Privacy Policy

Last updated: [add date when published]

Draft template — not legal advice. This page is a starting point written to match how PayMint actually works and the NZ Privacy Act 2020, not a substitute for review by a New Zealand lawyer. Given this service handles real payments and personal data, get it reviewed and adapted to your actual business setup before relying on it.

1. Who this applies to

This policy covers personal information PayMint("PayMint", "we", "us") collects about two groups of people: business owners who sign up for an account, and their customers, whose details appear on invoices sent through the service.

2. What we collect

From account holders: name, email address, password (stored as a one-way hash, never in plain text), business name, phone, location, website, GST-registration status, and an optional logo image.

From invoices: the customer's name, email address, and the invoice details (description, amount, due date) that the account holder enters. We don't collect or store card numbers or other payment details ourselves — those are entered directly into Stripe's own secure checkout and never pass through PayMint's servers or database.

3. Why we collect it

To create and run your account, generate and send invoices and receipts, process payments, show accurate GST and overdue status, and email you (or your customer) about an invoice. We don't use your data for advertising, and we don't sell personal information to anyone.

4. Who we share it with

We use a small number of service providers to run PayMint, each of which only sees what it needs to do its job:

  • Stripe — processes payments and holds the bank/KYC details for your connected account; card details go directly to Stripe, never to us.
  • Resend — sends invoice and receipt emails on our behalf.
  • Vercel — hosts the application, database (Postgres), and any uploaded logo images (Blob storage).

We don't share your information with anyone else except where required by law.

5. Security

Passwords are hashed with bcrypt and never stored or logged in plain text. Payment card details are handled entirely by Stripe under its own PCI-compliant infrastructure. Access to your data is limited to what's needed to run the service. No system is completely secure, but we take reasonable steps to protect your information.

6. Cookies

PayMint uses a single essential session cookie (via NextAuth) to keep you logged in. We don't use tracking or advertising cookies.

7. International data transfers

Our service providers (Stripe, Resend, Vercel) may store or process data outside New Zealand. Each provider maintains its own safeguards for handling this data; using PayMint means you accept that some data will be processed overseas as a result.

8. How long we keep it

We keep account and invoice data for as long as your account is active, since past invoices are financial records you may need later. If you close your account and ask us to delete your data, we'll do so except where we need to keep records for legal or tax purposes.

9. Your rights

Under the Privacy Act 2020, you can ask to access or correct the personal information we hold about you. Most of your own account and business details can be updated directly in Settings. For anything else, or if you're a customer who received an invoice through PayMint and want to know what data we hold, email help@paymint.co.nz.

10. Children's privacy

PayMint is a business tool and isn't directed at children. We don't knowingly collect personal information from children.

11. Changes to this policy

We may update this policy from time to time. Continuing to use PayMint after a change means you accept the updated policy.

12. Contact

Questions about this policy, or a request about your data? Email help@paymint.co.nz.