Tranxactor Privacy Policy
For Tranxactor New Zealand Limited and Tranxactor-operated products, websites, applications, platforms, programmes and services.
1. Introduction
This Privacy Policy explains how Tranxactor New Zealand Limited collects, uses, stores, protects and discloses personal information when providing its products and services. It is designed as the master privacy policy for Tranxactor-operated services so that individual product terms can refer to this policy rather than repeating privacy wording in full.
2. Who this Privacy Policy applies to
This Privacy Policy applies to customers, users, recipients, gift recipients, cardholders, account holders, programme participants, programme sponsors, merchants, retailers, business customers, website visitors and any other individuals whose personal information is collected or handled by Tranxactor in connection with its services.
3. Products and services covered
This Privacy Policy applies to Tranxactor-operated products and services, including i-PAY, PayZe, Give a Gift Card, Hampsta and any related websites, mobile applications, customer portals, payment services, gift card services, stored-value services, loyalty programmes, reward programmes, customer support services and communications channels.
Some product terms may include a short product-specific privacy note or addendum where additional context is useful. Those notes should be read together with this Privacy Policy.
4. Types of information we collect
The types of personal information we collect depend on the product or service used. This may include:
- name, contact details, email address, phone number, date of birth and residential address;
- identity information and verification documents;
- account details, payment details and transaction history;
- card or wallet information, gift card order information and recipient information;
- programme participation details;
- communications with us; and
- information needed to provide customer support.
5. How we collect information
We collect personal information directly from individuals when they register, use a service, place an order, make or receive a payment, contact customer support, participate in a programme, complete verification steps, submit forms, use a website or app, or otherwise communicate with us.
We may also collect information from third parties where this is necessary or permitted, including banks, payment partners, identity verification providers, fraud prevention services, merchants, retailers, programme sponsors, delivery providers, technology providers, regulators, law enforcement agencies and publicly available sources.
6. Why we collect, use and disclose information
We collect, use and disclose personal information for purposes connected with operating and administering our services, including to:
- provide and administer our services;
- verify identity and manage accounts;
- process transactions and issue or redeem cards and stored value;
- fulfil gift card orders and operate loyalty or reward programmes;
- provide customer support and communicate with customers;
- manage risk, prevent fraud and maintain records;
- comply with legal and regulatory obligations; and
- improve our services and enforce our terms.
7. Identity verification, AML/CFT, sanctions and fraud monitoring
For some services, we may be required or may reasonably choose to take steps to meet legal, regulatory, banking, payment partner and risk-management requirements. These steps may include:
- verifying identity;
- screening transactions and monitoring activity;
- assessing source of funds or source of wealth;
- conducting sanctions checks;
- detecting suspicious activity;
- preventing fraud; and
- managing chargeback or payment reversal risk.
8. Transaction, card, wallet, gift card and programme information
We may collect and use information about service activity, including:
- transactions, wallets, cards, gift cards, balances, redemptions, refunds and orders;
- recipients, merchants, retailers and programme sponsors;
- payment methods, device or account activity and related service events.
This information is used to operate the relevant product, manage customer support, reconcile payments, provide reports, prevent misuse, investigate disputes and meet legal, tax, accounting, trust administration, audit, regulatory and risk-management requirements.
9. Service providers and technology providers
We use trusted service providers to help deliver our services. These may include cloud hosting providers, software vendors, identity verification providers, payment processors, fraud prevention providers, communications platforms, delivery providers, analytics providers, customer support systems and professional advisers.
10. Banks, payment partners, merchants, retailers and programme partners
We may disclose personal information to banks, payment service providers, payout partners, merchants, retailers, programme sponsors, card issuers, trustees, settlement partners and other parties involved in providing, funding, processing, redeeming, settling, supporting or administering a Tranxactor service.
11. Overseas disclosure
Some personal information may be disclosed to or accessed by recipients outside New Zealand. These recipients may include:
- technology providers and cloud service providers;
- identity verification providers;
- payment partners and payout partners;
- customer support providers; and
- other service providers.
Where required by New Zealand privacy law, we will take reasonable steps to ensure that overseas recipients protect personal information with safeguards that are comparable to those under the New Zealand Privacy Act 2020, or we will otherwise rely on an available lawful basis for the disclosure.
12. Marketing and service communications
We may use contact details to send service messages, account notices, transaction updates, security alerts, programme information, support communications and other messages reasonably connected with the services used. Where permitted, we may also send marketing or promotional communications about Tranxactor products and services. Individuals may unsubscribe from marketing communications where an unsubscribe option is provided, but may still receive important service, legal, security or account-related communications.
13. Website visitors, cookies and online enquiries
When individuals visit a Tranxactor website, use an online form, request more information, subscribe to updates, download materials, contact us through a website, or interact with our online services, we may collect personal information such as contact details, organisation details, enquiry details, preferences, communications, website usage information, device information, IP address, browser information and related technical or security information.
We use this information to:
- respond to enquiries and provide requested information;
- manage sales or support follow-up;
- improve our websites and services;
- understand website engagement;
- maintain website security;
- prevent misuse or fraud;
- manage communications preferences; and
- send permitted service or marketing communications.
We may use cookies, analytics tools and similar technologies for website functionality, security, measurement and service improvement. Where required, individuals may manage cookie or marketing preferences through available browser, website or unsubscribe settings.
14. Security of information
We take reasonable steps to protect personal information from loss, unauthorised access, misuse, disclosure, alteration or destruction. Security measures may include access controls, authentication, encryption, monitoring, logging, staff training, supplier controls and operational procedures appropriate to the nature of the information and the services provided.
15. Retention of information
We keep personal information for as long as reasonably required for the purposes for which it was collected, including to:
- provide services;
- manage accounts and transactions;
- meet legal, tax, accounting, AML/CFT, sanctions, fraud prevention, trust administration, audit, dispute resolution and record keeping obligations; and
- protect our legitimate business interests.
When information is no longer required, we will take reasonable steps to securely delete, destroy or de-identify it.
16. Access and correction
Individuals may request access to personal information we hold about them and may request correction of personal information in accordance with the New Zealand Privacy Act 2020. We may need to verify identity before responding to an access or correction request. If we do not agree to make a requested correction, an individual may ask us to attach a statement of correction to the relevant information where required by law.
17. Privacy complaints
If you have a privacy concern or complaint, please contact us first so we can review and respond. If we are unable to resolve the matter, you may contact the Office of the Privacy Commissioner in New Zealand.
18. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our products, services, operations, legal obligations, technology, risk settings or business requirements. The current version will be published on the relevant Tranxactor website or otherwise made available through our usual customer communication channels.
19. Contact details
For privacy questions, access or correction requests, or privacy complaints, please contact: Privacy Officer, Tranxactor New Zealand Limited, Email: [email protected]