Privacy Policy

Last updated: 18 July 2026

Draft notice: This is a starter privacy policy adapted for RIPPRR. It must be reviewed by a qualified lawyer before being relied upon as a binding legal document.

What we collect, where it lives, who gets to see it, and how to get it back. Plain English first.

1. Who we are

RIPPRR is an AI phone agent for trade businesses, operated in New Zealand and Australia. This policy applies to everyone whose data passes through RIPPRR: the businesses that sign up (our "Customers"), their staff, and the end-customers who call or message them.

We are bound by the New Zealand Privacy Act 2020 and the Australian Privacy Act 1988. If anything in this policy reads more restrictively than the law requires, the stricter standard wins.

2. What we collect

To run an AI phone agent we need to hold three categories of data:

  • Account data from the business signing up: business name, your name, email, mobile number, business address, website URL, password, payment details (handled by Stripe), and the voice persona you choose for the AI agent.
  • Operational data generated as you use the service: call recordings and transcripts, voicemail messages, SMS and email content, customer names and contact details, booking times and addresses, job notes, photos, voice notes, quotes, invoices, and usage events (which features are used, call volumes, errors).
  • Technical data captured automatically: IP address, browser type, device, time zone, pages visited, and cookies. Used for security, debugging, and product improvement.

We do not collect biometric data, health records, or any "special category" data unless you put it there yourself (for example, in a free-text job note).

3. Why we collect it

  • To provide the AI phone agent service: answer calls, book jobs, take messages, send SMS.
  • To send transactional messages (booking confirmations, reminders, password resets).
  • To bill your RIPPRR subscription and process top-ups (via Stripe).
  • To detect abuse, fraud, and security issues.
  • To improve the product: fix bugs, train and tune the AI, optimise call quality.
  • To meet legal obligations (tax records, regulatory disclosures).

We never sell your data. We never share it with advertisers. We will never email your customers to promote our own product, your competitors, or anyone else.

4. Who we share it with

To run the product we use sub-processors. Each handles a specific piece of the puzzle and is contractually limited to what they need.

Sub-processorPurposeRegion
SupabaseDatabase, file storage, and authenticationProject-configured region
VercelApplication hostingGlobal edge / US
StripeSubscription billing and top-upsGlobal, processed in AU/US
VAPIVoice AI platform and call handlingUnited States
TwilioPhone numbers and inbound/outbound telephonyUnited States
SMS EveryoneSMS deliveryNew Zealand / Australia
OpenAILanguage model processing for calls and transcriptsUnited States
DeepgramSpeech-to-text transcriptionUnited States
ElevenLabsVoice synthesisUnited States
GoogleOptional Sign-In and Calendar syncGlobal
XeroOptional invoice syncGlobal
ResendTransactional emailUnited States
SentryError tracking and performance monitoringUnited States

For Stripe: we never see or store full card numbers. They are handled by Stripe under PCI-DSS compliance. We hold only a tokenised reference and the last four digits so receipts can be matched back to a payment.

5. Where it lives

Your live data is stored by Supabase in the region configured for the RIPPRR project. Nightly backups stay with the same provider. Some sub-processors (VAPI, OpenAI, Deepgram, ElevenLabs, Resend, Sentry, Vercel) are based in the United States; data sent to them is encrypted in transit and stays only as long as needed to do the job.

6. How we protect your data

  • Encryption in transit.All traffic to and from RIPPRR, and every call we make to a sub-processor's API, runs over TLS 1.2 or higher.
  • Encryption at rest. Databases and backups are encrypted on disk. OAuth tokens for Google Calendar and Xero are additionally encrypted at the application layer.
  • Least-privilege access.Production access is limited to the engineers who need it, with individual accounts and strong authentication. Row-level security and business-based access controls keep every customer's data isolated.
  • Minimal Google scopes. When you connect Google Calendar we request only the narrow permissions needed: read and write calendar events, read your calendar list, and your email address. We never request access to Gmail, Drive, Contacts, or other Google data.
  • Revocable at any time. You can disconnect Google Calendar or Xero from inside RIPPRR, or revoke our access directly at myaccount.google.com/permissions. Either way we delete the stored tokens.
  • Breach response. If a breach affecting your data ever occurs, we will notify you and the relevant regulator (the NZ Privacy Commissioner or the OAIC) as the law requires.

7. Google user data and Limited Use

If you choose to connect a Google account for calendar sync, RIPPRR accesses your Google Calendar through Google's APIs using the minimal scopes listed above. We use that access for one purpose only: to show your existing Google Calendar events as busy time inside RIPPRR, and to write the bookings you make in RIPPRR back to your Google Calendar.

RIPPRR's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • We only use Google user data to provide and improve the calendar-sync feature you switched on.
  • We do not transfer Google user data to anyone else, except as needed to provide or improve that feature, to comply with applicable law, or in connection with a merger or acquisition (with notice to you).
  • We do not use Google user data for advertising, and we never sell it.
  • We do not let humans read Google user data unless you give specific consent, it is necessary for security or to comply with the law, or the data has been aggregated and anonymised for internal operations.

8. How long we keep it

  • Account active:indefinitely, while you're using the service.
  • Payment and invoice records: 7 years after account closure, to satisfy NZ and AU tax law.
  • Call recordings and transcripts: configurable by the business owner, default 90 days, then permanently deleted.
  • SMS and email message bodies: 12 months, then permanently deleted.
  • Backup snapshots: rolling 30-day window.

If you close your account, you can request immediate deletion of everything except records we are legally required to keep.

9. Your rights

Under NZ and AU privacy law you can:

  • Accessthe data we hold about you. Log in and you can already see most of it; email us for anything you can't see in the UI.
  • Correct anything inaccurate.
  • Export your data via the dashboard at any time.
  • Delete your account and the data attached to it.
  • Complainto the NZ Privacy Commissioner (privacy.org.nz) or the OAIC (oaic.gov.au) if you think we've mishandled something.

10. Cookies

We use first-party cookies to keep you signed in and for security (CSRF protection). We may also use analytics cookies to understand how the website is used. You can refuse cookies through your browser settings, but some features may not work properly.

11. Children

RIPPRR is a B2B product. We do not knowingly collect data from anyone under 16. If a customer profile in your account is for a minor, the legal basis for processing that data is the consent of their parent or guardian given to you, not to us.

12. Changes to this policy

If we change anything material, we'll email every active account at least 14 days before the change takes effect. The "last updated" date at the top of this page is the source of truth.

13. Contact

Questions, requests, or anything privacy-related: support@ripprr.co.nz.

We aim to respond to every privacy request within 5 business days.