Your Privacy

Privacy Policy.

Your data is yours. Here's exactly what we collect, why we collect it, and how we protect it. No fine print, no surprises.

Last updated: April 2026

1. Introduction

PestFree NZ ("we", "our", "us") operates the PestFree NZ platform, connecting New Zealand landowners with licensed hunters for pest control services. We are committed to protecting your privacy in accordance with the New Zealand Privacy Act 2020.

2. Information We Collect

Account Information

  • Name, email address, and phone number
  • Account type (landowner or hunter)
  • Location and region
  • Profile photos

Hunter-Specific Information

  • Firearms licence number and expiry date
  • NZDA membership details
  • First aid certification
  • Equipment and experience details

Landowner-Specific Information

  • Property address and coordinates
  • Property descriptions and photos
  • Pest control requirements

Usage Information

  • Messages sent through the platform
  • Access agreements and digital signatures
  • Reviews and ratings
  • Device information and analytics data

3. How We Use Your Information

  • To provide and maintain the PestFree NZ platform
  • To match landowners with suitable hunters
  • To facilitate access agreements and digital signatures
  • To verify hunter credentials and licences
  • To send notifications about requests, responses, and messages
  • To improve our services through analytics
  • To comply with legal obligations

4. Third-Party Services

We use the following third-party services that may process your data:

  • Supabase: Database hosting and file storage (servers in Sydney, Australia)
  • Vercel: Application hosting
  • Sentry: Error tracking and monitoring
  • PostHog: Product analytics
  • UploadThing: File upload handling
  • Firebase Cloud Messaging : Push notifications
  • Resend / Gmail: Transactional emails

5. Data Retention

We retain your personal information for as long as your account is active. Access agreements are retained for 7 years to comply with legal requirements. When you delete your account, your personal data is permanently removed within 30 days, except where retention is required by law.

6. Your Rights

Under the New Zealand Privacy Act 2020, you have the right to:

  • Access: Request a copy of all personal information we hold about you
  • Correction: Request correction of inaccurate information
  • Deletion: Request deletion of your account and associated data
  • Export: Download your data in a machine-readable format

You can export your data or delete your account at any time from your account settings.

7. Data Security

We implement robust technical and organisational measures to protect your data. Below is a summary of the key security features built into PestFree NZ.

Encryption at Rest

Sensitive personal information, including phone numbers, firearms licence numbers, and digital signatures, is encrypted using AES-256-GCM encryption before being stored in our database. Each piece of data is encrypted with unique key material, so even in the unlikely event of a database breach, your personal information remains unreadable.

Encryption in Transit

All data sent between your device and PestFree NZ is protected by HTTPS (TLS) encryption. We enforce this with a Strict Transport Security policy, ensuring your browser always connects over a secure channel.

Password Protection

Your password is never stored in plain text. We use bcrypt hashing, a one-way process that means nobody, including PestFree NZ staff, can ever see or recover your password. We require a minimum of 8 characters. If you forget your password, you will receive a secure, time-limited reset link via email that expires after one hour.

Brute Force & Abuse Prevention

We actively monitor login attempts and platform activity. Our systems enforce strict rate limits to prevent automated attacks:

  • Failed login attempts are temporarily blocked to prevent password guessing
  • All API endpoints are protected against excessive or automated requests
  • Requests from unauthorised external websites are automatically rejected

Security Headers

We implement a comprehensive set of browser security headers to guard against common web threats, including clickjacking protection, cross-site scripting (XSS) prevention, a strict Content Security Policy, and referrer controls that limit what information is shared when navigating to external sites.

Input Validation

Every piece of information submitted to PestFree NZ is validated before it is accepted. Phone numbers are checked against valid New Zealand formats, email addresses are verified, and text fields have length limits to prevent abuse.

Session Management

Login sessions expire after 7 days and are refreshed in real-time. If an account is suspended or deactivated, access is revoked immediately, even during an active session.

Firearms Licence Security

Firearms licence numbers are encrypted at rest and only accessible to the licence holder and platform administrators during the verification process. PestFree NZ operates in alignment with the Arms Act 1983 and Arms Regulations 1992.

8. Your Privacy Controls

PestFree NZ gives you control over what other users can see:

  • Visibility settings : You choose whether your email, phone number, and region are visible to other users
  • Account deletion: You can delete your account at any time from your account settings; deletion requires password verification and your data is permanently removed within 30 days
  • Data export: You can download your data in a machine-readable format at any time

9. Cookies and Analytics

We use essential cookies for authentication and session management. We use PostHog for product analytics to understand how users interact with our platform. You can opt out of analytics tracking in your browser settings.

On Apple iOS devices, we request your permission via App Tracking Transparency before enabling analytics. If you decline, analytics tracking is fully disabled on your device. You can change this at any time in your device's Settings under Privacy & Security > Tracking.

10. Children's Privacy

PestFree NZ is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this privacy policy from time to time. We will notify registered users of any material changes via email or in-app notification.

12. Contact Us

If you have questions about this privacy policy or wish to exercise your rights, please contact us at pestfreenz@gmail.com.

You also have the right to lodge a complaint with the Office of the Privacy Commissioner at www.privacy.org.nz.