Privacy Policy

Last updated: 27 August 2026

This Privacy Policy explains what personal information we collect on www.shopilo.co.nz, why we collect it, who it may be disclosed to (including recipients outside New Zealand), and how you can access and correct it. It is written around the Privacy Act 2020 and its Information Privacy Principles (IPPs), and is intended to give you the information required by IPP 3 (and, for information we receive from other sources, IPP 3A). We take the protection of your information seriously and process personal information only to the extent strictly necessary.

1. Who we are

The agency responsible for personal information collected on shopilo.co.nz is:

DontPayFull SRL
Str. Zece Mese Nr. 9, Ap. 1
024061 Bucharest
Romania

Trade register entry: J40/14765/2015 (Registrul Comerțului, Bucharest)
VAT number: RO35294618

Legal representatives: Andrei Vasilescu (Chief Executive Officer), Adrian Cristea (Chief Technology Officer)

Email: [email protected]
Phone: +40 748 316 698

DontPayFull SRL is a Romanian company with no physical presence in New Zealand. Because we operate a website aimed at New Zealand users, we treat ourselves as an overseas agency carrying on business in New Zealand for the purposes of section 4 of the Privacy Act 2020, and we handle the personal information of our New Zealand users in accordance with that Act.

1.1 Privacy officer

As required by section 201 of the Privacy Act 2020, we have designated a privacy officer responsible for encouraging compliance with the Act and dealing with requests and complaints. You can reach our privacy officer at [email protected] (please mark your message “Privacy”).

1.2 What we do NOT collect

Shopilo.co.nz expressly does not collect:

  • Payment or bank details — purchases are completed exclusively on the merchants’ websites
  • Sensitive personal information such as health information, ethnicity, or political opinions
  • The contents of your shopping basket at any merchant
  • Affiliate tracking cookies — these are set exclusively by merchants on their own domains; shopilo.co.nz sets no affiliate cookies itself

The Shopilo mobile app additionally does not collect mobile advertising identifiers (Apple IDFA / Google Advertising ID) and embeds no advertising SDKs and no third-party analytics SDKs. Google Analytics 4 and Meta Pixel run only on the website, not in the app.

2. What information do we collect and why?

Under IPP 1 we collect personal information only where it is necessary for a lawful purpose connected with running the service, and under IPP 2 we collect it directly from you unless an exception applies (see section 3 for indirect collection). The following table sets out, as required by IPP 3, everything we collect on shopilo.co.nz, why, who receives it, and how long we keep it:

CategorySpecific informationPurpose of collectionIntended recipientsRetention
A. Usage dataAnonymised browsing history, city and country (derived from the IP address, which is truncated on our EU server and not stored in full), browser type, operating system, screen resolution, pages visited, session duration, referring URLAnalysis of website usage (Google Analytics 4), service improvement, fault diagnosisGoogle LLC (as our service provider; see sections 4 and 5)26 months (GA4 default)
B. Cookie preference dataYour cookie choices and the time they were made, recorded by CookieScriptRemembering and evidencing your cookie choicesCookieScript (as our service provider)365 days
C. Marketing dataPage views and conversion events via the Meta Pixel (active only if you have accepted marketing cookies)Audience analysis and reach measurement for marketing campaignsMeta Platforms Inc. (see sections 4 and 5)90 days
D. Account dataEmail address, display name, saved search preferences (only if you voluntarily register an account)Providing personalised features (watchlist, search history, price alert management)Not disclosed; stored on our EU hosting (Hetzner)Life of the account + 30 days after closure
E. Price alert dataEmail address for price notifications, the product you follow and your target price (only if you expressly sign up)Sending price notification emails when the price falls below your targetNot disclosed; stored on our EU hosting (Hetzner)Until you unsubscribe from the price alert

2.1 Collection is voluntary

Providing personal information to us is voluntary — no law requires or authorises the collection described above. The basic features of shopilo.co.nz can be used without providing any personal information at all. Where a particular feature (account, price alerts) requires certain details, you will be told at the point of entry. The only consequence of not providing them is that the feature in question cannot be used.

