PRIVACY POLICY
Storm Technology Limited
Last Updated: June 2026
Version: 2
This Privacy Policy explains how Storm Technology Limited ("Storm Technology", "we", "us", or "our") collects, uses, stores, discloses, and protects personal information in connection with our platforms and services, including SeaRoster.com, SARRoster.com, EMRoster.com, AquaRoster.com, and SeaTrack.io (collectively, the "Services" or individually, each a "Platform"), and any associated mobile applications available on the Apple App Store or Google Play Store.
We are committed to protecting your privacy and handling your personal information responsibly in accordance with the Privacy Act 2020 (New Zealand) and applicable international privacy standards.
Please read this Privacy Policy carefully. By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our Services.
1. WHO WE ARE AND HOW WE ACT
1.1 Storm Technology Limited
Storm Technology Limited is a New Zealand-registered company. The capacity in which we act in relation to your information depends on the information concerned, as set out in section 1.2 below.
Privacy Officer Contact:
Storm Technology Limited
Milford, Auckland 0620
New Zealand
If you have any questions, concerns, or requests relating to this Privacy Policy or your personal information, please contact our Privacy Officer at the address above. We will respond to all privacy enquiries within a reasonable timeframe and no later than 20 working days, as required under the Privacy Act 2020.
1.2 Our Role as Your Agent
We act in two different capacities depending on the information concerned. Which capacity applies determines who is responsible for the information and what we are permitted to do with it.
Customer Data means the information you and your Users enter into, upload to, or generate through the Platforms. It includes records about your personnel, crew, volunteers, members, vessels, schedules, qualifications, and operations. As between you and Storm Technology, this data is yours. You are the agency and, where applicable, the data controller responsible for it. We act as your agent, and we process Customer Data only in alignment with the Terms of Use and the instructions you give us through the Services. Your acceptance of the Terms of Use constitutes your authority for us to process Customer Data for the purpose of providing the Services to you.
Account Data means the information arising from your relationship with us rather than from your operational use of the Platforms. It includes registration and contact details, billing records, support correspondence, and the technical and usage data described in section 3.5. We are the agency and data controller for Account Data, and we process it for the purposes set out in section 4.
Where a provision of this Policy would apply differently to Customer Data and to Account Data, the provisions governing Customer Data prevail in respect of Customer Data. Nothing in this Policy authorises us to process Customer Data for our own purposes.
1.3 Your Data Is Yours
You retain ownership of your Customer Data at all times. We acquire no right to it beyond the limited permission necessary to host, transmit, secure, back up, and display it to you and your authorised Users in the course of delivering the Services.
We do not sell, rent, lease, license, or trade your data to any third party, for any purpose.
We do not make your data available to data brokers, advertising networks, or marketing platforms. See section 7.
All data in our Platforms is encrypted in transit and at rest by default, as described in section 12. Encryption is applied automatically and does not need to be enabled by you.
1.4 Your Responsibilities
Because you are the agency responsible for Customer Data, certain obligations rest with you rather than with us:
- You are responsible for all data you and your Users enter into the Platforms, including its accuracy, its lawfulness, and your authority to provide data about other individuals such as crew, volunteers, personnel, and emergency contacts. See section 3.9.
- You are responsible for deciding who within your Organisation should have access to that data, for assigning and reviewing user roles and permissions, and for removing access promptly when a person's role changes or ends.
- You are responsible for correcting, updating, or deleting user-entered data held within your Organisation's Account.
Our Platforms give Users holding the appropriate level of access the tools to carry out these tasks directly, without needing to ask us. Where you are unable to complete a task using those tools, our Privacy Officer will assist.
2. SCOPE OF THIS POLICY
This Privacy Policy applies to:
- All visitors to our Platforms and websites;
- All individuals who register for an Account with any of our Services;
- All Users of our mobile applications (iOS and Android);
- All individuals whose personal information we process in connection with providing our Services (including employees, crew members, volunteers, and operational personnel whose details are managed by an Organisation using our Services); and
- All individuals who communicate with us by any means.
