MeshTrace.nz
Effective 11 October 2026

Privacy Policy

MeshTrace NZ Limited · Privacy contact: info@meshtrace.nz.

1. Who we are and what this covers

MeshTrace NZ Limited operates MeshTrace NZ. This policy covers visitors, customers, people who contact us, and people whose information is included in research requests or reports. It explains our handling of personal information under the New Zealand Privacy Act 2020.

2. Information we collect

  • Details you supply for standard or custom research, such as names, contact identifiers, addresses, companies, vehicles and the information you want investigated.
  • Research findings and source information lawfully obtained, which may include information about people other than the requester.
  • Encrypted request, quote-response, conversation and report content, including encrypted report attachments and filenames; file sizes and identifiers; public encryption keys; hashed access tokens; request identifiers; message sender roles and timestamps; product, price, decisions, dates and delivery status.
  • Payment identifiers, crypto amounts, networks, receiving and refund addresses, transaction references, confirmation status and voucher issuance/redemption records. Voucher PINs are stored as salted hashes, not plaintext.
  • Messages and contact details you send us, and technical/security data such as request times, IP addresses and browser or device information available to our hosting and security services.

3. How and why we use information

We collect information from you, lawful public records and other sources we are permitted to use, and payment or technical service providers. We use it to assess requests, prepare quotes, conduct research, deliver reports, process payments and refunds, investigate misuse, resolve disputes, secure the service and meet legal obligations. We do not use request content for unrelated advertising or sell it as marketing data.

Providing research and payment details is voluntary, but we may be unable to assess or perform your request without the necessary information. Do not include unnecessary sensitive information or credentials in a request.

4. People named in research

A person being researched has privacy rights even where some records are public. We limit collection, use and disclosure to lawful purposes and do not treat public availability as unrestricted permission. We may refuse, limit or stop a request where privacy or access restrictions apply. Reports are disclosed to the requester only where lawful. If you believe information about you is being misused or is inaccurate, contact our privacy contact.

For information collected indirectly, we are responsible for assessing and meeting applicable notification requirements, including Information Privacy Principle 3A, unless an applicable exception permits otherwise. Publishing this policy does not replace individual notification where that is required.

5. Encryption and its limits

The website encrypts request details in your browser before uploading them. People performing the research can decrypt and read the request to assess and fulfil it. Quote messages and reports are encrypted to the customer’s public key before upload; the customer’s private key is used locally for decryption and is not uploaded by the application.

Two-way request messages are separately encrypted for the customer and our research team so both can read the conversation with their respective private keys. The server stores encrypted message content alongside sender-role and timestamp metadata. Messages remain associated with the request after delivery and follow the retention principles below. Unsent drafts exist only in the current page and are not saved by the service.

Encryption does not make the service anonymous. Product types, prices, request status, public keys, payment data and technical metadata are not all encrypted in the same way as request content. Email messages are outside the request-encryption workflow. Public blockchain records are visible independently of MeshTrace. No system can guarantee absolute security; protect your device and recovery credentials.

6. Sharing and service providers

We use providers for hosting, storage, security and payment processing, including Replit and NOWPayments. They receive information needed for their functions and may process it under their own applicable policies and legal obligations. The payment integration sends price, currency, order identifier and a general service description, not the decrypted research request. Do not put research details in a blockchain payment memo.

We may disclose information to professional advisers or authorities where required or permitted by law, to address a serious threat, or to establish or protect legal rights. We assess requests for disclosure and limit what we disclose to what is necessary.

7. Overseas processing

Hosting and payment providers may process information outside New Zealand. When overseas disclosure rules apply, we take reasonable steps to ensure appropriate safeguards or another lawful basis under the Privacy Act. Foreign laws and independent providers’ practices may differ from those in New Zealand. Contact us for information about the providers used for your request.

8. Retention and deletion

For surveillance enquiries, relevant information may be shared with an external private-investigation firm to assess availability, prepare a quote and perform accepted work. We request your agreement to this sharing in the enquiry form. Sharing is limited to what is needed for that purpose and is coordinated by authorised staff using an agreed secure method. Investigator and provider identities are not routinely disclosed for confidentiality and operational security, but may need to be disclosed under applicable law or legal proceedings. This does not remove your statutory privacy rights. Contact us to exercise those rights or ask about a disclosure.

We retain information while needed for research, delivery, access to reports, payment and refund handling, disputes, security and legal recordkeeping. The app does not currently apply a fixed automatic-deletion interval. We review retention when purposes end or a deletion request is received, and delete or de-identify information no longer required, subject to lawful retention needs.

Deleting an active record may not immediately remove copies from backups or independent providers. Public blockchain transactions cannot be erased by us. Downloaded reports and recovery files held by you are under your control. Contact us to discuss deletion or a retention concern.

9. Browser storage and technical services

The application uses browser storage for request recovery/session functionality and essential technical services to operate and secure the site. Your downloaded recovery file contains sensitive credentials. Shared devices, browser extensions or someone with access to your files can undermine their protection. Clearing browser storage may remove convenience features; keep an independent secure recovery copy.

10. Access, correction and privacy concerns

You may request access to or correction of personal information we hold about you by emailing info@meshtrace.nz with “Privacy request” in the subject. This applies to people named in research as well as customers. We may need proportionate evidence of identity and enough information to locate the relevant records. Never send private keys or recovery files.

We respond within the time required by law, normally no later than 20 working days for an access or correction decision, unless a lawful extension applies. Legal grounds may limit access, including protection of another person’s information. Where appropriate, we explain a refusal and your options. If a requested correction is not made, you may request a statement of correction to be attached. You can complain to the Office of the Privacy Commissioner.

11. Security incidents and policy changes

If we identify a privacy breach likely to cause serious harm, we assess and notify affected people and the Privacy Commissioner as required by law. We may update this policy as our service or obligations change, showing a new effective date. Material changes to existing uses of personal information will be handled in accordance with applicable law.