2.2 Agencies collecting and holding the information

The agency collecting and holding the information described in this policy is DontPayFull SRL, at the address in section 1. Where a service provider (such as Google or CookieScript) collects information on our behalf, it does so as our agent, on our instructions and for our purposes.

Shopilo mobile app — additional collection

In addition to the collection described above, the following applies when you use the Shopilo mobile app (iOS and Android). Sign-in to the app is passwordless: a one-time code or magic link is sent to your email address. Your account, followed stores and newsletter preferences are the same account data as on the website (see category D above). As required by IPP 3, the table below sets out what the app collects, why, on what basis under the Privacy Act 2020, and how long we keep it.

CategorySpecific informationPurpose of collectionLegal basisRetention
F. Push notification dataPush token (Expo push token), device model and operating system version, app platform and language, notification permission statusDelivery of push notifications in the app (e.g. updates from stores you follow)Collected directly from you with your authorisation (IPP 1–3, Privacy Act 2020), given via the operating system’s notification permission prompt; you can withdraw it at any time in your device settingsUntil you revoke notification permission, sign out or delete your account; invalid tokens are removed automatically
G. Device and security dataStable app-installation identifier (used for guest sessions before you sign in), device integrity attestation (Apple App Attest / Google Play Integrity), crash and error diagnostics (device model, operating system version, app version, technical error details)Secure operation of the app and its API, prevention of abuse and fraud, app stability and error diagnosisCollection necessary for a lawful purpose connected with our functions (IPP 1) — the security safeguards we are required to maintain under IPP 5 and the stable operation of the serviceInstallation identifier: for the duration of the app installation; attestation verdicts: short-lived (per session); crash diagnostics: 90 days

The information collected in the app because it is necessary for a lawful purpose connected with our functions (IPP 1) and for the security safeguards required by IPP 5 comprises: the stable app-installation identifier used to provide guest sessions and secure API access, the device integrity attestation performed via Apple App Attest and Google Play Integrity to protect our services against abuse and automated attacks, and crash and error diagnostics used to keep the app stable. Crash diagnostics are processed exclusively on our own self-hosted error-monitoring infrastructure (Sentry, operated by DontPayFull SRL on servers under our control) and are not disclosed to any third party. None of this information is used for advertising or profiling (IPP 10).

3. Information we receive from other sources (IPP 3A)

Since 1 May 2026, IPP 3A of the Privacy Act 2020 (inserted by the Privacy Amendment Act 2025) requires agencies to take reasonable steps to inform you when they collect your personal information indirectly — that is, from someone other than you. This section provides that notification.

In the course of operating an affiliate-financed service, we may receive limited information about you from the following sources:

  • Affiliate networks (e.g. AWIN, Rakuten, CJ Affiliate): when a purchase is completed after a click on one of our links, the network reports the conversion back to us. These reports are pseudonymous — they contain a click identifier, the merchant, the order value and the commission, but no name, email address or delivery address. We use them solely to account for commissions and to measure which offers work.
  • Technical partners: aggregated or pseudonymous measurement data from the analytics and security providers listed in section 4 (e.g. Cloudflare security logs containing IP addresses).

We do not use these sources to build profiles of identifiable individuals, and we do not receive information about you from data brokers or public registers. If we ever change what we collect indirectly, we will update this section.

4. Service providers and recipients

We use the following service providers to operate shopilo.co.nz. Under the Privacy Act 2020, information held by a provider that acts solely as our agent — storing or processing information on our instructions and not for its own purposes — is treated as held and used by us, rather than disclosed to a third party. Where a provider processes information outside New Zealand, the safeguards described in section 5 apply. We have data processing agreements in place with all providers listed below:

