Privacy · version 1.0
Privacy Policy
Neighbourhood is operated by Common Ground Tech Limited, a New Zealand company. This policy explains what personal information we collect, why we need it, how long we keep it and how you stay in control. It is written to meet the Privacy Act 2020 and the Information Privacy Principles, including IPP3A for information we collect indirectly.
The short version
- You can browse all of Neighbourhood without an account.
- Most of what we learn about your taste stays on your own device.
- We do not sell personal information and we run no advertising or tracking SDKs.
- Precise location is used only while you are using a screen that needs it.
- You can export or delete your information from Privacy & Data at any time.
Who we are
Neighbourhood is operated by Common Ground Tech Limited, a company incorporated in New Zealand. We are the agency responsible for the personal information described in this policy under the Privacy Act 2020.
- Registered address: [ADMIN ACTION REQUIRED — registered address]
- Privacy Officer: [ADMIN ACTION REQUIRED — Privacy Officer name]
- Privacy email: [ADMIN ACTION REQUIRED — privacy email]
These details are shown as clearly labelled placeholders because they have not yet been supplied to us for publication. Until they are, please use the request form in Privacy & Data inside the app, which reaches us directly.
Information we collect
The lists below come from our internal data inventory, which records every field the application actually writes today. Where something is planned but not yet collected, it is not listed here.
Information you provide
Your profile details and anything you type into Neighbourhood.
account id
Identify the profile so saves, plans and bookings belong to the right person
Required · Authentication service · Kept while the profile exists; erased on account deletion
name
Greet the person and show who they are inside shared plans
Required · On your device · Held on the device until the person clears it or deletes their profile; no server copy.
email
Sign-in, password recovery and booking confirmations
Required · On your device · Kept while the profile exists; erased on account deletion
Information generated through use of Neighbourhood
Signals created as you browse — the places you open, save, plan or book, and the preferences you set.
interests
Shape the first set of suggestions
Optional · On your device · Held on the device until the person clears it or deletes their profile; no server copy.
cuisine preferences
Explainable personalisation of recommendations
Optional · On your device · Signals decay after 30 days; capped at 200 signals
occasion preferences
Match occasions (date night, whānau, celebration) to venues
Optional · On your device · Signals decay after 30 days
atmosphere preferences
Match atmosphere (quiet, lively, cosy) to venues
Optional · On your device · Signals decay after 30 days
practical preferences
Filter for practical fit — whānau, pets, accessibility questions asked openly
Optional · On your device · Held on the device until the person clears it or deletes their profile; no server copy.
saved venues
Keep a personal shortlist
Optional · On your device · Held on the device until the person clears it or deletes their profile; no server copy.
searches
Return results for the current query
Optional · Not stored · Not retained — queries are handled in the session and discarded
venue views
Understand taste so recommendations can be explained
Optional · On your device · Signal log capped at 200 entries, decays after 30 days
recommendation interactions
Improve the ordering of suggestions for that person
Optional · On your device · Signals decay after 30 days
booking referrals
Send the person to the venue to complete the booking
Optional · On your device · Local booking list only; no referral log kept
rewards activity
Run the rewards balance
Optional · On your device · Held on the device until the person clears it or deletes their profile; no server copy.
notification preferences
Only send what they asked for
Optional · On your device · Held on the device until the person clears it or deletes their profile; no server copy.
support communications
Answer the question and evidence the response
Optional · Neighbourhood database · Two years from resolution
Location information
selected city
Show the right market's venues, events and transport
Required · On your device · Held on the device until the person clears it or deletes their profile; no server copy.
selected neighbourhood
Order suggestions by walking distance from where they usually are
Optional · On your device · Held on the device until the person clears it or deletes their profile; no server copy.
approximate location
Distance and transport estimates without needing device location
Optional · On your device · Held on the device until the person clears it or deletes their profile; no server copy.
precise location
Order 'near me' results and live departures for the closest stops
Optional · Not stored · Used for the current session only. Coordinates are never written to the database.
