify, suspend, or discontinue any feature, functionality, or aspect of Plattr at any time, with or without notice. We are not liable for any modification, suspension, or discontinuation of features.

12. Third-Party Services & Integrations

12.1 Plattr integrates with third-party services including Stripe, Instagram, TikTok, Meta, Mailchimp, Zapier, Shopify, WooCommerce, AWS, Cloudflare, and others. Your use of these integrations is subject to their respective terms of service and privacy policies.

12.2 We are not responsible for the availability, accuracy, content, or performance of third-party services. We are not liable for third-party service outages, data loss, service changes, or any loss arising from your use of those services.

12.3 You are responsible for understanding and complying with each third-party service’s terms, including payment processor rules and data provider agreements. Violations of third-party terms that affect our service may result in suspension of your Plattr account.

13. Governing Law & Jurisdiction

13.1 Governing law: These Terms, and any dispute or claim arising out of or in connection with them or their subject matter (including non-contractual disputes or claims), are governed by and construed in accordance with the laws of New Zealand.

13.2 Jurisdiction & dispute resolution: You and Plattr submit to the exclusive jurisdiction of the courts of New Zealand. Before starting court proceedings, the parties will first try in good faith to resolve any dispute by discussion for at least 30 days after one party gives the other written notice of the dispute. Nothing in this clause prevents either party from applying to a New Zealand court at any time for urgent interim or injunctive relief (for example, to protect intellectual property or Confidential Information).

13.3 Disputes Tribunal: Either party may instead bring a qualifying claim in the New Zealand Disputes Tribunal, for amounts within its jurisdiction (currently up to NZD $30,000).

13.4 Customers outside New Zealand: Our choice of New Zealand law and courts does not deprive you of the protection of any mandatory laws — including consumer-protection and data-protection laws — of the country where you are resident, where those laws cannot lawfully be excluded by agreement. If you deal with us as a consumer, you may also be entitled to bring proceedings in the courts of your own country where the law there gives you that right. In all other respects these Terms are governed by New Zealand law and subject to the jurisdiction described above, and you remain responsible for your own compliance with the local laws that apply to you and your customers.

14. Force Majeure

14.1 Neither party shall be liable for any failure or delay in performance due to causes beyond its reasonable control, including acts of God, natural disasters, pandemics, war, terrorism, government actions, internet outages, or infrastructure failures.

14.2 The affected party shall promptly notify the other and use commercially reasonable efforts to resume performance as quickly as possible.

15. Miscellaneous

15.1 Entire Agreement: These Terms, together with the Privacy Policy, any Data Processing Agreement, and any order forms or statements of work, constitute the entire agreement between you and Plattr relating to the Service, and supersede all prior agreements.

15.2 Severability: If any provision is found to be invalid, illegal, or unenforceable, that provision shall be modified to the minimum extent necessary to make it enforceable. If modification is not possible, the provision shall be severed. The remaining provisions continue in full effect.

15.3 Waiver: Our failure to enforce any provision of these Terms at any time does not constitute a waiver of our right to enforce that provision in the future.

15.4 Assignment: You may not assign, transfer, or delegate these Terms or any rights or obligations without our prior written consent. We may assign our rights and obligations to a successor entity without consent.

15.5 Survival: Sections 5 (IP Rights), 6–8 (Warranties, Liability, Indemnification), 9 (Data Protection), 13 (Governing Law), and 15 (Miscellaneous) survive any termination of these Terms.

15.6 Relationship of Parties: These Terms do not create a partnership, joint venture, employment, franchise, or agency relationship between the parties.

15.7 Notices: Legal notices to Plattr must be sent in writing to hello@plattr.nz. We may provide notices to you by email to the address on your account, or by in-app notification.

15.8 Contact: For questions or concerns, contact: Plattr Limited (NZBN 9429053737694) · 53 Ngae Place, Mangere East, Auckland 2024, New Zealand · hello@plattr.nz · www.plattr.nz.

Privacy Policy

Effective January 1, 2025 · Last updated May 29, 2026

1. Introduction

Plattr Limited (“we,” “us,” “our,” or “Plattr”) is a New Zealand company committed to protecting your privacy. We handle personal information in accordance with the New Zealand Privacy Act 2020 and its Information Privacy Principles. This Privacy Policy explains how we collect, use, process, disclose, and protect information when you use Plattr — including our website, applications, APIs, and services — and when you interact with our content. Where you or your customers are located outside New Zealand, additional privacy laws may apply, and we explain how we address those below.

