Sendd Privacy Policy

Last Updated: 25 September 2026

Version: 2.0

This policy applies to Sendd.store, Sendd.market, the Sendd mobile app, Rocky and the Sendd MCP server.


Who we are

Sendd Limited, a New Zealand company, and its wholly-owned subsidiary Sendd, Inc., a Delaware corporation. We refer to both together as “Sendd”, “we” and “us”.

Which entity is responsible for your information depends on which Sendd entity you contract with, as set out in section 1 of the Terms of Use: Sendd Limited for merchants in New Zealand and Australia, Sendd, Inc. for everyone else. Both apply this policy. The two act as joint controllers where the same data is handled by both, principally payment data, since Sendd, Inc. collects Sendd’s own fees for every merchant regardless of contracting entity.

  • Privacy contact: support@sendd.store
  • Privacy Officer: Adiraj Gupta, reachable at support@sendd.store
  • Security and vulnerability reports: support@sendd.store
  • Sendd Limited: 114 Viewmont Drive, Harbourview, Lower Hutt 5010, New Zealand
  • Sendd, Inc.: c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, United States

We work to the New Zealand Privacy Act 2020, the Australian Privacy Act 1988 and the Australian Privacy Principles, the EU GDPR and UK GDPR where they apply to a merchant or a buyer, and United States federal and state privacy laws including the CCPA and CPRA in California.


1. Who is responsible for what

Sendd sits between merchants and their buyers, so the answer differs by data type.

DataControllerSendd’s role
Your Sendd merchant account: name, email, login, business details, billingSenddController
Your buyers’ order data on your own storefrontThe merchantProcessor, on the merchant’s instructions
Your buyers’ order data in a Sendd.market cartThe merchant for their items; the Operator for marketplace operationProcessor for both, and controller for the payment collection below
Orchestrating marketplace payments, and the anti-fraud, sanctions and record-keeping that goes with itSenddController
Platform security, abuse prevention, fraud detection, service logsSenddController
Product analytics on how merchants use SenddSenddController
Storefront analytics about a merchant’s own shop visitorsThe merchantProcessor, on the merchant’s instructions
Shipping records retained and disclosed under our carrier agreementSenddController

A Data Processing Addendum is available on request and applies automatically where the law requires it.


2. What we collect

From merchants. Name, email, password (hashed), business legal and trading name, business address, phone, tax and verification details required by payment providers, billing information including a payment card held on file for monthly fee billing, support conversations, and everything you put into your store.

From buyers, on behalf of merchants. Name, email, delivery and billing address, phone, order contents and history, and, where the merchant enables it, account credentials and marketing preferences. We never receive or store full card numbers. The payment provider handles card data; we receive a confirmation, the card brand and the last four digits.

Automatically. Device and browser information, IP address, pages viewed, session activity, performance and error logs and cookies.

From third parties. Payment providers, for verification status, payout and dispute data. Authentication providers such as Google and Apple sign-in. Fraud and risk providers. Shipping providers, for tracking and delivery events. Infrastructure providers, for security and abuse signals.

The Sendd mobile app. Held on the device: authentication tokens, in the device’s secure storage (iOS Keychain or Android Keystore), cleared on logout. Read from the server but not stored on the device: event details, and attendee name, email, phone, ticket type and check-in status, fetched on demand and not cached. Permissions: camera, used only to scan ticket QR codes; no photos or video are captured or stored. The app does not collect analytics or telemetry, does not use third-party tracking or advertising SDKs, does not store attendee data on the device, and does not access contacts, location, microphone or other sensors.


PurposeLegal basis where GDPR or UK GDPR applies
Providing the Services, running stores, processing ordersPerformance of a contract
Orchestrating and allocating marketplace paymentsContract; legal obligation
Fraud prevention, sanctions screening, platform securityLegitimate interests; legal obligation
SupportContract; legitimate interests
Understanding how people use our own sites and the Sendd product, so we can find where they get stuck and fix itLegitimate interests, and consent for the cookies involved where required
Providing each merchant with analytics about their own storefrontContract, and consent for the cookies involved where required
Running Rocky when you use itContract
Tax, accounting, carrier and regulatory recordsLegal obligation
Marketing to merchantsConsent or legitimate interests where permitted

Where we rely on legitimate interests, we have balanced them against your rights, and you can object.