This is a single Privacy Policy shared across all Storm Technology platforms and marketing websites. The version published here applies equally to every Platform and website we operate. When a new version is issued it takes effect on all of them, carrying the same version number and effective date shown at the top of this page.
This Policy does not apply to third-party websites, applications, or services that may be linked to or integrated with our Services. We encourage you to review the privacy policies of any third-party services you access through our Platforms.
3. INFORMATION WE COLLECT
We collect personal information in the following categories:
3.1 Account and Registration Information
When you create an Account or register for the Services, we collect:
- Full name
- Email address
- Password (stored in encrypted form; we do not store plaintext passwords)
- Organisation or company name (if applicable)
- Job title or role
- Phone number (optional, for account recovery and notifications)
- Country and region
3.2 Profile and Operational Information
Depending on the Platform you use, we may collect additional operational information, including:
- SeaRoster.com: Seafarer certificates and qualifications, watchkeeping records, vessel assignments, duty schedules, crew ranks and roles, medical certificate expiry dates, port of engagement, and next of kin details (where provided by you or your Organisation).
- SARRoster.com: Volunteer and responder profiles, training records and qualifications, availability schedules, team assignments, incident response records, and emergency contact information.
- EMRoster.com: Personnel records, operational role assignments, training and qualification records, shift schedules, and emergency contact information.
- AquaRoster.com: Staff, instructor, and volunteer profiles, training records and qualifications, availability schedules, programme and session assignments, supervision and currency records, and emergency contact information.
- SeaTrack.io: Vessel identification (IMO number, MMSI, vessel name, flag state), voyage data, position data, AIS data, port calls, cargo type (where provided), and operator contact details.
3.3 Location Data
SeaTrack.io collects real-time and historical vessel position data as a core feature of the platform. This includes GPS coordinates, speed over ground, course over ground, and related navigational data transmitted by or associated with tracked vessels.
SeaRoster.com, including its mobile applications, captures a one-off device location at the moment you clock in or clock out of a rostered duty, where your Organisation has enabled clock-in and clock-out. This is used solely to confirm your presence within your Organisation's operational zone at the time of clocking. Location is accessed only while you are using the app, never in the background. The captured position is stored with your time record and is visible to your Organisation's administrators. Declining location access does not prevent you from clocking in or out. You will instead be asked to record a brief reason.
Where our mobile applications request access to device location, we will ask for your explicit permission before collecting location data. You may withdraw this permission at any time through your device settings, though this may affect the functionality of certain features.
3.4 Photo Check-In Images
Where your Organisation has enabled photo check-in for clock-in or clock-out, the SeaRoster mobile application captures a live photograph using your device's front camera at the moment you clock.
Photo check-in uses live capture only. The app does not access your photo library or gallery for this feature. Check-in photographs are visible to your Organisation's administrators for attendance-verification purposes, and they are automatically deleted 60 days after capture.
Photo check-in is not a biometric or facial-recognition feature. Photographs are reviewed by people, not matched by software.
3.5 Usage and Technical Data
When you access or use the Services, we automatically collect certain technical and usage information, including:
- Device type, operating system, and version
- Browser type and version (for web access)
- IP address
- Mobile device identifiers (device ID, advertising ID, where permitted by your device settings)
- App version
- Pages and features accessed
- Date and time of access
- Referring URLs
- Crash reports and performance data
- Session duration and interaction data
This data is used to operate, maintain, and improve the Services and is not used to identify you individually except where necessary for security or debugging purposes.
3.6 Payment and Billing Information
We do not store your full payment card details. Payment processing is handled by our third-party payment processor(s) (such as Stripe or equivalent). We receive and retain only:
- Billing name and address
- Payment method type (e.g., Visa, Mastercard)
- Last four digits of card number (for display purposes only)
- Transaction reference numbers and amounts
- Subscription status and history
You should refer to your payment processor's privacy policy for information about how your full payment details are handled.
3.7 Communications Data
When you contact us or communicate through the Services, we collect:
- The content of your messages, support requests, or enquiries
- Email correspondence
- In-platform messaging or notification interactions
- Survey or feedback responses (where provided)
3.8 Information from Third Parties
We may receive information about you from third parties in the following circumstances:
- Where your employer or Organisation registers you as a User and provides your details;
- From third-party single sign-on providers (such as Google or Microsoft) if you choose to use SSO to access our Services;
- From maritime data sources (such as AIS providers) in connection with SeaTrack.io vessel tracking functionality; and
- From analytics or error-reporting services we use to operate and improve the Services.
