About this policy
AVSBL LIMITED is a New Zealand company that provides website creation, publishing, hosting, analytics, website enquiries, connected services, an iOS companion app, bookings and related account support. This policy applies to AVSBL customers, people who use the AVSBL website, dashboard or iOS app, and people who submit information through a customer website hosted by AVSBL.
For information collected through a customer website, the website owner normally decides why the information is collected and how it will be used. AVSBL processes that information to provide the website and enquiry services. A website visitor can contact the website owner about their enquiry or contact AVSBL about the platform's handling of personal information.
AVSBL handles personal information in accordance with the New Zealand Privacy Act 2020 and other laws that apply to the service.
Information we collect
Depending on how you use AVSBL, we may collect:
- your name, email address, voluntarily provided telephone number and business details;
- account, sign-in, subscription, billing and customer-support records;
- website content, business information, domains, drafts, published pages, logos, images and other uploaded files;
- contact-form and booking details, including messages, selected services, staff, locations and appointment times;
- enquiry conversations, sender and recipient details, message content, timestamps, status, delivery identifiers and supported image attachments;
- connected-service account details, permissions and credentials needed to operate a service you authorise;
- payment and subscription metadata, such as customer, subscription, invoice, booking and payment-status identifiers; and
- mobile device-session identifiers, encrypted push-notification tokens, notification status and unread badge state; and
- technical, diagnostic and security information, including IP address, browser, app, operating-system and device details, crash and performance information, timestamps, sign-in events and abuse-prevention signals.
AVSBL's first-party website analytics may also record page path, referring website, device category, broad country and a pseudonymous visitor identifier. The analytics database does not store the raw IP address as that identifier, although infrastructure and security providers may process IP addresses in operational logs.
Providing information is generally voluntary, but we may be unable to create an account, process an enquiry or booking, connect a service or provide a requested feature without the information needed for it.
How we use information
We use personal information to:
- create and secure accounts;
- build, publish, host and maintain websites;
- process subscriptions, payments and customer support;
- receive, deliver and organise website enquiries and replies;
- provide authorised email, review, booking and payment integrations;
- provide website analytics, performance information and image processing;
- detect fraud, abuse, unsafe links, security threats and prohibited content;
- operate, troubleshoot and improve the service; and
- meet legal, accounting, security and regulatory obligations.
We do not sell personal information. We do not use private enquiry content or information received through connected accounts for unrelated advertising or to train general-purpose artificial-intelligence models.
AVSBL uses essential cookies or browser storage for account sessions, security, interface preferences, the selected website and saved privacy choices. With a visitor's permission, AVSBL also uses Meta Pixel on avsbl.com to measure visits and advertising performance, create advertising audiences and understand activity connected with Facebook and Instagram advertising. Meta may receive the visited page, browser and device information, IP address and cookies or similar identifiers under its own privacy policy.
Meta Pixel does not load before the visitor selects Allow. Rejecting does not affect access to the website. A visitor can change or withdraw the choice using the Privacy choices control below the website footer. Supported Global Privacy Control and browser Do Not Track signals default optional marketing tracking to rejected. The choice is saved in the visitor's browser for up to 180 days, after which AVSBL asks again. The prompt may also return if browser data is cleared or the consent version or website address changes; an ordinary website deployment does not reset the saved choice.
The authenticated AVSBL iOS companion app and dashboard do not use Meta Pixel, an advertising identifier or cross-app tracking. Optional marketing measurement is limited to the public avsbl.com website and remains subject to the consent controls described above.
Accounts and connected services
Accounts and sign-in. You may create an account using email and password, Sign in with Apple, Google Sign-In or Microsoft Sign-In. Depending on the method selected, AVSBL and its authentication provider receive the account identifier, verified email address and any basic profile details supplied by the sign-in provider. Social sign-in does not by itself permit access to Gmail, Outlook, Microsoft 365, Google Business Profile or other optional connected services.
