Privacy Policy
Last updated: 27 August 2026
This Privacy Policy explains what personal information we collect on www.shopilo.co.nz, why we collect it, who it may be disclosed to (including recipients outside New Zealand), and how you can access and correct it. It is written around the Privacy Act 2020 and its Information Privacy Principles (IPPs), and is intended to give you the information required by IPP 3 (and, for information we receive from other sources, IPP 3A). We take the protection of your information seriously and process personal information only to the extent strictly necessary.
1. Who we are
The agency responsible for personal information collected on shopilo.co.nz is:
DontPayFull SRLStr. Zece Mese Nr. 9, Ap. 1
024061 Bucharest
Romania
Trade register entry: J40/14765/2015 (Registrul Comerțului, Bucharest)
VAT number: RO35294618
Legal representatives: Andrei Vasilescu (Chief Executive Officer), Adrian Cristea (Chief Technology Officer)
Email: [email protected]
Phone: +40 748 316 698
DontPayFull SRL is a Romanian company with no physical presence in New Zealand. Because we operate a website aimed at New Zealand users, we treat ourselves as an overseas agency carrying on business in New Zealand for the purposes of section 4 of the Privacy Act 2020, and we handle the personal information of our New Zealand users in accordance with that Act.
1.1 Privacy officer
As required by section 201 of the Privacy Act 2020, we have designated a privacy officer responsible for encouraging compliance with the Act and dealing with requests and complaints. You can reach our privacy officer at [email protected] (please mark your message “Privacy”).
1.2 What we do NOT collect
Shopilo.co.nz expressly does not collect:
- Payment or bank details — purchases are completed exclusively on the merchants’ websites
- Sensitive personal information such as health information, ethnicity, or political opinions
- The contents of your shopping basket at any merchant
- Affiliate tracking cookies — these are set exclusively by merchants on their own domains; shopilo.co.nz sets no affiliate cookies itself
The Shopilo mobile app additionally does not collect mobile advertising identifiers (Apple IDFA / Google Advertising ID) and embeds no advertising SDKs and no third-party analytics SDKs. Google Analytics 4 and Meta Pixel run only on the website, not in the app.
2. What information do we collect and why?
Under IPP 1 we collect personal information only where it is necessary for a lawful purpose connected with running the service, and under IPP 2 we collect it directly from you unless an exception applies (see section 3 for indirect collection). The following table sets out, as required by IPP 3, everything we collect on shopilo.co.nz, why, who receives it, and how long we keep it:
| Category | Specific information | Purpose of collection | Intended recipients | Retention |
|---|---|---|---|---|
| A. Usage data | Anonymised browsing history, city and country (derived from the IP address, which is truncated on our EU server and not stored in full), browser type, operating system, screen resolution, pages visited, session duration, referring URL | Analysis of website usage (Google Analytics 4), service improvement, fault diagnosis | Google LLC (as our service provider; see sections 4 and 5) | 26 months (GA4 default) |
| B. Cookie preference data | Your cookie choices and the time they were made, recorded by CookieScript | Remembering and evidencing your cookie choices | CookieScript (as our service provider) | 365 days |
| C. Marketing data | Page views and conversion events via the Meta Pixel (active only if you have accepted marketing cookies) | Audience analysis and reach measurement for marketing campaigns | Meta Platforms Inc. (see sections 4 and 5) | 90 days |
| D. Account data | Email address, display name, saved search preferences (only if you voluntarily register an account) | Providing personalised features (watchlist, search history, price alert management) | Not disclosed; stored on our EU hosting (Hetzner) | Life of the account + 30 days after closure |
| E. Price alert data | Email address for price notifications, the product you follow and your target price (only if you expressly sign up) | Sending price notification emails when the price falls below your target | Not disclosed; stored on our EU hosting (Hetzner) | Until you unsubscribe from the price alert |
2.1 Collection is voluntary
Providing personal information to us is voluntary — no law requires or authorises the collection described above. The basic features of shopilo.co.nz can be used without providing any personal information at all. Where a particular feature (account, price alerts) requires certain details, you will be told at the point of entry. The only consequence of not providing them is that the feature in question cannot be used.
2.2 Agencies collecting and holding the information
The agency collecting and holding the information described in this policy is DontPayFull SRL, at the address in section 1. Where a service provider (such as Google or CookieScript) collects information on our behalf, it does so as our agent, on our instructions and for our purposes.
