Privacy Policy

Last updated 3 October 2026

1.Who is responsible for your information

WellWishes Limited (NZ company number 9434049, NZBN 9429053715852) operates wellwishes.co.nz and is the agency responsible for personal information collected through it, in terms of the Privacy Act 2020. Our privacy officer is Andrew Muller, co-director of WellWishes Limited. Contact us about privacy at hello@wellwishes.co.nz, or write to us at 57/120 Rintoul Street, Newtown, Wellington 6021, New Zealand.

A few words we use throughout. A "registry owner" is the person or people who create and run a registry, whether that is one person or two. A "guest" is anyone who sends a gift. The "recipient" is the registry owner whose Stripe account receives the gifts. This policy covers every kind of celebration a registry can be for: a wedding, engagement, honeymoon, baby shower, housewarming, birthday, wishing well or similar occasion.

2.What we collect and why

If you are a registry owner:

  • Your email address, used to sign you in and to send you receipts, gift notifications and service emails about your own registry. It is also the reply-to address on invitations and thank-you emails we send for you, so guests who receive them can see it.
  • A record that you agreed to our Terms of Service and this policy: the date and the versions you agreed to.
  • The names on the registry, the date of your celebration and everything you choose to put on your registry page: photos, stories, gift items and settings, including any registry password you set.
  • Your Stripe account reference and its verification status, so we know your payout account is ready. Identity documents you provide during payout onboarding go directly to Stripe; we never see or store them. When you provide personal information to set up payouts, Stripe receives it and processes it in accordance with Stripe's Privacy Policy. We also share your email address and details of the gifts and payouts on your registry with Stripe so it can verify you and pay you.
  • Security events on your payout account: when your payout settings are opened or your bank account changes, and your answer if we ask whether it was you. If gifts to your registry look like fraud, we may pause your payouts automatically while we check.
  • Your guest list, if you use the invitations feature: the names and email addresses you add, whether each invitation was sent, whether it was opened and whether that guest visited your registry from it. See "If you are on someone's guest list" below.

If you are a guest sending a gift:

  • Your name, your email address (for your receipt, your cancellation link and any thank-you note the registry owner sends you), your gift amount and any message you write to the registry owner. If you choose to give anonymously, your name and email are hidden from the registry owner (see section 5) but still kept by us for your receipt, your refund link and the financial record.
  • Your card details are entered into Stripe's secure payment form and go directly to Stripe. They never touch WellWishes servers and we cannot see them.
  • When you open a registry page, Stripe's payment script loads so checkout is fast. Stripe uses it and its own cookies to detect fraud. Stripe processes your payment details and this information in accordance with Stripe's Privacy Policy. If you pay with Apple Pay, Google Pay or Link, that provider also handles your payment under its own privacy policy.
  • To protect registry owners and guests from payment fraud, after a gift is paid, or when a card is declined at checkout, we keep the coarse card information Stripe shares with us: the card brand, whether it is credit or debit, its last 4 digits, the country it was issued in and a code Stripe uses to recognise when the same card is used again. This is never the card number and cannot be used to charge the card. We use it only to spot fraud, for example one card pretending to be many different gifters.

If you are on someone's guest list:

  • A registry owner can add your name and email address to their registry so that we can send you an invitation to view it on their behalf. We collect that information from the registry owner, not from you. The owner agrees in our terms that they have the right to share it and to invite you.
  • We use it only to send the invitation the owner asked us to send, and to show the owner whether it was sent, opened and followed and whether you sent a gift (never an anonymous one). The invitation contains a tiny image that tells us when it is opened, and its link tells us when you visit the registry from it. We never use guest-list details for our own purposes, never add them to any list of ours and never send anything to them other than the owner's invitation.
  • Guest lists are part of the registry and are deleted with it. Our record of each invitation email (your address and the subject line) is deleted after 18 months, and the record of opens and clicks after 180 days.
  • If you would rather not be invited, use the unsubscribe link at the bottom of the invitation, tell the owner or email us at hello@wellwishes.co.nz and we will block further invitations to your address. If you want your details deleted, email us: we will remove you from every guest list you are on and from our email records, and ask our email provider to delete its copies. We keep your address only on our list of people not to invite, so that the block keeps working.

