Privacy Policy

Last updated: March 2026

1. Who We Are

South Island Food Trucks operates the platform at sifoodtrucks.nz. We are committed to protecting your personal information in accordance with the New Zealand Privacy Act 2020. This policy explains what data we collect, why we collect it, how we store it, and your rights in relation to it.

Questions or requests regarding your data can be directed to privacy@sifoodtrucks.nz.

2. Information We Collect

Account information: Name, email address, password (hashed), and role (customer or operator).

Operator information: Business name, food truck details, menu, photos, operating location, bank account details (held by Stripe — we do not store bank details directly).

Booking information: Contact name, email, phone number, event date, location, guest count, event details, and payment status.

Payment information: Payment is processed by Stripe. We store transaction references, amounts, and statuses — we do not store card numbers or full payment instrument details.

Communications: Messages sent through the in-platform booking messaging system.

Usage data: Page views, booking actions, and feature usage for platform analytics and improvement. We do not use third-party advertising trackers.

3. How We Use Your Information

  • To operate and improve the platform
  • To facilitate bookings between customers and operators
  • To process payments and manage subscriptions
  • To send booking confirmations, payment notifications, and status updates
  • To respond to enquiries and provide customer support
  • To detect and prevent fraud or misuse
  • To comply with our legal obligations under New Zealand law

4. Third-Party Service Providers

We use the following third-party services to operate the platform. Each acts as a data processor under our instructions:

  • Stripe — payment processing and operator payouts. Data may be stored in the United States. See Stripe’s Privacy Policy.
  • Supabase — database hosting (PostgreSQL), hosted in Sydney, Australia.
  • Resend — transactional email delivery. See Resend’s Privacy Policy.
  • Vercel — platform hosting and deployment, with servers in the United States and globally via CDN.

Where data is transferred outside New Zealand, we ensure appropriate safeguards are in place consistent with the Privacy Act 2020.

5. Cookies

We use session cookies to maintain your login state (via NextAuth). These are essential for the platform to function and do not track you across other websites. We do not use advertising or profiling cookies.

6. Data Retention

We retain your account data for as long as your account is active. Booking records are retained for 7 years to meet our financial and legal obligations. You may request deletion of your account at any time — see section 8 below.

7. Security

We take reasonable technical and organisational measures to protect your data, including encrypted connections (HTTPS), hashed passwords, row-level database security, and access controls. No system is completely secure — please use a strong, unique password for your account.

8. Your Rights

Under the New Zealand Privacy Act 2020, you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your account and personal data (subject to our legal retention obligations)
  • Complain to the Office of the Privacy Commissioner if you believe we have breached the Act

To exercise any of these rights, email privacy@sifoodtrucks.nz. We will respond within 20 working days as required by the Act.

9. Children

Our platform is not directed at children under 18. We do not knowingly collect personal information from anyone under 18.

10. Changes to This Policy

We may update this policy from time to time. We will notify you of significant changes by email or via a notice on the platform. The date at the top of this page indicates when the policy was last revised.