Shopilo mobile app — additional collection
In addition to the collection described above, the following applies when you use the Shopilo mobile app (iOS and Android). Sign-in to the app is passwordless: a one-time code or magic link is sent to your email address. Your account, followed stores and newsletter preferences are the same account data as on the website (see category D above). As required by IPP 3, the table below sets out what the app collects, why, on what basis under the Privacy Act 2020, and how long we keep it.
| Category | Specific information | Purpose of collection | Legal basis | Retention |
|---|---|---|---|---|
| F. Push notification data | Push token (Expo push token), device model and operating system version, app platform and language, notification permission status | Delivery of push notifications in the app (e.g. updates from stores you follow) | Collected directly from you with your authorisation (IPP 1–3, Privacy Act 2020), given via the operating system’s notification permission prompt; you can withdraw it at any time in your device settings | Until you revoke notification permission, sign out or delete your account; invalid tokens are removed automatically |
| G. Device and security data | Stable app-installation identifier (used for guest sessions before you sign in), device integrity attestation (Apple App Attest / Google Play Integrity), crash and error diagnostics (device model, operating system version, app version, technical error details) | Secure operation of the app and its API, prevention of abuse and fraud, app stability and error diagnosis | Collection necessary for a lawful purpose connected with our functions (IPP 1) — the security safeguards we are required to maintain under IPP 5 and the stable operation of the service | Installation identifier: for the duration of the app installation; attestation verdicts: short-lived (per session); crash diagnostics: 90 days |
The information collected in the app because it is necessary for a lawful purpose connected with our functions (IPP 1) and for the security safeguards required by IPP 5 comprises: the stable app-installation identifier used to provide guest sessions and secure API access, the device integrity attestation performed via Apple App Attest and Google Play Integrity to protect our services against abuse and automated attacks, and crash and error diagnostics used to keep the app stable. Crash diagnostics are processed exclusively on our own self-hosted error-monitoring infrastructure (Sentry, operated by DontPayFull SRL on servers under our control) and are not disclosed to any third party. None of this information is used for advertising or profiling (IPP 10).
3. Information we receive from other sources (IPP 3A)
Since 1 May 2026, IPP 3A of the Privacy Act 2020 (inserted by the Privacy Amendment Act 2025) requires agencies to take reasonable steps to inform you when they collect your personal information indirectly — that is, from someone other than you. This section provides that notification.
In the course of operating an affiliate-financed service, we may receive limited information about you from the following sources:
- Affiliate networks (e.g. AWIN, Rakuten, CJ Affiliate): when a purchase is completed after a click on one of our links, the network reports the conversion back to us. These reports are pseudonymous — they contain a click identifier, the merchant, the order value and the commission, but no name, email address or delivery address. We use them solely to account for commissions and to measure which offers work.
- Technical partners: aggregated or pseudonymous measurement data from the analytics and security providers listed in section 4 (e.g. Cloudflare security logs containing IP addresses).
We do not use these sources to build profiles of identifiable individuals, and we do not receive information about you from data brokers or public registers. If we ever change what we collect indirectly, we will update this section.
4. Service providers and recipients
We use the following service providers to operate shopilo.co.nz. Under the Privacy Act 2020, information held by a provider that acts solely as our agent — storing or processing information on our instructions and not for its own purposes — is treated as held and used by us, rather than disclosed to a third party. Where a provider processes information outside New Zealand, the safeguards described in section 5 apply. We have data processing agreements in place with all providers listed below:
| Provider | Address | Purpose | Country | Safeguards (IPP 12) | Privacy information |
|---|---|---|---|---|---|
| Google LLC | 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA | Google Analytics 4 (web analytics) | USA | Contractual data protection terms comparable to the Privacy Act; IP truncation before transfer | policies.google.com/privacy |
| Meta Platforms Inc. | 1 Hacker Way, Menlo Park, CA 94025, USA | Meta Pixel (marketing, only with your acceptance) | USA | Contractual data protection terms; active only after your informed authorisation via the cookie banner | facebook.com/privacy/policy |
| Hetzner Online GmbH | Industriestr. 25, 91710 Gunzenhausen, Germany | Hosting and server operation (incl. the EU proxy for GA4) | Germany (EU) | Acts as our agent; subject to the GDPR, which provides safeguards comparable to the Privacy Act | hetzner.com/legal/privacy-policy |
| Cloudflare Inc. | 101 Townsend St., San Francisco, CA 94107, USA | CDN, DDoS protection, web security | USA (processing via regional points of presence) | Acts as our agent; contractual data protection terms comparable to the Privacy Act | cloudflare.com/privacypolicy |
| CookieScript | EU | Cookie consent management (consent management platform) | EU | Acts as our agent; subject to the GDPR, which provides safeguards comparable to the Privacy Act | cookie-script.com/privacy-policy |
Other third parties receive your personal information only where disclosure is required or authorised by law (for example, at the request of a law enforcement agency presenting a valid legal order — one of the exceptions in IPP 11) or where you expressly authorise it.
