Privacy Policy
Last updated: 4 May 2025
1. Who we are
AutoShopper NZ ("we", "us", "our") operates the website autoshopper.co.nz. We are based in New Zealand and comply with the Privacy Act 2020.
2. Information we collect
Account information
When you create an account we collect your name, email address, and password (stored securely hashed). If you sign in with Google, we receive your name and email from Google.
Listing information
When you list a car for sale we collect vehicle details, photos, your chosen contact email, and your region.
Communications
When you send an enquiry about a listing, we transmit your message to the seller. Your email address is included as a reply-to address so the seller can respond directly.
Usage data
We use Google Analytics and Google Tag Manager to collect anonymised browsing data (pages visited, device type, referral source). No personally identifiable information is sent to Google.
3. How we use your information
- To provide and maintain your account
- To display your listings to potential buyers
- To facilitate communication between buyers and sellers
- To send transactional emails (verification, password reset, enquiry notifications)
- To improve our services and fix bugs
4. Contact email & reply-to disclosure
Important: When a buyer sends an enquiry about your listing, the email is delivered to your contact email address. The buyer's email address is included in the reply-to field so you can reply directly. By replying to an enquiry, you share your contact email address with the buyer. We act only as an intermediary for the initial message — subsequent communication occurs directly between buyer and seller.
Similarly, if you are a buyer and send an enquiry, your email address will be visible to the seller when they receive your message.
5. Data sharing
We do not sell your personal information. We share data only with:
- Email service providers — to deliver transactional emails
- Cloud hosting providers — to store your data securely
- Google (OAuth & Analytics) — for sign-in and anonymised analytics
6. Data retention
We retain your account data for as long as your account is active. Listing data is retained for 12 months after a listing is marked as sold or deleted. You can delete your account at any time from Settings, which removes all personal data within 30 days.
7. Your rights
Under the Privacy Act 2020 you have the right to:
- Access your personal information
- Request correction of inaccurate data
- Request deletion of your data
- Withdraw consent for marketing emails at any time
8. Cookies
We use essential cookies for authentication sessions and optional analytics cookies via Google Tag Manager. No third-party advertising cookies are used beyond Google AdSense.
9. Security
We use HTTPS encryption, secure password hashing, and access controls to protect your data. However, no system is 100% secure — use a strong unique password for your account.
10. Changes
We may update this policy from time to time. Changes will be posted on this page with an updated date.
11. Contact
For privacy enquiries, email [email protected].