4. Artificial intelligence

4.1 Rocky

When you use Rocky, your prompt and the store content needed to answer it are transmitted to a third-party AI model provider to generate the response.

We use more than one model provider, and which one handles a given request depends on the task. Different models suit different jobs, and we change them as better options appear. The providers we currently use are listed in section 5, and that list is kept current. We give notice of changes in the same way as any other sub-processor.

What we do not do.

  • We do not train generalised AI models on identifiable merchant or buyer data.
  • We do not permit our model providers to train their models on your content. Where a request is routed through an aggregator, we use the account setting that excludes any provider who would.
  • We do not use buyer personal information to generate content for a different merchant.

Do not paste buyer personal information into Rocky. It does not need it, and doing so sends that information to a model provider for no reason.

4.2 Connecting Sendd to AI tools of your own

Sendd runs an MCP server, which lets an AI assistant work with a store directly. This works in two directions, and both involve your data moving somewhere we do not control.

An AI tool you connect to Sendd. You can authorise an outside AI assistant to connect to your store through our MCP server. Once you do, that tool can read and act on your store data within the access you granted. Whatever it reads goes to whoever operates that tool, under their privacy policy, not ours.

Sendd connecting out to a tool you authorise. Rocky can connect to third-party MCP servers you authorise. When it does, the store data needed for that task is sent to that service.

In both cases:

  • You choose the tool and you authorise the connection. We do not pick it and we do not vet it.
  • These are not Sendd sub-processors and they are not in our list, because the relationship is between you and that provider.
  • You are responsible for what you connect, including holding whatever agreement that provider requires and making sure it is appropriate for buyer personal information if your store data contains it.
  • You can revoke access at any time from your Sendd settings. Revoking stops future access; it does not reach back and delete anything the tool already received.

Grant the narrowest access that does the job. An assistant that only needs to read products should not be authorised to read customers.

4.3 Automated decisions

We use automated checks for fraud, abuse and risk, which can result in a payment being declined, a payout being held or an account being suspended. You can ask for a human review at support@sendd.store.


5. Who we share it with

Our sub-processors

Each is bound by a written agreement, processes personal information only on our instructions for the purpose stated, and is subject to appropriate transfer safeguards.

Infrastructure and hosting

Sub-processorWhat it doesProcessed in
RenderHosts the Sendd application, the merchant dashboard and merchant storefronts. Order and account data sits here.United States
VercelHosts our own websites at www.sendd.store  and www.sendd.market Global edge network
CloudflareDNS, CDN, TLS certificates including for merchant custom domains, DDoS and firewall protection, and Turnstile bot detection at checkout. Sits in front of our application, so request metadata including IP addresses passes through it.Global edge network

Payments

Sub-processorWhat it doesProcessed in
StripeCard processing, connected accounts, payouts, identity verification, fraud and disputes, and billing your card on file for monthly fees. Sendd never receives full card numbers.United States and Stripe’s own regions
Other integrated payment providersProcessing payments on methods you enable. Which providers apply depends on your country and what you switch on; the current list is in your dashboard.Per provider

Email

Sub-processorWhat it doesProcessed in
ResendAll email we send on a merchant’s behalf. Transactional messages such as order confirmations, shipping updates and receipts, and marketing campaigns, which send from the merchant’s own connected domain.United States

Shipping

Sub-processorWhat it doesProcessed in
Auctane / ShipStationShipping rates, labels, tracking and address validationUnited States
GoSweetSpotNew Zealand carrier aggregationNew Zealand
CarriersDelivery. Which carrier depends on the service the merchant selects.Destination country