2. Scope

This Privacy Policy applies to:

  • www.plattr.nz and all subdomains (e.g., *.onplattr.com)
  • Plattr web and mobile applications
  • Plattr API and integrations
  • Customer-branded storefronts hosted on our platform
  • Third-party integrations that use our APIs (those services have their own privacy policies)

3. Information We Collect

3.1 Information You Provide Directly:

  • Account Registration: Name, email address, phone number, business name, physical address, and payment information
  • Business Data: Menu items, prices, descriptions, images, inventory levels, and customer data you enter
  • Staff & Team: Employee names, email addresses, phone numbers, roles, and schedules
  • Customer Data: Names, emails, phone numbers, order history, loyalty points, and preferences of your customers
  • Payments: Credit/debit card details (processed by Stripe and never stored on our servers)
  • Communications: Support emails, feedback, survey responses, and chat messages
  • Content: Photos, videos, descriptions, social media posts, and branded materials you upload

3.2 Information Collected Automatically:

  • Device Information: IP address, browser type, operating system, and device type
  • Usage Data: Pages visited, time spent, clicks, scrolls, features used, and performance metrics
  • Cookies & Tracking: Session cookies, persistent cookies, web beacons, pixel tags, and analytics identifiers
  • Crash Reports & Diagnostics: Error logs and system performance data
  • Location Data: Approximate location based on IP address (not precise GPS unless you enable it)
  • Third-Party Analytics: Data collected via Google Analytics, Segment, Mixpanel, or similar tools

3.3 Information from Third Parties:

  • Payment Processors: Stripe shares transaction data, fraud signals, and chargeback information
  • Social Media: Instagram, TikTok, and Facebook APIs share account info, audience insights, and post performance
  • Email Providers: Resend, AWS SES, and Mailchimp share email delivery, open, and click data
  • Business Intelligence: Company registration data and industry data from public sources
  • User Referrals: If someone refers you, they share your name and contact information with us

4. How We Use Your Information

4.1 Primary Purposes:

  • (a) Providing the Service: Account management, order processing, payment collection, customer support, and platform maintenance
  • (b) Business Operations: Billing, invoicing, tax reporting, and compliance with legal obligations
  • (c) Product Improvement: Analysing usage patterns, fixing bugs, developing new features, and improving the platform
  • (d) Security: Fraud detection, account protection, DDoS prevention, and abuse monitoring
  • (e) Marketing: Promotional emails, in-app notifications, case studies, and testimonials (with your consent)
  • (f) Legal Compliance: Responding to legal requests, meeting regulatory obligations, and resolving disputes

4.2 Secondary Purposes:

  • (a) Personalisation: Customised dashboard, recommended features, and saved preferences
  • (b) Analytics: Aggregated performance metrics, market research, and trend analysis
  • (c) Communications: Newsletters, product updates, and important notices
  • (d) Training & Testing: Improving AI-assisted features and testing new functionality (using anonymised data where possible)

4.3 Why we are allowed to collect and use your information: Under the Privacy Act 2020, we collect and use personal information only for lawful purposes connected with our functions and activities, and in accordance with the Information Privacy Principles. In practice we rely on: (a) performing our agreement with you and providing the Service; (b) our legitimate business interests, such as security, fraud prevention and improving the product; (c) meeting legal obligations, such as tax and record-keeping; and (d) your consent — for example, for marketing emails and non-essential cookies, which you can withdraw at any time. If you or your customers are located outside New Zealand, additional bases may apply under the laws of those places.

5. Data Processing & Storage

5.1 Data Processors: We use the following categories of third-party processors, each under written data processing agreements:

  • Cloudflare — CDN, DDoS protection, and edge hosting
  • Amazon Web Services (AWS) — cloud storage and email infrastructure (SES, S3)
  • Hetzner / OVH — server infrastructure
  • Stripe — payment processing (PCI-DSS Level 1 certified)
  • Google Analytics — website and product analytics
  • Resend / Mailchimp / AWS SES / Migadu — email delivery
  • Segment — customer data management
  • Third-party integrations you authorize (Zapier, Shopify, WooCommerce, Meta, etc.)