ProviderAddressPurposeCountrySafeguards (IPP 12)Privacy information
Google LLC1600 Amphitheatre Pkwy, Mountain View, CA 94043, USAGoogle Analytics 4 (web analytics)USAContractual data protection terms comparable to the Privacy Act; IP truncation before transferpolicies.google.com/privacy
Meta Platforms Inc.1 Hacker Way, Menlo Park, CA 94025, USAMeta Pixel (marketing, only with your acceptance)USAContractual data protection terms; active only after your informed authorisation via the cookie bannerfacebook.com/privacy/policy
Hetzner Online GmbHIndustriestr. 25, 91710 Gunzenhausen, GermanyHosting and server operation (incl. the EU proxy for GA4)Germany (EU)Acts as our agent; subject to the GDPR, which provides safeguards comparable to the Privacy Acthetzner.com/legal/privacy-policy
Cloudflare Inc.101 Townsend St., San Francisco, CA 94107, USACDN, DDoS protection, web securityUSA (processing via regional points of presence)Acts as our agent; contractual data protection terms comparable to the Privacy Actcloudflare.com/privacypolicy
CookieScriptEUCookie consent management (consent management platform)EUActs as our agent; subject to the GDPR, which provides safeguards comparable to the Privacy Actcookie-script.com/privacy-policy

Other third parties receive your personal information only where disclosure is required or authorised by law (for example, at the request of a law enforcement agency presenting a valid legal order — one of the exceptions in IPP 11) or where you expressly authorise it.

Shopilo mobile app — additional service providers and recipients

If you enable push notifications in the Shopilo mobile app, a push token is generated via the Expo Push Service (650 Industries, Inc., USA) and notifications are delivered through the notification service of your device platform — Apple Push Notification service (Apple Inc.) on iOS or Firebase Cloud Messaging (Google LLC) on Android. The push token is a technical routing identifier; it is not used for advertising or cross-app tracking. To protect our API against abuse, the app verifies the integrity of the device and of the app installation using Apple App Attest (iOS) and the Google Play Integrity API (Android); in the course of this check, Apple or Google receives a technical attestation request from your device. The app also periodically checks for application updates via Expo’s EAS Update service, which technically involves transmitting your IP address to Expo’s servers. These providers are located in the United States; the disclosure to them is made under IPP 12 as described in section 5.

Provider / recipientPurpose (mobile app)CountrySafeguards (IPP 12)Privacy information
650 Industries, Inc. (“Expo”)Expo Push Service (routing of push notifications) and EAS Update (delivery of app updates)USAActs as our agent; contractual data protection terms (data processing agreement) comparable to the Privacy Actexpo.dev/privacy
Apple Inc.Apple Push Notification service (delivery of push notifications on iOS) and App Attest (device integrity checks)USAContractual data protection terms comparable to the Privacy Act; only technical identifiers are disclosedapple.com/legal/privacy
Google LLCFirebase Cloud Messaging (delivery of push notifications on Android) and Play Integrity API (device integrity checks)USAContractual data protection terms comparable to the Privacy Act; only technical identifiers are disclosedpolicies.google.com/privacy

5. Disclosure outside New Zealand (IPP 12)

Because we are based in Romania and use international service providers, personal information collected on shopilo.co.nz leaves New Zealand. IPP 12 of the Privacy Act 2020 permits disclosure of personal information outside New Zealand only where the recipient is subject to safeguards comparable to the Privacy Act — for example privacy laws of a comparable standard or contractual clauses (the Office of the Privacy Commissioner publishes model contract clauses for this purpose) — or where you expressly authorise the disclosure after being informed that comparable safeguards may not apply.

5.1 Where your information goes

  • Romania / European Union (DontPayFull SRL, Hetzner, CookieScript): our own processing and hosting takes place in the EU. EU recipients are subject to the General Data Protection Regulation (GDPR), a privacy regime that provides safeguards comparable to — and in several respects stronger than — the New Zealand Privacy Act.
  • United States (Google, Meta, Cloudflare): these providers process certain data on US servers. We rely on their contractual data protection commitments, under which the information may be used only to provide the contracted service, as comparable safeguards for the purposes of IPP 12. For Google Analytics we additionally truncate IP addresses on our EU server before any data reaches Google, and Google Signals is disabled; the Meta Pixel only runs at all if you have accepted marketing cookies after being informed here of where the data goes.

5.2 Use by our agents is not “disclosure”

Under the Privacy Act, information processed by a provider acting purely as our agent (storing or processing information on our behalf and not using it for its own purposes) is treated as being used by us rather than disclosed. We nevertheless apply the same contractual safeguards to all providers, wherever they are located.