3.9 Information You Provide About Others
If you provide us with personal information about other individuals (such as crew members, team members, or emergency contacts), you are responsible for ensuring that you have the authority to do so and that those individuals have been informed of and have consented (where required) to this sharing. Please share this Privacy Policy with any individuals whose details you provide to us.
4. HOW WE USE YOUR INFORMATION
We use the personal information we collect for the following purposes:
4.1 Providing and Operating the Services
The primary purpose for which we collect and use personal information is to provide, operate, maintain, and improve our Services. This includes:
- Creating and managing your Account;
- Providing the scheduling, rostering, tracking, and operational features of the relevant Platform;
- Processing your subscription and payments;
- Providing technical support and customer service;
- Communicating service-related information (account confirmations, receipts, technical notices, security alerts, and administrative messages); and
- Ensuring the security and integrity of the Services.
4.2 Transactional Communications
We send transactional communications that are necessary to provide the Services and manage your account. These include:
- Account creation and verification emails;
- Password reset and account security notifications;
- Subscription confirmation, renewal, and payment receipts;
- Billing and invoice communications;
- Service availability notices and scheduled maintenance alerts;
- Operational alerts and notifications generated by the Platform in connection with your use of the Services (such as roster reminders, expiry alerts, or vessel tracking notifications); and
- Responses to your direct enquiries or support requests.
Transactional communications are necessary to provide the Services and are not subject to marketing opt-out preferences, although you may manage notification preferences within your Account settings where available.
4.3 Marketing Communications (Opt-In Only)
With your express consent, we may send you marketing communications about:
- New features, products, or enhancements to the Services you use;
- Other Storm Technology platforms that may be relevant to your operational context;
- Webinars, guides, industry updates, and educational content directly related to the Services; and
- Promotional offers relating to our Services.
We will only send you marketing communications if you have actively opted in to receive them. You may withdraw your consent and unsubscribe from marketing communications at any time by:
- Clicking the "unsubscribe" link in any marketing email;
- Updating your communication preferences in your Account settings; or
- Contacting us at privacy@stormtechnology.io.
Withdrawal of consent will not affect the lawfulness of any processing carried out before withdrawal, and will not affect your receipt of transactional communications necessary to operate your Account.
We do not send unsolicited marketing communications and we do not sell, rent, or share your personal information with third parties for their own marketing purposes.
4.4 Analytics and Service Improvement
We use aggregated and, where practicable, anonymised usage data to:
- Understand how users interact with the Services;
- Identify and fix bugs and performance issues;
- Develop new features and improve existing functionality;
- Produce internal analytics and reporting; and
- Train and improve AI-powered features within the Services (using anonymised or de-identified data only; see clause 4.5).
4.5 AI and Machine Learning Features
Where the Services incorporate artificial intelligence or machine learning features, personal information may be processed as part of those features to provide functionality such as intelligent scheduling suggestions, anomaly detection, or operational insights. That processing takes place at the time you use the feature, in order to return a result to you.
We do not use your personal information to train, improve, or refine AI models. Where we improve AI features, we do so using irreversibly anonymised data only, as described in section 4.4.
4.6 Legal and Safety Purposes
We may use personal information where necessary to:
- Comply with applicable laws, regulations, and legal obligations;
- Respond to lawful requests from courts, regulators, or law enforcement agencies;
- Enforce our Terms of Use and other agreements;
- Protect the rights, property, or safety of Storm Technology, our Users, or third parties; and
- Detect, prevent, or investigate fraud, security breaches, or other harmful activity.
5. LEGAL BASIS FOR PROCESSING
Where applicable law requires us to identify a legal basis for processing personal information, we rely on the following:
- Contract performance: Processing necessary to provide the Services under our Terms of Use, including managing your Account, processing payments, and delivering platform functionality.
