Privacy Policy
Effective 28 August 2026.
Who we are. Hamish Palmer, sole trader, trading as phas (phas.nz / phas.au). phas is based in Australia and carries on business in New Zealand through phas.nz. Privacy contact: [email protected].
This policy is written to the Information Privacy Principles of the NZ Privacy Act 2020 and the Australian Privacy Principles (Privacy Act 1988 (Cth)), and it applies to everything we do with personal information.
1. What we collect
- Account data: name, email address, phone number, password (stored hashed), and two-factor secrets.
- Domain registrant data: for each domain contact role — name, organisation, postal address, email, phone; for .au domains, eligibility identifiers (ABN/ACN/trademark details) as auDA requires.
- Billing data: your card is collected and stored by Stripe, our payment processor — we never see or store full card numbers. We keep transaction records (what was bought, amounts, Stripe references).
- Support data: tickets, emails you send us, and a support verification code shown in your account.
- Service data: hosting account metadata, DNS records you configure, email-sending domains and delivery events for the transactional email add-on, backup and monitoring records for those add-ons.
- Technical data: IP addresses, browser user-agent, session and login records (shown to you on your sessions page), and server logs.
We collect it directly from you, from your use of the services, and from our suppliers processing on our behalf. We don't buy data about you.
2. Why we collect it
To deliver and bill the services you've ordered; to verify eligibility where a registry requires it; to secure accounts (login history, 2FA, fraud signals from Stripe Radar); to provide support; to meet legal and registry obligations; and to send service email. Marketing: we don't send marketing email. If that ever changes, marketing messages will be sent only with your consent and with a working unsubscribe in every message, as the Unsolicited Electronic Messages Act 2007 (NZ) and the Spam Act 2003 (Cth) require.
3. Who we disclose it to
We disclose personal information only as needed to run the services:
| Recipient | What | Where |
|---|---|---|
| Stripe (payments, fraud screening) | billing identity, card (held by Stripe), transactions | United States |
| Synergy Wholesale (registrar of record) | registrant contact + eligibility data | Australia |
| Domain registries and their operators (InternetNZ for .nz, auDA/Identity Digital for .au, gTLD registries), and ICANN-approved escrow agents for gTLDs | registrant data as their policies require | varies by registry; escrow typically United States |
| Cloudflare (DNS hosting) | zone and record data you configure | United States |
| Postmark / ActiveCampaign (email delivery, in and out) | email content and delivery metadata for mail we send you, support mail, and the transactional email add-on | United States |
| Hosting infrastructure | your hosted content, on servers in the region you choose at checkout | Australia, New Zealand or Singapore |
| Sentry (error monitoring) | technical error context, which can incidentally include account identifiers | United States |
We also disclose where the law requires it — subpoenas, court orders, or regulator demands — and we tell you when we lawfully can.
.nz register / WHOIS. Domain registration data is published according to the registry's rules (the .nz Query Service for .nz; WHOIS/RDAP for gTLDs and .au). .nz individuals not in significant trade can ask us to apply the Individual Registrant Privacy Option, which withholds phone and address from the public register.
4. Cross-border handling
phas is based in Australia, so your information is held by an Australian business; some suppliers above are elsewhere (chiefly the United States). Before disclosing outside New Zealand we take the steps IPP 12 of the Privacy Act 2020 requires — we disclose only to recipients we reasonably believe are subject to comparable safeguards (such as the Australian Privacy Act) or that are bound by contractual safeguards, or with your informed consent — and, where the disclosure is also from Australia, the steps APP 8 of the Privacy Act 1988 requires. We remain accountable for our suppliers' handling where the Acts make us so.
5. Security
Passwords are hashed; panel access uses single-sign-on links rather than stored passwords; support and admin access is role-limited; sessions are listed in your account and individually revocable; two-factor authentication is available (and recommended); backups of our own database are encrypted with a key held offline. No internet service can promise perfect security, but we build so that a single failure doesn't cascade.
6. Retention
We keep personal information while your account is active and as long afterwards as the law and registry rules require — tax and business records (7 years, NZ; 5 years, AU), .nz registration data (6 years after a domain is cancelled or transferred, per InternetNZ rules), and accounting/audit trails. When you delete your account, we anonymise personal data and keep only the event and accounting history the law requires; the deletion record itself is retained as evidence of the deletion.
7. Access, correction, export, deletion
Under IPPs 6 and 7 you have the right to access the personal information we hold about you and to ask us to correct it. Your account pages let you see and correct most data directly, export a machine-readable copy of everything we hold about you, and delete your account (once no live paid services remain). Anything you can't reach self-service, ask via [email protected] — we'll respond as soon as practicable and within 20 working days, as the Privacy Act 2020 requires. If we decline a correction, you can require a statement of correction to be attached to the information.
8. Data breaches
If a privacy breach is likely to cause you serious harm, we will notify the Office of the Privacy Commissioner and affected people as soon as practicable (we aim for within 72 hours of becoming aware), as the notifiable privacy breach scheme in the Privacy Act 2020 requires — and the OAIC where the Australian Notifiable Data Breaches scheme also applies — with what happened, what data was involved, and what we're doing about it.
9. Cookies
phas uses cookies for sign-in sessions and security (CSRF) only. We set no analytics or advertising cookies.
10. Complaints
Complain to us first at [email protected] — we'll acknowledge promptly and answer within 20 working days. If you're not satisfied: in New Zealand, the Office of the Privacy Commissioner (privacy.org.nz); in Australia, the Office of the Australian Information Commissioner (oaic.gov.au).
11. Changes
Material changes are emailed to your account address 30 days before they take effect, matching the Terms of Service change process.