Shopilo mobile app — additional service providers and recipients
If you enable push notifications in the Shopilo mobile app, a push token is generated via the Expo Push Service (650 Industries, Inc., USA) and notifications are delivered through the notification service of your device platform — Apple Push Notification service (Apple Inc.) on iOS or Firebase Cloud Messaging (Google LLC) on Android. The push token is a technical routing identifier; it is not used for advertising or cross-app tracking. To protect our API against abuse, the app verifies the integrity of the device and of the app installation using Apple App Attest (iOS) and the Google Play Integrity API (Android); in the course of this check, Apple or Google receives a technical attestation request from your device. The app also periodically checks for application updates via Expo’s EAS Update service, which technically involves transmitting your IP address to Expo’s servers. These providers are located in the United States; the disclosure to them is made under IPP 12 as described in section 5.
| Provider / recipient | Purpose (mobile app) | Country | Safeguards (IPP 12) | Privacy information |
|---|---|---|---|---|
| 650 Industries, Inc. (“Expo”) | Expo Push Service (routing of push notifications) and EAS Update (delivery of app updates) | USA | Acts as our agent; contractual data protection terms (data processing agreement) comparable to the Privacy Act | expo.dev/privacy |
| Apple Inc. | Apple Push Notification service (delivery of push notifications on iOS) and App Attest (device integrity checks) | USA | Contractual data protection terms comparable to the Privacy Act; only technical identifiers are disclosed | apple.com/legal/privacy |
| Google LLC | Firebase Cloud Messaging (delivery of push notifications on Android) and Play Integrity API (device integrity checks) | USA | Contractual data protection terms comparable to the Privacy Act; only technical identifiers are disclosed | policies.google.com/privacy |
5. Disclosure outside New Zealand (IPP 12)
Because we are based in Romania and use international service providers, personal information collected on shopilo.co.nz leaves New Zealand. IPP 12 of the Privacy Act 2020 permits disclosure of personal information outside New Zealand only where the recipient is subject to safeguards comparable to the Privacy Act — for example privacy laws of a comparable standard or contractual clauses (the Office of the Privacy Commissioner publishes model contract clauses for this purpose) — or where you expressly authorise the disclosure after being informed that comparable safeguards may not apply.
5.1 Where your information goes
- Romania / European Union (DontPayFull SRL, Hetzner, CookieScript): our own processing and hosting takes place in the EU. EU recipients are subject to the General Data Protection Regulation (GDPR), a privacy regime that provides safeguards comparable to — and in several respects stronger than — the New Zealand Privacy Act.
- United States (Google, Meta, Cloudflare): these providers process certain data on US servers. We rely on their contractual data protection commitments, under which the information may be used only to provide the contracted service, as comparable safeguards for the purposes of IPP 12. For Google Analytics we additionally truncate IP addresses on our EU server before any data reaches Google, and Google Signals is disabled; the Meta Pixel only runs at all if you have accepted marketing cookies after being informed here of where the data goes.
5.2 Use by our agents is not “disclosure”
Under the Privacy Act, information processed by a provider acting purely as our agent (storing or processing information on our behalf and not using it for its own purposes) is treated as being used by us rather than disclosed. We nevertheless apply the same contractual safeguards to all providers, wherever they are located.
Apple Inc., Google LLC and 650 Industries, Inc. (Expo) — mobile app
For the Shopilo mobile app, Apple Inc. (Apple Push Notification service, App Attest), Google LLC (Firebase Cloud Messaging, Play Integrity) and 650 Industries, Inc. (“Expo”, Expo Push Service and EAS Update) process certain information on servers in the United States. IPP 12 of the Privacy Act 2020 permits us to disclose personal information to them because each recipient is subject to contractual data protection commitments comparable to the Privacy Act, under which the information may be used only to provide the contracted service. In the case of Expo, these commitments form part of Expo’s data processing agreement, which covers push tokens and app-update requests. The information disclosed is limited to technical identifiers (push tokens, attestation requests, IP addresses for update checks) and is not used by these providers for advertising or profiling on our behalf.
7. Newsletters and price alerts — commercial emails
Commercial electronic messages we send to New Zealand recipients are governed by the Unsolicited Electronic Messages Act 2007. We comply with it as follows:
- Consent: we send price alerts and (if we offer one in the future) newsletters only to people who have signed up for them — that sign-up is your express consent under the Act. You will never be added to a mailing list merely for creating an account or using the website.
- Sender identification: every message clearly and accurately identifies DontPayFull SRL as the sender and includes contact details that remain valid for at least 30 days after the message is sent.
- Unsubscribe: every message contains a functional, free unsubscribe facility in the same medium (a link in the email). Unsubscribing takes effect promptly and no reason is required.
The Act is enforced by the Department of Internal Affairs, to which spam can be reported at www.dia.govt.nz.
