Information Privé handles
If you create an account, Supabase Auth processes your email address, password and sign-in session. The service stores your account role and the dates you accepted the terms. Privé does not receive or store payment-card details; paid checkout is not connected.
Provider profiles can include a display name, city and suburb, description, services, rates, availability, media and optional personal or appearance details. A provider application also asks for a private legal name and contact mobile for moderation; those fields are restricted to authorised moderation use and are not shown publicly. Draft information may be saved in the browser on the device where it was entered; use “Clear unsaved device draft” before sharing that device. Customers can send private enquiries, which are stored and made available to the provider they contact. Venue advertisers can submit a business type, business name, city and short description.
For a provider’s one-time ID and 18+ check, a moderator views original photo ID in person or by live video. Privé does not upload or retain the ID document, its image or number, or the person’s date of birth. The record kept is the check result, method, moderator and date. The listing may show that the check was recorded; it is not a background check or a guarantee of identity or conduct.
How and why information is used
Account and profile information supports sign-in, the listing and enquiry service, moderation, security, service messages and support. Moderators use application and verification details to review provider listings and follow up where needed. Enquiries are shared with the provider the customer chose. Privé does not currently send promotional email campaigns.
Privé uses Netlify for website hosting and Web Analytics. Analytics reports site traffic such as page views, estimated visitors, referral sources and general locations. Netlify’s documentation says its Web Analytics uses server logs rather than browser cookies or a client-side tracking script; its visitor estimates use IP addresses. Google Fonts and jsDelivr provide page resources and receive ordinary browser request information when loaded. Privé does not intentionally send profile or enquiry contents to those resource providers.
Supabase provides sign-in, database, private profile-media storage and backend functions. Resend delivers Supabase Auth verification and recovery messages and Privé service emails, including approval and trial reminders. Cloudflare R2 holds a separate recovery copy of provider media. These providers process information as needed to supply their services. No payment processor is connected.
What other people can see
Only approved and published provider profile details and approved media appear in the directory. Optional details are private unless the provider chooses to display them. Provider email, private application fields and contact preferences are not public. A provider phone number appears only if that provider turns on phone display. WhatsApp, when enabled, opens WhatsApp as a separate service. Venue advertisements appear only after moderation and show the submitted business category, name, city and approved description.
Visitors can copy or save public content. Providers should keep private addresses, personal phone numbers and other sensitive information out of public profile text.
Storage, location and safeguards
The live Supabase project is in Sydney, Australia. Provider media is stored in a private Supabase bucket; media is shown with time-limited links after moderation approval and publication. Role-based database and storage rules restrict access to account and media records. Provider sign-ins use authenticator multi-factor authentication. Cloudflare R2 stores separate recovery copies in a private bucket; its Asia-Pacific location hint is best effort and does not guarantee a particular country. Netlify uses a content-delivery network. The providers may process information outside New Zealand.
In local demo mode, sample account and profile information is saved in that browser’s local storage and is not sent to Supabase. In the live service, Supabase handles account and profile data. Access credentials for backend services are kept server-side and are not placed in the public website code.
Supabase Pro database backups are retained for seven days. Cloudflare R2 automatically removes objects in the media-backup snapshots/ folder after 30 days. These are separate recovery copies with different retention periods. Privé keeps account, profile, enquiry and moderation records while needed to operate the service, handle safety or disputes, or meet applicable requirements. When an account is closed, Privé will remove or de-identify information no longer needed; backup copies and provider logs can remain until their normal expiry. You can request account closure and ask what information is held using the contact below.
Your privacy choices
Providers choose what optional profile details to submit and which supported details to display. New media stays private until review is complete. Providers can remove their own media and update their profile. You may ask to access or correct personal information Privé holds about you, or request account closure, by emailing the privacy contact below. We may need to verify the request before acting.
New Zealand’s Privacy Act 2020 provides rights to request access to and correction of personal information, subject to the Act. Read the Office of the Privacy Commissioner’s access guidance and correction guidance. Some information is processed outside New Zealand. See the Commissioner’s Principle 12 guidance.
Privacy contact
For privacy requests, complaints or suspected privacy issues, contact Privé NZ at prive.nz.support@gmail.com. Do not send passwords or identity documents by email. Privé NZ is the public trading name and contact identity for this service.