Privacy Policy
Version 1.1 · Last updated 3 October 2026 · Written to meet the New Zealand Privacy Act 2020
1. Who we are
AuraPier Tech (“we”, “us”) runs this website and Client Hub. We are responsible for the personal information described below. Our privacy contact is the contact in the footer of this page; send privacy questions, access, correction or deletion requests there.
2. Two kinds of people this covers
- Our customers (people with a Client Hub account) and people who contact us through the website.
- Our customers’ own clients and contacts. Customers store details about their clients in Client Hub. For that information the customer decides why and how it is used; we only store and process it on the customer’s behalf, to provide the Service. If you are on a business’s client list and want your details corrected, removed or not to be emailed, ask that business first. Every email sent through Client Hub has an unsubscribe link, and if you cannot reach the business you can contact us and we will help.
3. What we collect and why
| Information | Why |
|---|---|
| Account: email, optional name, a salted hash of your password (never the password), the time and version of Terms you accepted | To create and secure your account and keep a record of your agreement |
| Licence key and its dates | To provide and enforce your licence |
| Your clients’ details and notes that you enter | To provide the Service to you |
| Calendar events you create (title, times, location, notes, optional linked client), if the calendar is enabled for you | To provide the calendar feature |
| Notification settings: your browser’s push address (an endpoint URL) for each device where you turn reminders on, your time zone, and the reminders queued for you | To deliver event reminders to your devices |
| Linked email connection (an app password or access token, stored encrypted) and your email address | To send the messages you tell us to send |
| Send log: recipient address, time, success or failure (not message content) | To apply sending limits, prevent abuse and show you counts |
| Contact-form messages: name, email, message | To reply to your enquiry |
| Unsubscribe records | To stop emailing people who have opted out |
| Technical data: a sign-in cookie, and your IP address held briefly in memory for rate limiting; standard server logs | To keep you signed in and protect the Service from abuse |
We collect this directly from you (or, for client details, from our customers). We do not buy personal information, sell it, use it for advertising, or build profiles.
4. Email access
A linked email account is used only to send messages you explicitly choose to send. We do not read, scan or download your inbox. You can unlink at any time in Settings, which deletes the stored credentials (and revokes access with Google where applicable). We also recommend revoking the app password with your email provider.
5. Who we share it with
- Your email provider (for example Google, Microsoft, Yahoo, Apple or your own mail server) receives the messages you send, under its own privacy policy.
- Our hosting provider stores the data on our behalf (see section 6). It may not use it for its own purposes.
- Browser notification services (if you turn on reminders): reminders are delivered through your browser maker’s push service (for example Google, Apple or Mozilla). We send it a short content-free signal addressed to your device. The reminder text itself is fetched by your device directly from us, so the push service never sees your events. You can turn this off at any time in Settings, which deletes the device address from our records.
- Maps (calendar feature): when you use “Find address”, the address text you type is sent from our server to OpenStreetMap’s search service (Nominatim) to find its location. When you open an event that has a map, your browser loads a small map from openstreetmap.org, which will see your IP address. Clicking “Start directions” opens Google Maps (or Apple Maps on iPhone) with the destination, under their privacy policies. No map or address service is contacted unless you use those features.
- Our website administrators can see account emails, licence status, usage counts and contact-form messages. The admin tools do not display your clients’ details or notes.
- We disclose information if the law requires it or to protect people from serious harm.
Our pages load no third-party scripts, fonts or trackers; all code is served from our own server. The only third-party content is the optional map shown on a calendar event, described in section 5.
6. Where your information is stored
Our servers are hosted by Vultr in Sydney, Australia, so your information is stored outside New Zealand. We take reasonable steps to make sure it is protected with safeguards comparable to the Privacy Act. Messages you send are delivered by your own email provider, which may process them in other countries.
7. How long we keep it
- Account, clients, notes and licence details: while your account exists. You can delete clients or notes yourself at any time, and delete your whole account in Settings (or ask us to).
- Send log: 90 days. Website enquiries: 24 months, then deleted. Sessions: expire after 14 days.
- Unsubscribe records stay with the client record so opted-out people are not emailed again; they are deleted with it.
- After you delete your account we remove your account data and linked mail connection. Routine server backups, if any, are overwritten on a rolling basis.
8. Security
Passwords are hashed, sessions use secure cookies, stored mail credentials are encrypted at rest, accounts are isolated from each other, traffic uses HTTPS and sign-in attempts are rate-limited. No system is perfectly secure, so please use a strong, unique password. If a privacy breach is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and the people affected as the Privacy Act requires.
9. Your rights
You can ask for a copy of the personal information we hold about you and ask us to correct it. Account holders can download their data and delete their account in Settings; otherwise contact us and we will respond within 20 working days. If you are in the EU or UK you may have additional rights (for example erasure and portability) and we will honour them. If you are unhappy with how we handle your information, please contact us first; you can also complain to the Office of the Privacy Commissioner (privacy.org.nz).
10. Children
The Service is for businesses and adults. It is not directed at anyone under 18 and we do not knowingly collect their information.
11. Cookies
We use one essential cookie (“sid”) to keep you signed in. We use no advertising or analytics cookies, so there is no cookie banner to dismiss.
12. Changes
If we make a material change to this policy we will tell account holders by email or in the app before it takes effect. The date above shows the latest version.