8. Security and retention
Under IPP 5 we protect personal information with reasonable security safeguards against loss, unauthorised access, use, modification or disclosure — including encrypted transmission (TLS), access controls and EU-based hosting. Under IPP 9 we keep personal information no longer than it is required for the purposes for which it may lawfully be used. The following table summarises our retention periods:
| Category | Retention period | Reason / source |
|---|---|---|
| A. Usage data (GA4) | 26 months | GA4 default setting; automatic deletion by Google afterwards |
| B. Cookie preference data (CookieScript) | 365 days | Record of your choices; you are asked again after expiry |
| C. Marketing data (Meta Pixel) | 90 days | Meta’s standard period for pixel event data |
| D. Account data | Life of the account + 30 days after closure | Providing the service; 30-day buffer against accidental deletion requests |
| E. Price alert data | Until you unsubscribe | Deleted promptly after you unsubscribe |
| Server logs (security) | 7 days (Cloudflare) / 30 days (Hetzner) | Security logging; automatically overwritten afterwards |
Statutory record-keeping obligations that apply to us as a Romanian company (for example accounting and tax retention periods under Romanian law) may in individual cases justify longer retention. In that case, processing is limited to what those obligations require.
9. Your rights: access and correction
The Privacy Act 2020 gives you two core rights, which you can exercise free of charge by emailing [email protected] (mark your message “Privacy”). We will respond as soon as reasonably practicable, and no later than 20 working days after receiving your request, as the Act requires:
| Right | Source | What it means |
|---|---|---|
| Access | IPP 6, Privacy Act 2020 | Confirmation of whether we hold personal information about you, and access to that information |
| Correction | IPP 7, Privacy Act 2020 | Correction of information that is wrong or incomplete; if we do not agree to correct it, you may require that a statement of the requested correction be attached to the information |
9.1 What we offer beyond the Act
In addition to your statutory rights, we voluntarily offer every user:
- Deletion on request — we will delete your account and associated personal information on request, subject only to record-keeping obligations that apply to us by law
- Withdrawal of any acceptance — cookie choices and email subscriptions can be withdrawn at any time, with effect for the future
- No automated decision-making — we make no decisions with legal effect on you based solely on automated processing
9.2 Verifying your identity
To protect your information from unauthorised access, we may ask for reasonable proof of identity before acting on a request. Identification details collected for this purpose are used solely to handle your request and are deleted afterwards.
10. Privacy breaches
If a privacy breach occurs that has caused, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner (via its NotifyUs portal) and the affected individuals as soon as practicable, as required by sections 112 to 118 of the Privacy Act 2020. Our notification will describe what happened, what information was involved, and what steps you can take to protect yourself.
11. Children and young people
Shopilo.co.nz is not directed at children. IPP 4 of the Privacy Act 2020 requires that the way information is collected must be fair and not unreasonably intrusive, particularly where it is collected from children or young persons — and we design our collection accordingly: we do not knowingly collect personal information from children, we run no features aimed at them, and creating an account is subject to our terms, which require users to be at least 18. If we become aware that we have collected personal information from a child, we will delete it promptly.
12. Complaints
If you believe we have interfered with your privacy, the complaint path is as follows:
- Contact us first: email [email protected] (mark your message “Privacy”). We take every complaint seriously and will respond within 20 working days. The Privacy Commissioner generally expects complainants to attempt to resolve the issue with the agency first.
- Office of the Privacy Commissioner: if you are not satisfied with our response, you can complain to the Privacy Commissioner under Part 5 of the Privacy Act 2020.
- Human Rights Review Tribunal: complaints that cannot be resolved through the Commissioner may be taken to the Human Rights Review Tribunal.
PO Box 10094, Wellington 6143, New Zealand
Website: www.privacy.org.nz (complaints can be lodged online)
The right to complain to the Privacy Commissioner does not affect any other remedies available to you.
13. Contact and changes to this policy
For all questions about privacy, to exercise your rights, or for privacy-related notices, please contact:
DontPayFull SRL — Privacy OfficerStr. Zece Mese Nr. 9, Ap. 1
024061 Bucharest
Romania
Email: [email protected]
Phone: +40 748 316 698
We answer privacy requests free of charge within 20 working days. For complex or numerous requests, the Privacy Act allows this period to be extended; if that happens we will tell you in advance and explain why.
13.1 Changes to this Privacy Policy
We may update this Privacy Policy when legislation, technology or our service changes. We will announce material changes at least 14 days before they take effect through a prominent notice on shopilo.co.nz or, where possible, by email to registered users. Changes are not deemed accepted through continued use of the service; instead, we will ask you to actively take note of them. The date of the last update at the top of the page will be adjusted accordingly.
Further legal information can be found in our Legal Notice, the Terms and Conditions and the Cookie Policy.
Version: 27 August 2026 - DontPayFull SRL, Bucharest, Romania - J40/14765/2015 - VAT RO35294618