Privacy & Security Policy
NZAviator Privacy Policy (Website + App)
Applies to:
Website: nzaviator.co.nz (including mock exams and website accounts)
App: app.nzaviator.co.nz (the “NZAviator App”)
Last updated: 8th Feb 2026
1. RESPONSIBILITY
NZAviator (“NZAviator”, “we”, “us”, “our”) cares about your privacy. To operate our Platforms and Services, we need to collect and use some information about you. We think it’s important you understand when we collect personal information, what we collect, how we store it, and how it is used.
This Privacy Policy applies to personal information collected by NZAviator from visitors, users, customers, subscribers, and anyone who engages with our Platforms and Services.
We are bound by our obligations under the Privacy Act 2020 (New Zealand) and the Information Privacy Principles (IPPs).
Your use of any part of our Platforms and/or Services constitutes your consent to the collection, use, storage, disclosure, and other handling of your personal information in accordance with this Privacy Policy. If you do not agree, please do not use our Platforms or Services.
We may amend this Privacy Policy by publishing a revised version on our Platforms.
2. DEFINITIONS
“App” means the NZAviator application available at app.nzaviator.co.nz.
“Personal information” has the meaning given in the Privacy Act 2020 (NZ) — broadly, information about an identifiable individual.
“Platforms” means:
nzaviator.co.nz (and its subdomains), and
app.nzaviator.co.nz,
and any other websites, pages, or applications we operate from time to time.
“Services” means the services we provide via the Platforms, which may include:
pilot logbook storage and reporting tools (App)
training, currency, endorsements, and document storage features (App)
user-controlled sharing and review workflows (App)
mock exams, subscriptions, and learning services (Website)
support and communications relating to the above
“Third-party service providers” means vendors who help us operate our Platforms or deliver Services (e.g., hosting, analytics, email delivery, authentication, and payment processing).
“You” / “your” means any person using our Platforms, Services, or contacting us.
3. COLLECTION OF INFORMATION
3.1 What we collect
We may collect the following categories of personal information depending on what you use (Website, App, or both):
(A) Account and identity information
App (Google Sign-In):
your name and email address provided by Google
your profile photo (if available and enabled)
a unique Google account identifier used for authentication
login/session timestamps
Important: We do not receive or store your Google password. We do not access your Google Drive, Gmail, Contacts, or other Google services beyond basic sign-in profile data.
Website (website login):
name (if provided), email address, username
password (stored in encrypted/hashed form where applicable)
account settings and preferences
(B) Profile and contact details you provide
May include (depending on features used):
email address, phone number, address (if provided)
company or organisation details (if applicable)
profile settings and preferences
(C) Aviation profile, logbook, and training data (primarily App)
Examples include:
licence/rating/medical certificate details and expiries
flight entries (dates, times, routes, aircraft details, roles, conditions)
take-offs, landings, approaches, instrument time
training records, endorsements, checks, exams, notes/remarks
instructor/examiner names/details you add
(D) Documents and uploads (App and/or Website if enabled)
Examples include:
verification documents (e.g., licence, employment letter)
endorsement certificates and scanned documents
profile photo
any other files you choose to upload
(E) Transaction and payment information
purchases/subscriptions and access entitlements (Website and/or App)
payment confirmations and receipts
Payments: If you buy tokens/subscriptions, payment processing is handled by Stripe. We do not store your full card details. We receive transaction confirmations and purchase records.
(F) Technical, usage, and analytics information
When you use our Platforms, we may automatically receive and record information such as:
IP address
approximate location derived from IP (not precise GPS unless you explicitly enable it in a feature that requires it)
device type, operating system, browser type
pages visited, features used, session duration
cookie identifiers and similar technologies
error logs and diagnostic events
3.2 How we collect information
We collect information when:
you register, sign in, or update your profile
you use features (e.g., logbook entries, uploads, mock exams, purchases)
you contact support or communicate with us
you interact with our Platforms (including cookies and analytics)
we lawfully receive information from third parties (e.g., Google authentication response, Stripe payment confirmations)
3.3 Minimisation
We only collect personal information that is reasonably necessary to provide Services, operate the Platforms, meet legal obligations, and improve security and functionality.
4. IMPORTANT: TWO PLATFORMS ARE SEPARATE (WEBSITE VS APP)
NZAviator operates two separate systems:
the Website (nzaviator.co.nz) uses a website account login
the App (app.nzaviator.co.nz) uses Google Sign-In
Your Website account and App account are not automatically linked, and data is not automatically merged between the two platforms, even if the same email is used, unless we introduce an opt-in account linking feature.
5. HOW WE USE YOUR PERSONAL INFORMATION
We will use personal information for the purpose it was collected for, including to:
complete your registration and administer your account
deliver our Services (e.g., mock exams, subscriptions, logbook features)
tailor content and improve your experience (where available)
communicate with you about your account, service changes, and support matters
send password reset and account security messages
administer promotions, surveys, and collect feedback (where offered)
monitor usage and improve our Platforms, Services, and customer support
prevent and detect misuse, fraud, and security incidents
comply with legal obligations and enforce our Terms
How we contact you
We may contact you by:
email
in-platform notifications/messages
and, where you have provided it, other contact methods such as mobile phone
6. APP DATA PRIVACY + USER-CONTROLLED SHARING
In the App, your data is private by default:
other users cannot see your profile/logbook/documents unless you grant access
sharing occurs only through the App’s Sharing & Access features
you control what is shared, with whom, and you can revoke access
when you request an instructor review, we share only what is needed based on the access level you choose
7. SHARING INFORMATION WITH OTHERS
We do not sell your personal information.
