Privacy Policy

Last updated: April 2026  ·  Governing legislation: NZ Privacy Act 2020  ·  ShiftScript Ltd, Palmerston North, New Zealand

This policy explains how ShiftScript Ltd collects, stores, uses, and protects personal information in accordance with the Privacy Act 2020 (New Zealand) and its 13 Information Privacy Principles (IPPs).

1. Who we are

ShiftScript Ltd ("ShiftScript", "we", "us") is a software company registered in New Zealand, operating the ShiftScript platform at shiftscript.nz. We are the agency responsible for the personal information we collect and hold.

Privacy Officer contact: [email protected]
Postal address: ShiftScript Ltd, Palmerston North, New Zealand

2. What information we collect

Account information

When you create a ShiftScript account, we collect: your name, email address, organisation name, and a handle (username). We do not collect payment card details — payments are processed directly by Stripe Inc.

Usage data

We log queries submitted to your workspace, the documents retrieved in response, the timestamp of each query, and the staff member handle associated with each query. This constitutes the audit log that is a core feature of the Service.

Document content

Documents you upload are stored as encrypted chunks in Cloudflare R2. We do not read, index, or otherwise access your document content except as required to provide the retrieval service (vectorisation and chunk retrieval).

Technical data

We collect standard server logs including IP addresses, browser type, and request timestamps for security and debugging purposes. We do not use advertising cookies or cross-site tracking technologies.

3. Why we collect it (legal basis)

PurposeInformation usedLegal basis (NZ Privacy Act 2020)
Providing the ServiceAccount info, document chunks, query logsIPP 1 — collected for a lawful purpose (contract performance)
Billing and subscriptionsEmail, org name, plan typeIPP 1 — lawful purpose (contract); passed to Stripe for processing
Audit log featureQuery content, handle, timestampIPP 1 — collected at your direction for compliance purposes
Security and debuggingIP addresses, request logsIPP 1 — legitimate interest in platform security
Welcome emailsEmail addressIPP 1 — transactional communication directly related to your account

4. How we use your information

We use personal information only for the purposes stated above. Specifically:

5. Data storage and residency

All ShiftScript data is stored on Cloudflare's infrastructure. Cloudflare operates data centres globally; your data may be stored or processed in any Cloudflare data centre region. Cloudflare has data processing agreements covering GDPR and equivalent standards. ShiftScript is operated from New Zealand. We do not use self-hosted servers or third-party cloud storage providers other than Cloudflare.

For organisations with specific data residency requirements, contact us at [email protected] to discuss arrangements.

6. Third-party processors

The following third-party services process data on our behalf as part of delivering the Service:

ProcessorPurposeData sharedPrivacy link
Cloudflare IncInfrastructure: file storage, database, edge computeAll platform datacloudflare.com/privacypolicy
Stripe IncPayment processingEmail, billing detailsstripe.com/privacy
Resend IncTransactional email (welcome, account)Email address, nameresend.com/privacy
AIML API / AI providersQuery processing (AI model inference)Document fragments (3–5 chunks per query, ~4,800 chars)No training on API data under API terms

7. Your rights under the NZ Privacy Act 2020

Under the Privacy Act 2020 and its 13 Information Privacy Principles, you have the right to:

To exercise any of these rights, contact [email protected]. We will respond within 20 working days in accordance with IPP 6.

8. Data retention

Data typeRetention period
Account informationRetained while account is active + 30 days after cancellation
Uploaded documentsRetained while in your workspace. Permanently purged within 24 hours of deletion or workspace closure.
Query / audit logsRetained for 12 months from query date, then purged. Exportable at any time.
Billing recordsRetained for 7 years (NZ tax law requirement)
Security / access logs90 days, then purged

9. Security

We implement the following technical security measures:

Despite these measures, no system is perfectly secure. If you believe a security incident has occurred, contact [email protected] immediately.

10. Privacy breach notification

In the event of a privacy breach that creates a risk of serious harm, we will notify affected individuals and the Office of the Privacy Commissioner as required by section 113 of the Privacy Act 2020, and no later than 72 hours of becoming aware of the breach. We will also notify you directly if your workspace data is involved.

11. Cookies

ShiftScript uses no advertising cookies, no third-party analytics tracking, and no cross-site tracking technologies. We use a session cookie strictly necessary for authentication. This cookie is not shared with third parties.

12. Cross-border data transfer

Your data is processed on Cloudflare's global infrastructure and may be transferred to servers outside New Zealand. Cloudflare operates under contractual data processing agreements that meet the requirements of IPP 12 for cross-border disclosures. AI model inference involves sending document fragments to AI provider APIs; these providers operate under API terms that prohibit training on customer data.

13. Children

ShiftScript is not directed at children under 16. We do not knowingly collect personal information from children.

14. Changes to this policy

We will notify account holders via email at least 14 days before any material changes to this policy take effect. The current version is always at shiftscript.nz/privacy.html.

15. Contact and complaints

Privacy Officer: [email protected]
ShiftScript Ltd, Palmerston North, New Zealand

If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner (New Zealand) at privacy.org.nz or by calling 0800 803 909.