Privacy Policy
Last Updated: July 2026
1. Introduction
This Privacy Policy explains how Bundle Holdings Limited (“Bundle”, “we”, “us”) collects, uses, and protects your personal information when you visit our website, interact with our marketing pages, contact us, join a waitlist or mailing list, create an account, or use our property documentation and management service.
By using Bundle, you agree to the collection and use of information as described in this Policy.
Capitalised terms not defined in this Policy have the meaning given in the Terms of Use, unless stated otherwise.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, phone number, password
- Property Information: Property addresses, details, and all documentation you upload
- User Content: Documents, photos, notes, service contact details where enabled, and any other content you add to Bundle.
- Feedback and Ratings: ratings, reactions, comments, or other feedback you provide about AI responses, records, features, or the Service.
- Communications: Messages and other interactions between us
- Inbound Email Attachment Content: attachments sent or forwarded to Bundle ingestion addresses from senders the account has authorised and the Service has verified, together with limited related metadata such as the sender address, the recipient ingestion address, and details about the file and its delivery, where enabled. Email body content is not ingested into the Property Record.
- Archive Copy Information: content included in an Archive Copy at or around the time of a Professional-to-Owner transfer. Archive Copies are stored independently under the Professional’s account.
- Website and marketing information: information you provide through our website or marketing pages, such as email addresses, contact-form submissions, demo requests, waitlist or signup interest, and communication preferences.
2.2 Information Collected Automatically or Generated Through Use
- Usage Data: Features used, actions taken, time spent, search queries
- AI Interactions: Questions you ask, responses generated, interaction history, retrieved context or retrieved-context references, ratings, feedback comments, assistant exchange records, technical diagnostics, and related metadata used to provide, support, secure, diagnose, and improve AI-assisted features.
- Device Information: IP address, browser type, device type, operating system
- Log Data: Access times, pages viewed, errors encountered
- Access Logs: (name, email, timestamps and IP address, where available)
2.3 Google Authentication
If you sign in with Google, we receive your basic profile information (name and email) from Google.
2.4 Indirect Collection (Access)
If you grant access to someone, we receive their Personal Information (for example, name and email) from you for the purpose of providing access. We will present accessing users with our Terms of Use and this Privacy Policy when they access a Property Bundle so they can understand how their information will be processed. Anyone, by accepting access, also agrees that their information may be processed by our service providers for the purposes described in this Policy.
2.5 Cookies and similar technologies
We may use cookies, pixels, local storage, and similar technologies on our website and Service to operate the site, remember preferences, understand usage, improve performance, support security, and measure marketing or product effectiveness. These technologies may collect information such as device information, browser information, pages viewed, links clicked, referral source, approximate location, and interaction data. You can control cookies through your browser settings, although disabling some cookies may affect site or Service functionality.
Where enabled, we may use website analytics tools such as Google Analytics or Google Search Console to understand how visitors find and use our website, improve performance, and measure marketing effectiveness.
You do not have to provide us with the personal information we request but if you do not then we may be unable to provide you with all or some of our services.
3. How We Use Your Personal Information
We use your information to:
- Provide and maintain Bundle's services
- Process and respond to your AI queries about your Property, Property Record, and related property information
- Generate property-specific insights, recommendations, schedules, summaries, and other property-related outputs based on your Property Record and AI interactions, where available
- Provide maintenance task management, reminders, tracking, scheduling workflows, or similar structured maintenance features, where enabled
- Store, display, and organise property records and, where enabled, service contact information
- Help users manage property-related service relationships or maintenance history, where enabled
- Make property records searchable and retrievable through Bundle features, including AI-assisted features
- Manage access permissions, including ongoing access for connected contacts where enabled
- Review feedback, ratings, and reactions to improve the Service, AI-assisted features, support, safety, and quality.
- Improve and develop new features
- Process payments and manage subscriptions
- Ensure security and prevent fraud
- Comply with legal obligations
- Communicate with you about the Service (including important service notifications and security alerts)
- Marketing communications (only with your consent; you can withdraw at any time)
4. How We Share Your Personal Information
4.1 We Don't Sell Your Data
We never sell your personal information to anyone.
4.2 Service Providers
In providing our services, we generally act as a service provider/processor on behalf of account holders. For certain limited purposes (such as maintaining security, complying with law, or generating anonymised analytics), we act as the agency/controller.
We also use third-party service providers (“sub-processors”) who help us operate Bundle, including:
- Cloud hosting and storage (e.g. Google Cloud for uploaded-file storage)
- Application hosting and databases (e.g. Render)
- Website, web application hosting and content delivery (e.g. Netlify, Replit)
- AI processing, search-grounding, and OCR (e.g. OpenAI; Google Cloud AI services, including Gemini; Perplexity for web search), where enabled — used for inference only, not training
- Payment processing (e.g. Stripe)
- Email delivery (e.g. Postmark)
- Logging, observability, and error monitoring (e.g. BetterStack, Sentry)
- In-memory caching (e.g. Upstash)
Some of these providers may process or store information outside New Zealand, including in the United States, Europe, and other countries. Our service providers are contractually required to protect your information and may only use it to provide, secure, and support the services we have engaged them for. We may add or change service providers as our platform evolves. We’ll update this section when we do.
4.3 Access
You can share access to property information (which may include your personal information) via email or QR codes you generate. You can also grant ongoing access to certain service contacts you designate as connected contacts. These contacts may continue to access the permitted parts of the property record until that status is removed by you or otherwise ends in accordance with the Service settings and these policies.
Private records are visible only to Owners and Admins for the relevant Property and excluded from retrieval for other users through records, search, chat, or similar features. Bundle and its service providers may still process private records where necessary to provide, secure, maintain, and support the Service.
