This document explains our privacy policy for Kinwi Limited. Our marketplace is at the website address: https://kinwi.co.nz (which we’ll refer to as our “Platform”) and includes our mobile application (“App”).
In using our Platform, you acknowledge that your personal information will be treated as described in this policy. We respect your privacy and the following document provides transparency in how and why your personal information is collected and protected.
We confirm that we will comply with the applicable privacy laws, including the Privacy Act 2020, any applicable Privacy Codes and other laws when dealing with your information.
By accepting our Terms of Use, you confirm that you have read and understood our Privacy Policy. If you don’t want us to collect or process your personal information in the ways described in this policy, please do not use our Platform. We are not responsible for the content or the privacy policies or practices of any of our sellers, or third-party websites and apps.
When you visit our Platform, we collect certain information about your device, your interaction with the Platform, and information necessary to process your purchases. We use your personal Information to provide our services to you, which includes: offering products for sale, processing payments, shipping and fulfillment of your order, and may include keeping you up to date on new products, services, and offers. We collect information to improve and build our Platform and to provide a better experience for our users.
In our Privacy Policy, we refer to any information that can uniquely identify an individual as “Personal Information”. Please view the list below for examples about what Personal Information we collect and why;
Device information
Registration and account set up information
Guest information
Seller information
Location information
Order and transaction information
Fraud and safety measures
Customer support information
Analytic information
Information from third parties
Other information
You understand and agree that the Kinwi Platform and Stripe may share Your Data in order to facilitate your use of Stripe Connect or the Platform Services. Where Stripe receives Your Data from Connect Platforms, Stripe may use the Data in accordance with the Stripe Services Agreement and the Stripe Privacy Policy.
Kinwi will only use Stripe Connect and Connected Account Data consistent with our Terms of Use and Privacy policy. We will obtain consent from Connected Accounts before using Connected Account Data for any purpose other than providing Platform Services. Kinwi will use all reasonable efforts to protect and secure Connected Account Data from unauthorized use or disclosure.
We respect your privacy, and will not disclose your name, email address or other personal information to third parties without your consent, except as specified in this policy. As we provide a voluntary service, you can choose whether or not to use the Kinwi Platform.
To deliver our service, we rely on technical infrastructure in other parts of the world. For example, our server is based in Australia. This means we need to transfer your personal information to other locations, as necessary to provide this service, in accordance with the contract between us (our Terms of Use).
We may use your information to detect and prevent fraud, spam, abuse, security incidents, and other harmful activity and disclose your personal information for law enforcement reasons.
Buying and Selling: As part of the buying and selling process, you authorise Kinwi to share information, between the buyer and seller involved in the transaction, such as your name, delivery address, email address, and payment status. This can also involve us sharing your information with some of our third party partners, such as our payment and delivery partners to enable us to facilitate our service to you. Such partners will process your personal information in accordance with their own privacy policies. These partners, not Kinwi, are responsible for the protection of personal information under their control. By making a sale or a purchase on Kinwi, you are directing us to share your information in this way.
Since this is an important part of the service we provide, we need to do this in order to perform our obligations under our Terms of Use. We may partner with third parties to enable you to make a purchase from a Kinwi seller on that third party’s website or mobile app. That third parties’ terms of service and privacy policy will apply, in addition to Kinwi’s own policies, and they will collect information directly from you in connection with your purchase. The third party partner will share information collected from you with Kinwi for purposes of fulfilling the order and for any other purpose disclosed to you at the time you provide your information.
Both Kinwi and the sellers using our Platform process personal information (for example, buyer name, email address, and delivery address) and are therefore considered separate and independent data controllers of a buyer’s personal information. That means that each party is responsible for the personal information it processes in providing service. For example, if a seller accidentally discloses a buyer’s name and email address when fulfilling another buyer’s order, that seller, not Kinwi, will be responsible for that unauthorised disclosure. If, however, Kinwi and sellers are found to be joint data controllers of buyers’ personal information, and if Kinwi is sued, fined, or otherwise incurs expenses because of something that you did as a joint data controller of buyer personal information, you agree to indemnify Kinwi for the expenses it occurs in connection with your processing of buyer personal information.
