FiveStar Growth / Legal

Privacy Policy

Effective date: 8 August 2026

FiveStar Growth provides digital loyalty, customer engagement, Google review, promotional communication and Wallet-pass services to participating New Zealand businesses.

This Privacy Policy explains how FiveStar Growth collects, uses, stores and shares personal information when customers, merchants, salespeople and staff use FiveStar Growth websites, loyalty programmes, Wallet passes, dashboards and related services.

01

Who we are

FiveStar Growth operates the FiveStar Growth loyalty platform.

In this policy, “FiveStar”, “we”, “our” and “us” mean FiveStar Growth. “Merchant” means a participating business using FiveStar Growth. “Customer” means a person enrolled in a merchant’s loyalty programme. “Service” means our websites, loyalty platform, digital Wallet passes, merchant dashboards, staff checkout terminals and related communication services.

Contact
Email: hello@fivestargrowth.nz
Phone: 020 451 0002
Privacy page: https://fivestargrowth.nz/privacy

02

Information we collect

Customer information

  • First name
  • Mobile number
  • Optional email address
  • Marketing consent and unsubscribe status
  • Merchant loyalty memberships
  • Points or stamp balances
  • Visit and transaction history
  • Purchase amounts or qualifying items entered by merchant staff
  • Rewards earned, selected and redeemed
  • Review-request status, including whether a review link was selected
  • Google Wallet or Apple Wallet pass identifiers and status
  • Checkout and redemption codes
  • Notification and communication status
  • Customer support communications

We do not collect the content or star rating of a Google review through the FiveStar platform.

Location and device information

Where enabled by a merchant and permitted by the user, we may collect approximate or precise device location to confirm that a customer is physically near a participating store.

  • Browser and device type
  • Operating system
  • IP address
  • Date and time of activity
  • Security and diagnostic logs
  • NFC or QR interaction information
  • NTAG security data, including tag identifiers, counters and authentication results
  • Essential cookie, session and local-storage information

Merchant and sales-team information

  • Owner and staff names
  • Business and personal contact information
  • Business name, category and physical address
  • Loyalty programme and reward settings
  • Subscription plan and status
  • Staff-device information
  • Salesperson assignment and referral information
  • Commission rates and estimated commission amounts
  • Dashboard activity, access and security logs
  • Support and onboarding communications

03

How we collect information

We may collect information:

  • Directly from customers, merchants, salespeople and staff
  • When a customer enrols or uses a loyalty programme
  • When merchant staff confirm a purchase or redemption
  • Through NFC, QR, Wallet and checkout interactions
  • From participating merchants acting in connection with their loyalty programme
  • From Google Wallet, Apple Wallet, SMS and email delivery providers
  • Automatically through security, diagnostic and service logs
  • Through sales-referral and merchant-onboarding links

Where information is supplied by a merchant or another authorised person, we use it only for operating the relevant FiveStar service and related lawful purposes.

04

Why we use personal information

We use personal information to:

  • Create and manage loyalty accounts
  • Identify returning customers
  • Award and deduct points or stamps
  • Display balances, rewards and progress
  • Create and update digital Wallet passes
  • Process reward redemptions
  • Confirm customer visits and purchases
  • Prevent duplicate taps, misuse and fraudulent activity
  • Apply merchant cooldown and location rules
  • Display customers awaiting service on an authorised staff terminal
  • Deliver transactional SMS, email and Wallet updates
  • Deliver promotional communications where consent has been given
  • Present Google review requests according to merchant settings
  • Provide merchant dashboards, reports and customer activity
  • Operate sales attribution and commission reporting
  • Respond to support and privacy requests
  • Protect the security and reliability of the Service
  • Meet legal, accounting and regulatory obligations

05

Promotional communications and consent

Providing an email address for promotional offers is optional. A customer does not need to provide an email address to collect loyalty points, obtain a Wallet pass, redeem a reward or use the Service.

Promotional email consent is merchant-specific. Consent to receive offers from one merchant does not give another merchant permission to send promotional email.

We only save a promotional email address when the customer actively submits the promotional-email form.

Marketing messages will identify the relevant merchant or FiveStar Growth and include an unsubscribe facility.

Customers may:

  • Use the unsubscribe link in an email
  • Reply STOP to supported promotional SMS messages
  • Disable Wallet notifications through their device
  • Remove a Wallet pass
  • Contact FiveStar Growth or the relevant merchant

When a promotional-email unsubscribe is processed, promotional consent is disabled, the plaintext email address is removed from the active subscription record, and a one-way email hash may be retained as a suppression record. The suppression record helps prevent the address from being accidentally added to or contacted through a future campaign.