Connected Gmail and email accounts. Customers may choose to connect a Gmail, Google Workspace, Microsoft 365, Outlook or Zoho Mail account to AVSBL Email Center. When a customer connects Gmail or Google Workspace, AVSBL uses the gmail.send permission to send website-enquiry replies written and initiated by the customer, including attachments selected by the customer. AVSBL uses the gmail.readonly permission to check a limited recent Inbox window and retrieve only messages and attachments matched to an existing AVSBL website enquiry by mailbox, email thread, known customer address and subject.
AVSBL does not display or import the customer's general Gmail inbox, import unrelated messages, or modify, delete, archive or label Gmail messages. AVSBL stores the connected mailbox address, encrypted authorisation credentials, granted permissions, connection status, and matched enquiry-conversation information such as message text, sender and recipient addresses, subject, timestamps, delivery status, Gmail message and thread identifiers, and attachment metadata.
AVSBL does not persist Gmail attachment file contents. Where Gmail supplies attachment data while a matched message is processed, the file contents are discarded after processing and retrieved again from Gmail when the authenticated customer opens or downloads the attachment.
Disconnecting Gmail removes the encrypted connection credentials and attempts to revoke AVSBL's Google authorisation. When disconnecting, the customer may keep the existing Email Center history or choose to permanently delete the messages, Gmail identifiers and attachment metadata synced through that mailbox. This does not delete messages from Gmail or remove the original website enquiries stored in AVSBL. Customers can also delete individual conversations and websites, or request account deletion, subject to normal backup, recovery, security and legal-retention periods.
Customers can also revoke AVSBL's access at any time through their Google Account third-party connections.
AVSBL personnel do not access Google message content or attachments except with the customer's affirmative permission to access specific data for support, where necessary to investigate security incidents or abuse, or where required by law.
AVSBL does not sell Google user data, use it for advertising, credit decisions or unrelated purposes, or use Gmail message content or attachments to train general-purpose artificial-intelligence models. AVSBL's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google Business Profile reviews. A website owner may separately authorise the Google account that manages an eligible Business Profile and select a location. AVSBL retrieves that location's identifying details, rating, review count and customer reviews for display on the owner's website. Within AVSBL this is a read-only integration: it does not change business information, create posts, write or reply to reviews, or delete Google content.
Limited location and review information may be cached and refreshed periodically. Disconnecting removes the stored authorisation, selected location and cached review information controlled by that connection.
AVSBL's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
AVSBL iOS companion app
The AVSBL iOS app is an existing-customer companion for the hosted AVSBL service. It uses a short-lived, one-use authentication handoff and stores the resulting app session in the iOS Keychain with device-only protection. AVSBL stores the corresponding device-session identifier while the session remains authorised.
If a customer enables notifications, Apple supplies an APNs device token. AVSBL sends that token over an authenticated encrypted connection, encrypts it at rest and uses it only to deliver AVSBL service notifications, such as new website-enquiry alerts and the current unread Inbox badge. Notification permission is controlled by iOS and can be changed at any time in iPhone Settings. AVSBL revokes the associated mobile session and notification registration on sign-out, relevant account changes, account deletion or when Apple reports that a token is no longer valid.
Optional Face ID or device-biometric app lock is performed by iOS. AVSBL does not receive or store a face image, biometric template or biometric measurement; the app receives only whether the device authentication succeeded. The local setting recording whether app lock is enabled remains on the device.
The app may process app version, device and operating-system details, security events, and crash or performance diagnostics through AVSBL and its service providers to authenticate the device, prevent abuse, troubleshoot failures and improve reliability. The app does not sell this information or use it for advertising tracking.
Website enquiries, messages and uploads
When a visitor submits a form on an AVSBL-hosted customer website, AVSBL may store their name, email address, voluntarily provided telephone number, message and supported image attachments. Information may be saved before an email notification is attempted so a temporary delivery failure does not lose the enquiry.
AVSBL stores enquiry messages and replies as a conversation for the website owner. This can include contact details, message content, sending and delivery status, timestamps, provider identifiers and attachments. The website owner is responsible for using enquiries lawfully, responding only in connection with the visitor's request and providing any additional privacy notice their business requires.
Customers may upload website text, business details, domains, logos, images and other material. Content chosen for a published website becomes publicly accessible. Drafts and private account records do not become public merely because a website is published.