If you contact us: your email address, your name and your message, including any report of abuse, used to deal with it. If you complain about content on a registry, we may share your complaint with the registry owner. Tell us if you do not want your name passed on.

Collected automatically from everyone:

  • Cookies and browser storage the site needs to work: your sign-in session, your "keep me signed in" choice, which registry you last opened, whether you have entered a registry's password (until you close your browser), your progress through setting up a registry and your agreement to our terms (up to 7 days). Short-lived ones, lasting up to an hour, hold a sign-in, cancellation, unsubscribe or payout security link while you press Continue. Some pages save drafts in your own browser, such as a guest list you are importing or a thank-you note, until you finish. We do not use analytics or advertising cookies.
  • Bot protection. When you sign in, sign up, send a gift, apply a voucher or send invitations, a script from Vercel and its security partner Kasada checks technical signals from your browser and device to confirm a real person is using it. We do not receive or store those signals.
  • Our hosting, database and error-reporting providers receive your internet address and browser type when you use the site, as part of delivering it and keeping it secure.
  • Visit counts. So we know how many people use the site, each page load records which page you arrived on, the website that sent you (its name only), your country and whether you are on a phone, tablet or computer. We tell visitors apart with a scrambled code made from your internet address and browser type using our own secret key, and we never store the address or browser type themselves. This uses no cookies and nothing in your browser. We only use it to count visitors, and it is deleted after 35 days.
  • Error reports when something breaks, through Sentry, so we can fix it. A report says what went wrong and on which page, with the part of the address after the "?" removed. It does not include your cookies, what you typed into a form or email addresses. Signed-in visitors are tagged with an internal account id (never an email) so we can find who was affected.
  • Session replays, through Sentry. To understand how a problem happened we record a browsing session only when an error occurs in it. These replays are masked before they leave your browser: they show the layout of the page and where you clicked, but every piece of text, every image and everything you type is blanked out. Your name, your message, your card details and anything else you can read on screen are never part of a replay. Sentry keeps a small marker in your browser for the length of the visit.
  • Email records. Our email provider records whether each email we send was delivered, opened or had a link clicked, using a tiny image and tracked links in the email. We use this to make sure receipts and important notices actually arrive, to stop sending to addresses that bounce or complain, and to see whether our emails are useful. Invitation emails also let the registry owner who invited you see whether you opened the invitation and whether you visited the registry from it. A mail app that blocks images will not register an open. Some of our emails also load their typefaces from Google Fonts, so Google sees the internet address of the device that opens them.
  • For abuse prevention we rate-limit requests by internet address and by email address. Both are scrambled (hashed) with a secret key before they are stored, and the stored values are deleted after a day.
  • For fraud prevention, each gift also records a scrambled (hashed) version of the internet address it was sent from, made with a separate secret key. Without that key the stored value cannot be linked back to an address. We only use it to notice many supposedly different gifters sending from the same connection, and it is kept with the gift's financial record.
  • Server logs. Our servers write operational logs (what happened, when, and any error), kept by our hosting provider, so we can keep the service running and investigate problems. They may include account or registry ids and page addresses without the part after the "?". Email addresses are masked and we never put card details in them.

We also use this information to run and protect the service, including internal alerts to our team about new sign-ups, gifts, failed payments and suspected fraud. These alerts are stored in our email inbox (see section 4).

3.What we never do

  • We do not sell personal information. To anyone, ever.
  • We do not share it with advertisers and we do not run advertising trackers.
  • We do not send marketing email. The only emails we send are service emails about your own registry or gift, invitations and thank-you emails a registry owner has asked us to send, and notices about changes to our terms or this policy.
  • We do not knowingly collect information from anyone under 18. WellWishes is not intended for people under 18, and you must be at least 18 to create an account or send a gift. If you believe someone under 18 has given us their information, email us and we will delete it.

