Privacy Policy
Last updated: 30 July 2026
This policy explains what personal information the Affordable Deliverys website collects, why we collect it, who else processes it on our behalf, how long we keep it, and how you can ask to see it, correct it or have it deleted. It covers the website at affordabledeliverys.co.nz and the booking and quoting features on it. Affordable Deliverys is a Christchurch based courier service and is the agency responsible for this information under the New Zealand Privacy Act 2020.
1. Information you give us
When you request a quote. The quote form asks for, and we store:
- your name
- your phone number or email address, whichever you choose to give
- the pickup address
- the delivery address
- anything you type into the notes box
- the job details you select: truck size, whether you want an extra worker, the estimated hours, the delivery zone, whether there are stairs or a tight fit, and whether the job is commercial
- the price we quoted you, excluding and including GST, along with the breakdown behind it, and where a job needs manual review, the reason it was flagged
- a snapshot of the rate card in force at the moment you were quoted, so a later price change can never quietly rewrite what you were actually told
- the date and time of the request and its status
The notes box is free text and we do not inspect what goes into it. Please do not put anything in it that you would not want stored, such as card numbers or health information. We only need what is required to price the job and carry it out.
When you leave a review. We store the name you give, your star rating and your review text. A review is saved as soon as you submit it but is not shown on the site until it has been approved. If you want a review taken down, email us and we will remove it.
2. Information collected automatically
Website analytics. Every page loads Google Analytics 4, which sets cookies in your browser and sends Google information about the pages you view, your device and browser, and an approximate location that Google derives from your IP address. We use this only to understand how the site is used in aggregate. You can opt out across all sites with the Google Analytics opt-out browser add-on at tools.google.com/dlpage/gaoptout.
Hosting logs. The site runs on Google Cloud, whose infrastructure keeps standard request logs.
Refused admin sign in attempts. This site has a private admin area used by the business owner. If a sign in to that area is refused, we keep a security record of the email address on the Google account that was used, the IP address seen on the request, the browser user agent, the sign in provider and the time. This lets us tell an honest mistake apart from an attack. It applies only to attempted admin sign ins. Requesting a quote or leaving a review never creates one of these records.
3. How we use your information
- to price your job and get back to you about it
- to carry out the delivery you booked
- to schedule a confirmed job in the business calendar
- to review and publish customer reviews
- to keep the admin area secure
- to understand how the website is used, in aggregate
We do not sell your information. We do not use it for advertising or profiling. We do not share it with anyone other than the service providers listed in section 4.
4. Who else processes your information
These providers process information on our instructions so that the site can work:
- Resend delivers the email that notifies us of your quote request or your review. Your name, contact detail, pickup and delivery addresses and notes are contained in that email.
- Google Cloud hosts the website on Firebase App Hosting and stores the data in Firestore.
- Google Calendar API is used to schedule a confirmed booking. See section 6 for exactly what is sent and what is read.
- Google Analytics measures website usage, as described in section 2.
5. How long we keep it
- Quote requests: 90 days. Every quote request record is stamped with a deletion date 90 days after you submit it, and is then deleted. This is enforced, not merely promised, and by two independent mechanisms: the database itself automatically expires and removes records once that date passes, and this application also deletes expired records as it runs.
- Refused admin sign in records: 90 days, deleted automatically the same way.
- Reviews are kept while they are published, and are removed when you ask us to remove them.
- The Google Calendar authorisation is kept until the connection is disconnected or the access is revoked in the Google Account it belongs to.
You do not have to ask for the 90 day deletion and there is nothing to opt into. It happens on its own.
6. Google user data and the Google Calendar connection
The business owner can connect a Google Calendar so that a confirmed job is scheduled automatically. The connection authorises this application against the business owner's own Google Account. It is never a connection to a customer's Google Account, and customers are never asked to sign in with Google.
