Last updated: 11 June 2026
At Paidnice, we take your privacy seriously and are committed to protecting the personal information we collect and process. This Privacy Policy (the "Policy") explains how Paidnice Limited ("Paidnice", "we", "us", "our") collects, uses, discloses, and protects personal information when you use our website (paidnice.com) and our accounts receivable automation platform (together, the "Services").
We comply with applicable privacy laws, including New Zealand's Privacy Act 2020 (as amended by the Privacy Amendment Act 2025), the EU General Data Protection Regulation (GDPR) and UK GDPR for our European and United Kingdom users, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) and other applicable US state privacy laws, and Australia's Privacy Act 1988.
By accessing our website or using our Services, you acknowledge that your personal information will be handled as described in this Policy. If you do not agree with this Policy, please do not use our website or Services.
1. Applicability of this Policy
This Policy applies to all users of Paidnice worldwide. Paidnice integrates with third-party services such as Xero, QuickBooks, and Stripe to provide our automated accounts receivable services. This Policy does not cover third-party products, services, or software that you connect to Paidnice. We recommend reviewing the privacy policies of those providers as well.
2. Our Role: When We Act as a Controller or a Processor
It is important to understand the two different roles Paidnice plays:
- As a controller (or "agency" under New Zealand law): When you register for and use Paidnice, we are responsible for the personal information we hold about you and your team, such as your name, email address, and billing details.
- As a processor: When you connect your accounting platform, Paidnice processes personal information about your customers (such as contact names, email addresses, phone numbers, postal addresses, and invoice details) on your behalf and on your instructions, solely to provide the Services. You remain responsible for that information, including ensuring you have an appropriate lawful basis to share it with us and that your own customers are informed about how their information is used.
If you are a customer of a business that uses Paidnice (for example, you have received an invoice reminder, statement, or payment link sent through our platform), the business you deal with controls your information. Please direct privacy questions to that business in the first instance. You may also contact our Privacy Officer, and we will assist or refer your request to the relevant business.
3. Collection of Personal Information
We collect personal information that is necessary to provide our Services, improve our offerings, and comply with legal obligations. This includes:
- Name and contact details (email address, phone number)
- Company and billing information
- Accounting and financial data (e.g., invoices, customer contact details, payment status) from integrated platforms
- Usage data, including user actions, IP addresses, device and browser information, and approximate location
- Communications you send us, including support enquiries
We collect personal information directly from you when you:
- Register for our Services: name, email address, company details, and payment information.
- Use our Services: information about your use of the platform, including metadata such as user actions, IP addresses, device information, and location data.
- Contact us: communications with our support and sales teams are recorded.
- Visit our website: via cookies and similar technologies, as described in our Cookie Policy.
We also collect personal information from third-party sources:
- Xero and QuickBooks integrations: we collect and process accounting data (e.g., invoices, contact details, transaction details) that flows from these platforms into our Services. We follow data minimisation principles and only access and store the data necessary to deliver our core functionality and reporting features.
- Payment providers (e.g., Stripe): if you or your customers use a connected payment provider, we may receive payment-related data (such as payment status and amounts) through that integration. Paidnice does not store or process credit card numbers directly.
Indirect collection notice (IPP3A): Where we collect personal information about individuals indirectly (for example, debtor contact details received through your accounting platform), New Zealand's Privacy Act requires that those individuals are made aware of the collection. As we process this information as your processor, you are responsible for taking reasonable steps to notify your customers, such as through your own privacy notice. This Policy also serves as notice that Paidnice receives such information from our customers' accounting platforms for the purpose of providing accounts receivable services on their behalf, and that individuals have rights of access to and correction of their information as described in section 8.
4. Use and Disclosure of Personal Information
Paidnice collects and processes personal information to:
- Provide our Services: automate accounts receivable processes, including sending invoice reminders, statements, late fees, payment plans, and managing payments (performance of our contract with you).
- Improve our Services: analyse usage to enhance workflows, develop new features, and improve customer experience (our legitimate interests).
- Communicate with you: respond to enquiries and send service-related notifications such as billing and security alerts (performance of contract and legitimate interests).
- Send marketing communications: where permitted by law or with your consent (see section 10).
- Comply with legal obligations: meet requirements under the Privacy Act 2020, GDPR, UK GDPR, US state privacy laws, and other applicable laws.
For users in the EEA and UK, the legal bases noted above apply as required by the GDPR and UK GDPR.
We may disclose personal information to trusted third-party service providers (sub-processors) who assist us in providing the Services, including cloud hosting, payment processing (Stripe), customer support (Intercom), and product analytics (Mixpanel). These providers are bound by contractual obligations to protect personal information and may only process it on our instructions. A current list of sub-processors is available on request from our Privacy Officer.
We do not sell personal information. Our website uses advertising cookies and pixels (such as Google Ads and Meta) for retargeting, which may be considered "sharing" for cross-context behavioural advertising under the CCPA/CPRA; you can opt out as described in section 8 and in our Cookie Policy. We will not disclose your personal information to other third parties without your consent unless required or permitted by law (for example, to comply with a court order or to protect our legal rights).
5. Cross-Border Data Transfers
Paidnice is a New Zealand company serving customers worldwide. To provide our Services, personal information may be transferred to, and processed in, countries outside New Zealand, including the United States and the European Union. We ensure such transfers comply with applicable data protection laws:
- New Zealand Privacy Act 2020 (IPP12): we only disclose personal information overseas where the recipient is subject to comparable privacy safeguards, including through contractual protections.