- Legitimate interests: Processing for our legitimate business interests, including improving the Services, ensuring security, and sending transactional communications, where those interests are not overridden by your rights.
- Consent: Processing for marketing communications and, where required, certain uses of cookies or tracking technologies, based on your freely given, specific, and informed consent.
- Legal obligation: Processing required to comply with applicable law.
Under the Privacy Act 2020 (New Zealand), we collect, use, and disclose personal information in accordance with the Information Privacy Principles set out in that Act.
6. HOW WE SHARE YOUR INFORMATION
We do not sell, rent, or trade your personal information to third parties for their own commercial purposes. We share personal information only in the following circumstances:
6.1 Within Your Organisation
Where you access the Services as a User within an Organisation Account, certain information in your profile (such as your name, role, qualifications, and schedule) will be visible to Administrators and other authorised Users within your Organisation, as appropriate to the functionality of the Platform.
6.2 Infrastructure Providers and Sub-Processors
We do not engage sub-processors to access, mine, analyse, profile, or otherwise use your data for any purpose of their own.
A small number of infrastructure providers are necessarily involved in delivering the Services. Each is engaged under contract, is permitted to process data only on our instructions and only for the purpose of providing its service to us, and acquires no right to use your data for any purpose of its own. These providers fall into the following categories:
- Cloud hosting and infrastructure, for data storage, computing, and operation of the Platforms;
- Product analytics and error monitoring, for platform performance, reliability, and the diagnosis of faults;
- Payment processing, for subscription billing. See section 3.6.
- Transactional email, for the delivery of account, security, and service notifications.
We do not engage any other category of sub-processor. We will provide our current list of providers on request. Please contact privacy@stormtechnology.io.
Third parties that are not sub-processors.Two categories of third party mentioned elsewhere in this Policy do not process data on our behalf and are not sub-processors. Single sign-on providers, such as Google or Microsoft, authenticate a User at that User's own election and under that User's existing relationship with the provider. We receive an authentication result, and we do not send Customer Data to them. Maritime data sources, such as AIS providers, supply inbound data to SeaTrack.io. We do not disclose your data to them. See sections 3.7 and 14.
6.3 Business Transfers
If Storm Technology is involved in a merger, acquisition, sale of assets, restructuring, or other corporate transaction, your personal information may be transferred to the acquiring entity as part of that transaction. We will notify you by email or by prominent notice on the applicable Platform before your personal information becomes subject to a materially different privacy policy.
6.4 Legal Requirements
We may disclose personal information where we are required to do so by law, court order, or other governmental or regulatory authority, or where we believe disclosure is necessary to protect our rights, enforce our Terms of Use, or protect the safety of Users or the public.
6.5 With Your Consent
We may share personal information with third parties in other circumstances where we have obtained your prior express consent to do so.
7. WE DO NOT SELL YOUR PERSONAL INFORMATION
Storm Technology does not sell, rent, lease, or otherwise provide your personal information to third parties in exchange for money or other valuable consideration.
Your personal information is used solely to:
- (a) operate, provide, maintain, and improve the Services;
- (b) send you transactional communications necessary to manage your Account and use of the Services; and
- (c) send you marketing communications about our Services, but only where you have expressly opted in to receive them.
8. DATA RESIDENCY AND INTERNATIONAL TRANSFERS
Our Platforms are hosted with Google Cloud Platform. Hosting is localised to your region, and your data is stored at rest in the region that applies to you:
- Asia-Pacific, including Australia and New Zealand: Sydney, Australia and Singapore.
- Europe, the Middle East and Africa: London, United Kingdom.
We do not currently host data in the Americas. If your region is not listed above, we will confirm where your data will be hosted before you are onboarded to the Services.
Changes to hosting region. Any decision to change the region in which your data is hosted is ours to make. We will give you advance written notice before any such change takes effect. If you do not accept the change, you may terminate the affected Service in accordance with the Terms of Use before the change takes effect.
Access from New Zealand. Storm Technology is based in New Zealand, and our personnel access these hosting regions from New Zealand for support, administration, security, and maintenance purposes. That access is granted on the Least Privilege basis described in section 12, and it is logged. It constitutes a cross-border access to your data, and we disclose it here so that you are aware of it.
