Privacy Policy

Last Updated: 03 January 2026

1. Introduction

This Privacy Policy outlines how PayLock ("we", "us") manages personal information in compliance with the New Zealand Privacy Act 2020. PayLock is committed to minimal data collection and does not store unnecessary personal information.

2. Information we collect

PayLock collects only the data required to operate the service:

Information you provide directly:

  • Email address (for sending magic links and notifications)
  • Offer metadata (Offer amount, timestamps)
  • Dispute evidence voluntarily submitted

Information handled by Stripe:

PayLock does not collect or store:

  • Credit card numbers
  • Bank account details
  • Identity documents
  • Verification information

All financial and identity information is handled by Stripe, which is subject to strict global security standards and operates from a local office in Wellington, New Zealand.

3. Why we collect information

We collect minimal information strictly for:

  • Sending offers emails
  • Creating secure magic-link sessions
  • Processing payments via Stripe
  • Managing escrow flow
  • Reviewing disputes

We do not use data for marketing unless you explicitly opt-in.

4. Data storage

PayLock stores:

  • Offer logs
  • Email addresses
  • Escrow status updates

PayLock does not store:

  • Payment information
  • Identity documents
  • Bank accounts
  • Sensitive personal data

All financial data is stored and encrypted by Stripe.

5. Sharing information

We share information only with:

  • Stripe, for payment processing
  • Law enforcement if required by NZ law
  • Third-party dispute reviewers if applicable

We do not sell, trade, or lease data to anyone.

6. Cookies

PayLock uses basic session cookies for functionality only. We do not use tracking, advertising, or analytics cookies unless explicitly stated.

7. Your rights

Under the NZ Privacy Act 2020, you may:

  • Request access to your personal data
  • Request correction of inaccurate information
  • Request deletion where legally permissible

Requests can be made via the contact page.

8. Data security

We use secure NZ-based hosting and HTTPS encryption. Stripe manages all high-risk financial data with PCI-DSS compliance.

9. International transfers

Stripe may process data offshore but must comply with New Zealand privacy safeguards and international security standards.

10. Changes to this policy

We may update this policy. Any changes will be published on our website.

11. Contact

For privacy concerns or data requests, contact us.