Privacy Policy
Last updated: 13 May 2026
1. Who We Are
Bonvale NZ Limited (NZ Company Number: 9413956 / NZBN: 9429053524249), incorporated in New Zealand, with its registered office at Unit A, Ground Level, 26 Hobson Street, Auckland Central, Auckland 1010, New Zealand ("Bonvale", "we", "us", "our"), is the agency (as defined in the Privacy Act 2020) responsible for personal information collected from customers in New Zealand through our website (bonvale.com), mobile application, and related services (our "Services"). We handle personal information in accordance with the Privacy Act 2020 and the thirteen Information Privacy Principles ("IPPs"). We may share personal information with the Bonvale group and related entities as described in Section 6. Where personal information is disclosed outside New Zealand, we comply with IPP 12 (see Section 7).
2. Personal Information We Collect
2.1 Information You Provide Directly
When you create an account, place an order, contact us, or otherwise use our Services:
- Identity: full name, date of birth
- Contact: email address, telephone number, postal address
- Account: username, password (stored in hashed form), preferences
- Transaction: products purchased, order and returns history, payment method type (full card numbers are held by our payment gateway, not by Bonvale)
- Communications: messages sent to our customer care team
- Marketing preferences: email, SMS, and push notification opt-in and opt-out choices
2.2 Information We Collect Automatically
When you visit our Website or use our App:
- Device and technical: IP address, browser type and version, operating system, device identifiers, time zone
- Usage: pages viewed, products browsed, search queries, clickstream, session duration, referral source
- Tracking: data collected via cookies, pixels, and similar technologies (see Section 5)
- Location: approximate location from IP address (we do not collect GPS location unless you grant App permission)
2.3 Information We Receive From Third Parties
- Payment gateways: transaction status, fraud risk signals, and payment verification data
- Logistics providers: delivery status, confirmation, and address validation data
- Meta Platforms: aggregated advertising performance data and, where you have consented to Meta's terms, audience matching data via the Meta Pixel (see Section 5)
- Google: analytics and advertising performance data via Google Analytics and Google Ads (see Section 5)
3. How and Why We Use Your Personal Information
We collect, hold, use, and disclose personal information for the purposes set out below. These purposes are consistent with IPPs 1–4 (collection) and IPPs 10–11 (use and disclosure).
| Data Collected | Purpose | Primary Basis under the Privacy Act 2020 / IPPs | Retention |
|---|---|---|---|
| Name, contact, order, payment data | Processing your order: fulfilment, dispatch, returns | Purpose of collection (IPPs 1, 10) | 7 years from transaction (NZ tax compliance) |
| Account data | Creating and managing your account | Purpose of collection | 3 years after last account activity |
| Contact, order data | Customer care and dispute resolution | Directly related purpose (IPP 10) | 3 years from last interaction |
| Email, phone, preferences | Transactional communications (order confirmations, dispatch, returns) | Purpose of collection | Duration of customer relationship |
| Email, phone, preferences | Marketing emails, SMS, push notifications | Authorisation / consent (IPPs 10 & 11); Unsolicited Electronic Messages Act 2007 | Until consent withdrawn |
| Browsing, purchase history | Personalised product recommendations | Directly related purpose (IPP 10) | 3 years from last activity |
| Device, browsing, purchase data via Meta Pixel & Google Analytics | Profiling for targeted advertising on Meta and Google | Consent | Per Meta/Google terms; our data: 2 years |
| IP, device, transaction data | Fraud detection, security, and abuse prevention | Directly related purpose (IPP 10) | 2 years |
| All categories | Legal obligations (tax, AML, court orders) | Required or authorised by New Zealand law | As required by law (min. 7 years) |
| Aggregated, anonymised data | Analytics and business intelligence | Not personal information (de-identified) | Indefinite |
4. Marketing Communications
We send marketing communications (email, SMS, push notifications) only where you have given consent. You may withdraw consent at any time by:
- Clicking 'unsubscribe' in any marketing email
- Replying STOP to any marketing SMS
- Adjusting push notification preferences in your device settings or Bonvale account
- Contacting us at privacy@bonvale.com
Withdrawing marketing consent does not affect transactional communications (order confirmations, dispatch, returns), which are sent under our contract with you. New Zealand: Unsolicited Electronic Messages Act 2007 We comply with the Unsolicited Electronic Messages Act 2007. We send commercial electronic messages only where you have given consent (express, inferred, or deemed consent as defined in the Act); every message identifies Bonvale as the sender and includes a functional unsubscribe facility, and we will action unsubscribe requests promptly and in any event within 5 business days.
