Privacy Policy
Last updated: 13 September 2026
1. Who this applies to
This policy covers personal information PayMint Limited ("PayMint", "we", "us") collects about two groups of people: business owners who sign up for an account, and their customers, whose details appear on invoices sent through the service.
2. What we collect
From account holders: name, email address, password (stored as a one-way hash, never in plain text), business name, phone, location, website, GST-registration status, and an optional logo image.
From invoices: the customer's name, email address, and the invoice details (description, amount, due date) that the account holder enters. We don't collect or store card numbers or other payment details ourselves — those are entered directly into Stripe's own secure checkout and never pass through PayMint's servers or database.
When you connect a Stripe account, Stripe collects and verifies identity information about your business directly — for example your legal name, date of birth, business ownership details, and a form of ID — as part of its own Know Your Customer (KYC) checks. That verification happens on Stripe's own hosted pages; we don't collect, see, or store that identity or ID information ourselves.
3. Why we collect it
To create and run your account, generate and send invoices and receipts, process payments, show accurate GST and overdue status, and email you (or your customer) about an invoice. We don't use your data for advertising, and we don't sell personal information to anyone.
4. Who we share it with
We use a small number of service providers to run PayMint, each of which only sees what it needs to do its job:
- Stripe — processes payments, and independently verifies your identity and bank details for KYC/anti-money-laundering purposes when you connect your account; card details go directly to Stripe, never to us.
- Resend — sends invoice and receipt emails on our behalf.
- Vercel — hosts the application, database (Postgres), and any uploaded logo images (Blob storage).
- Google — measures whether one of our adverts led to a signup. This runs on our public pages only, never inside your account, and never sees an invoice, a customer or a payment. See section 7.
We only use information about your connected Stripe account to provide PayMint's own features — like showing whether you're set up to accept payments yet — never for anything else without asking you first. We don't share your information with anyone else except where required by law.
5. Access by our own staff
PayMint is run by a small team, and we think you should know exactly what we can see rather than having to infer it.
We have an internal admin page listing every account: the account holder's name and email address, business name, signup date, whether a Stripe account is connected, how many invoices and quotes have been created, and total amounts paid. It does not show the contents of individual invoices or any of your customers' details.
We can also administer accounts from that page — suspend or reinstate one, send a password reset, correct an email address, or delete an account. Every one of those actions is recorded in an audit log with who did it, to which account, and when.
Separately, because we operate the database, we are technically able to read anything stored in it — including invoice and quote contents, and therefore your customers' names and email addresses. We do this only where it's genuinely needed: to investigate a fault or a security problem, to recover data, or where the law requires it. We don't read account data out of curiosity, for marketing, or to build any product other than the one you're using.
We also have a support tool that lets an administrator open your account and see it as you see it — your dashboard, invoices, quotes, GST report and settings, which includes your customers' names, email addresses and payment history. We use it to answer support questions and investigate faults. It is read-only: while it's in use, nothing can be created, changed, sent or deleted in your account, and no connection to your Stripe account can be made. Each session is limited to 30 minutes, requires a written reason, and both its start and its end are recorded in the audit log along with that reason and who opened it. We can't see your password at any point, as it's only ever stored as a one-way hash.
6. Security
Passwords are hashed with bcrypt and never stored or logged in plain text. Payment card details are handled entirely by Stripe under its own PCI-compliant infrastructure. Access to your data is limited to what's needed to run the service — see section 5 for what that means in practice. No system is completely secure, but we take reasonable steps to protect your information. If a privacy breach ever occurs that is likely to cause serious harm, we'll notify the Office of the Privacy Commissioner and the people affected, as the Privacy Act 2020 requires.
7. Cookies
PayMint uses a single essential session cookie (via NextAuth) to keep you logged in, and a first-party cookie that remembers which link brought you to the site the first time, so we can tell which of our own efforts actually work. Neither identifies you.
We also advertise on Google. On our public pages — not inside your account — Google's conversion tag runs so we can see whether an advert led to someone signing up. It sets cookies belonging to Google.
We turn ad personalisation off: this data is never used to build a remarketing audience or personalise ads shown to you elsewhere. It is used only to count whether an advert led to a signup, which is the narrowest purpose the tag can serve while still telling us anything useful. It does not run on any page inside your account, so nothing you do while actually invoicing is seen by it.
8. International data transfers
Our service providers (Stripe, Resend, Vercel) may store or process data outside New Zealand. They hold it as our processors, only to provide their services to us — which means we remain responsible for that information under the Privacy Act 2020, and each provider is bound by its own contractual and security safeguards. Stripe is different in one respect: the identity information it collects for its KYC checks (see section 2) it collects for its own compliance purposes, under its own privacy policy.
9. How long we keep it
We keep your account and its data for as long as the account is open. Anything with records in it stays: past invoices are financial records you may need years later, so removing them for you would do you harm rather than a favour.
The exception is an account that was never used at all. If an account reaches six months old with no invoice ever created on it and no Stripe account connected, we email the address on it giving 30 days' notice and then close it. Using it at any point in that window stops the closure — sending one invoice, or connecting Stripe, is enough. Either way you're emailed a copy of everything it holds before it goes. This exists because an account nobody ever used is personal information we have no reason to keep, not to hurry anyone along.
You can close your account yourself, from Settings, or ask us to do it. Either way we email you a complete export first — every invoice, quote and payment as spreadsheets, along with your business details — and copy it to our support address. Only then is the account deleted. If that email can't be sent, nothing is deleted: you get your records first, or not at all.
After that, deletion means deletion. Your data is removed from the live database, and our encrypted nightly backups are kept for 30 days, so within a month there is nothing left to recover from anywhere. Note that Inland Revenue requires business records to be kept for seven years, and that obligation is yours rather than ours — it doesn't end when you stop using PayMint, so keep the export somewhere safe.
10. Your rights
Under the Privacy Act 2020, you can ask to access or correct the personal information we hold about you. Most of your own account and business details can be updated directly in Settings. For anything else, or if you're a customer who received an invoice through PayMint and want to know what data we hold, email hello@paymint.co.nz. We'll respond to access and correction requests within 20 working days, as the Privacy Act requires.
If you're not happy with how we've handled your information, tell us first and we'll try to put it right. You can also complain to the Office of the Privacy Commissioner (privacy.org.nz) at any time — it's free.
11. Children's privacy
PayMint is a business tool and isn't directed at children. We don't knowingly collect personal information from children.
12. Changes to this policy
We may update this policy from time to time. Continuing to use PayMint after a change means you accept the updated policy.
13. Contact
Questions about this policy, or a request about your data? Email hello@paymint.co.nz.