Apple Inc., Google LLC and 650 Industries, Inc. (Expo) — mobile app

For the Shopilo mobile app, Apple Inc. (Apple Push Notification service, App Attest), Google LLC (Firebase Cloud Messaging, Play Integrity) and 650 Industries, Inc. (“Expo”, Expo Push Service and EAS Update) process certain information on servers in the United States. IPP 12 of the Privacy Act 2020 permits us to disclose personal information to them because each recipient is subject to contractual data protection commitments comparable to the Privacy Act, under which the information may be used only to provide the contracted service. In the case of Expo, these commitments form part of Expo’s data processing agreement, which covers push tokens and app-update requests. The information disclosed is limited to technical identifiers (push tokens, attestation requests, IP addresses for update checks) and is not used by these providers for advertising or profiling on our behalf.

6. Cookies and tracking

The Shopilo mobile app itself sets no cookies and embeds no third-party tracking, advertising or analytics SDKs. This section concerns the website only.

The New Zealand position: there is no dedicated cookie legislation in New Zealand, and no statutory opt-in requirement. Cookies are covered by the Privacy Act 2020 to the extent that they collect personal information — which is why we disclose here and in our Cookie Policy exactly which cookies we use, what they collect and where the data goes. As a matter of good practice, we nevertheless operate a consent banner: analytics and marketing cookies are only set if you accept them.

6.1 Managing preferences with CookieScript

On your first visit to shopilo.co.nz you are shown a cookie banner operated by CookieScript. There you can accept or decline individual cookie categories. Your preferences are stored and can be changed or withdrawn at any time via the cookie settings link in the footer. Withdrawal does not affect processing that took place beforehand.

6.2 Cookie categories

Strictly necessary cookies (set without asking): essential for operating the service, e.g. remembering your cookie choices (the CookieScript cookie) or providing basic security functions (Cloudflare).

Analytics cookies (only if you accept them): Google Analytics 4 — active only after your acceptance, with IP truncation on our EU server before any data reaches Google.

Marketing cookies (only if you accept them): Meta Pixel — active exclusively after your express acceptance.

6.3 Affiliate cookies

Shopilo.co.nz sets no affiliate tracking cookies of its own. When you click a merchant link and visit the merchant’s website, the merchant or the relevant affiliate network may set cookies on their own domains. Those cookies are governed exclusively by the privacy policy of the merchant or network concerned, not by this policy.

6.4 Google Analytics opt-out

In addition to the cookie banner, you can disable data collection by Google Analytics 4 with Google’s browser add-on: tools.google.com/dlpage/gaoptout

Detailed information on all cookies used, their durations and providers can be found in our Cookie Policy.

7. Newsletters and price alerts — commercial emails

Commercial electronic messages we send to New Zealand recipients are governed by the Unsolicited Electronic Messages Act 2007. We comply with it as follows:

  • Consent: we send price alerts and (if we offer one in the future) newsletters only to people who have signed up for them — that sign-up is your express consent under the Act. You will never be added to a mailing list merely for creating an account or using the website.
  • Sender identification: every message clearly and accurately identifies DontPayFull SRL as the sender and includes contact details that remain valid for at least 30 days after the message is sent.
  • Unsubscribe: every message contains a functional, free unsubscribe facility in the same medium (a link in the email). Unsubscribing takes effect promptly and no reason is required.

The Act is enforced by the Department of Internal Affairs, to which spam can be reported at www.dia.govt.nz.

8. Security and retention

Under IPP 5 we protect personal information with reasonable security safeguards against loss, unauthorised access, use, modification or disclosure — including encrypted transmission (TLS), access controls and EU-based hosting. Under IPP 9 we keep personal information no longer than it is required for the purposes for which it may lawfully be used. The following table summarises our retention periods:

CategoryRetention periodReason / source
A. Usage data (GA4)26 monthsGA4 default setting; automatic deletion by Google afterwards
B. Cookie preference data (CookieScript)365 daysRecord of your choices; you are asked again after expiry
C. Marketing data (Meta Pixel)90 daysMeta’s standard period for pixel event data
D. Account dataLife of the account + 30 days after closureProviding the service; 30-day buffer against accidental deletion requests
E. Price alert dataUntil you unsubscribeDeleted promptly after you unsubscribe
Server logs (security)7 days (Cloudflare) / 30 days (Hetzner)Security logging; automatically overwritten afterwards

Statutory record-keeping obligations that apply to us as a Romanian company (for example accounting and tax retention periods under Romanian law) may in individual cases justify longer retention. In that case, processing is limited to what those obligations require.

