What we collect
- To fulfil orders: name, email address, shipping address, phone number (for courier delivery only).
- Payment data: handled by Stripe — we never see your card number. Stripe stores it under their own privacy policy at stripe.com/nz/privacy.
- First-party analytics (run by us): a private, cookieless log of how the site is used — pages viewed, the order you visit them in, how long you actively spend on a page, how far you scroll, on-site search terms, the brand/model you look up in the finder, and where you arrived from (referrer / campaign tags). Your IP address is truncated (the last part removed) and a daily, throwaway one-way code stands in for "a visitor" — neither identifies you, and the code can't be linked back to you after the day ends. This data stays on our own server in New Zealand and isn't shared.
- Order attribution: if you place an order, we may link that on-site journey to the resulting order (so we can tell which pages and searches help people find the right part). This link lives only in our own systems.
- Google Analytics 4: pseudonymous traffic data (page views, time on site, where you came from), processed by Google and stored on Google's servers in the US/EU. We don't send Google your name.
- Core Web Vitals: anonymous page-performance timings (load speed, responsiveness) sent to our own analytics so we can keep the site fast.
- Browser storage: a small amount of first-party storage for your cart contents, plus a first-party visitor id (in your browser's local storage) and a per-visit session id used only to join your visit to an order, if you buy. There is also a Stripe cookie during checkout and Google's analytics cookies. No advertising or cross-site tracking cookies. We honour your browser's Global Privacy Control (Sec-GPC) and Do-Not-Track signals — if either is on, our first-party analytics records nothing for your visit.
- How long we keep it: first-party analytics rows are automatically deleted after 12 months (and the IP-derived parts are dropped after 30 days). Order records we're legally required to keep — see below.
What we don't do
- We don't sell, rent, or trade your details to anyone.
- We don't share order data with marketing companies.
- We don't run retargeting / remarketing pixels at this time.
Who sees your data
- Us (the one-person operator) — for fulfilment and replying to your messages.
- Our fulfilment partner — receives your name, shipping address, and phone (for courier) so the package can be addressed. Nothing more.
- NZ Post / courier — for delivery to your address.
- Stripe — handles your payment.
- Google (Analytics 4) — pseudonymous browsing data, no personal identifiers, processed in the US/EU.
- Our own first-party analytics — stays on our New Zealand server; not shared with any third party.
Your rights under the Privacy Act 2020
You can email us at any time to:
- Get a copy of the personal information we hold about you
- Correct anything that's wrong
- Ask us to delete your account and historical orders (we'll keep order records the IRD requires us to retain — usually 7 years — and delete everything else)
Data storage
Order data is stored on a server we operate ourselves in New Zealand. Stripe stores payment metadata in their own infrastructure (US/EU). Google Analytics data is stored on Google's servers (US/EU).
How to contact us about privacy
CapacitorsNZ Ltd is the agency responsible for your personal information under the Privacy Act 2020. Our privacy officer is the site operator — contact us here to ask about, access, or correct your information, or to raise a privacy concern. We respond within a working day. If you're not satisfied, you can contact the Office of the Privacy Commissioner (privacy.org.nz).