5. Cookies, Pixels, and Tracking Technologies
5.1 What We Use
Essential Cookies Strictly necessary for core functionality including shopping basket, login, security, and fraud prevention. Cannot be disabled. Analytics Cookies: Google Analytics We use Google Analytics (Google LLC) to understand how visitors use our Website including pages visited, session duration, referral source, and device. This aggregated data improves our Services. Data is transferred to Google's servers, which may be outside New Zealand (see Section 7). You may opt out via the Google Analytics Opt-Out Browser Add-on at tools.google.com/dlpage/gaoptout or by rejecting analytics cookies in our consent banner. Advertising and Targeting Cookies: Meta Pixel We use the Meta Pixel (Meta Platforms, Inc.) to measure advertising effectiveness, build audiences, and track conversions. When active, it collects your IP address, browser data, page URL, and on-site actions (such as product views and purchases). This data is transmitted to Meta and used to serve targeted advertisements on Facebook, Instagram, and the Meta Audience Network ('retargeting'). Meta may also use it for its own purposes under its Privacy Policy. We activate the Meta Pixel only with your consent; you may withdraw consent at any time via your cookie preferences.
5.2 Consent Management
We use Shopify's native cookie consent banner to manage cookie consent on our Website. On your first visit, our cookie banner presents the categories of cookies in use. Non-essential cookies, including analytics and advertising categories, do not activate until you actively accept them. Your consent choice is recorded with a timestamp and the version of this Policy in force at the time. You can review or change your preferences at any time via the "Cookie Settings" link in the footer of our Website. Withdrawing consent for a category takes effect immediately. Any tracking scripts relying on that consent will stop firing for your session.
5.3 Your Cookie Choices
Manage preferences via our cookie preference centre (footer of our Website), your browser settings, or the opt-out tools provided by Google and Meta. Restricting certain cookies may affect Website functionality.
6. Who We Share Your Personal Information With
We do not sell or rent your personal information. We share it only as described below.
6.1 Service Providers
We share data with service providers acting under our instruction, including:
- Shopify Inc.: storefront platform, transactional emails, order notifications, and native cookie consent management.
- Shopify Payments and Klarna Bank AB: payment processing, fraud screening, and Buy Now, Pay Later. Your full card details are held by the relevant payment provider, not by Bonvale.
- KEC and KLN: outbound logistics from our fulfilment warehouse and inbound returns logistics to our local New Zealand returns partner.
- Aramex (NZ) Limited: last-mile delivery within New Zealand.
- Loop Returns, Inc. (with EasyPost for return label generation): returns and exchanges portal.
- Gorgias, Inc.: customer support and ticketing.
- Klaviyo, Inc.: marketing emails, SMS, and push notifications.
- Amazon Web Services, Inc.: cloud infrastructure for custom apps and integrations.
- Google LLC (Google Analytics): Website usage analytics.
- Meta Platforms, Inc. (Meta Pixel): advertising measurement and audience targeting, subject to consent.
6.2 Legal and Regulatory Disclosure
We disclose personal information to law enforcement, courts, or regulators only where required or authorised by New Zealand law, court order, or regulatory direction. We will notify you of such disclosures where legally permitted.
6.3 Business Transfers
If Bonvale NZ Limited undergoes a merger, acquisition, or asset sale, your information may transfer to the relevant entity. We will notify you and ensure equivalent protections apply.
6.4 Group Companies
We may share data with the Bonvale group and related entities for the purposes set out in this Policy, including group-wide analytics, IT infrastructure, and customer support. All intra-group transfers are subject to an intra-group data sharing agreement and the safeguards described in Section 7.