Images may be optimised and may be automatically checked for serious prohibited content. Flagged material may be quarantined and reviewed by authorised AVSBL personnel. Temporary uploads and enquiry attachments are removed in accordance with the applicable operational retention settings.
Payments, bookings and third-party services
Stripe currently processes AVSBL subscription billing through Stripe-hosted Checkout. Complete card details are entered into Stripe-secured payment fields and are not received or stored by AVSBL. AVSBL receives the customer, subscription, invoice and payment-status information needed to manage the subscription and billing portal.
A website owner may connect Stripe for commerce and Calendly for bookings. AVSBL may receive authorised Stripe account, product, price, checkout and payment-status identifiers, and Calendly account, event-type and booking information required to operate those features. Payment-card details are entered directly into Stripe Checkout and are not received or stored by AVSBL.
A website owner may connect Square or use an approved third-party booking link or widget. For connected Square bookings, AVSBL may use authorised locations, services, team members and availability, then send the visitor's booking details to Square. Card details are entered directly into Square's payment fields. AVSBL may receive a payment token, identifier and status needed to complete and reconcile the booking.
AVSBL uses service providers where necessary to operate the platform, including Google, Microsoft and Zoho for connected email; Apple, Google and Microsoft also for sign-in, Apple for iOS platform services and push delivery, and Google for optional Business Profile reviews; Supabase for authentication, database and permitted storage; Vercel and Cloudflare for hosting, delivery, security and storage; Amazon Web Services and Resend for email, file processing and delivery; Stripe for AVSBL subscription billing and optional connected website commerce; Square for connected bookings and payments; Calendly as an optional booking provider; Sentry for error and performance monitoring; and Meta for optional advertising measurement on the public website after visitor consent.
Third-party links, payment pages, maps, booking widgets and connected services may receive information directly under their own privacy policies. AVSBL may also disclose information where required by law, to investigate fraud or security incidents, protect people or the service, or as part of a genuine business restructuring subject to applicable privacy obligations.
Security, international processing and retention
AVSBL uses administrative, technical and access controls designed to protect information, including restricted administrative access, protected connection credentials, database access controls, transport encryption and security monitoring. No online service can guarantee absolute security. Please contact us promptly if you believe an AVSBL account or customer website has been compromised.
AVSBL and its providers may process information in New Zealand, Australia, the United States and other countries where they operate. Privacy and data-protection laws may differ between countries. We use reputable providers and contractual, organisational and technical safeguards appropriate to the information and service.
We keep information only for as long as reasonably needed to provide the service, meet legal and accounting duties, resolve disputes, prevent abuse and maintain security. Retention depends on the type of record:
- account and website data is generally kept while the account or website is active;
- a cancelled website is normally scheduled for permanent deletion approximately 30 days after cancellation;
- connected-service credentials are removed when the relevant connection is disconnected or deleted;
- temporary uploads and stored enquiry attachments are removed under shorter operational schedules;
- billing, fraud-prevention, security and legal records may be kept for longer where reasonably required; and
- providers may retain records independently under their own legal duties and policies.
Deletion from active systems may be followed by limited retention in backups or provider recovery systems until normal backup cycles complete.
Privacy rights
Under the New Zealand Privacy Act 2020, you may ask whether AVSBL holds personal information about you and request access to or correction of that information. You may also raise a concern about how we have handled it.
Contact support@avsbl.com with enough detail for us to identify the relevant account, website or enquiry. We may need to verify your identity or authority before responding. If information was provided to an AVSBL customer through their website, contacting that business directly may be the quickest way to resolve the request.
Customers may request complete deletion of their AVSBL account and associated data from Account & privacy in the authenticated dashboard or iOS app, or by contacting support@avsbl.com. AVSBL may verify the requester's identity or authority before processing the request. Deletion remains subject to the limited backup, security, billing and legal-retention requirements described in this policy.
If you are not satisfied with our response, you can contact the Office of the Privacy Commissioner.
Changes and contact
We may update this policy to reflect changes to the service, providers or law. We will update the date above and, where appropriate, provide notice through the service or by email before a material change takes effect.
Privacy questions, requests and complaints can be sent to AVSBL LIMITED in New Zealand at support@avsbl.com.