DRAFT FOR LEGAL REVIEW — NOT IN FORCE. Every field, purpose and retention period below was checked against the running database and code. Where the answer is "we do not do that", it says so, because a privacy policy that describes a system you do not have is worse than none.
Privacy Policy — Kiwi Eats Drivers
This covers information about you, the driver. Information about customers is covered separately and is not yours to control; see "Customers' information" below.
Who holds it: Tauranga Food Limited, NZBN 9429046588135, 70 Tynan Street, Te Puke 3119. Privacy Officer: Charandeep Singh — info@kiwieats.co.nz.
REVIEWER: Privacy Act 2020 s201 requires a named Privacy Officer, and that obligation starts at the first delivery rather than at scale — so this is now filled rather than blank. The contact is a role mailbox on purpose: the Act wants a named person, but printing a personal address means the policy is wrong the day that person changes.
Practically this is the person who receives an access or correction request (20 working days to answer), who assesses a breach under Part 6, and — the live one — who answers a customer asking about a photograph of their front door. Deletion is deliberately not something the API can do: the instance role has no
s3:DeleteObject, so it is a manualaws s3 rm --recursiveby prefix, documented inDEFERRED.mdD-47. By prefix, because that also reaches superseded retakes and rejected uploads whichphoto_keynever names.
What we hold about you
Everything, and nothing else:
| What | Why | Where it comes from |
|---|---|---|
| Email address | It is your login, and how we send you a sign-in code | You |
| Name (optional) | So the store knows who is collecting an order | You |
| Phone number (optional) | So a store can reach you about a delivery in progress | You |
| Which stores you deliver for | To decide which jobs you are offered | Us |
| Notification token for your phone | To tell you a delivery is available | Your device |
| Your notification and availability preferences | To respect them | You |
| The deliveries you accepted and completed | To calculate what you are owed, and to resolve disputes | The system |
| Sign-in codes and session tokens | To sign you in and keep you signed in | The system |
Sign-in codes are stored hashed, never in readable form, and are deleted 7 days after they expire. Old session tokens are deleted after 30 days.
What we do NOT hold
Stated explicitly, because people reasonably assume otherwise about delivery apps:
- We do not track your location. The app does not report where you are, we have no system that records it, and there is no map of where drivers have been. If that ever changes — a dispatch feature that finds the closest driver would need it — we will reissue this policy and ask you to accept it before turning it on.
- We do not record how fast you drive, or anything else about how you drive.
- We do not have a driver rating or performance score. Nothing scores you, and nothing shows a star rating to anyone.
- We do not hold your bank details in this app.
[CONFIRM once payments are built — Phase 5 will change this and this policy must be reissued.] - We do not sell your information to anyone, ever.
Why we can hold it
To run the delivery service you contract with us to provide: to offer you work, tell you about it, let the store know who is collecting, work out what you are owed, and sort out problems. We do not use it for anything else.
Who else sees it
- The store you are delivering for sees your name and phone number, for that delivery.
- Our hosting and email providers (Amazon Web Services, in Sydney) hold the data on our behalf. Your sign-in code is sent by email through them.
- The notification service (Expo) receives your device token to deliver notifications. It does not receive your name, your email, or any customer's details.
- Nobody else, unless the law requires it.
Your information is held in Australia (AWS Sydney). [REVIEWER — IPP 12 / cross-border disclosure. AU is generally treated as comparable, but please confirm the wording.]
How long we keep it
- Your account: while it is open, and after you close it we keep the record of deliveries but not your identity — see below.
- Sign-in codes: deleted 7 days after they expire.
- Session tokens: deleted 30 days after they expire.
- Delivery records: kept. They are the record of work done and money owed, and both of us may need them later.
[REVIEWER — retention period? Tax record-keeping is commonly 7 years.]
Closing your account
You can delete your account from the app at any time. When you do:
- your email address is released, so you could sign up again later;
- your name and contact details are scrambled;
- the record of deliveries you completed survives, because it is also the store's record of work done and money paid, and deleting it would erase their books as well as yours.
Customers' information
While delivering you see a customer's name, address and phone number. That is not your information and this policy does not give you rights over it.
- You see a customer's full address only after you accept a delivery. Before that you see the suburb.
- Your own trip history shows only the suburb afterwards.
- Proof-of-delivery photos are photographs of a customer's property. They are kept 30 days and then deleted automatically. If a customer asks us to delete one sooner, we do — and that request is theirs to make, not yours, because it is their home.
Your rights
Under the Privacy Act 2020 you can ask what we hold about you and ask us to correct it. Contact the Privacy Officer above. We will respond within 20 working days.
If you are not happy with how we handle it, you can complain to the Office of the Privacy Commissioner: privacy.org.nz, 0800 803 909.
If something goes wrong
If information about you is lost or exposed in a way that could cause you serious harm, we will tell you, and we will notify the Privacy Commissioner as the Privacy Act requires.
Changes
If we change this policy we will show you the new version in the app and ask you to accept it. Accepting this version is not acceptance of a later one.