We expect our sellers to respect the privacy of the buyer whose information they have received. As described in Kinwi’s Terms of Use, you have a limited license to use that information only for Kinwi-related communications or for Kinwi-facilitated transactions. Kinwi has not granted a license to you to use the information for unauthorised transactions or sending unsolicited commercial messages in violation of any applicable laws or consent requirements.
Service providers: We may need to disclose some of your Personal Information with third party service providers to help us fulfill our contracts with you and grow our Platform. These providers have limited access to your personal information to perform tasks on our behalf. Examples of these providers include; delivery agents, server providers, third party plugins, marketing partners, data analytics providers, safety and security providers, developers, lawyers, accountants and insurers. They are contractually obliged to use your personal information consistently with this Privacy Policy. In using the Platform, you authorise such disclosure.
As some of these service providers are located outside of New Zealand, they may not be subject to New Zealand Privacy laws. However, we will take reasonable steps to confirm that those organisations are required to protect your information in a way that provides comparable safeguards to those under the Privacy Act 2020.
Examples of where we may share your personal information
You can opt out of targeted advertising at the links below:
Additionally, you can opt out of some of these services by visiting the Digital Advertising Alliance’s opt-out portal at: http://optout.aboutads.info/.
Third Party Plugins: Third-party plug-ins also collect information about your use of the Platform. For example, when you load a page on Kinwi that has a social plug-in from a third-party site or service, such as a “Like” or “Share” button, you are also loading content from that third-party site. That site may request cookies directly from your browser. Please be aware that when you use third-party sites or services, their own terms and privacy policies will govern your use of those sites or services. If you link, connect, or log in to your account with a third party service, for example, Facebook, Instagram, Pinterest, that third party service may send us information as authorized by you via your privacy settings at that service. More information can be found in your account settings on the respective platforms, including in Google’s Privacy Centre and in Facebook’s Ad Settings. To the full extent applicable, Kinwi is not responsible for the privacy or security practices of other websites on the internet, even those linked to, or from our Platform.
Mobile Applications: may include third-party application software development kits (“SDKs”) that provide mobile performance and analytics data, bug reporting features, and application program interfaces (“APIs”) to third parties that help provide the Platform service, for social media functionality, and for marketing and advertising.
A note about links and embedded content:
We follow generally accepted industry standards to protect your personal information, both during transmission and after it is received. We have chosen Stripe as our payment gateway due to the advanced security features they offer.
Stripe Radar uses sophisticated machine learning trained daily on data from millions of global businesses to protect you from fraud. Stripe’s machine learning system continuously monitors all payments processed by our users. This fraud prevention toolset contains powerful machine learning algorithms. This process detects patterns across payments processed with Stripe, assessing the risk level of each. By learning from millions of global businesses processing hundreds of billions in payments each year, Stripe can assign risk scores to every payment and automatically block many high-risk payments. Stripe algorithms adapt quickly to shifting fraud patterns It even monitors for fraudulent activity after a transaction has been processed. This can occur if Stripe detects further activity on the card which now suggests it’s being used fraudulently, or if they receive an alert from the card network.
Stripe is fully PCI-DSS compliant with Stripe Elements hosted input fields. This means Stripe Elements transmits all sensitive data directly to Stripe without passing through our servers to remain PCI-DSS compliant. Stripe has been audited by a PCI-certified auditor and is certified to PCI Service Provider Level 1. This is the most stringent level of certification available in the payments industry. To accomplish this, they use the best-in-class security tools and practices to maintain a high level of security. Stripe forces HTTPS for all services using TLS (SSL) and uses HSTS to ensure that browsers interact with Stripe only over HTTPS. All card numbers are encrypted at rest with AES-256.