4.Who processes information for us

Like almost every online service, we run on specialist providers. Each one processes only what its job requires:

ProviderJobWhere the data lives
StripePayments, payouts, identity verification and payment fraud detection. Stripe also uses this information for its own purposes (see below the table)Global (headquartered in the US)
SupabaseOur database and photo storageSydney, Australia
VercelHosting the website, and checking that sign-ins, gifts and invitations come from a real browser, not a bot (with its security partner Kasada)Our servers run in Sydney, Australia; pages are delivered through Vercel's worldwide network (a US company)
ResendSending our emails and recording delivery, opens and clicksEmails are sent from Tokyo, Japan (Resend is a US company)
SentryError reports and masked session replaysEuropean Union
Google FontsThe typefaces in some of our emails. Your mail app downloads them from Google, which sees your internet addressGlobal (Google is a US company)
Microsoft 365 (through GoDaddy)Our email inbox, where messages you send us, abuse reports and our internal alerts are storedAustralia or New Zealand (Microsoft is a US company)
UnsplashBackground images on password-protected and closed registry pages. Your browser loads them from Unsplash, which sees your internet addressGlobal

Stripe is different from the other providers. As well as handling payments for us, Stripe decides for itself how to use some of this information, for example to prevent fraud across its network, verify identities and meet its own legal obligations. For that use Stripe is responsible for your information in its own right, under Stripe's Privacy Policy. You agree to us sharing your information with Stripe for these purposes when you send a gift or set up payouts.

Because some providers are outside New Zealand, some information is stored overseas. We choose providers that commit contractually to protect personal information to standards comparable to New Zealand's Privacy Act, and our European provider operates under the EU's GDPR, which is stricter than NZ law in most respects.

Beyond these providers, we disclose personal information only if the law requires it (for example a court order), if it is necessary to prevent a serious threat, or to Stripe, a bank or an authority when we are investigating suspected payment fraud and the law allows or requires it.

5.Who can see what

  • Your registry page is public. Anyone who has the link can open it and see the names, date, photos, story and gift items on it. We tell search engines not to index registry pages, so they should not turn up in search results, but anyone you share the link with can pass it on. If you want to limit who can open the page, set a registry password in your settings; then only people who have both the link and the password can view it.
  • Registry owners see who gave what. When a guest sends a gift, the registry owner sees the guest's name, email address, gift amount, the item it was for and any message, in their dashboard, in the notification and thank-you emails we send them, and in a spreadsheet they can download. Guests who choose to give anonymously are shown to the owner as anonymous, with no name or email, and we build the owner's spreadsheet so that an anonymous gift cannot be matched back to a named guest.
  • Registry owners see invitation activity. If you were invited through WellWishes, the owner can see whether the invitation was sent, opened and followed through to the registry, and whether you sent a gift (never an anonymous one).
  • Guests see the owner's email address. Invitations and thank-you emails use the registry owner's email address as the reply-to address, so guests who receive them can see it and reply directly.
  • Guests see totals, not people. A guest viewing a registry sees how each gift item is going. They do not see other guests' names, emails or messages.
  • Registry owners are responsible for what they do with guest information. We give it to them so they can thank their guests and keep a record of their celebration. Our terms require them to use it only for that.

6.How we protect it

  • All traffic to and from the site is encrypted (HTTPS).
  • The database enforces row-level rules so each account can only ever read its own information, even if our application code had a bug.
  • Card numbers are handled entirely by Stripe, which is certified to the highest card-industry security standard (PCI DSS Level 1).
  • Access to production systems is limited to the people who operate the service.
  • Your account has no password to steal. You sign in with a one-time link or code sent to your email, so protecting your email account protects your WellWishes account.
  • A registry password is different. It is a simple word or phrase you choose and share with your guests so that only they can open your page, not an account-security credential. Because you need to be able to share it, we store it in a form we can show you again and we email it to you as a reminder when you set it. Choose something you do not use anywhere else.

