Your data is yours. Here's exactly what we collect, why we collect it, and how we protect it. No fine print, no surprises.
PestFree NZ ("we", "our", "us") operates the PestFree NZ platform, connecting New Zealand landowners with licensed hunters for pest control services. We are committed to protecting your privacy in accordance with the New Zealand Privacy Act 2020.
We use the following third-party services that may process your data:
We retain your personal information for as long as your account is active. Access agreements are retained for 7 years to comply with legal requirements. When you delete your account, your personal data is permanently removed within 30 days, except where retention is required by law.
Under the New Zealand Privacy Act 2020, you have the right to:
You can export your data or delete your account at any time from your account settings.
We implement robust technical and organisational measures to protect your data. Below is a summary of the key security features built into PestFree NZ.
Sensitive personal information, including phone numbers, firearms licence numbers, and digital signatures, is encrypted using AES-256-GCM encryption before being stored in our database. Each piece of data is encrypted with unique key material, so even in the unlikely event of a database breach, your personal information remains unreadable.
All data sent between your device and PestFree NZ is protected by HTTPS (TLS) encryption. We enforce this with a Strict Transport Security policy, ensuring your browser always connects over a secure channel.
Your password is never stored in plain text. We use bcrypt hashing, a one-way process that means nobody, including PestFree NZ staff, can ever see or recover your password. We require a minimum of 8 characters. If you forget your password, you will receive a secure, time-limited reset link via email that expires after one hour.
We actively monitor login attempts and platform activity. Our systems enforce strict rate limits to prevent automated attacks:
We implement a comprehensive set of browser security headers to guard against common web threats, including clickjacking protection, cross-site scripting (XSS) prevention, a strict Content Security Policy, and referrer controls that limit what information is shared when navigating to external sites.
Every piece of information submitted to PestFree NZ is validated before it is accepted. Phone numbers are checked against valid New Zealand formats, email addresses are verified, and text fields have length limits to prevent abuse.
Login sessions expire after 7 days and are refreshed in real-time. If an account is suspended or deactivated, access is revoked immediately, even during an active session.
Firearms licence numbers are encrypted at rest and only accessible to the licence holder and platform administrators during the verification process. PestFree NZ operates in alignment with the Arms Act 1983 and Arms Regulations 1992.
PestFree NZ gives you control over what other users can see:
We use essential cookies for authentication and session management. We use PostHog for product analytics to understand how users interact with our platform. You can opt out of analytics tracking in your browser settings.
On Apple iOS devices, we request your permission via App Tracking Transparency before enabling analytics. If you decline, analytics tracking is fully disabled on your device. You can change this at any time in your device's Settings under Privacy & Security > Tracking.
PestFree NZ is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children.
We may update this privacy policy from time to time. We will notify registered users of any material changes via email or in-app notification.
If you have questions about this privacy policy or wish to exercise your rights, please contact us at pestfreenz@gmail.com.
You also have the right to lodge a complaint with the Office of the Privacy Commissioner at www.privacy.org.nz.