7. Cross-Border Disclosure of Personal Information (IPP 12)
Bonvale NZ Limited is located in New Zealand. Some of our service providers and group companies are located outside New Zealand, which means your personal information may be disclosed to recipients in overseas countries including Singapore, the United States, and other countries where our service providers operate. Before disclosing personal information to a foreign person or entity, we comply with IPP 12 of the Privacy Act 2020. We will only do so where one of the following applies:
- The recipient is subject to privacy laws that, overall, provide comparable safeguards to the Privacy Act 2020;
- The recipient is required by contract (for example, through the New Zealand Privacy Commissioner's model contract clauses or equivalent safeguards) to protect the information in a way comparable to the Privacy Act 2020;
- You have expressly authorised the overseas disclosure after being informed that the safeguards may not be comparable; or
- Another ground in IPP 12 applies.
By providing your personal information you acknowledge that it may be disclosed to overseas recipients for the purposes described in this Policy.
8. How Long We Keep Your Personal Information
We retain personal information only as long as necessary for the purposes described in this Policy, or as required by New Zealand law (IPP 9).
| Data Category | Retention Period |
|---|---|
| Order, transaction, and payment records | 7 years from date of transaction (NZ tax record-keeping) |
| Account data | 3 years after last account activity or closure (whichever is later) |
| Customer care communications | 3 years from last interaction |
| Marketing preferences and consent records | Until consent withdrawn, plus 1 year (UEMA compliance evidence) |
| Fraud and security logs | 2 years from the relevant event |
| Cookies and tracking data | 2 years from collection (see also Meta and Google terms) |
| Legal hold data (disputes, access requests, litigation) | Duration of matter plus applicable limitation period |
| Anonymised/aggregated analytics data | Indefinite (not personal information) |
On expiry of the retention period, we take reasonable steps to destroy or de-identify the information (IPP 9).
9. How We Protect Your Personal Information (IPP 5)
We implement technical and organisational safeguards to protect your information, including:
- Encryption in transit (TLS/SSL) and at rest
- Access controls and role-based permissions
- Regular security assessments and penetration testing
- Staff privacy training
- Incident response procedures (see Section 10)
Payment card data is processed by our PCI-DSS certified payment gateway. We do not store full card numbers. If you believe your account has been compromised, contact us at privacy@bonvale.com immediately.
10. Privacy Breach Notification
We comply with the notifiable privacy breach regime under Part 6 of the Privacy Act 2020. On becoming aware of a privacy breach that has caused, or is likely to cause, serious harm, we will:
- Investigate the breach and assess whether it is notifiable
- Where it is a notifiable privacy breach, notify the Office of the Privacy Commissioner and affected individuals as soon as practicable after becoming aware of the breach (section 114 of the Privacy Act 2020)
- Document the breach and our response
Office of the Privacy Commissioner contact details: privacy.org.nz · 0800 803 909 · PO Box 10094, The Terrace, Wellington 6143.
11. Your Rights Under New Zealand Privacy Law
Under the Privacy Act 2020 and the IPPs, you have the following rights:
| Right | What It Means |
|---|---|
| Right of Access (IPP 6) | Request confirmation of whether we hold personal information about you and access to that information. We respond as soon as reasonably practicable, and in any event within 20 working days. |
| Right to Correction (IPP 7) | Ask us to correct personal information that is inaccurate, incomplete, out-of-date, irrelevant, or misleading. If we decline to correct, you may request a statement of correction be attached. |
| Right to Opt Out of Direct Marketing | Opt out of receiving marketing communications at any time. Actioned immediately. |
| Right to Complain | Make a privacy complaint directly to us, or escalate to the Office of the Privacy Commissioner if unsatisfied (see Section 12). |
| Right re Automated Decisions | We do not currently make solely automated decisions about you with legal or similarly significant effects. |
To exercise any right, contact privacy@bonvale.com. We may ask you to verify your identity. We do not charge for access or correction requests.
12. Complaints & the Privacy Commissioner
If you have a concern about how we handle your personal information, please contact us first at privacy@bonvale.com. We will acknowledge your complaint within 5 business days and respond substantively within 20 working days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Privacy Commissioner:
- Website: privacy.org.nz
- Telephone: 0800 803 909
- Address: PO Box 10094, The Terrace, Wellington 6143
13. Children's Privacy
Our Services are for individuals aged 18 and over. We do not knowingly collect personal information from under-18s. If you believe a child has provided us with their information, contact privacy@bonvale.com and we will promptly delete it unless retention is required by law.
14. Third-Party Links
Our Website and App may link to third-party sites. This Policy does not cover those sites and we are not responsible for their privacy practices.