5.2 Data Retention:

  • (a) Account Data: Retained while your account is active; deleted 30 days after termination
  • (b) Customer Order Data: Retained per your retention settings, typically 3–7 years for tax and legal compliance
  • (c) Payment Records: Retained for 6 years to satisfy tax and audit requirements
  • (d) Analytics & Logs: Retained for 12–24 months
  • (e) Email Communications: Retained for 2 years unless you request earlier deletion
  • (f) Cookies: Session cookies expire at browser close; persistent cookies expire within 12 months

5.3 Where your data is stored & overseas disclosure: Your data is primarily stored on servers located in New Zealand and Australia. Some of the processors listed in section 5.1 are based overseas, which means your information may be stored or processed outside New Zealand. Where we disclose personal information to a party outside New Zealand, we comply with Information Privacy Principle 12 of the Privacy Act 2020 and take reasonable steps to ensure the recipient protects the information with safeguards comparable to those required in New Zealand. Where your customers are located in the EU or UK, we put in place the transfer mechanisms their laws require — the European Commission’s Standard Contractual Clauses for EU data, and the UK International Data Transfer Agreement (or Addendum) for UK data. For personal information about Australian individuals, we handle overseas disclosure in line with Australian Privacy Principle 8.

5.4 Encryption: All data in transit is protected by TLS 1.2 or higher. All data at rest is encrypted using AES-256. Payment data is tokenized by Stripe and never stored on Plattr infrastructure.

6. Your Rights

6.1 Your rights under the Privacy Act 2020 (New Zealand): You have the right to ask us whether we hold personal information about you, to access that information, and to request correction of anything that is wrong. If we decline a request, we will tell you why and note your requested correction where appropriate. You can make a complaint to us or to the Office of the Privacy Commissioner (www.privacy.org.nz) if you believe we have not handled your information properly. In limited circumstances the Privacy Act allows us to withhold information or charge a reasonable cost.

6.2 If you or your customers are outside New Zealand: Where the laws of another country apply, you may have additional rights, and we will honour them to the extent those laws require:

  • (a) EU / UK (GDPR): access, rectification, erasure, restriction of processing, data portability, objection, withdrawal of consent, the right to complain to your national Data Protection Authority, and rights relating to automated decision-making.
  • (b) California (CCPA / CPRA): the right to know, access, delete, and correct personal information; to opt out of its “sale” or “sharing” (we do not sell or share personal information as those terms are defined); to limit the use of sensitive personal information; and to be free from discrimination for exercising these rights. You may use an authorised agent to make a request. Where we handle personal information on a business customer’s behalf we act as their “service provider” and use it only to provide the Service.
  • (c) Canada (PIPEDA): access and portability, correction and deletion, and unsubscribe via CASL-compliant mechanisms.
  • (d) Australia (Privacy Act 1988): access and correction, and the right to complain to the Office of the Australian Information Commissioner.

6.3 How to exercise your rights: Submit requests to hello@plattr.nz or privacy@plattr.nz. We will verify your identity before acting on a request. For access and correction requests under the Privacy Act 2020 we will respond as soon as reasonably practicable and no later than 20 working days after we receive your request. Requests are free of charge, although the Privacy Act allows us to charge a reasonable cost in limited circumstances.

6.4 Data access & portability: We provide requested information in portable, machine-readable formats (CSV, JSON) where technically feasible. You can also access and export much of your data directly from your Plattr dashboard.

7. Cookies & Tracking Technologies

7.1 Types of Cookies We Use:

  • (a) Essential / Strictly Necessary: Required for login sessions, CSRF protection, authentication, and session management. These cannot be disabled without breaking core functionality.
  • (b) Analytics: Google Analytics, Mixpanel, and similar tools to track user IDs, session duration, navigation paths, and feature usage.
  • (c) Marketing & Conversion: Tracking conversions, retargeting campaigns, affiliate attribution.
  • (d) Third-Party: Social media pixels (Facebook Pixel, Instagram), Stripe fraud prevention, and authorized integration cookies.

7.2 Cookie Consent: For users in the EU, UK, Canada, and other jurisdictions where required, we present a consent management platform before placing non-essential cookies. You may withdraw or modify your cookie preferences at any time via our cookie settings panel.

7.3 Do Not Track (DNT): If your browser transmits a DNT signal, we respect your preference and limit non-essential tracking where technically possible.

7.4 Local Storage & Similar Technologies: We use browser local storage, IndexedDB, and session storage for performance caching, user preferences, and offline functionality. These are not traditional cookies but serve similar purposes.

8. Children & Minors

8.1 Plattr is a business management platform intended for adults operating food businesses. We do not knowingly collect personal data from individuals under the age of 18 without verifiable parental or guardian consent.