Technical and device information
device information
Render the right layout and keep the service secure
Required · Not stored · Not retained by Neighbourhood beyond the hosting request log
diagnostic information
Find and fix faults
Required · Not stored · Kept only as long as needed to diagnose the fault
Information received from third parties
If you sign in with a third-party identity provider, we receive the email address and name from that account. We also receive place, imagery and transport data from the open sources listed under Publicly available information. We do not buy personal information, and we do not receive advertising or attribution data from anyone.
Business account information
When someone claims a venue on behalf of a business, we collect the details needed to verify that claim and to record who confirmed each fact or image right.
business account information
Verify who may edit a venue and record confirmed facts
Required · Neighbourhood database · Kept while the claim stands; rights confirmations kept as an audit record
Publicly sourced information
Venue listings are built from public sources. See Publicly available information below.
Why we collect information
- To provide Neighbourhood and show the right city, venues and opening hours.
- To create and manage your profile, and to keep you signed in.
- To support local discovery, search and map browsing.
- To personalise and explain recommendations, when you have personalisation turned on.
- To remember your saved places and shared plans.
- To let you request a table inside Neighbourhood and to track your rewards points.
- To send only the communications you have switched on.
- To keep the service secure and to diagnose faults.
- To improve the product by reviewing how features perform overall.
- To meet legal obligations, including our obligations under the Privacy Act 2020.
We do not currently run an analytics SDK, and no subscription or payment processing is connected, so we hold no analytics profiles and no billing or card information. If that changes, this policy and the data inventory will be updated first.
Location
Location is never taken silently. You choose one of three modes in Privacy & Data: off, suburb only, or precise while using the app.
- Off — you pick a city and browse. No location is read from your device.
- Suburb only — we use the approximate suburb you select. This is stored on your device.
- Precise while using — after your browser or device permission prompt, we read your coordinates for the screen you are on: distance and walking time, nearby results, and closest transport stops.
Precise coordinates are held in memory for that session and are not written to our database, so we do not build a location history. Your chosen city and suburb are saved on your device so you do not have to pick them again. Before a weather lookup, coordinates are rounded so the request does not identify a street address.
You can change or switch off location at any time in Privacy & Data, and separately in your browser or device settings. Neighbourhood remains fully usable with location off.
Personalisation
When personalisation is on, Neighbourhood orders and explains suggestions using signals such as the interests you chose, the places you save, what you search for, the venues you open, and how you respond to earlier recommendations.
These signals are stored on your device, decay after 30 days and are capped at the 200 most recent. We only use what you have actually done in the app — we do not infer sensitive characteristics, and we do not claim to know facts about you that you have not given us or shown us through use.
You can switch personalisation off, stop new signals being recorded, or clear the signals entirely in Privacy & Data. With personalisation off, results are ordered by openness, distance and editorial merit only.
Third parties
We use a small number of service providers, and only as processors acting on our instructions. We do not sell personal information. The list below is the register of providers the application actually uses today.
Application backend and authentication (Lovable Cloud / Postgres)
Store the venue register, business claims, privacy events and privacy requests
Information sent: account id, business account information, privacy events, privacy requests, venue and rights records
Open-Meteo
Weather forecast used in the greeting and weather-aware suggestions
Information sent: coarse latitude and longitude of the selected city or rounded device location
OpenStreetMap / Nominatim
Discover venues and reverse-geocode addresses during ingestion
Information sent: venue coordinates and search terms from back-office jobs only
Wikimedia Commons
Openly licensed venue imagery
Information sent: venue name and suburb search terms from back-office jobs only
Lovable AI Gateway
Generate the plain-language sentences that explain a recommendation
Information sent: venue facts, the current context sentence (time, weather, chosen mood), inferred preference labels
Error reporting (development platform)
Report runtime faults so they can be fixed
Information sent: error message, stack trace, route path, browser user agent
Not connected today, and therefore receiving nothing: Metlink (Greater Wellington Regional Council); Auckland Transport; Google Places; Google Sign-In. There is no analytics provider, no payment processor, no advertising network and no third-party booking provider connected. If you download the app from the App Store, Apple handles that distribution under its own privacy policy; we receive no personal information from Apple beyond what any developer receives.
