Legal

Privacy Policy

Last updated: 8 February 2026

This Privacy Policy explains how PTT NZ Limited ("PTT NZ", "we", "us" or "our") collects, uses, discloses and protects personal information through our customer web portal at portal.pttnz.net and our companion mobile applications for iOS and Android (together, the "Services"). By creating an account or using the Services, you agree to the collection and use of information as described here.

1. Who we are

PTT NZ Limited is a New Zealand-registered telecommunications reseller and Push-to-Talk device platform provider (NZBN 9429053660978), registered office 14 Hazeldean Road, Addington, Christchurch 8024, New Zealand. We are the "controller" (or, under New Zealand law, the "agency") responsible for the personal information described in this policy.

2. What this policy covers

This policy applies to:

  • The PTT NZ customer web portal (account holders, sub-users, and reseller/sub-reseller staff);
  • The PTT NZ mobile app for iOS and Android, used to manage SIMs/eSIMs, purchase data and Travel Data Packs, and operate Push-to-Talk radio devices; and
  • Support interactions with our team (email, phone, in-app support tickets).

It does not cover third-party websites or apps we link to, or the separate privacy notices of the network operators (e.g. Spark, One NZ, 2degrees or our international roaming partners) whose networks carry your SIM traffic — their own privacy policies govern how they handle traffic on their networks.

3. Information we collect

Account & business information: name, email address, phone number, physical/postal address, business/company name, and (where relevant to invoicing) GST/tax numbers.

Payment information: we use Stripe as our payment processor. We do not store your full card number — Stripe collects and stores card details directly and shares only a payment confirmation, card brand and last 4 digits with us for your receipts.

SIM, eSIM & device information: ICCID, IMEI/device serial numbers, SIM/eSIM status, device labels you assign, and Push-to-Talk radio/device identifiers.

Network usage data: data volume used, call/session detail records (CDRs — time, duration and network of sessions, not the content of your communications), plan and Travel Data Pack purchase/renewal history.

Network connection data: to activate, route and bill for connectivity, our underlying network and roaming partners inherently process technical connection data such as which country/network your SIM is connected to, cell/tower-level location, and session/device identifiers. This happens for every active SIM as a normal part of mobile connectivity, and is separate from (and does not require) the optional Push-to-Talk GPS fleet-tracking feature described below — see Section 7 for how these partners handle this data.

Location data: if you use the Push-to-Talk fleet features, we collect GPS location from enrolled radio devices (including, where a device is configured for it, while the app runs in the background) so a fleet operator/dispatcher can see device location on a map. Location is only collected from devices enrolled by an account administrator, not from a customer's personal phone browsing the web portal.

Voice, video & recordings: if your account has Push-to-Talk voice, video or call recording features enabled, audio/video transmitted over those channels — and recordings, where enabled by the account administrator — are processed and stored to provide that feature.

Device management (MDM) data: for devices enrolled in our Android device management, we collect device compliance status, installed app inventory (for managed devices only), and policy configuration state needed to remotely secure or configure that device.

Support & communications: the content of support tickets, emails or calls you send us, and any files you attach to a support request.

Technical data: IP address, browser/app type and version, device operating system, and basic access logs, collected automatically for security and troubleshooting.

4. Device permissions (mobile apps)

Our mobile app requests the following device permissions. You can review or withdraw these at any time in your device's Settings — some features will not work if a required permission is withdrawn:

  • Location (foreground and, for enrolled fleet devices, background): to show device location for Push-to-Talk fleet tracking.
  • Microphone: to transmit and receive Push-to-Talk voice calls.
  • Camera: for Push-to-Talk video calling, where enabled on your account.
  • Notifications: to alert you to incoming PTT calls, SIM/data alerts and account notifications.
  • Photos/files: to attach a photo or document to a support ticket, if you choose to.

5. How we use your information

  • Provide, maintain and bill for SIM, eSIM, Travel Data Pack and Push-to-Talk services;
  • Process payments and issue tax invoices/receipts;
  • Provide fleet location, voice/video and device management features you or your organisation enable;
  • Detect and prevent fraud, abuse and network faults;
  • Respond to support requests;
  • Send service, billing and security notifications (and, only with your consent, marketing updates);
  • Comply with our legal, tax and regulatory obligations.

We do not sell your personal information, and we do not use it for third-party advertising.

6. Our legal basis for processing

As a New Zealand company, we handle personal information in accordance with the New Zealand Privacy Act 2020 and its Information Privacy Principles. Where the GDPR or UK GDPR applies to you (for example, if you access our Services from the EU/UK), our legal bases are: performance of a contract with you, our legitimate interests in operating and securing the Services, your consent (for location, microphone/camera access, and marketing), and compliance with legal obligations. Where the California Consumer Privacy Act (CCPA/CPRA) applies to you, see Section 10 for your rights.