15. Cookie Policy
What are cookies? Cookies are small text files placed on your device when you visit our Website. They allow the site to remember your actions and preferences over time, and help us and our third-party partners understand how visitors interact with our content. Similar technologies, including pixels and device identifiers, work in an equivalent way. The cookies we use We use four categories of cookies. The table below lists each cookie, who sets it, what it does, and how long it remains on your device. Category 1: Strictly Necessary These cookies are essential for our Website to function. They cannot be disabled. No consent is required to set them.
| Cookie Name | Set By | Purpose | Duration |
|---|---|---|---|
_shopify_session |
Shopify | Maintains your shopping session, keeps you logged in, and supports checkout security | Session (deleted when browser closes) |
_shopify_y |
Shopify | Assigns a unique visitor ID used to support analytics and personalisation within Shopify's platform | 1 year |
cart |
Shopify | Stores the contents of your shopping cart so items are retained as you browse | 2 weeks |
secure_customer_sig |
Shopify | Verifies that you are logged into your account securely | 20 years |
_ab |
Shopify | Tracks whether you were directed to a specific storefront variant (used internally by Shopify) | 2 years |
_tracking_consent |
Shopify | Records your cookie consent preferences, including which categories you accepted or rejected and the date and version of the policy at the time | 1 year |
Category 2: Analytics These cookies help us understand how visitors use our Website. The data is aggregated and not used to identify you personally. These cookies are set only with your consent.
| Cookie Name | Set By | Purpose | Duration |
|---|---|---|---|
_ga |
Google LLC (Google Analytics 4) | Assigns a unique identifier to distinguish visitors and aggregate usage data | 2 years |
_ga_[ID] |
Google LLC (Google Analytics 4) | Stores and maintains session state for a specific GA4 property | 2 years |
_gid |
Google LLC (Google Analytics 4) | Distinguishes individual users for a 24-hour session | 24 hours |
_gat |
Google LLC (Google Analytics 4) | Throttles the rate of analytics data requests to Google's servers | 1 minute |
Google Analytics data is transferred to Google's servers, which may be located outside New Zealand. See Section 7 of this Policy on cross-border disclosure. You may opt out of Google Analytics tracking at any time using the Google Analytics Opt-Out Browser Add-on or by adjusting your preferences in our cookie banner. Category 3: Marketing and Advertising These cookies are used to deliver targeted advertising based on your browsing and purchase behaviour on our Website, and to measure the effectiveness of our advertising campaigns. They are set only with your consent.
| Cookie Name | Set By | Purpose | Duration |
|---|---|---|---|
_fbp |
Meta Platforms, Inc. | Identifies browsers for advertising measurement and retargeting via Facebook and Instagram (Meta Pixel) | 3 months |
_fbc |
Meta Platforms, Inc. | Stores the click identifier when you arrive at our Website via a Facebook or Instagram advertisement | 3 months |
fr |
Meta Platforms, Inc. | Used by Meta to deliver, measure, and improve targeted advertisements shown on Meta platforms | 3 months |
Meta Pixel data is transferred to Meta's servers in the United States. See Section 7 on cross-border disclosure and Section 5.1 for a full description of how the Meta Pixel operates. Managing your preferences You can review and change your cookie preferences at any time by clicking Cookie Settings in the footer of our Website. You can also:
- Use your browser settings to block or delete cookies. Blocking strictly necessary cookies will affect core Website functionality.
- Opt out of Google Analytics via the Google Analytics Opt-Out Browser Add-on.
- Manage your Meta advertising preferences at facebook.com/ads/preferences.
Withdrawing consent for analytics or advertising cookies takes effect immediately. It does not affect the lawfulness of any processing that took place while consent was in place.
16. Updates to This Policy
We may update this Policy to reflect changes in our data practices, applicable law, or our Services. The updated Policy will be published with a revised 'Last Updated' date. For material changes, we will notify you by email or prominent Website notice before the change takes effect. Continued use of our Services after the effective date constitutes acceptance of the updated Policy.
17. Contact Us
For all privacy queries, requests, and complaints: Email: privacy@bonvale.com We aim to respond within 20 working days. If unsatisfied, you may escalate to the Office of the Privacy Commissioner (see Section 12).