- GDPR and UK GDPR: for users in the EEA and UK, we rely on Standard Contractual Clauses (and the UK Addendum or International Data Transfer Agreement where applicable), adequacy decisions, or other approved transfer mechanisms. New Zealand holds an EU adequacy decision, meaning personal data may flow from the EEA to New Zealand without additional safeguards.
- US state privacy laws: we handle personal information of US residents in accordance with the CCPA/CPRA and other applicable state laws.
6. Security of Personal Information
Paidnice takes appropriate technical and organisational measures to protect personal information from unauthorised access, modification, or disclosure, including:
- Encryption: all data is encrypted in transit (TLS) and at rest using industry-standard encryption.
- Secure infrastructure: our Services are hosted on a secure cloud platform with continuous monitoring and backups.
- Access controls: access to customer data is limited to authorised staff on a need-to-access basis, protected by strong authentication including enforced two-factor authentication, with full access logging and auditing.
- Data minimisation: we only access and retain the accounting data necessary to deliver our Services.
No method of transmission over the internet is completely secure, and we cannot guarantee absolute security. For more detail, see our Security & Trust page. To report a suspected vulnerability, email hello@paidnice.com.
7. Retention of Personal Information
We retain personal information only for as long as necessary to provide the Services and meet legal obligations. Customer account and financial records are generally retained for 7 years, consistent with tax and financial record-keeping requirements, unless a longer period is required by law. If you disconnect your accounting integration or close your account, you may request deletion of your data. When personal information is no longer required, we securely delete or anonymise it.
8. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal information:
For New Zealand residents (Privacy Act 2020):
- Right to access: request access to the personal information we hold about you.
- Right to correct: request correction of personal information that is inaccurate or incomplete.
- Right to complain: if you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner.
For EEA and UK residents (GDPR / UK GDPR):
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate personal data.
- Right to erasure: request deletion of your personal data in certain circumstances.
- Right to restrict processing: request that we limit how we process your personal data.
- Right to data portability: receive your data in a structured, commonly used, machine-readable format.
- Right to object: object to processing based on legitimate interests, and to direct marketing at any time.
- Right to withdraw consent: where processing is based on consent, withdraw it at any time.
- Right to complain: lodge a complaint with your local supervisory authority, or with the UK Information Commissioner's Office (ICO).
For US residents (CCPA/CPRA and other state privacy laws):
- Right to know/access: request details about the personal information we collect, use, and disclose.
- Right to correct: request correction of inaccurate personal information.
- Right to deletion: request deletion of your personal information, subject to certain exceptions.
- Right to opt out of sale or sharing: Paidnice does not sell personal information. To opt out of "sharing" via advertising cookies on our website, decline non-essential cookies via your browser or cookie settings, or contact our Privacy Officer.
- Right to limit use of sensitive personal information: we do not use or disclose sensitive personal information for purposes beyond those permitted under the CCPA/CPRA.
- Right to non-discrimination: we will not discriminate against you for exercising your privacy rights.
For Australian residents (Privacy Act 1988): you have rights to access and correct your personal information, and to complain to the Office of the Australian Information Commissioner (OAIC).
To exercise any of these rights, contact our Privacy Officer (section 14). We will verify your identity and respond within the timeframe required by applicable law (within 20 working days under the New Zealand Privacy Act, one month under the GDPR/UK GDPR, and 45 days under the CCPA). Where we process information as a processor on behalf of one of our customers, we may refer your request to that customer and assist them in responding.
9. Use of Cookies and Tracking Technologies
Paidnice uses cookies and similar tracking technologies to provide a better user experience, authenticate users and manage sessions, analyse site traffic, remember your preferences, and deliver and measure advertising (including retargeting on platforms such as Google Ads and Meta). You can control cookies through your browser settings, although disabling some cookies may limit the functionality of parts of our website and Services. For more information, please see our Cookie Policy.
10. Marketing Communications
Paidnice may send you marketing and promotional material about our Services, including new features and updates. You can opt out at any time by following the unsubscribe instructions in each email or by contacting our Privacy Officer. Opting out of marketing emails will not affect important service-related communications, such as billing notifications or security alerts. We comply with applicable electronic messaging laws, including New Zealand's Unsolicited Electronic Messages Act 2007.
11. Age Restrictions
Paidnice is a business tool and is not directed at children. We do not knowingly collect personal information from individuals under the age of 16. If you become aware that a person under 16 has provided us with personal information, please contact our Privacy Officer and we will take steps to delete it.
12. Data Breach Notification
In the event of a privacy breach that has caused, or is likely to cause, serious harm, we will notify affected individuals and the Office of the Privacy Commissioner (New Zealand) as required by the Privacy Act 2020, and, where applicable, relevant supervisory authorities under the GDPR and UK GDPR (within 72 hours where feasible) and US state regulators. Notifications may be provided via email, in-app messages, or public notice, depending on the severity and scope of the incident.
13. Updates to This Privacy Policy
We may update this Policy from time to time to reflect changes in our Services, legal requirements, or operational practices. When we make material changes, we will notify you via email or through our website, and the revised Policy will be effective when posted. We encourage you to review this Policy periodically. Your continued use of Paidnice after changes are posted constitutes acceptance of the updated Policy.
14. Contact Us / Privacy Officer
Paidnice Limited is incorporated in New Zealand. Suite 14537, 17B Farnham Street, Parnell, Auckland 1052, New Zealand.
If you have questions, requests, or complaints about this Policy or our handling of personal information, contact our Privacy Officer at hello@paidnice.com. We will respond within a reasonable timeframe and in accordance with applicable laws.
