Privacy Policy
Last updated: 9 February 2026
Sebenza Limited ("Sebenza", "we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our workforce management platform and related services.
1. Information We Collect
1.1 Information You Provide
- Account information — name, email address, phone number, profile photo
- Identity documents — passport details, visa status, work permits, IRD number, tax details
- Employment information — skills, certifications, work history, availability, worker classifications
- Organisation information — company name, NZBN, industry, addresses, bank account details for payroll
- Communications — messages sent through our in-app messaging system
1.2 Information Collected Automatically
- Location data — GPS coordinates during clock-in/clock-out for timesheet verification (only when actively using the app for work)
- Device information — device type, operating system, browser type
- Usage data — pages visited, features used, time spent in the app
- Log data — IP addresses, access times, error logs
1.3 Information from Third Parties
- vSure — visa and work rights verification results
- IRD Gateway — tax number validation and RWT rate information
- Xero — accounting and payroll data for connected organisations
- Stripe — payment processing information
2. How We Use Your Information
We use your information to:
- Provide, maintain, and improve our workforce management platform
- Process payroll, payments, and financial transactions
- Verify identity, visa status, and work rights
- Enable GPS-verified timesheets and location-based crew management
- Facilitate communication between workers, managers, and organisations
- Generate compliance reports (IRD, Labour Inspectorate, Zespri audits)
- Send notifications about shifts, schedules, visa expiry, and certifications
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations under New Zealand law
3. How We Share Your Information
We do not sell your personal information. We share your information only in the following circumstances:
- With your organisation — employers and hiring managers within your connected organisation can view your work profile, timesheets, and compliance status
- With integration partners — Xero (payroll), Stripe (payments), vSure (visa verification), IRD (tax validation) — only the minimum data required
- With service providers — hosting (Vercel, Supabase), analytics, and communication services that process data on our behalf
- For legal compliance — when required by law, regulation, or legal process
- With your consent — for any other purpose with your explicit consent
4. Data Storage and Security
- Your data is hosted on Supabase with servers located in the Sydney, Australia region (closest to New Zealand)
- All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
- We implement role-based access controls and row-level security policies
- Audit logs are retained for 7 years per New Zealand regulatory requirements
- We conduct regular security reviews and maintain SOC 2-aligned practices
5. Your Rights
Under the New Zealand Privacy Act 2020, you have the right to:
- Access your personal information held by us
- Correct any inaccurate or incomplete information
- Request deletion of your personal information (subject to legal retention requirements)
- Withdraw consent for optional data processing
- Complain to the Office of the Privacy Commissioner if you believe your privacy has been breached
6. Data Retention
- Active accounts — data is retained for as long as your account is active
- Closed accounts — profile data is deleted within 90 days; financial and compliance records are retained for 7 years as required by NZ tax law
- Location data — GPS check-in/out records are retained for the duration of employment plus 2 years
7. Children's Privacy
Sebenza is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification. Your continued use of Sebenza after changes constitutes acceptance of the updated policy.