8.2 If you are under 18, please do not use Plattr without the explicit consent and oversight of a parent or legal guardian.

8.3 If we discover that we have inadvertently collected data from a minor, we will promptly delete the data and notify the account holder. If you believe we have collected data from a minor, please contact privacy@plattr.nz immediately.

9. Marketing & Communications

9.1 Marketing Emails: We send promotional emails, product updates, feature announcements, and newsletters. You can unsubscribe at any time via the unsubscribe link in each email or via your account settings.

9.2 SMS Marketing: We obtain explicit written opt-in before sending any SMS marketing. You can opt out at any time by replying STOP to any message. Message and data rates may apply.

9.3 Push Notifications: Mobile app push notifications require your explicit consent. You may disable notifications via your app settings or device notification preferences.

9.4 Anti-spam compliance: Our marketing communications comply with the New Zealand Unsolicited Electronic Messages Act 2007 and, where they apply, overseas equivalents such as the Spam Act 2003 (Australia), CAN-SPAM (US) and CASL (Canada). Every marketing message includes (a) clear sender identification, (b) a functioning unsubscribe mechanism, and (c) our contact details; SMS marketing is sent only with your prior consent. We honour unsubscribe requests promptly, and in any event within 5 working days as required by New Zealand law.

9.5 Transactional Communications: Order confirmations, payment receipts, password resets, security alerts, and support responses are transactional in nature and are not subject to marketing opt-out preferences.

10. How We Share Your Data

10.1 We Do Not Sell Your Data: Plattr does not sell, rent, or trade personal data to third parties for their independent marketing or advertising purposes.

10.2 Data Sharing Circumstances:

  • (a) Service Providers: We share data with authorized processors (Stripe, AWS, Cloudflare, etc.) under written data processing agreements that prohibit them from using data for their own purposes.
  • (b) Authorized Integrations: Data shared with third-party services you connect (Instagram, Mailchimp, Zapier) is subject to your authorization and their terms.
  • (c) Legal & Regulatory Requests: We disclose data to law enforcement or regulators when required by valid legal process (warrant, court order, or equivalent), and we notify affected users where legally permitted.
  • (d) Aggregated & Anonymous Data: We may share anonymized, aggregated insights (e.g., industry benchmarks) where no individual can be identified.
  • (e) Business Transfers: In the event of a merger, acquisition, or sale of assets, data may be transferred to the successor entity. We will provide notice and your rights are protected.
  • (f) With Your Consent: We share data with third parties only with your explicit, informed consent.

10.3 Overseas disclosure: Where we disclose personal information to a party outside New Zealand, we comply with Information Privacy Principle 12 of the Privacy Act 2020 and take reasonable steps to ensure the information is protected by comparable safeguards. Where the laws of another country also apply, we use the transfer mechanisms those laws require — for example the Standard Contractual Clauses for EU data, the UK International Data Transfer Agreement for UK data, and Australian Privacy Principle 8 for Australian data.

10.4 Third-Party Privacy Policies: Third-party services (Stripe, Instagram, Google) have their own privacy policies independent of ours. We recommend reviewing them before connecting those services.

11. Security & Data Protection

11.1 Technical & Organisational Security Measures:

  • (a) End-to-end encryption via TLS 1.2+ for all data in transit
  • (b) AES-256 encryption for data at rest
  • (c) Regular third-party security audits and annual penetration testing
  • (d) Multi-factor authentication (MFA) and passkey (WebAuthn) support
  • (e) Role-based access control (RBAC) with least-privilege principles
  • (f) DDoS protection and Web Application Firewall (WAF) via Cloudflare
  • (g) Daily automated backups with geographically distributed storage
  • (h) Formal incident response and disaster recovery procedures
  • (i) Aligned with recognised frameworks, including PCI-DSS (via our payment processor, Stripe) and the New Zealand Privacy Act 2020

11.2 Your Security Responsibilities: Keep credentials secure and never share passwords; enable 2FA; report suspected unauthorized access to security@plattr.nz immediately; ensure staff follow least-privilege access; and keep your contact information current so we can notify you of security events.

