Privacy Policy

Version 1.4 · Effective 2026-09-08

1. Who we are and what this covers

ONYX1 LIMITED, a New Zealand Limited Company, company number 9453894, NZBN 9429053908322, registered 23 August 2026. Registered office: 189 Upper Harbour Drive, Greenhithe, Auckland, 0632. ONYX1 LIMITED operates ONYX1, a job-management service for New Zealand trade businesses. This policy explains how we collect, use, store and disclose personal information under the Privacy Act 2020 and its Information Privacy Principles. It covers three groups of people, and the rules are not the same for each: Staff users: the people a trade business invites to use ONYX1 at work (owners, office, technicians, contractors). Portal users: people who set a password on the ONYX1 client portal to view files a trade business has shared with them. A portal login is an ONYX1 account. It is not an account of any one trade business. Email contacts: people a trade business stores as a customer or a contact, who may receive invoices, quotes, site reports or reminders by email without ever logging in. If you are a portal user or an email contact, "you" in the sections that follow means you, not the trade business.

2. What we collect

Staff accounts: name, email, phone, role, and password (stored only as a secure hash). Business information: company name, NZBN, contact details, branding. Service content: the jobs, customers, quotes, invoices, photos, reports and messages the business enters. Technical information: sign-in times, IP addresses, device and browser type, and service logs kept for security and support. Location at clock-in: if the trade business has clock-in location capture switched on, we record the worker's device position (latitude, longitude and how accurate the reading was) at the moment they clock in, and whether that position was on or off the job's site. The device is asked for its most accurate fix. It is taken at clock-in only, never continuously, and never while someone is off the clock. It is used to flag an off-site clock-in for whoever approves the timesheet, and it never stops anyone starting work. A worker can see their own; the people who run the business can see everyone's, as with the rest of the timesheet. This setting is ON unless an owner or admin turns it off, and while it is off nothing is recorded. Payment card details for a trade business's ONYX1 subscription are collected only by Stripe. Card numbers never touch our systems. Portal accounts: email (unique across all ONYX1 customers), name if we have one, password hash, two-factor secret (encrypted), notification preferences, an outstanding sign-up token, an outstanding request to change the sign-in address together with the address it would move to, and session records (token hash, expiry, IP address, user-agent). We also hold a flag recording that the address has been checked. It is set when a sign-up link we emailed to the address is used to set a password, and when a new sign-in address is confirmed from a link we send to that address. A sign-up link the trade business passed to you itself does not set it, because a link held by staff proves nothing about who reads mail at the address. We collect the password from you when you set it. We usually receive the email and name from the trade business that invited you, or from you if you request a sign-up link yourself. Email contacts: name, email, phone, role label, and which kinds of mail the trade business has marked you to receive. That information is typed or imported by the trade business. We also store an unsubscribe token and the time you last unsubscribed. We do not have to collect a portal password for you to be on file as a contact. Setting a password is optional and is what opens the client portal.

3. Who is responsible (the agency)

Trade-business files. When a trade business stores its customers' and contacts' details, jobs, invoices, quotes, photos and reports in ONYX1, that business is collecting that information and must have a lawful basis to hold it. We host and process it to provide the service. Requests about those files (a wrong address on an invoice, a photo that should not have been shared) should go to that business. We will help them meet an access or correction request. Portal logins. ONYX1 LIMITED is the agency for the client-portal account itself: the email, password, sessions, two-factor settings and notification preferences. No trade business can see your password or your other providers' files. A trade business can invite or revoke access to its own files only. Requests about the login go to support@onyx1.app. If a request covers both (for example "delete me"), we will deal with the login and tell each linked trade business so they can deal with their own file.

4. One login, several trade businesses

A portal email address can only exist once on ONYX1. That is deliberate: so you are not asked to keep a separate password for every plumber or electrician you use. It has a consequence we want to be honest about. If a second trade business puts your email on their customer record and invites you, we will attach their files to the same login. Their staff will be able to see that the address is already an ONYX1 client. They will not be told which other business you use, and they cannot open that other business's files. You can change the sign-in email from your account page. The new address does not take effect until you confirm a link we send to it, so a change typed wrongly, or made by somebody else, stops there. The new address must be one no other ONYX1 client is already using. A trade business can revoke its own link at any time; that hides their files from you and does not delete the login.