You have the option to save your card information for subsequent use, and if you choose this option, your credit or debit card details will be encrypted and securely stored.
Your account information is protected by a password. It is important that you protect against unauthorised access to your account and information by choosing your password carefully, and by keeping your password and computer secure, such as by signing out after using the Platform.
Your security is of the highest importance to us, but unfortunately no method of transmission over the internet, or method of electronic storage is 100% secure, so we regret we cannot guarantee absolute security. We would notify you and the Office of the Privacy Commissioner if a potentially harmful data breach of your personal information did occur.
Kinwi will retain your information only for as long as is necessary for the purposes set out in this policy, for as long as your account is active, or as needed to provide services to you. If you no longer want Kinwi to use your information to provide services to you, you may close your account. We will then retain and use your information only to the extent necessary to comply with our legal obligations, resolve disputes, enforce our agreements, and as otherwise described in this policy. In addition, Kinwi sellers may also be required to retain and use your information in order to comply with their own legal obligations. Please note that closing your account may not free up your email address, username, or shop name (if any) for reuse on a new account. We also retain log files for internal analysis purposes. These log files are generally retained for a brief period of time, except in cases where they are used for site safety and security, to improve site functionality, or we are legally obligated to retain them for longer time periods.
We generally retain your history of using the site, as under the Tax Administration Act we need to retain financial information for at least seven years, meaning we can’t just delete your transactional history straight away. We also need to be able to retain information for security purposes to guard against fraud.
Store content may be retained even after listings have sold or been removed. This is to help with any disputes, to help prevent fraud and facilitate legal processes, to comply with financial record-keeping and to help with product recommendations. Listing content may also persist elsewhere when third parties access and cache listings while they are live. For example, Google do this when they index the web for searching, so expired listings may show in Google searches for a period of time.
Service related messages: On occasion, Kinwi will need to contact you. Primarily, these messages are delivered by email. For this reason, every account is required to keep a valid email address on file to receive messages.
You understand and agree that Kinwi can send you service related emails, such as those related to transactions, your account, security, or product changes. Examples of service-related messages include an email address confirmation, welcome email when you register your account, notification of an order, delivery updates, relaying messages with buyers, and correspondence with Kinwi’s customer support team. We may also contact you by telephone to provide support if you specifically request that we call you.
If you no longer wish to use the Platform or receive service-related messages (except for legally required notices), then you may contact us to close your account.
Buying and Selling: As part of the buying and selling process, Kinwi will facilitate the communication of information between the two members involved in the transaction.
This includes information such as a buyer’s name, delivery address, email address, and payment status. Address and phone details may also be passed on to shipping providers to provide a delivery service. These shipping providers may communicate directly with you for the purpose of providing delivery updates.
Marketing messages: When you register for an account, subscribe to a newsletter, or provide us with your email address or phone number, such as for a Guest Checkout purchase, you agree to receive marketing emails and messages from us. We may send, or show you promotional messages, marketing, advertising, and other information about our Platform, including information that we think may be of interest to you. For example, we may make product suggestions on our websites or through email. You can opt out of receiving any marketing communications via email by following the unsubscribe link in any marketing email you receive.
As noted above, we collect and use personal information for business purposes, including providing and improving the Platform, maintaining the safety and security of the Platform and its users, processing sale and purchase transactions, and for advertising and marketing services. We never sell your personal information to third parties.
We use both technically necessary (for the functioning and security of the Platform) and non-technically necessary cookies and similar technologies. This collection may occur across devices.
Kinwi uses Cookie Technologies to recognize your logged-in state, to understand what products visitors are interested in, to help the Kinwi platform function for you, and to help your browsing experience and use of the Platform feel more seamless and customised. Some cookie and similar technology functions are necessary and vital to ensuring that Kinwi works properly for visitors and members, such as maintaining the security, safety, and integrity of the Platform, authentication and logging into Kinwi (including remembering permissions and consents you have granted), and ensuring the ability to securely complete transactions.