Where personal information is transferred or accessed outside the country in which it is stored, we take steps to ensure that appropriate safeguards are in place and that the transfer complies with the Privacy Act 2020, including by ensuring that recipients are subject to comparable privacy protections.
If you would like more information about our data residency arrangements, please contact our Privacy Officer.
9. DATA RETENTION
We retain personal information for as long as necessary to fulfil the purposes set out in this Privacy Policy, unless a longer retention period is required or permitted by law.
The factors we consider in determining retention periods include:
- Whether you have an active Account with us (we retain account data for the life of the Account plus a reasonable period thereafter);
- Our legal and regulatory obligations (certain records may need to be retained for specified periods under applicable law);
- Whether retention is necessary to resolve disputes or enforce our agreements; and
- Applicable industry standards and operational best practices.
When personal information is no longer required, we will securely delete or anonymise it in accordance with our data retention practices.
Deletion requests: You may request deletion of your personal information by contacting privacy@stormtechnology.io. We will respond to deletion requests within 20 working days. Please note that we may not always be able to delete all information, for example where retention is required by law or where information is necessary to fulfil contractual obligations.
10. YOUR PRIVACY RIGHTS
Subject to applicable law, you have the following rights in relation to your personal information:
10.1 Right of Access
You have the right to request access to the personal information we hold about you. We will provide this information within 20 working days of receiving a verified request, subject to any lawful basis for withholding information.
10.2 Right to Correction
If you believe that any personal information we hold about you is inaccurate, incomplete, or out of date, you have the right to request that we correct it. You may also update much of your information directly through your Account settings.
10.3 Right to Deletion and Erasure
You may request that we delete the personal information we hold about you. If you choose to leave the Services, you may exercise your right to be forgotten. On a verified request we will delete or irreversibly anonymise your personal information from our live systems.
We may be unable to give full effect to a deletion request in the following circumstances, which we will identify to you where they apply:
- Where retention is required by law, regulation, or lawful order, or where the information is subject to a legal hold in connection with an actual or anticipated dispute, investigation, or claim;
- Where the information is necessary to establish, exercise, or defend legal claims, or to fulfil a subsisting contractual obligation;
- Where you are a User within an Organisation Account and the information forms part of that Organisation's records. In that case the request is properly directed to the Organisation as the agency responsible for that data; and
- Where the information persists in encrypted backups. Backups are retained on a rolling cycle and overwritten in the ordinary course. Deleted information is not restored to live systems from backup, and it is removed when the relevant backup expires.
10.4 Right to Withdraw Consent
Where we process your personal information based on your consent (such as for marketing communications), you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
10.5 Right to Complain
If you are not satisfied with how we handle your personal information or respond to a privacy request, you have the right to lodge a complaint with the Office of the Privacy Commissioner (New Zealand) at www.privacy.org.nz. We encourage you to contact us first so we have the opportunity to address your concerns directly.
10.6 Right to Export Your Data
You may request an export of your data at any time, including where you have decided to leave the Services. We will not unreasonably refuse such a request. Exports are provided in a structured, commonly used, machine-readable format.
Where the Platform provides self-service export tools, Users holding the appropriate level of access may generate an export directly. For larger or non-standard exports, please contact our Privacy Officer, who will agree a format and timeframe with you. We may decline a request that is manifestly excessive or repetitive, that would require us to disclose another person's information, or that we are legally prohibited from fulfilling. Where we decline a request, we will tell you why.
How to Exercise Your Rights
To exercise any of the above rights, please contact our Privacy Officer at privacy@stormtechnology.io. We may need to verify your identity before processing your request. We will respond to all requests within 20 working days.
11. COOKIES AND TRACKING TECHNOLOGIES
We and our service providers use cookies, web beacons, and similar tracking technologies on our web-based Platforms to:
- Maintain your login session and authentication state;
- Remember your preferences and settings;
- Analyse usage patterns and improve the Services;
- Measure the effectiveness of our communications; and
- Provide security features.
Types of cookies we use:
- Strictly necessary cookies: Required for the Services to function. These cannot be disabled as they are essential to providing the service you have requested.