We may share personal information as follows:
7.1 Service providers (to operate Services)
We may share information with third-party service providers under contract to us to support:
hosting and infrastructure
analytics and error monitoring
email delivery and notifications
authentication (Google for App login)
payments (Stripe)
application hosting and backend services (Base44)
These providers may only use your information to perform services for us and must protect it appropriately.
7.2 User-initiated sharing (App)
Where you choose to share data (e.g., instructor/examiner/employer), we share only what you authorise through Sharing & Access.
7.3 Aggregated or de-identified information
We may share aggregated or de-identified information (which does not identify you) with partners or service providers to understand how users collectively use our Platforms.
7.4 Legal and compliance
We may disclose information where required or authorised by law, including responding to lawful requests from government agencies, regulators, or law enforcement (including the New Zealand Civil Aviation Authority (CAA)), court orders, or where necessary to protect rights, safety, and security, or to investigate suspected fraud or misuse.
7.5 Business transfer
If NZAviator is involved in a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction, subject to appropriate safeguards and notice where required.
8. DATA RETENTION
We keep personal information only as long as reasonably necessary to:
provide Services and maintain account continuity (e.g., logbook history)
comply with legal, tax, accounting, and dispute-resolution obligations
maintain reasonable backups for business continuity
Where we de-identify information (so it can no longer be associated with you) for analytics or statistical purposes, we may use it without further notice.
9. MODIFY OR RESTRICT YOUR INFORMATION
9.1 Updating information
You can change certain information through your account settings (Website and/or App) where that functionality exists.
If you are having trouble accessing or updating your information, contact us at info@nzaviator.co.nz.
9.2 Restricting sharing (App)
You can restrict or revoke App sharing permissions through Sharing & Access.
Please note: restricting certain information may limit features that depend on it (for example, instructor reviews or verification workflows).
10. ACCESS AND CORRECTION OF PERSONAL INFORMATION
You may request access to, or correction of, the personal information we hold about you.
We may require identity verification before releasing information to protect confidentiality
We will respond within the applicable timeframe under the Privacy Act 2020 (often within 20 working days, subject to lawful extensions)
In some cases we may refuse access where the Privacy Act permits (e.g., privacy of others, legal privilege, safety, or where prohibited by law). If we refuse, we will explain why and how you can complain.
11. SECURITY (SSL SECURED)
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. Safeguards may include:
HTTPS/SSL encryption in transit
access controls and least-privilege permissions
monitoring/logging for security events
secure authentication (Google Sign-In for the App)
You are responsible for protecting your account credentials. For Website accounts, select a strong password and keep it confidential. Sign out when using shared devices.
No method of transmission over the internet is completely secure. Transmission is at your own risk.
Security incidents
If information under our control is compromised due to a breach of security, we will take reasonable steps to investigate and, where appropriate, notify affected individuals and regulators in accordance with applicable laws.
12. UNSOLICITED INFORMATION
If you provide personal information we did not request:
we will only retain it if it is reasonably necessary for Services or permitted by law
otherwise we will delete/destroy it where lawful and reasonable
13. OVERSEAS DISCLOSURE
Your information may be stored or processed in New Zealand and other countries where our service providers operate (for example, via hosting, analytics, email, or payment vendors).
Where overseas disclosure occurs, we take reasonable steps to ensure appropriate protections are in place consistent with the Privacy Act 2020.
14. COOKIE POLICY
We use cookies and similar technologies to:
keep you logged in and maintain sessions
secure the Platforms and prevent fraud
remember preferences
analyse usage to improve our Services
Analytics (including Google Analytics)
We may use Google Analytics and/or other analytics tools to better understand how people use our Platforms. These tools may use cookies to collect information such as:
time of visit, pages visited, time spent on pages
IP address (or truncated IP depending on configuration)
device/operating system and browser type
You can refuse cookies via browser settings, but some functionality may not work correctly (especially authentication/session features).
15. THIRD-PARTY WEBSITES
Our Platforms may contain links to other sites. NZAviator is not responsible for the privacy policies or practices of third-party sites. When linking to another site, you should review that site’s privacy policy.
16. ACCOUNT DELETION
Website
If you want to delete your Website account, you can request this via the Website contact options (where available) or by emailing info@nzaviator.co.nz.
App
If you want to delete your App account, you can do this inside the App:
Profile & Settings → Account Closure → Delete My Account
This will permanently delete your account and associated App data (subject to the “Data retention” section of this Privacy Policy, including limited backup retention and any records we must keep for legal, tax, security, or dispute-resolution purposes).
If you cannot access the App or are unable to delete your account using the steps above, you can request deletion by emailing info@nzaviator.co.nz
Backups and shared copies
Even after you delete information from your account, copies may remain:
where information has been shared with others (to the extent it was accessed or retained under your sharing choices), or
in backups for a limited period until those backups are rotated/removed in the ordinary course
17. COMPLAINTS AND DISPUTES
If you have questions, concerns, or complaints about privacy, contact us:
Email: info@nzaviator.co.nz
We will investigate and attempt to resolve your complaint.
If you are not satisfied, you may contact the Office of the Privacy Commissioner (New Zealand):
Website: privacy.org.nz
Phone: 0800 803 909 (Monday to Friday │10am to 3pm)
18. AVAILABILITY AND CHANGES TO THIS POLICY
This Privacy Policy is available on our Platforms. We may update it from time to time by publishing a revised version. If updates are significant, we may provide notice on our Website and/or within the App.