A cookie is a small amount of information that’s downloaded to your computer or device when you visit our Platform. They are stored in your browser’s cache and allow a website or a third party to recognise your browser. We use a number of different cookies, including functional, performance, advertising, and social media or content cookies. Cookies make your browsing experience better by allowing the website to remember your actions and preferences (such as login and region selection). This means you don’t have to re-enter this information each time you return to the site or browse from one page to another. Cookies also provide information on how people use our website, for instance whether it’s their first visit or they are a frequent visitor.
Cookies may be “session” cookies or “persistent” cookies.
Certain Cookie Technologies are employed to make the Platform function for its intended purpose, and are provided based on contractual necessity based on your agreement with Kinwi to perform the services you have requested. You can control and manage cookies in various ways, but please be aware that removing or blocking cookies can negatively impact your user experience and we may not be able to provide you with certain services.
Most browsers automatically accept cookies, but you can choose whether or not to accept cookies through your browser’s “Tools” or “Preferences” menu. More information on how to modify your browser settings, or how to block, manage or filter cookies can be found through such sites as www.allaboutcookies.org.
Please note that blocking cookies may not completely prevent how we share information with third parties, such as our advertising partners. To exercise your rights or opt-out of certain uses of your information by these parties, please visit http://optout.aboutads.info/
Other Technologies
In addition to cookies, there are other similar technologies used by Kinwi. These include; Web beacons, Social widgets, UTM codes, Application SDKs, Local Storage Objects, and Internet of Thing identifiers.
Kinwi gives you the choice of accessing, editing, or removing certain information on your account. You may change or correct your personal information through your account settings. Please get in touch with us if you require assistance updating your information. Only your chosen Display name will be publicly visible through the Platform, for example in reviews you have made. You can also request to permanently close your account and delete your personal information, except information we are required to retain by law, regulation, or to protect the safety, security, and integrity of Kinwi.
Right to Withdraw Consent: Where we rely on consent, you can choose to withdraw your consent to our processing of your information using specific features provided to enable you to withdraw consent, like an email unsubscribe link. If you have consented to share your precise device location details but would no longer like to continue sharing that information with us, you can revoke your consent to the sharing of that information through the settings on your mobile device. This is without prejudice to your right to generally permanently close your account and delete your personal information.
Please note that for security reasons, we may verify your identity before we are able to process any of the above requests.
We may use your information to resolve disputes with, or between any of our Platform users. We will seek your permission before disclosing your contact details to a third party involved in a dispute, unless this is permitted under the Privacy Act 2020
We may use your information to enforce our agreements with other Platform users or third parties, to conduct investigations, allow auditing and make risk assessments.
You have a right to access the personal information we hold about you. Your right to access this information comes from Information Privacy Principle 6 of the Privacy Act 1993. You also have a right to seek correction of any information we hold that is out of date or incorrect.
In some cases we may redact or withhold information to ensure what’s released doesn’t compromise an ongoing investigation by a government agency, create a security risk, or prejudice Kinwi’s commercial position.
Examples of information we may hold includes; your username, account holder name, your phone number, delivery and billing address and any edits made to these. It also includes the date your account was created, the dates of your account logins, the credits and debits recorded to your account, your account balance, product listing details (including purchase price, date of purchase, buyer username), details of products purchased (including purchase price, date of purchase, seller username)
If you wish to access your information, please contact us.
We may update this Privacy Policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal, or regulatory reasons. We encourage you to check back regularly and review any updates. If there are significant changes we may notify you directly via email.
If we undertake or are involved in any merger, acquisition, reorganisation, sale of assets, bankruptcy, or insolvency event, then we may sell, transfer or share some or all of our assets. In this event, we will notify you before your personal information is transferred and becomes subject to a different privacy policy.
If you have any questions or require further information about our Privacy Policy, you are welcome to contact us at customercare@kinwi.co.nz or fill in our contact form here.