- Functional cookies: Enable enhanced functionality and personalisation, such as remembering your preferences.
- Analytics cookies: Help us understand how you interact with the Services, used in aggregate and anonymised form.
We do not use advertising cookies or share cookie data with advertising networks.
Where required by law, we will ask for your consent before setting non-essential cookies. You may manage cookie preferences through your browser settings, though disabling certain cookies may affect the functionality of the Services.
Our mobile applications do not use browser cookies but may use equivalent device-based identifiers as described in section 3.5.
12. SECURITY
We design our software platforms to the Least Privilege standard. Access to data is granted only to the extent necessary for a person or a system to perform a defined function, and no further. Our technical and organisational security measures include:
- Encryption of data in transit using TLS/HTTPS;
- Encryption of data at rest using AES-256 encryption or better;
- Least Privilege access controls and role-based permissions, reviewed periodically;
- Logging of access to our systems and to the data held within them;
- Secure password hashing. We do not store plaintext passwords;
- Regular security assessments and monitoring;
- Incident response procedures; and
- Staff training on data protection obligations.
Encryption in transit and at rest is applied across our Platforms by default. It is applied automatically and does not need to be enabled by you.
No method of transmission over the internet or electronic storage is completely secure. While we take all reasonable steps to protect your personal information, we cannot guarantee absolute security.
12.1 Security Incidents and Breach Notification
If we become aware of a security incident that has compromised, or is reasonably likely to have compromised, your data, we will notify you without undue delay. Our notice will describe, so far as it is known to us at the time, the nature of the incident, the categories of data involved, the steps we are taking in response, and any action you may need to take. Where we do not yet hold complete information, we will provide further detail as it becomes available rather than delay the initial notice.
We will also notify the Office of the Privacy Commissioner, and any other regulator or supervisory authority, where we are required to do so under the Privacy Act 2020 or other applicable law.
13. CHILDREN'S PRIVACY
Our Services are not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13 without verifiable parental or guardian consent. If you believe that we have inadvertently collected personal information from a child under 13, please contact us at privacy@stormtechnology.io and we will take steps to delete that information promptly.
Certain Platforms (including SARRoster.com, EMRoster.com, and AquaRoster.com) may be used by organisations that include junior or cadet volunteers, junior instructors, or programme participants who may be under 18. Where an Organisation registers individuals under the age of 18, the Organisation is responsible for ensuring it has the necessary consents and authorisations from parents or guardians as required by applicable law.
14. THIRD-PARTY LINKS AND INTEGRATIONS
Our Services may contain links to third-party websites or integrate with third-party services. This Privacy Policy does not apply to those third-party services, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services you access through our Platforms.
15. MOBILE APPLICATIONS: APP STORE SPECIFIC DISCLOSURES
The following disclosures are provided in connection with our mobile applications available on the Apple App Store and Google Play Store.
15.1 Data Collected by Our Mobile Apps
Our mobile applications may collect the following categories of data:
| Data Category | Examples | Purpose |
|---|---|---|
| Contact information | Name, email address | Account management, transactional comms |
| Identifiers | User ID, device ID | Account linking, security |
| Usage data | Feature interactions, session data | Service improvement, analytics |
| Diagnostics | Crash logs, performance data | Bug fixing, stability |
| Location | Device GPS (where permitted) | Platform features (e.g. SeaTrack.io) |
| User content | Data entered into the app | Service delivery |
15.2 Data Linked to Your Identity
The following data collected by our apps may be linked to your identity:
- Contact information (name, email)
- Identifiers (user ID)
- User content (data you enter into the app)
- Usage data (where associated with your Account)
15.3 Data Not Linked to Your Identity
The following data may be collected but is not linked to your identity:
- Anonymised diagnostics and crash reports
- Aggregated analytics data
15.4 Data Sharing
We do not share data collected through our mobile apps with third parties for advertising or marketing purposes. Data may be shared with our service providers as described in section 6.2, solely to operate the Services.
15.5 Data Deletion
You may request deletion of data associated with your Account at any time by contacting privacy@stormtechnology.io or through your Account settings. Upon deletion of your Account, we will delete or anonymise your personal information within a reasonable timeframe, subject to any legal retention requirements.
