
Loading...

Loading...
The What's In? Gazette · Legal Notices
Your Data, Explained Plainly
Last updated: 1 January 2026 · Jurisdiction: New Zealand
✓ We collect info to run the marketplace safely.
✓ We never sell your data. Not to anyone.
✓ We share some info with Stripe (payments) and Anthropic/OpenAI (AI identification). That's it.
✓ You can request all your data or ask us to delete it at any time.
✓ We use cookies. You control which ones.
✓ NZ Privacy Act 2020 applies. We take it seriously.
What's In? is operated by [Company Name], New Zealand. We are the Privacy Act "agency" responsible for the personal information we collect.
Our platform is built and maintained by SaaSy Cookies who act as a data processor on our behalf under a data processing agreement.
Contact our Privacy Officer: privacy@whatsin.co.nz
| Information | When collected | Why |
|---|---|---|
| Name | Signup | Account identification |
| Email address | Signup | Login, notifications, security |
| Username | Signup | Public profile |
| Profile photo | Optional, profile setup | Public profile display |
| Bio | Optional, profile setup | Public profile display |
| NZ region | Signup / profile | Shipping estimates, localisation |
| Bank account details | Seller setup via Stripe | Payouts — stored by Stripe, not us |
| Listing photos | When listing | Display to buyers |
| Messages | When messaging | Facilitating buyer-seller communication |
| Information | Why |
|---|---|
| IP address | Security, fraud prevention, geographic compliance |
| Browser type and version | Security, compatibility |
| Pages visited and time spent | Platform improvement (analytics) |
| Login timestamps | Security audit log |
| Cookies and local storage | Session management, preferences |
| NZ Post tracking data | Order management, dispute evidence |
| Source | Information | Why |
|---|---|---|
| Stripe | Payment status, payout status, KYC verification status | Processing payments and payouts |
| Stripe Identity | Identity verification result (pass/fail) | Dispute fraud prevention |
| Google / Apple | Name, email (if you sign in with Google/Apple) | Authentication |
| NZ Post API | Parcel tracking events | Order management |
| Anthropic (Claude AI) | Item identification results | AI listing assistance |
Important: We receive verification results from Stripe Identity (pass/fail), not copies of your identity documents. Your documents are stored by Stripe under their privacy policy.
Create and manage your account · Display your listings · Process purchases and sales · Manage payments and payouts · Coordinate shipping tracking · Facilitate buyer-seller communication.
This is the most important use of your data. Our safety systems — including KYC verification — exist to protect honest buyers and sellers from scammers.
Verify seller identity via Stripe Connect before payouts · Verify buyer identity via Stripe Identity at dispute time · Detect and prevent fraudulent activity · Operate our strike and ban system · Report verified fraud to NZ Police where legally required.
Transactional emails (order updates, payment notifications) · Security alerts · Dispute notifications · Marketing communications (with your consent, opt-out available).
When you upload a photo to list an item, the image is sent to Anthropic's Claude AI for identification and pricing. Images are sent securely and are not used to train Anthropic's AI models. The result is returned to you immediately.
All data encrypted in transit (TLS 1.3) · Database encrypted at rest (AES-256) · Passwords hashed (bcrypt, never stored in plain text) · Row-level security — users can only access their own data · Payment data stored by Stripe, not on our servers · Regular security audits.
In the event of a data breach that poses a risk of harm, we will notify affected users and the NZ Privacy Commissioner as required by the Privacy Act 2020 (mandatory breach notification).
| Information | Retention period |
|---|---|
| Account data | Duration of account + 2 years after closure |
| Transaction records | 7 years (NZ tax and financial records requirement) |
| Messages | 2 years from last message |
| Dispute records | 7 years |
| KYC verification results | 7 years (financial compliance) |
| Security/login logs | 1 year |
| Analytics data | 2 years (anonymised after 90 days) |
| Deleted account data | Anonymised within 30 days; financial records retained per above |
Request a copy of all personal information we hold about you. We will respond within 20 working days.
Request correction of inaccurate information.
Request deletion of your account and personal information. Note: some information must be retained for legal and financial compliance (see Section 6).
Request your data in a machine-readable format (CSV/JSON). Available via Account Settings → Download My Data.
If you believe we have breached the Privacy Act, contact our Privacy Officer at privacy@whatsin.co.nz. If unresolved, you may complain to the NZ Privacy Commissioner at privacy.org.nz.
To exercise any right: Email privacy@whatsin.co.nz with your username and request. We will verify your identity before processing.
What's In? is not intended for users under 18. We do not knowingly collect information from anyone under 18. If we discover an account belongs to someone under 18, we will close it and delete their data.
Our third-party processors (Stripe, Anthropic) are US-based companies. By using What's In?, you consent to your information being processed in the United States and other countries where our processors operate, subject to appropriate safeguards.
When What's In? launches in Australia, this Privacy Policy will be supplemented by an Australia-specific addendum covering the Australian Privacy Act 1988 (Cth), Australian Privacy Principles (APPs), and Notifiable Data Breaches (NDB) scheme.
We will notify you of material changes by email and platform notice, with at least 14 days before changes take effect.