9. Your rights: access and correction

The Privacy Act 2020 gives you two core rights, which you can exercise free of charge by emailing [email protected] (mark your message “Privacy”). We will respond as soon as reasonably practicable, and no later than 20 working days after receiving your request, as the Act requires:

RightSourceWhat it means
AccessIPP 6, Privacy Act 2020Confirmation of whether we hold personal information about you, and access to that information
CorrectionIPP 7, Privacy Act 2020Correction of information that is wrong or incomplete; if we do not agree to correct it, you may require that a statement of the requested correction be attached to the information

9.1 What we offer beyond the Act

In addition to your statutory rights, we voluntarily offer every user:

  • Deletion on request — we will delete your account and associated personal information on request, subject only to record-keeping obligations that apply to us by law
  • Withdrawal of any acceptance — cookie choices and email subscriptions can be withdrawn at any time, with effect for the future
  • No automated decision-making — we make no decisions with legal effect on you based solely on automated processing

9.2 Verifying your identity

To protect your information from unauthorised access, we may ask for reasonable proof of identity before acting on a request. Identification details collected for this purpose are used solely to handle your request and are deleted afterwards.

10. Privacy breaches

If a privacy breach occurs that has caused, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner (via its NotifyUs portal) and the affected individuals as soon as practicable, as required by sections 112 to 118 of the Privacy Act 2020. Our notification will describe what happened, what information was involved, and what steps you can take to protect yourself.

11. Children and young people

Shopilo.co.nz is not directed at children. IPP 4 of the Privacy Act 2020 requires that the way information is collected must be fair and not unreasonably intrusive, particularly where it is collected from children or young persons — and we design our collection accordingly: we do not knowingly collect personal information from children, we run no features aimed at them, and creating an account is subject to our terms, which require users to be at least 18. If we become aware that we have collected personal information from a child, we will delete it promptly.

12. Complaints

If you believe we have interfered with your privacy, the complaint path is as follows:

  1. Contact us first: email [email protected] (mark your message “Privacy”). We take every complaint seriously and will respond within 20 working days. The Privacy Commissioner generally expects complainants to attempt to resolve the issue with the agency first.
  2. Office of the Privacy Commissioner: if you are not satisfied with our response, you can complain to the Privacy Commissioner under Part 5 of the Privacy Act 2020.
  3. Human Rights Review Tribunal: complaints that cannot be resolved through the Commissioner may be taken to the Human Rights Review Tribunal.
Office of the Privacy Commissioner | Te Mana Mātāpono Matatapu
PO Box 10094, Wellington 6143, New Zealand
Website: www.privacy.org.nz (complaints can be lodged online)

The right to complain to the Privacy Commissioner does not affect any other remedies available to you.

13. Contact and changes to this policy

For all questions about privacy, to exercise your rights, or for privacy-related notices, please contact:

DontPayFull SRL — Privacy Officer
Str. Zece Mese Nr. 9, Ap. 1
024061 Bucharest
Romania

Email: [email protected]
Phone: +40 748 316 698

We answer privacy requests free of charge within 20 working days. For complex or numerous requests, the Privacy Act allows this period to be extended; if that happens we will tell you in advance and explain why.

13.1 Changes to this Privacy Policy

We may update this Privacy Policy when legislation, technology or our service changes. We will announce material changes at least 14 days before they take effect through a prominent notice on shopilo.co.nz or, where possible, by email to registered users. Changes are not deemed accepted through continued use of the service; instead, we will ask you to actively take note of them. The date of the last update at the top of the page will be adjusted accordingly.

Further legal information can be found in our Legal Notice, the Terms and Conditions and the Cookie Policy.


Version: 27 August 2026 - DontPayFull SRL, Bucharest, Romania - J40/14765/2015 - VAT RO35294618