5. Why we use information

Staff and business information: to provide and secure the service, to support you, to bill you, to send service messages (trial reminders, security notices), and to understand aggregate usage so we can improve the product. We send marketing to a trade-business contact only with consent, and every such message has a working unsubscribe, as the Unsolicited Electronic Messages Act 2007 requires. Portal information: to authenticate you, to show you the files each linked provider has shared, to honour the email preferences you set, and to keep the account secure, including the sign-up link and the address confirmation you ask for yourself. We do not sell personal information. We do not use service content or portal content to train AI models.

6. Email we send to customers and contacts

ONYX1 sends some messages to people a trade business works with. The platform sender is ONYX1 LIMITED, a New Zealand Limited Company, company number 9453894, NZBN 9429053908322, registered 23 August 2026. Registered office: 189 Upper Harbour Drive, Greenhithe, Auckland, 0632. Contact: support@onyx1.app. The trade business authorises its customer mail and must provide accurate contact details under section 13 of the Unsolicited Electronic Messages Act 2007. The From line looks like "Acme Plumbing (via ONYX1)" and uses our sending address. Reply-To is the trade business's own email when they have given us one, so a reply reaches them. What goes out automatically (invoices, quotes, overdue payment reminders, a copy of an approved site report) is chosen by the trade business: they mark which contact receives which kind of mail. If you also have a portal login, invoices, quotes and overdue reminders also honour the choices on your account page. Those portal choices start off. Site-report copies follow the trade business's contact flags; there is not yet a portal switch for those. The Unsolicited Electronic Messages Act 2007 requires consent for commercial electronic messages. A current business relationship may support inferred consent, but a stored address or a contact flag does not by itself establish it. The classification and consent basis for each message type have not yet been settled with a lawyer. The trade business must have the right to send each message. A portal login's own switches, where they exist, are express choices on top of that. Automatic customer mail selected by the notification system includes an unsubscribe link that stops further automatic mail to that address from that trade business. Confirming it takes one extra click so that mail scanners cannot unsubscribe you by opening the link. We honour it as soon as you confirm. A person at the trade business can still send a specific invoice or quote by hand after that. The app tells them you unsubscribed and records if they send anyway. You can also email the trade business, or us at support@onyx1.app, and ask to be removed. Account email about your portal login is not marketing, and each message identifies ONYX1 when it goes out. Four kinds come straight from us, and all four are sent even while the automatic mail below is switched off. You did not ask for two of them: a sign-up link you asked for yourself, using the form on the portal; a sign-up link your trade business asked us to email you, which you did not ask for and which arrives from us rather than from them; the confirmation of a new sign-in address, sent to the new address, which is what makes the change take effect; notice that the sign-in address on an account has changed, sent to the old address, so that a login being moved is never silent. Automatic email to customers, meaning the invoices, quotes, overdue reminders and report copies a trade business schedules, is switched off on this deployment at present and is prepared rather than delivered. A trade business may also hand you a sign-up link itself, outside ONYX1, by whatever means it chooses. We will say so here when the automatic mail changes.

7. Where information is stored and who processes it

ONYX1 is a New Zealand company. The service is hosted on cloud systems that may store or process information outside New Zealand: Vercel (application hosting and private file storage for photos, signatures, PDFs and documents), Neon (database), Resend (email delivery), Stripe (subscription payments by the trade business). If a trade business connects Xero, customer and invoice information they choose to sync is sent to Xero. Address lookup uses OpenStreetMap Nominatim and Photon (komoot.io). The dispatch map draws its background from the OpenStreetMap tile servers (tile.openstreetmap.org), which the browser contacts directly, so those servers see the viewer's IP address and which area of the map is on screen. If a staff user enables browser push, the push service for their device (for example Apple, Google or Mozilla) receives a device endpoint. The countries used by the production services and the contractual safeguards for overseas processing are not yet determined. We have not verified the applicable ground under Information Privacy Principle 12 of the Privacy Act 2020 for each overseas disclosure. Storage or processing solely on our behalf is treated differently from a provider using information for its own purposes. Accepting this policy does not authorise overseas disclosure without the protections the Act requires. If a trade business turns on AI/MCP connectivity, questions they ask through their own AI assistant are run against their business's data under that user's permissions. That assistant is a service they hold with its provider, under that provider's terms, and it may be overseas. Portal users' files that sit in that business's account can be in the scope of those questions. Airwallex (customer Pay Now) and iPayroll are not live. They will be named here before they receive personal information. Pay-now card details, when that feature is live, will be collected by the payment provider, not by us.