Analytics, AI and sign-in

Sub-processorWhat it doesProcessed in
PostHogProduct and website analytics, and error monitoring, on Sendd’s own sites and inside the Sendd product only. It does not run on merchant storefronts or at checkout.United States
AnthropicGenerates Rocky’s responses, page builds and suggestions. Which provider handles a request depends on the task.United States
OpenAIAs aboveUnited States
Google, Gemini modelsAs aboveUnited States
OpenRouterRoutes some requests to additional model providers, including open models. The provider that handles a given request depends on the model selected.Varies by model provider
Google and AppleSign-in for merchants and buyersGlobal

This section is the notice. We keep the list above current, and we publish an addition or replacement here at least 30 days before that sub-processor begins processing buyer personal data. We do not send the list out, so check this page if it matters to you.

A merchant may object to a new sub-processor on reasonable data-protection grounds within that 30 day window. If we cannot resolve the objection, they may terminate without penalty.

Merchants and marketplace operators

A buyer’s order data goes to the merchant selling that item. In a Sendd.market cart containing items from several sellers, each seller receives the buyer’s details for their own items, and the marketplace Operator receives order and commission data for the marketplace.

Carriers and certified carrier auditors

Where shipping features are used, delivery data goes to the carrier. Under our shipping-provider agreement we are also required to retain merchant identity, transaction and payment records and disclose them to a certified carrier on request. We do so only where genuinely required.

Where required by law, legal process, a regulator or a payment provider’s compliance obligations. And on a merger, acquisition, financing or restructuring, with notice where required.

What we do not do

We do not sell personal information. We do not share personal data for cross-merchant advertising. We do not market to a merchant’s buyers. We do not cross-market between merchants.


6. Analytics

There are two separate things here and they work differently, so we set them out separately.

6.1 Analytics on the Sendd product, for us

We use PostHog to understand how Sendd itself is used, so we can find where merchants get stuck and fix it.

Where it runs. Our own websites at www.sendd.store  and www.sendd.market , our sign-in and sign-up screens, and the authenticated Sendd dashboard. This is about people using and evaluating Sendd itself, whether they are already merchants or just looking.

On the public marketing pages we use it to understand how people move from reading about Sendd to signing up, so we can work out which parts of that are unclear. In the dashboard we use it to see where merchants get stuck.

What we collect. Pages and screens viewed in the dashboard, actions taken, feature usage, errors and performance data, and the device and browser information that comes with any web request.

Session recording, and exactly where it applies. Recording is limited to the signed-in product. It is easiest to show as a table.

SurfacePage views and eventsSession recording
www.sendd.store  and www.sendd.market YesNo
Sign-in, sign-up and the Sendd dashboardYesYes
Merchant storefronts and checkoutNot by us, see section 6.2No

Where we do record, sensitive inputs are masked and are never captured, including passwords and payment details. If you are browsing our marketing pages, or shopping on a store built with Sendd, you are not being recorded.

What we use it for. Finding and fixing bugs, seeing which parts of setup people abandon, deciding what to build next, and checking whether a change actually helped.

What we do not do with it. We do not sell it. We do not use it to advertise to you. We do not use one merchant’s usage data to benefit another merchant commercially.

Your choice. This runs on our legitimate interest in improving a product you pay to use. You can object, or ask us to exclude your account from session recording, at support@sendd.store.

6.2 Analytics on merchant storefronts, for the merchant

Every Sendd store gets analytics about its own shop: page views, product views, funnels, conversion and similar. This is how a merchant sees what is working.

This is the merchant’s data, not ours. We collect it on their behalf so we can show it to them in their dashboard. The merchant is the controller and we are their processor, exactly as with order data. We do not use a store’s visitor analytics for our own purposes, we do not combine it across stores for anything other than running the service, and we do not sell or share it.

No session recording happens on a storefront or at checkout. Storefront analytics are counts and journeys, not recordings of what you did on screen.