The scopes we request, and exactly what we do with each:
https://www.googleapis.com/auth/calendar.freebusyis used to ask Google which time ranges are already taken on each of the calendars the business owner has chosen to check, so the application can pick a slot that is free. This returns busy and free time ranges only. It does not return event titles, descriptions, attendees or locations, and we neither read nor store any event content.https://www.googleapis.com/auth/calendar.eventsis described by Google as "View and edit events on all your calendars". We state it as Google grants it rather than as narrowly as we use it: it is a broad permission that allows this application to read the full content of calendar events, including titles, descriptions, locations and attendees, and to create, change and delete events, on the calendars the connected Google Account can reach.https://www.googleapis.com/auth/calendar.calendarlist.readonlyis described by Google as "See the list of Google calendars you're subscribed to". Stated as Google grants it: it allows this application to read every calendar the connected Google Account is subscribed to, including calendars that are hidden in Google Calendar, and for each one its name, description, location, time zone, colours, reminder and notification settings, and the level of access the account holds on it. It does not return any event content and it does not allow anything to be changed. It is requested so that the business owner can choose, in the admin area, which calendar bookings are added to and which calendars are checked for clashes. Without it the application could only ever see the default calendar, and a job booked while an appointment sat on a second or shared calendar would be booked on top of it.
What we actually do with the events permission is limited to three things:
- we create the calendar event for a confirmed job, on the single calendar the business owner selected. That event holds the quote reference, the customer name, the customer contact detail, the pickup and delivery addresses and the scheduled start and end time, so the driver has the job details on the day;
- when the admin page is opened, we read the name of the connected primary calendar so the page can show which Google Account is currently connected; and
- when the business owner asks the admin page to show the availability calendar, we read upcoming event times for the next two weeks on calendars the connected account owns, plus the private quote marker our application puts on its own bookings so they can be labelled. We do not request personal event titles. For a calendar that is merely shared with the account, we ask for busy and free times alone, so no title, description, attendee or location is ever read.
We do not change or delete any event we did not create, we do not read personal event titles in the availability view, and we do not copy calendar content anywhere. Nothing read for the admin view is stored: it is fetched when the page asks for it and is not written to our database. We request no other Google scopes, and no access at all to Gmail, Drive, Contacts, Photos or any other Google service.
How the token is stored. The refresh token Google issues is held server side only, in a single database document (calendar_connection/live) that the database security rules deny to every browser and client request, so it is reachable only by this application's server code. It is never sent to a browser, never included in the JavaScript your device downloads, and never written to logs. The same document also records which calendar the business owner chose for bookings and which calendars are checked for clashes. That is the calendar identifiers only, and no event content.
How to revoke it. The connection can be disconnected from the admin area at any time, or revoked directly at myaccount.google.com/permissions. Revoking stops all further calendar access immediately.
Limited Use. Affordable Deliverys's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- we do not transfer Google user data to anyone else, except as necessary to provide or improve this booking feature, to comply with applicable law, or as part of a merger or acquisition;
- we do not use Google user data for advertising of any kind, and we do not sell it;
- no human reads Google user data, other than with the connected account holder's explicit consent, where required for security purposes such as investigating abuse, where required by law, or where the data is aggregated and anonymised.
7. Your rights
Under the Privacy Act 2020 you can ask us for a copy of the personal information we hold about you, and ask us to correct it if it is wrong. You can also ask us to delete a quote request before its 90 day window runs out. Email jacob@affordabledeliverys.co.nz and we will respond as soon as we can, and in any case within 20 working days.
If you are not satisfied with how we have handled your information or your request, you can complain to the Office of the Privacy Commissioner at privacy.org.nz.
8. Security
The admin area is protected by Google sign in plus a server side check that the account carries an explicit administrator claim. The database collections holding quote requests, the calendar connection and the admin sign in records are denied to every browser and client request by the database security rules, and are reachable only by this application's server code. Refused admin sign in attempts are recorded, as described in section 2.
9. Children
This website is not directed at children and we do not knowingly collect personal information from them.
10. Changes to this policy
If this policy changes, we will update the date shown at the top of this page.
11. How to contact us
For anything to do with your privacy or this policy, email jacob@affordabledeliverys.co.nz.