7. Who we share information with

We share personal information only as needed to provide the Services, with:

  • Network & roaming partners (our underlying mobile network operators and international roaming aggregators) — to activate, route and bill for SIM/eSIM connectivity. For the network connection data described in Section 3, these partners typically act as independent controllers under their own privacy policies, rather than as our contractors;
  • Push-to-Talk platform provider — the third-party radio/dispatch platform that powers voice, video, GPS and recording features;
  • Stripe, Inc. — payment processing;
  • Email & SMS delivery providers — to send account, billing and alert notifications;
  • Cloud hosting & infrastructure providers — to securely host the Services and any files you upload;
  • Google — for Android Enterprise device management, if your organisation enrols devices into MDM;
  • Professional advisers and regulators — where required by law, to enforce our terms, or to protect the rights, property or safety of PTT NZ, our customers or the public;
  • A successor entity — in connection with a merger, acquisition or sale of assets, subject to this policy continuing to apply to your information.

Every third party we share personal information with is contractually required to protect it to a standard consistent with this policy and applicable law.

8. International data transfers

Because our Services involve international mobile roaming and cloud infrastructure, your information may be processed in countries outside New Zealand, including the United States and other countries where our service providers operate. Where we transfer personal information internationally, we take reasonable steps to ensure it continues to be protected to a standard comparable to New Zealand law.

9. Data retention

We keep account and usage information for as long as your account is active, and for a reasonable period afterwards to resolve disputes, prevent fraud and enforce our agreements. Tax invoices and billing records are retained for at least seven years to meet Inland Revenue (NZ) record-keeping requirements. Push-to-Talk voice/video recordings and location history are retained only for the period configured by your account administrator, and are deleted or anonymised after that period or on account deletion, whichever is sooner. When a SIM or eSIM is deactivated and later reassigned to a new customer, we do not carry over the previous customer's usage, location or communications history to the new assignee's account.

10. Your rights and choices

Subject to applicable law, you can:

  • Access and correct the personal information we hold about you, from your account settings or by contacting us;
  • Request a copy of, or the deletion of, your personal information (see Section 11);
  • Withdraw consent for location, microphone or camera access at any time via your device settings;
  • Opt out of marketing emails using the unsubscribe link in any marketing message;
  • (California residents) request details of the categories of information collected and shared, and request deletion, without being charged a different price or denied service for exercising these rights;
  • (EU/UK residents) lodge a complaint with your local data protection supervisory authority.

To exercise any of these rights, contact us using the details in Section 16.

11. Deleting your account and data

You can request deletion of your account and associated personal information at any time:

  • In the app/portal: from Account Settings, choose "Delete account", confirm your password and type DELETE to confirm.
  • By email: write to [email protected] from your account email address requesting account deletion — no login or app download is required.

On a verified deletion request, we cancel any active paid SIM subscriptions, release SIMs/eSIMs back to stock, and anonymise your personal account data. We retain de-identified transaction and tax records only as required by law (see Section 9) — these can no longer be linked back to you. Deletion requests cannot be completed while an account has an outstanding unpaid balance.

12. Children's privacy

The Services are intended for business and personal use by adults and are not directed to children. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, contact us and we will delete it.

13. Security

We use industry-standard safeguards — including encryption in transit (TLS), encrypted storage of sensitive fields, access controls, and staff authentication with optional two-factor authentication — to protect your information. No method of transmission or storage is 100% secure, but we work to protect your information and will notify affected users and relevant authorities of any data breach as required by the New Zealand Privacy Act 2020 and other applicable law.

14. Cookies (web portal)

Our web portal uses only strictly necessary cookies/local storage to keep you signed in and remember your session — we do not use third-party advertising or cross-site tracking cookies. Our mobile apps do not use browser cookies; see Section 4 for the device permissions they request instead.

15. Changes to this policy

We may update this policy from time to time to reflect changes to our Services or legal requirements. We will update the "Last updated" date above and, for material changes, notify account holders by email or an in-app notice before the change takes effect.

16. Contact us

If you have questions about this policy or wish to exercise your privacy rights, contact:

PTT NZ Limited
14 Hazeldean Road, Addington, Christchurch 8024, New Zealand
© 2026 PTT NZ Limited. All rights reserved.

We use only strictly necessary cookies/local storage to keep this site working — no third-party advertising or cross-site tracking cookies. Learn more