Signed data-processing terms for each provider: [ADMIN ACTION REQUIRED — processor agreements on file].
Bookings
Booking requests are completed inside Neighbourhood. When you request a table, the details — the venue, time and party size — are recorded against your own profile on your device so you can see and manage them.
Neighbourhood is not currently connected to any external reservation platform, so we do not hand your details to a third-party booking provider, and there is no booking attribution or conversion tracking of any kind. If we later add an external provider, we will name it here and explain exactly what is sent before that feature goes live.
Overseas storage and disclosure
Neighbourhood runs on managed cloud infrastructure, and the application database, authentication service, hosting, error reporting and AI text generation are provided by overseas providers. This means personal information may be stored on, or accessed from, servers outside New Zealand.
Where an overseas provider holds information as our processor and only acts on our instructions, the Privacy Act 2020 treats that as our own holding rather than a disclosure. Where information is genuinely disclosed to an overseas agency, we will only do so where IPP12 allows it — in practice, where the recipient is required to protect the information with safeguards comparable to those in the Privacy Act.
Confirmed hosting and database regions for each provider: [ADMIN ACTION REQUIRED — confirmed hosting regions]. We will name the countries in this section once those regions are confirmed in writing.
Publicly available information
Neighbourhood is a register of places, so much of our venue content comes from public sources rather than from the person or business it relates to (IPP3A). Being publicly available does not make information exempt from the Privacy Act, so we record where every value came from, how confident we are in it, and when it was last checked.
Venue and operator details
Source: OpenStreetMap, the NZ Business Register, official venue websites
Public business information only. Field-level provenance, confidence and review status are recorded for every value.
Venue imagery
Source: Wikimedia Commons, business uploads, recorded permissions
No image is displayed without a recorded rights basis. Photographer credit is retained where the licence requires it.
Operator contact details on a listing
Source: Published business contact information
Used only to reach the business about its listing. Operators can correct or ask for removal at any time.
Most of this concerns a business, not a person. Where a value identifies an individual — a sole trader's name, a personal phone number used as a venue contact, or a photographer credit — we treat it as personal information and assess it under IPP3A before it is published, including whether it is reasonable to collect it without telling that person first. If a listing includes information about you as an individual, ask us and we will correct or remove it.
Data retention
We keep personal information only for as long as it is reasonably required for the purposes set out in this policy, or for as long as a legal obligation requires. Retention periods are configured in our data inventory rather than written into prose, so what the app does and what this policy says stay aligned.
Anything held on your device (profile basics, saves, plans, preferences)
No fixed period — kept only while the purpose lasts. Deleted when you clear it, delete your profile, or clear browser storage.
Why: Only needed while you are using Neighbourhood on that device
Taste signals used for personalisation
30 days, capped at the 200 most recent signals. Older signals are discarded automatically.
Why: Recent behaviour is all that is useful for recommendations
Account and authentication records
No fixed period — kept only while the purpose lasts. Removed when the account is deleted.
Why: Needed to give you access to your own account
Privacy events and privacy requests
2 years from resolution. Deleted after the period ends.
Why: Evidence that we handled the request properly · pending operator sign-off
Business claims, verification and image rights confirmations
No fixed period — kept only while the purpose lasts. Kept while the listing stands, then archived as an audit record.
Why: Shows we had a lawful basis to publish a listing or an image · pending operator sign-off
Error reports and hosting request logs
Short-term only. Held by the hosting and error-reporting providers under their own schedules.
Why: Fault diagnosis and service security · pending operator sign-off
Sign-off on these periods: [ADMIN ACTION REQUIRED — retention sign-off].
Security
We take reasonable technical and organisational steps to protect personal information. Access to our database is controlled by row-level security, so a signed-in person can only reach their own records. Consumer information is kept separate from public venue information, privileged operations run server-side only, and administrative functions are restricted to named roles held in a separate roles table. Traffic to and from the app uses HTTPS.
No system can be guaranteed completely secure, and we do not promise that. If something goes wrong, we would rather tell you than pretend otherwise.