06

Transactional communications

We may send communications necessary to operate a loyalty account, such as:

  • Account and Wallet-pass confirmations
  • Points, stamps and reward updates
  • Redemption information
  • Security notices
  • Important service changes
  • Responses to support requests

Transactional communications are separate from optional promotional-email consent, although users may still control applicable Wallet and device-notification settings.

07

How merchants use information

A merchant may access information connected with its own loyalty programme, including customer identity, loyalty balance, visit history, transaction details and redemption activity.

Merchants cannot access another merchant’s customer data through FiveStar.

Merchants are responsible for using customer information lawfully and only for legitimate loyalty, service and consented marketing purposes.

08

When we share information

We may share personal information with:

  • The participating merchant whose loyalty programme the customer joined
  • Hosting, database and infrastructure providers
  • SMS and email delivery providers
  • Google Wallet and Apple Wallet
  • Security, encryption and authentication providers
  • Professional advisers, insurers or regulators where necessary
  • Government or law-enforcement authorities where legally required
  • A purchaser or successor if the FiveStar business is reorganised or transferred, subject to appropriate privacy protections

Service providers may include Supabase, Vercel, Twilio, Resend or Postmark, Google, Apple and Amazon Web Services.

We do not sell customer personal information.

09

Overseas processing

Some technology providers may process or store information outside New Zealand, including in Australia, the United States or other countries.

Where personal information is disclosed overseas, we will take reasonable steps to ensure the recipient provides privacy safeguards consistent with New Zealand privacy requirements.

10

Security

We use reasonable technical and organisational safeguards designed to protect personal information, including:

  • Encrypted network connections
  • Restricted administrative access
  • Hashed access credentials and sensitive identifiers
  • Merchant-specific access controls
  • Signed customer, unsubscribe and redemption links
  • Database constraints and transaction controls
  • Security logging
  • NFC authentication and replay protections where supported
  • Staff-device revocation controls

No internet or storage system can be guaranteed to be completely secure. Customers and merchants should protect their devices, passwords, access keys and accounts.

11

Retention

We retain personal information only for as long as reasonably necessary to provide the Service, maintain accurate loyalty and redemption records, resolve disputes, prevent fraud or duplicate use, and meet legal, accounting and security obligations.

Information may be anonymised or deleted when it is no longer required. Suppression hashes may be retained after an email unsubscribe to ensure the address is not accidentally contacted again.

12

Access, correction and deletion

Individuals may ask us to:

  • Confirm whether we hold their personal information
  • Provide access to their personal information
  • Correct inaccurate or incomplete information
  • Delete information that is no longer required
  • Withdraw promotional consent
  • Explain how their information has been used or disclosed

Requests can be sent to hello@fivestargrowth.nz.

We may need to verify the requester’s identity before providing or changing personal information. Some information may need to be retained where required for security, legal, transaction or fraud-prevention purposes.

13

Cookies, sessions and local storage

Our websites and installed web applications may use essential cookies, browser storage and session information to:

  • Keep authorised users signed in
  • Pair staff checkout devices
  • Maintain secure sessions
  • Support PWA installation and offline loading
  • Protect the Service
  • Improve reliability and loading performance

We do not currently use this information for third-party behavioural advertising.

14

Automated loyalty and security rules

The Service may automatically:

  • Calculate points or stamps
  • Determine reward eligibility
  • Enforce tap cooldowns
  • Reject invalid or duplicated NFC interactions
  • Apply merchant reward settings
  • Check optional store-distance requirements

Merchants remain responsible for confirming purchases and redemptions where staff confirmation is required.

15

Privacy breaches

If a privacy breach occurs that has caused or is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected individuals as required by the Privacy Act 2020.

16

Complaints

Privacy concerns should first be sent to:

Privacy Officer
FiveStar Growth
Email: hello@fivestargrowth.nz
Phone: 020 451 0002

We will investigate and respond to privacy concerns within a reasonable period.

Individuals may also contact the New Zealand Office of the Privacy Commissioner: https://www.privacy.org.nz.

17

Changes to this policy

We may update this Privacy Policy when our services, providers or legal obligations change.

The latest version will always be available at https://fivestargrowth.nz/privacy.

Material changes may also be communicated through the Service, by email or through merchant communications.

WhatsApp