What is collected. Pages and products viewed, referring source, general location derived from IP, device and browser type, and steps through the checkout funnel.

This is built by us and stays with us. Storefront analytics are Sendd’s own, running on Sendd’s infrastructure. No third-party analytics service is involved, and no storefront data is sent to one. Our product analytics provider does not run on storefronts at all.

Cookies and consent. Storefront analytics rely on cookies or similar technologies, which means consent is required in the EEA and the UK before they load. See section 8, which is honest about where that stands today. Each merchant’s own store privacy policy sets out what their store collects.

6.3 Tracking tools a merchant adds to their own store

Merchants can connect their own third-party tools to their storefront, such as Google Analytics or the Meta pixel.

These are the merchant’s tools, not ours. We give merchants the setting; we do not choose the vendor, we do not receive the data, and we are not a party to that arrangement. The merchant decides what to connect and why.

What that means for a shopper. If a store has connected one of these, data about your visit goes to that vendor as well, and the vendor may use it for that merchant’s advertising and measurement. An advertising pixel typically shares data with a large advertising network, and that can extend beyond the store you are on. The store’s own privacy policy and cookie notice say which tools it uses, and we require merchants to disclose them.

Who is responsible. The merchant is the controller for anything their own tools collect, and in some cases a joint controller with the vendor. Those tools are not Sendd sub-processors and do not appear in our sub-processor list, because the relationship is between the merchant and that vendor. If you want that data deleted or want to object, the merchant is the right contact, and the vendor’s own controls may also apply.

What we do. We require merchants to disclose the tools they add and to obtain consent where the law requires it, and where our consent mechanism is in place it governs merchant-added tools too. We can disable a tool that breaks a store, breaches our terms or is used unlawfully.


7. Your rights

Anyone covered by this policy can ask us to access, correct or delete their personal information, to port it, to object to processing based on legitimate interests and to withdraw consent. Email support@sendd.store. We respond within 30 days, or one month under GDPR, extendable by two months for complex requests with notice. We may verify your identity first.

If you are a buyer, your relationship is with the merchant you bought from. Contact them first: they control that data and we act on their instructions. If you cannot reach them, contact us and we will help.

Marketing email is the exception, and you do not need to ask anyone. Use the unsubscribe link in any marketing message. Unsubscribes are monitored and applied automatically at the platform level, so the merchant cannot send you further marketing through Sendd and cannot override it. We keep a record that you unsubscribed, which is how we prove the request was honoured. You will still receive transactional messages about orders you actually place, such as confirmations and shipping updates.

New Zealand. Access and correction under the Privacy Act 2020. You can complain to the Office of the Privacy Commissioner at privacy.org.nz.

Australia. Access, correction and complaint under the Privacy Act 1988. You can escalate to the OAIC at oaic.gov.au.

European Union and United Kingdom. Access, rectification, erasure, restriction, portability and objection. You can complain to your national supervisory authority, or to the ICO at ico.org.uk.

California. The right to know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information, and not be discriminated against for exercising these rights. We do not sell or share personal information as the CCPA and CPRA define those terms.


8. Cookies and tracking

CategoryPurpose
Strictly necessarySign-in sessions, security tokens, cart state, load balancing and Cloudflare Turnstile bot detection
FunctionalPreferences, locale and dismissed notices
AnalyticsTwo kinds, as set out in section 6. Analytics on the Sendd dashboard and our own marketing sites, for us. Analytics on merchant storefronts, for that merchant.

We do not use advertising cookies and we do not track you across other sites. If we introduce marketing or cross-site tracking cookies, we will update this section before they load, not after.

You can block or delete cookies in your browser settings. Blocking the strictly necessary ones will stop sign-in and checkout working.

We honour Global Privacy Control signals where the law requires it. We do not currently act on browser Do Not Track headers.

Analytics data goes to PostHog as our processor. It is not sold, and it is not shared with advertisers.