8. Security

Information is encrypted in transit and at rest. Every business's data is isolated at the database layer (row-level security), access within your business is controlled by roles you assign, passwords are hashed with a modern algorithm, and two-factor authentication is available for every account. No system is perfectly secure, but security is engineered into the product, not added on.

9. How long we keep information

While a trade business's account is active, three kinds of operational data age out on that business's plan window, which is 1 year on Basic, 3 years on Pro and 5 years on Enterprise: site photos, in-app notifications and activity history. A monthly job deletes them once they are older than the window, automatically and with no warning beforehand, so anything worth keeping should be exported while it is still inside the window. Financial and statutory records, including the health-and-safety register and signed site reports, are never rotated and are kept for the life of the account in line with New Zealand record-keeping law. When a trade business's account closes, that business has 30 days to export its data, after which we delete personal information unless we are legally required to keep it. Closing an account also ends its people's ability to sign in, so a closed business cannot export by itself: email support@onyx1.app within those 30 days and we will either restore access long enough for you to export or produce the export for you. Ask before you close if you can. Portal accounts are separate from trade-business accounts. Revoking the last provider link does not delete a portal login. The retention period for an unlinked portal login and its acceptance records is not yet determined; contact support@onyx1.app to request closure or ask what remains held.

10. When we disclose information

To the processors in section 7, to the extent needed to run the service; when the law requires or permits it (for example a court order or a Privacy Act request); and in a business sale or restructure, to a successor bound by this policy. Never to advertisers, and never for profit from the data itself.

11. Your rights of access and correction

You may ask for a copy of the personal information we hold about you and ask us to correct it (Information Privacy Principles 6 and 7). Write to support@onyx1.app. Say whether you are a staff user, a portal user, or an email contact, and which email you use. We respond within 20 working days as the Act requires. Portal users can already change their sign-in email, password, two-factor settings and email-notification choices on the account page. They cannot change a trade business's job file (the name on an invoice, a site address) from the portal. That correction goes to the trade business. If you want the portal login closed, email support@onyx1.app. Closing the login does not by itself delete invoices or reports held for a trade business. If you are not satisfied with our response you can complain to the Office of the Privacy Commissioner, privacy.org.nz, through its website.

To ask us to delete an account and its personal data, including without the app installed, see Delete your account and data.

12. If something goes wrong

If a privacy breach occurs that is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and the affected people as soon as practicable, as Part 6 of the Privacy Act 2020 requires. We will say what happened, what information was involved, and what we are doing about it. If the breach is of a portal login (emails, passwords, sessions), we notify the portal users. If it is of a trade business's job file, we notify that business so it can notify its customers, and we notify individuals ourselves where we are required to. If it is of both, we do both.

13. Cookies

ONYX1 uses cookies to keep you signed in, to keep the service secure, and to remember display choices you make. The client portal uses omni_customer_session for its 14-day sign-in session, including access to shared media, and omni_customer_mfa during two-factor sign-in. Quote links do not require an account cookie. The staff app also stores four preference cookies for a year each: hh-theme (light or dark), hh-text (text size), hh-nav-collapsed (sidebar width) and hh-view (which home screen you last used). They hold only that choice and are not used to identify or follow you. We do not use third-party advertising or cross-site tracking cookies.

14. Changes and contact

If we change this policy materially, the new version takes effect when we publish it, and we ask for acceptance then rather than after a notice period. We do not currently send advance notice by email. A trade business's owner or admin is shown the new version in the app and must accept it before they can keep using the service. A portal user is shown the current collection notice and asked to accept it the next time they sign in. The version a trade business accepted, and when, is recorded and available to that business. Contact: support@onyx1.app. ONYX1 LIMITED, a New Zealand Limited Company, company number 9453894, NZBN 9429053908322, registered 23 August 2026. Registered office: 189 Upper Harbour Drive, Greenhithe, Auckland, 0632.