Kiwi Eats

In reviewVersion 0.1.0-draft · DRAFT — not in force

DRAFT FOR LEGAL REVIEW — NOT IN FORCE. Every field, purpose and retention period below was checked against the running database and code. Where the answer is "we do not do that", it says so, because a privacy policy that describes a system you do not have is worse than none.

Privacy Policy — Kiwi Eats Drivers

This covers information about you, the driver. Information about customers is covered separately and is not yours to control; see "Customers' information" below.

Who holds it: Tauranga Food Limited, NZBN 9429046588135, 70 Tynan Street, Te Puke 3119. Privacy Officer: Charandeep Singh — info@kiwieats.co.nz.

REVIEWER: Privacy Act 2020 s201 requires a named Privacy Officer, and that obligation starts at the first delivery rather than at scale — so this is now filled rather than blank. The contact is a role mailbox on purpose: the Act wants a named person, but printing a personal address means the policy is wrong the day that person changes.

Practically this is the person who receives an access or correction request (20 working days to answer), who assesses a breach under Part 6, and — the live one — who answers a customer asking about a photograph of their front door. Deletion is deliberately not something the API can do: the instance role has no s3:DeleteObject, so it is a manual aws s3 rm --recursive by prefix, documented in DEFERRED.md D-47. By prefix, because that also reaches superseded retakes and rejected uploads which photo_key never names.

What we hold about you

Everything, and nothing else:

WhatWhyWhere it comes from
Email addressIt is your login, and how we send you a sign-in codeYou
Name (optional)So the store knows who is collecting an orderYou
Phone number (optional)So a store can reach you about a delivery in progressYou
Which stores you deliver forTo decide which jobs you are offeredUs
Notification token for your phoneTo tell you a delivery is availableYour device
Your notification and availability preferencesTo respect themYou
The deliveries you accepted and completedTo calculate what you are owed, and to resolve disputesThe system
Sign-in codes and session tokensTo sign you in and keep you signed inThe system

Sign-in codes are stored hashed, never in readable form, and are deleted 7 days after they expire. Old session tokens are deleted after 30 days.

What we do NOT hold

Stated explicitly, because people reasonably assume otherwise about delivery apps:

Why we can hold it

To run the delivery service you contract with us to provide: to offer you work, tell you about it, let the store know who is collecting, work out what you are owed, and sort out problems. We do not use it for anything else.

Who else sees it

Your information is held in Australia (AWS Sydney). [REVIEWER — IPP 12 / cross-border disclosure. AU is generally treated as comparable, but please confirm the wording.]

How long we keep it

Closing your account

You can delete your account from the app at any time. When you do:

Customers' information

While delivering you see a customer's name, address and phone number. That is not your information and this policy does not give you rights over it.

Your rights

Under the Privacy Act 2020 you can ask what we hold about you and ask us to correct it. Contact the Privacy Officer above. We will respond within 20 working days.

If you are not happy with how we handle it, you can complain to the Office of the Privacy Commissioner: privacy.org.nz, 0800 803 909.

If something goes wrong

If information about you is lost or exposed in a way that could cause you serious harm, we will tell you, and we will notify the Privacy Commissioner as the Privacy Act requires.

Changes

If we change this policy we will show you the new version in the app and ask you to accept it. Accepting this version is not acceptance of a later one.