Your rights
Under the Privacy Act 2020 you can ask us for a copy of the personal information we hold about you (IPP6) and ask us to correct it (IPP7). There is no charge for a routine request.
The quickest route is Privacy & Data in the app: it gives you an immediate export of everything held for you, and a request form for access, correction or a complaint. You can also write to us at the address in Contact. We aim to respond within 20 working days, which is the statutory maximum.
Account deletion
You can delete your Neighbourhood account yourself: Privacy & Data → Delete Account. No email, phone call or explanation is required.
Deletion removes your profile, saved places, plans, preferences, taste signals and rewards balance from your device, and removes or de-identifies the records held for you in our database.
We keep only what we are reasonably or legally required to keep: a record that a deletion request was made and actioned, records of privacy requests for the period set out above, and — where a business claim was made — the audit trail showing who confirmed a venue fact or an image right, since a published listing must remain accountable. Those records are not used to re-identify you or to rebuild a profile.
Withdrawing permissions
Everything is reversible, in one place, without having to ask us.
- Location: Privacy & Data → Location, or your browser or device settings.
- Notifications: Privacy & Data → Communications, each type separately, plus your device notification settings.
- Personalisation: Privacy & Data → Personalisation, including clearing signals.
- Your data: download a copy or clear it from this device at any time.
Privacy breaches
We keep an internal register of privacy incidents and assess each one. If a privacy breach is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and the affected people as soon as practicable, as the Privacy Act 2020 requires. Not every security incident is a notifiable privacy breach, so we do not promise to notify you of every event — we promise to assess every one properly and to notify where the law requires it or where telling you is the right thing to do.
Owner of the breach assessment process: [ADMIN ACTION REQUIRED — breach process owner].
Children
Neighbourhood is intended for adults. Many listed venues are licensed premises, and accounts are not designed for or directed at children. We do not knowingly collect personal information from children and we do not build behavioural profiles of children.
Whether a venue suits whānau or tamariki is a fact about the venue, confirmed by the business or by verified evidence — it is never inferred from anything about you or your family. If you believe a child has created an account, contact us and we will remove it.
Changes to this policy
We record a version, an effective date and a publication date for every release of this policy, shown at the top of this page. Minor clarifications are published with an updated date. If we make a material change — for example, collecting a new category of information, or connecting a new provider — we will tell you in the app before it takes effect and ask you to acknowledge the new version in Privacy & Data.
Contact
- Privacy Officer: [ADMIN ACTION REQUIRED — Privacy Officer name]
- Common Ground Tech Limited, New Zealand
- Privacy email: [ADMIN ACTION REQUIRED — privacy email]
- Postal address: [ADMIN ACTION REQUIRED — postal address]
Until those details are published, the request form in Privacy & Data reaches us and is the fastest way to be heard.
Office of the Privacy Commissioner
If you are not satisfied with how we have handled your privacy, you can raise it with the Office of the Privacy Commissioner in New Zealand at privacy.org.nz, or by phoning their enquiries line. You can complain to them whether or not you have come to us first, though we would like the chance to put it right.
Related documents
See also our Terms of Use and Licences & Attributions.
Outstanding information (ADMIN ACTION REQUIRED)
This policy is complete and accurate about what the application does. The following organisational details must be supplied by Common Ground Tech Limited before it is published to the App Store or a public website.
Registered company address
IPP3 requires the collecting agency's address to be identified in the collection notice.
Name of the Privacy Officer
The Privacy Act 2020 requires every agency to appoint and identify a Privacy Officer.
Monitored privacy email address
Access and correction requests must reach a mailbox that is actually monitored.
Postal address for privacy correspondence
People must be able to make a request in writing.
Confirmed hosting and database regions for each provider
IPP12 disclosure wording depends on where information is actually held.
Signed data-processing terms for each provider
Overseas disclosure under IPP12 relies on comparable-safeguard assurances.
Sign-off on the retention periods in the data inventory
Retention must be no longer than reasonably required for the stated purpose.
Named owner of the privacy breach assessment process
Notifiable breaches must be assessed and reported without undue delay.