9. How long we keep it

DataRetained for
Merchant account dataWhile the account is active, then 12 months after closure
Order and transaction records7 years, for tax and financial record-keeping
Shipping: merchant identity, transaction and payment recordsThe term of our shipping-provider agreement plus 2 years, as that agreement requires
Payment and dispute recordsAs required by the payment provider and applicable financial regulation, typically 7 years
Support conversations24 months
Security and access logs12 months
Marketing consent recordsUntil withdrawn, then 3 years as proof of consent
Rocky prompts and outputsAs long as needed to provide and debug the service, and no longer than 12 months
Rocky agent action logs, what Rocky did and whenAs long as the Account is active, then deleted with the store
BackupsDeleted data persists in backups for up to 35 days before being overwritten

Deletion requests go to support@sendd.store. Where we must keep something by law, we will tell you what and why.


10. Where your information is processed

Sendd is a New Zealand company operating internationally, and personal information is processed in more than one place depending on what it is for.

  • Our core platform, meaning the application, the dashboard, storefronts, our databases, email sending and analytics, is hosted in the United States.
  • Delivery and carrier services are processed where the service operates. New Zealand carrier aggregation is processed in New Zealand, and delivery data goes to the destination country for the parcel.
  • Content delivery and security run on global edge networks, so request metadata is handled at whichever location is nearest the visitor.
  • Payments are processed by our payment providers in their own regions.

The processing location for each individual provider is set out in section 5, and that table is the authoritative answer rather than this summary. If we add processing in a new region, we update it there.

What this means for you

Where you areWhat applies
New ZealandSome of your information is processed overseas. We rely on Information Privacy Principle 12 and take reasonable steps to ensure our overseas processors protect it comparably to the Privacy Act 2020, which we do through our contracts with them.
AustraliaAustralian Privacy Principle 8 applies, and we take reasonable steps to ensure our processors handle your information consistently with the Australian Privacy Principles.
European Union and United KingdomWhere information leaves the EEA or the UK, we rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, together with transfer risk assessments, and on our processors’ own certifications where they hold them.
ElsewhereYour information may be processed in any of the locations named in section 5.

11. Security and breaches

We maintain encryption in transit and at rest, role-based access controls, authentication controls, monitoring and logging and periodic security review.

If a breach occurs we will investigate and contain it, and notify affected individuals where the breach is likely to cause them harm or where the law requires; the Office of the Privacy Commissioner in New Zealand as soon as practicable, where it is a notifiable privacy breach under the Privacy Act 2020; the OAIC, EU and UK supervisory authorities within 72 hours where GDPR applies and US state regulators, as applicable; and affected merchants, where their buyers’ data is involved, so they can meet their own obligations.

No system is perfectly secure. Report a vulnerability to support@sendd.store.


12. Merchant obligations

If you run a store on Sendd, you are the controller of your buyers’ data. Publish an accurate privacy notice, obtain the consents you need, respond to your buyers’ requests, use buyer data only for the purposes you disclosed, and keep it secure. The default store privacy policy Sendd generates is a template you must review, not a compliance guarantee.


13. Children

The Services are not directed to children under 13, or under 16 where local law sets that age. We do not knowingly collect their personal information, and we delete it if we learn we have.


14. Changes, and contact

The version published on our site is always the current one, and it is the version that applies. We publish a dated changelog beside it and keep previous versions at sendd.store/legal/archive.

Most updates take effect when we publish them, and we do not notify anyone individually. Where a change materially affects how we collect, use or share personal information, we give merchants at least 30 days by email and in the dashboard before it takes effect, and we do not apply such a change to information already collected unless we have a lawful basis to do so.

Sendd Privacy Team · support@sendd.store

Sendd Limited, 114 Viewmont Drive, Harbourview, Lower Hutt 5010, New Zealand Sendd, Inc., c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, United States

Logo

Contact us

Email: support@sendd.storeTurn your Sendd store into a new stream of distribution and growth.Made with ❤️ in
Wellington, New Zealand
© 2026 Sendd. All rights reserved.