Privacy Policy
1.Who this policy is for
This policy applies to anyone whose personal information passes through Suddenly Sorted, which includes:
- Business owners — the people who sign up to use the dashboard
- End customers — the people who chat with the AI on a business's website or booking page
- Website visitors — anyone who visits suddenly.co.nz or related pages
"We", "us", and "our" mean Suddenly Sorted (NZBN 9429053711434), a business based in New Zealand. We are an "agency" under the Privacy Act 2020.
2.What we collect
From business owners (account holders)
- Business name, contact email, password (stored hashed — we never see the plain text)
- If you sign in with Google: your name and verified email address. We do not access your Gmail, Google Contacts, Google Drive, or any other Google service.
- Business info you choose to add: services, prices, hours, location, policies, welcome message, widget colour
- Billing details (handled by Stripe — we receive your subscription status and last 4 digits of your card, never the full number)
- Logs and usage data: when you signed in, what API endpoints you called, error reports
From end customers (people who chat with the AI)
- The messages they send to the AI
- The AI's responses
- Any booking details captured during the chat (name, phone, email, service, preferred time, notes)
- Basic technical info (IP address, browser type, timestamps) for security and abuse prevention
A note on who can see this: the business you're chatting with can review these conversations in their dashboard — including ones that don't end in a booking — so they can follow up and improve their service.
From website visitors
- Basic analytics (page views, referrer) — we use privacy-respecting analytics where possible
- Anything you submit through forms (e.g. waitlist signups)
3.How we use it
We use your information to:
- Provide and run the Service (deliver chat responses, save bookings, send notification emails)
- Manage your account and process payments
- Send transactional emails (booking confirmations, password resets, account notifications)
- Improve the Service (fix bugs, understand what's working)
- Keep the Service secure (detect and prevent abuse, fraud, or misuse)
- Comply with our legal obligations (tax, accounting, lawful requests)
What we don't do: we don't sell your data. We don't use end-customer chat messages to train AI models. We don't send you marketing emails unless you opt in.
4.Who we share it with
We use a small number of trusted third parties ("sub-processors") to actually run the Service. They only get the information they need to do their part, and they're bound by their own privacy obligations.
| Provider | What they do for us | Where |
|---|---|---|
| Cloudflare | Hosting, database (D1), CDN, security | Global (incl. NZ edge) |
| Anthropic | AI language model (Claude) — generates chat responses | USA |
| Stripe | Payment processing for paid plans | USA / Ireland |
| Resend | Sending transactional emails (booking notifications, password resets) | USA |
| Sign-in (name + email only, if you choose this option) and Google Calendar sync (only if you connect it) | USA | |
| TNZ Group (optional) | SMS confirmations & reminders, our primary SMS provider — only if SMS is enabled on your plan | New Zealand |
| ClickSend (optional, fallback) | SMS confirmations & reminders, used only as a fallback if our NZ provider is unavailable | Australia |
| Sentry | Error monitoring & diagnostics, to keep the Service reliable | USA |
We may add or change sub-processors over time. We'll update this list when we do.
We may also share information when we have to — for example, in response to a lawful request from law enforcement, to protect our rights, or as part of a business sale or restructure (in which case the new owner will be bound by this policy or a substantially similar one).
5.Where your data is stored
The Service is built on Cloudflare's global network. Your data is primarily stored in databases hosted by Cloudflare and processed at edge locations close to you. Our primary SMS provider, TNZ Group, is based in New Zealand. Some sub-processors (notably Anthropic, Stripe, Resend, Google, Sentry) are based in the United States, and our fallback SMS provider ClickSend is in Australia, which means some of your personal information may be sent to and stored overseas.
Where we send personal information outside New Zealand, we take reasonable steps to make sure it's protected by comparable privacy safeguards (such as standard contractual terms, or transferring only to jurisdictions with adequate privacy laws).
6.How long we keep it
We keep personal information for as long as we need it for the purpose we collected it, plus any period required by law:
- Account data — for the life of your account, plus up to 12 months after closure (for audit and dispute resolution)
- Bookings and chat transcripts — for the life of your account, unless you ask us to delete them sooner
- Billing records — at least 7 years (IRD record-keeping requirements)
- Logs and security data — typically 30–90 days
You can ask us to delete your account and most associated data at any time (see section 8).
7.Keeping data safe
We take reasonable technical and organisational steps to protect personal information from loss, misuse, and unauthorised access. These include:
- HTTPS encryption for all traffic to and from the Service
- Password hashing using PBKDF2-SHA256 (we never store plain-text passwords)
- JWT-based authentication with short-lived tokens
- Access controls limiting which staff can see which data
- Routine security updates to our infrastructure
No system is ever 100% secure. If a serious privacy breach happens, we'll let you know and report it to the Office of the Privacy Commissioner as required by the Privacy Act 2020.
8.Your rights under the Privacy Act 2020
Under New Zealand's Privacy Act 2020 you have the right to:
- Access — ask us what personal information we hold about you
- Correct — ask us to correct anything that's wrong or out of date
- Delete — ask us to delete information we no longer need (subject to legal retention requirements)
- Object — let us know you don't want us to use your information for a particular purpose
- Withdraw consent — for anything you've consented to, you can change your mind at any time
To make a request, email our Privacy Officer at hello@suddenly.co.nz. We'll respond within 20 working days (often much sooner) and there's no charge for a reasonable request.
9.Cookies and browser storage
We use cookies and similar technologies (localStorage, sessionStorage) for:
- Keeping you signed in — your JWT auth token is stored in localStorage so you don't have to log in every visit
- Remembering preferences — small bits of state in the dashboard
- Basic analytics — page view counts, where you came from
We don't use third-party advertising cookies and we don't sell information about your browsing to advertisers. You can clear cookies/storage at any time from your browser settings.
10.Children
The Service isn't designed for use by children under 16. We don't knowingly collect personal information from children. If you think a child has signed up or shared information with us, please email hello@suddenly.co.nz and we'll delete it.
11.Updates to this policy
We may update this policy from time to time. The "Last updated" date at the top tells you when it last changed. If the change is significant we'll let account holders know by email or via the dashboard.
12.Contact our Privacy Officer
Got questions about privacy, or want to make a request about your data? Email us:
Privacy Officer
Suddenly Sorted
hello@suddenly.co.nz
13.Complaints
If you're not happy with how we've handled your personal information, please tell us first — we'd genuinely like a chance to put it right. Email hello@suddenly.co.nz and mark it "Privacy complaint".
If you're still not satisfied after we've responded, you can make a complaint to the New Zealand Office of the Privacy Commissioner:
- Online: privacy.org.nz
- Phone: 0800 803 909
14.Google API Services Limited Use
Suddenly Sorted's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice, if you connect Google Calendar we use that access only to check your availability and to create, update and remove booking events on your behalf, so your Suddenly Sorted calendar and your Google Calendar stay in sync. We do not use Google user data for advertising, we do not sell it, and we do not transfer it to anyone except where it is needed to provide this feature you asked for, or where you give consent, for security purposes, or to comply with the law. We do not allow humans to read your Google Calendar data except with your consent, for security or debugging with your permission, or where required by law.
You can disconnect Google Calendar at any time from your dashboard, and you can revoke Suddenly Sorted's access directly in your Google Account permissions.