4.4 Account Transfers
When you transfer control of a Property in Bundle, property information, which may include personal information, transfers to the new Owner. All existing access grants are reset on transfer.
For Professional-to-Owner transfers, the Owner receives control of the live Property. If the Professional elects to retain an Archive Copy and has the required Professional subscription, Bundle will make a separate archive record available under the Professional’s account.
An Archive Copy may contain personal information included in the Property Record at or around the time of transfer, including records marked private and related metadata where applicable. After transfer, the Owner’s Property and the Professional’s Archive Copy are separate records. Each is processed, retained, corrected, shared, and deleted independently. Changes made to one do not affect the other, except through specific Service features such as Update Proposals.
For Archive Copies, the Professional is the agency/controller for personal information they retain, and Bundle processes that information on their behalf. Professionals are responsible for managing access to Archive Copies, reviewing whether retained personal information remains required, and using available deletion tools or contacting Bundle where deletion assistance is needed.
Bundle may retain limited metadata linking a transferred Property and any related Archive Copy for auditing, security, traceability, and compliance purposes.
After transfer, any new documents added by the Professional to an Archive Copy may be offered to the Owner as Update Proposals. These proposals are optional for the Owner and do not modify the Owner’s Property Record unless accepted by an Owner or authorised Admin.
4.5 Update Proposal Metadata
When a Professional offers a document from an Archive Copy to an Owner’s Property Bundle, the Service generates an Update Proposal. We record limited metadata about these events for auditing, security, fraud prevention, and compliance. This metadata is primarily internal and is generally not visible to either party unless required by law.
4.6 Legal Requirements
We may disclose information when required by law, court order, or to protect:
- Our legal rights
- The safety of users or the public
- Against fraud or security threats
4.7 Business Transfers
If Bundle is acquired or merged, your information may transfer to the new Owner. We'll notify you before this happens.
5. Data Retention
- Active accounts: We retain your data while your account is active
- User-initiated deletions: Deletion depends on your access role. Owners and Admins may delete records and contributions within a Property, including content added by other users. Contributors and Viewers cannot delete content, including content they added themselves. Deletions are permanent, subject to limited backup, audit, security, fraud prevention, legal, and retention requirements. If you intend to keep records for the next Owner, do not delete them.
- Closed accounts: At your request, we delete your account and personal data within 30 days, but believe this is unfortunate as property records may be needed later by future property Owners. Deleted data may persist in backups maintained by our providers, until those backups expire, but is not accessible during normal operations. If you have already transferred a property, its record continues for the new Owner. Professionals are responsible for deciding whether they still need the Archive Copy and for requesting/using deletion where available.
- Inactive/Orphan accounts: We reserve the right to delete or anonymise data from accounts with no verified contact details, unclaimed transfers, unpaid fees, or no activity for 12 months, after giving 30 days’ notice.
- Website, contact, and waitlist information: We retain website form submissions, contact enquiries, demo requests, waitlist/signup interest, and related email addresses for as long as needed to respond, manage the relationship, maintain records of the communication, or until you unsubscribe or ask us to delete your details, subject to legal, security, and backup limits.
- Anonymised data: We may retain anonymised analytics indefinitely to improve our services.
- Legal obligations: Some data may be retained longer if required by law, including transaction records, tax or accounting records, audit records, or records retained by Professionals for applicable statutory or record-keeping obligations.
- Audit trail: We may retain limited logs or records if required by law or for security, fraud prevention or auditing.
- Archive Copies: Where a Professional elects to retain an Archive Copy during transfer, the Archive Copy is retained under the Professional’s account until deleted or otherwise handled in accordance with these Terms, this Policy, applicable subscription requirements, and any legal or record-keeping obligations.
- Linked metadata: Minimal identifiers linking Archive Copies to their originating property may be kept for audit and security purposes. Metadata relating to Update Proposals may be retained for auditing, security, and fraud prevention, even if the related file is declined or deleted.
6. Data Breaches
If a privacy breach occurs that poses a risk of serious harm, we’ll notify affected users and, where required, the Office of the Privacy Commissioner in accordance with the Privacy Act 2020.
7. Your Rights and Choices
7.1 Access and Correction
You can access and update your information through your Bundle account or by contacting us. If you need a copy of your information, contact support@mybundle.app and we’ll assist (export may be a manual process at this time).
7.2 Account Closure
You can request account closure and data deletion. While we believe property records have long-term value for all future Owners, we respect your right to deletion. Contact us at support@mybundle.app to discuss your options.
7.3 Marketing Communications
You can opt-out of marketing emails you have opted in to using the unsubscribe link or contacting us.
7.4 Cookies and analytics
We use cookies and similar technologies as described in this Policy. Most browsers allow you to control or disable cookies. Disabling cookies may limit some website or Service features.
8. International Data Transfers
Some of our current sub-processor service providers (for example, cloud hosting, AI processing, and payment providers) process information outside New Zealand, including in the United States and Europe. We take reasonable steps to ensure these providers protect your information and only use it to deliver the services we have engaged them for. These steps may include contractual safeguards consistent with international data transfer requirements.
9. New Zealand Privacy Act
You have rights under the Privacy Act 2020:
- Right to access your personal information
- Right to request correction of errors
- Right to complain to the Privacy Commissioner
We act in accordance with the Information Privacy Principles under the Act.
If you access the Service from outside New Zealand, you are responsible for complying with local laws.
10. Changes to This Policy
We may update this Policy occasionally. We'll notify you of material changes via email or Service notification. Your continued use after changes means acceptance.
11. Contact Us
For privacy questions or to exercise your rights contact our Privacy Officer at:
Bundle Holdings Limited
Email: privacy@mybundle.app
Address: 25 Tainui Road, Devonport, Auckland, NZ 0624
For complaints, you may also contact:
Office of the Privacy Commissioner