Privacy Policy
Last updated: 30 July 2026.
HelloRegulars is a loyalty card that lives in a phone's wallet. To do that it needs an email address and a count of visits. That is very nearly all it collects, and this page explains the rest.
Who is responsible for what
HelloRegulars is operated by New Zealand Directory (2007) Limited, Christchurch, New Zealand.
There are two different relationships on this page, and it matters which one applies to you:
- If you are a shop owner who subscribes to HelloRegulars, we collect information about you directly, and we are responsible for it.
- If you are a customer who has a loyalty card from a shop, that information belongs to the shop. We hold and process it on the shop's behalf so their loyalty program works. If you want your details changed or removed, you can ask us or ask the shop — see "Your rights" below.
What we collect about shop owners
- Your email address, and your shop's name and branding choices.
- Your password, stored only as a cryptographic hash — we cannot read it.
- Billing details, held by Stripe. We never see or store your full card number.
- Ordinary technical logs: requests to our servers, with IP addresses and timestamps.
What we collect about your customers
When someone adds one of your loyalty cards, we collect:
- Their email address. Required. It is what makes a lost card recoverable when they change phones, and it is how we confirm the card is theirs.
- Their first name, if they choose to give it. Optional, and clearly marked as such. It exists so staff can greet them by name.
- Whether they ticked the marketing box. Not ticked by default, ever.
- Their card activity — stamps earned, visits used, offers redeemed, and when.
We do not collect their phone number, their address, their date of birth, or anything about what they bought or what they spent. HelloRegulars does not connect to any point-of-sale system, so we could not know that even if we wanted to.
We do not track customers across other websites, and this site sets no advertising or analytics cookies.
Why we collect it
- To issue the wallet card and keep its stamp count up to date.
- To confirm an email address belongs to the person who gave it.
- To send a card back to someone who has lost their phone.
- To let a shop send a message to the holders of one of its cards.
- To bill shop owners, and to provide support.
- To keep the service secure and working.
Marketing
We never market to your customers. We do not sell, rent or share personal information with anyone for their own marketing.
A shop may market to its own customers, but only to those who both ticked the marketing box and confirmed their email address by following the link we send. The export marks exactly who that is. Ticking a box that was never pre-ticked, and then proving the address is yours, is what consent means here.
Every card holder can stop hearing from a shop by deleting the card from their wallet, or by asking the shop or us to remove them.
Who else sees it
We use a small number of service providers, and only to run the service:
- Amazon Web Services — hosting and storage, in the Asia Pacific (Sydney) region.
- Amazon Simple Email Service — sending the confirmation and card-recovery emails.
- Apple and Google — delivering and updating the wallet card on the customer's phone.
- Stripe — subscription payments from shop owners.
We disclose personal information otherwise only where the law requires it.
Where it is stored
Customer and shop data is stored in Sydney, Australia (AWS ap-southeast-2). Some providers above, in particular Apple, Google and Stripe, operate globally and may process information outside New Zealand and Australia in the course of delivering cards and payments.
How long we keep it
- Card and customer records: for as long as the shop's subscription is active.
- After a subscription ends: 90 days, so the shop can return or export, then deletion.
- Card recovery links: seven days, single use, then they expire automatically.
- Technical logs: a short rolling window for security and fault-finding.
Security
Everything travels over encrypted connections and is stored encrypted at rest. Shop accounts and staff devices authenticate separately, and a shop's staff can only ever see cards belonging to that shop. Passwords are hashed, not stored. Staff devices pair by scanning a one-time code rather than by typing a shared password, and a shop can sign out every device at once from the portal if one goes missing.
What staff see when they scan a card is deliberately minimal: the balance, and a first name if one was given. Email addresses and marketing preferences are never shown on the scanning device — they are only available to the shop owner, signed in to the portal.
No system is perfectly secure. If a breach occurs that is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected people, as the Privacy Act 2020 requires.
Your rights
Under the Privacy Act 2020 you may ask for a copy of the personal information we hold about you, and ask us to correct it if it is wrong.
Email hello@helloregulars.co.nz. We will respond within 20 working days, which is the statutory limit.
If you are a customer of a shop and ask us to delete your details, we will action it and tell the shop; you may also ask the shop directly. Deleting your details means the card stops working and any stamps or prepaid visits on it are gone, so we will make sure you know that before we do it.
Children
HelloRegulars is not designed for or directed at children, and we do not knowingly collect information from them.
Complaints
If you are unhappy with how we have handled your personal information, tell us first at hello@helloregulars.co.nz and we will try to put it right.
If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner: privacy.org.nz, or 0800 803 909.
Changes
If we change this policy in a way that materially affects how we handle personal information, we will email subscribing shop owners before it takes effect. The date at the top always reflects the current version.
Contact
New Zealand Directory (2007) Limited
Christchurch, New Zealand
hello@helloregulars.co.nz