7.How long we keep it

  • Registry information lives for as long as the registry does. About 30 days after a registry closes, we email the registry owner a full keepsake summary and then permanently delete the registry's content, photos, messages and guest list from our systems. A published registry that its owner has not closed closes automatically two weeks after its date, so its content is deleted about six weeks after the date at the latest.
  • The one exception is financial records. New Zealand law (the Tax Administration Act 1994 and the Companies Act 1993) requires businesses to keep records of money that moved for 7 years, so for each gift we keep the amount, fees, date, payment references, the guest's name and email, and the fraud-prevention details described in section 2 (coarse card information and the scrambled internet address) until 7 years after the end of the tax year (1 April to 31 March) the gift was made in. We keep the same kind of record of each setup fee, with the payer's email. Those records are then deleted automatically. Messages, photos and the registry itself are never part of that record.
  • If you delete your account, we delete it straight away: your registries, photos, stories, gift items, guest lists and messages. We also remove your email address from our email records, fraud alerts and voucher lists. What stays: the 7-year financial record of your setup fee and of any gifts; our security log, which records ids and your registry's web address, never your email address; copies of Stripe payment notifications until their personal details are removed at 180 days; any payout hold record, for 180 days after it is released; and, if you unsubscribed from invitations, your address on our do-not-email list. Stripe keeps its own payment records.
  • We also delete abandoned things automatically. A draft registry whose setup fee was never paid, and whose owner has not signed in or made a change for 60 days, gets a warning email and is deleted 30 days later if nothing changes. An account that never created a registry, never paid and never set up payouts is deleted after 90 days without a sign-in. Paid and published registries are never deleted this way.
  • Payment and transaction records are retained by Stripe under financial regulations, which is separate from us and outside the deletion above.

In more detail:

WhatHow long
Registry content: page, photos, story, gift items, messages and your guest listUntil about 30 days after the registry closes, or immediately when you delete your account. A published registry closes automatically two weeks after its date if you have not closed it sooner
Abandoned unpaid draft registriesDeleted 30 days after a warning email that goes out once the owner has been inactive for 60 days
Accounts that never built anythingDeleted after 90 days without a sign-in
Financial record of each gift and each setup fee7 years after the end of the tax year (1 April to 31 March) the payment was made in, as the law requires, then deleted automatically
Copies of the payment notifications Stripe sends usPersonal details removed after 180 days; the record deleted after 400 days
Email records: what we sent, to whom, and any bounce or spam complaint18 months, then deleted automatically
Email opens and link clicks180 days, then deleted automatically
Fraud-prevention alerts18 months, then names, email addresses and other details are removed and only a record of what kind of alert it was stays
Declined card attempts on a gift checkout (never card numbers)90 days
Security audit log (account and registry ids and registry web addresses, never email addresses)The same 7 years as the financial record it explains
Addresses that unsubscribed from invitationsFor as long as we need to keep honouring the request. Ask us if you want yours removed
Scrambled internet addresses used for rate limiting1 day
Visit counts (scrambled visitor code, landing page, referring website, country and device type)35 days, then deleted automatically
Sign-in links and codesRemoved about 30 days after they expire
Payout security reports (your answer to "Was this you?")180 days, then deleted automatically
Payout holds180 days after the hold is released, then deleted automatically. An active hold is kept until it is released
Your agreement to our terms and this policyFor as long as your account exists
Messages you send us, including abuse reportsAs long as we need to deal with the matter and keep a record of it
Our email provider's own sending logsKept by Resend under its own retention settings
Error reports and session replays (Sentry)Up to 90 days

8.Your rights

  • Under the Privacy Act 2020 you may ask us for a copy of the personal information we hold about you, and ask us to correct it. Email hello@wellwishes.co.nz and we will respond within 20 working days as the Act requires.
  • You can delete your account yourself from the account menu. If your registry has received gifts, or a gift is still going through or is disputed with a bank, we can't delete it automatically: email us and we will sort out refunds or payouts first, then delete it.
  • If you are a guest or on a guest list and want your details removed, email us. We will take you off every guest list you are on, delete our email records about you, ask our email provider to delete its copies and stop any further invitations to your address. The 7-year financial record of a gift you sent has to stay, and fraud alerts that mention a gift lose their personal details after 18 months.
  • If you are unhappy with how we have handled your information, tell us first and we will try to put it right. You can also complain to the Office of the Privacy Commissioner (privacy.org.nz).

9.If something goes wrong

If we ever suffer a privacy breach that is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and the affected people as the Privacy Act 2020 requires, and tell you plainly what happened and what we are doing about it.

10.Changes to this policy

If we change this policy in a way that matters, we will tell you by email or by a notice on the site before the change takes effect. The current version will always live at wellwishes.co.nz/privacy.

Questions about privacy? Write to hello@wellwishes.co.nz.