11.3 Privacy breach notification: If we become aware of a privacy breach that it is reasonable to believe has caused, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner and the affected individuals as soon as practicable, in accordance with Part 6 of the Privacy Act 2020. Where a breach affects a merchant’s customers, we will support that merchant (as the agency responsible for its customers’ information) to meet its own notification obligations. Our notification will describe what happened, the information involved, the likely consequences, and the steps we are taking. Where the laws of other countries apply, we meet their breach-notification requirements as well: for the EU and UK, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours (Article 33 of the EU / UK GDPR), and affected individuals where the breach is likely to result in a high risk to them; and for Australia, we notify the Office of the Australian Information Commissioner and affected individuals of any eligible data breach under the Notifiable Data Breaches scheme. Where we act as a processor for a customer, we support that customer to meet these obligations.

12. Data Processing Agreement

12.1 When you may need one: Under the Privacy Act 2020 you are the agency responsible for your customers’ personal information, and we handle it on your behalf as your service provider. If you need a written data processing agreement — for example because you also serve customers in the EU or UK — we provide a Standard DPA on request.

12.2 Standard DPA Coverage: Identification of you as data controller and Plattr as processor; scope, nature, and purpose of processing; technical and organisational security measures; sub-processor management and authorization; assistance with data subject rights; audit rights; the transfer mechanisms required for international data (the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, and equivalent safeguards for other regions); and liability allocation.

12.3 Requesting a DPA: Email hello@plattr.nz with the subject line “DPA Request”. Enterprise customers may negotiate custom DPA terms.

12.4 Sub-Processors: Our current list of sub-processors — the third parties that help us deliver the Service and where each one operates — is available at plattr.nz/legal/sub-processors. We will notify you of any changes with at least 30 days’ notice.

12.5 EU / UK Representative: Where we are required under Article 27 of the EU GDPR or the UK GDPR to designate a representative in the EU or the UK, we will appoint one and publish their contact details here and in this Privacy Policy. Until then, individuals in the EU and UK can raise any data-protection matter with our Privacy Officer at privacy@plattr.nz, and we will respond as those laws require.

13. Retention & Deletion

13.1 Data Retention Schedule:

  • (a) Active Account Data: Retained for the lifetime of your active account
  • (b) Account Data After Termination: Deleted 30 days after account termination
  • (c) Payment & Financial Records: Retained for 6 years to satisfy tax and audit requirements
  • (d) Customer Order & Transaction Data: Retained per your settings or applicable legal requirements
  • (e) Analytics & System Logs: Retained for 12–24 months, then automatically purged
  • (f) Email Campaign Archives: Retained for 2 years or until you delete from your account
  • (g) Backups: Encrypted backups retained for up to 90 days then overwritten

13.2 Deletion Requests: You may request deletion of specific data at any time by contacting hello@plattr.nz or through your account dashboard. We will process deletion within 30 days, except where retention is required by law (e.g., tax records, ongoing legal proceedings).

13.3 Pseudo-Anonymisation: Some data may be anonymised for aggregate analytics purposes and retained indefinitely in a form that cannot be linked back to any individual or business.

14. Updates & Changes to This Policy

14.1 We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service features. Minor updates take effect upon posting.

14.2 Material changes (such as new categories of data collection, new sharing practices, or new data uses) will be communicated via email and prominent in-app notice at least 30 days before taking effect.

14.3 Your continued use of Plattr after the effective date of any update constitutes your acceptance of the revised Privacy Policy. If you do not agree with material changes, you may terminate your account before the effective date.

15. Contact Information

15.1 For privacy questions, requests, or complaints:

  • Email: hello@plattr.nz
  • Privacy Officer: privacy@plattr.nz
  • Web: www.plattr.nz/privacy
  • Address: Plattr Limited (NZBN 9429053737694), 53 Ngae Place, Mangere East, Auckland 2024, New Zealand
  • Response time: as soon as reasonably practicable, and no later than 20 working days for Privacy Act 2020 access and correction requests

15.2 Privacy regulators:

  • New Zealand: Office of the Privacy Commissioner (privacy.org.nz) — our primary regulator
  • Australia: Office of the Australian Information Commissioner (oaic.gov.au)
  • EU / EEA: European Data Protection Board (www.edpb.europa.eu) or your national Data Protection Authority
  • UK: Information Commissioner’s Office (ico.org.uk)
  • United States: Federal Trade Commission (ftc.gov); California: California Attorney General (oag.ca.gov)
  • Canada: Office of the Privacy Commissioner of Canada (priv.gc.ca)

15.3 If you are in New Zealand and we cannot resolve your concern, you have the right to complain to the Office of the Privacy Commissioner. If you are elsewhere, you may complain to the relevant regulator listed above, without prejudice to any other legal remedy. We encourage you to contact us first so we can address your concern directly.

Back to top