15.6 Permissions
Our mobile applications may request the following device permissions:
- Location:Used by SeaTrack.io for vessel position features, and by SeaRoster to confirm your presence within your Organisation's operational zone when you clock in or out of a rostered duty. Location is accessed only while you are using the app, never in the background. You may deny or revoke this permission at any time in your device settings. Declining location does not prevent you from clocking in or out.
- Notifications (Push): Used to deliver operational alerts, roster reminders, and transactional notifications. You may manage notification permissions in your device settings.
- Camera / Photo Library: Only where you use features that involve taking or uploading photos, such as a profile photo, a document upload, or photo check-in at clock-in and clock-out where your Organisation enables it. Check-in photographs are captured live with the front camera, are never sourced from your photo library, and are automatically deleted after 60 days. Not accessed without your initiation.
- Biometrics: Used for convenient re-authentication (Face ID / fingerprint login) if you enable this feature. Biometric data is processed by your device OS and is not transmitted to or stored by Storm Technology.
We only request permissions that are necessary for specific features you use. You can revoke any permission at any time through your device operating system settings.
16. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by:
- Posting the updated Privacy Policy on the applicable Platform with a revised "Last Updated" date;
- Sending an email notification to the address associated with your Account (for material changes); and/or
- Displaying an in-app notice (for mobile application users).
We encourage you to review this Privacy Policy periodically. Your continued use of the Services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you do not agree with the updated Privacy Policy, you must cease using the Services and may request deletion of your Account.
Because this Policy is shared across all Storm Technology platforms and marketing websites, an updated version is published to each of them at the same time, and it carries the same version number and effective date on every one.
17. GOVERNING LAW
This Privacy Policy is governed by the laws of New Zealand. Any disputes relating to this Privacy Policy shall be subject to the jurisdiction of the courts of New Zealand.
18. CONTACT US
For any questions, concerns, or requests relating to this Privacy Policy or our privacy practices, please contact:
Privacy Officer
Storm Technology Limited
Milford, Auckland 0620
New Zealand
Email: privacy@stormtechnology.io
We are committed to working with you to resolve any privacy concerns. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner (New Zealand):
Office of the Privacy Commissioner
PO Box 10094
Wellington 6143
New Zealand
Phone: 0800 803 909
APPENDIX A — SUMMARY OF DATA PRACTICES
This summary is provided for convenience only. The full Privacy Policy above governs in all cases, and where this summary and the Policy differ, the Policy prevails.
| Who owns your data? | You do. We act as your agent in respect of it. See section 1.2. |
|---|---|
| Do we sell your data? | No. Never, to anyone, for any purpose. See section 7. |
| Do we share data with advertisers? | No. We use no advertising cookies or networks. |
| Do we use sub-processors? | No, beyond the four infrastructure providers listed in section 6.2. |
| Where is your data stored? | Google Cloud Platform, in your region. APAC is Sydney and Singapore. EMEA is London. |
| Can we move your data? | Only with advance written notice, and you may terminate if you do not accept the change. |
| How is data secured? | Least Privilege access control, AES-256 at rest, TLS in transit, encrypted by default. |
| What happens if there is a breach? | We notify you without undue delay. See section 12.1. |
| Can you access your data? | Yes. See section 10.1. |
| Can you export your data? | Yes, in a structured, machine-readable format. See section 10.6. |
| Can you delete your data? | Yes, subject to the limits set out in section 10.3. |
| Do we train AI on your data? | No. AI features process your data only to return a result to you. See section 4.5. |
| Do we send marketing emails? | Only with your explicit opt-in, and you may withdraw at any time. |
| Governing law? | New Zealand. Privacy Act 2020. See section 17. |
| Privacy contact? | privacy@stormtechnology.io |
This Privacy Policy was last updated in June 2026 and is Version 2. Storm Technology Limited reserves the right to update this Policy at any time in accordance with section 16. This Policy is shared across all Storm Technology platforms and marketing websites, and the current version is published on each of them.
© 2026 Storm Technology Limited. All rights reserved.