Privacy Policy
Seance is provided by Scott Mills, a sole trader in New Zealand (“we”, “us”). This policy explains what personal information we hold, why, who else handles it, and your rights under the Privacy Act 2020.
The short version
- We collect what's needed to run Seance for you — nothing for advertising, and we never sell data.
- Information a business keeps about its customers belongs to that business. We store it on their behalf.
- It's stored in Sydney, Australia, sent over encrypted connections, and protected by your login.
- You can ask to see or correct your information at any time: privacy@seance.co.nz.
1. Two kinds of information
About you as a Seance user (business owners and team members): we're responsible for this, and this policy covers it.
About a business's own customers (names, contact details, addresses, job and invoice details, notes): the business that uses Seance collects and controls this. We hold and process it only as their agent, to provide Seance to them — so under the Privacy Act it's treated as held by that business. If you're a customer of a business that uses Seance, please contact that business about your information; we'll help them respond.
2. What we collect about users
- Account details: your name, email address and password (stored only as a secure one-way hash — we can't see it), your role, and your colour and display preferences.
- Business details you enter in Settings: business name, contact details, address, GST number, bank account for invoices, logo.
- Email sending settings: the address quotes and invoices are sent from, and an app password, which is encrypted before it's stored.
- Work you record: visits you're assigned to, time on site (timer start and stop times), notes you write.
- Support requests you send us, with the page you were on and your browser type, so we can help.
- Security information: failed log-in attempts (to lock out password guessing) and password-reset requests.
3. Public forms and quote links
A business can switch on a public enquiry form, and can send its customers a private link to view and accept a quote. Details entered there (name, contact details, address, message, the name typed to accept a quote, a reason for declining) go to that business, and are stored in Seance on their behalf as described above. We note when a quote link is first opened so the business can see it's been read.
4. How we use it
- to provide Seance: log you in, show your business's information, send the emails you ask it to send;
- to keep Seance and your data secure, and to prevent misuse;
- to answer support requests and tell you about important changes (such as to these policies or pricing);
- to fix problems and improve Seance.
We don't sell personal information, use it for advertising, or share it with anyone for their own marketing.
5. Who else handles it
We use a small number of service providers. They can only use the information to provide their service to us:
- Vercel — hosts the Seance website and app (servers in Sydney, Australia; Vercel is a US company and its network may pass traffic through other countries).
- Neon — our database, where all Seance data is stored (Amazon Web Services, Sydney, Australia).
- Your business's own email provider (for example Google or Microsoft) — quotes, invoices, reminders and notifications are sent through the email account the business connects.
- Photon (by komoot, Germany) — when you type an address, what you've typed is sent to find matching New Zealand addresses. No names or other details are sent.
- OSRM (Project OSRM) — to estimate drive times, the start and end map points of a trip are sent. No names or addresses are sent.
- OpenStreetMap — map images are loaded from OpenStreetMap's servers, which see your device's internet address, as with any website.
Some of these providers are outside New Zealand. We choose providers with privacy and security protections comparable to New Zealand's, and we'll keep this list up to date. We may also disclose information if the law requires it.
6. Cookies and similar
Seance uses only the cookies it needs to work: a log-in session cookie and a security cookie that protects forms. Your browser also remembers small preferences, like light or dark mode. There are no advertising or tracking cookies.
7. Keeping it safe
- Everything is sent over encrypted (HTTPS) connections.
- Passwords are hashed; connected email passwords are encrypted.
- Each business can only ever see its own information.
- Repeated wrong passwords lock an account for a while; removed team members can no longer log in.
- The database is backed up by our provider.
If a privacy breach is likely to cause serious harm, we'll tell the affected businesses and people, and the Privacy Commissioner, as soon as we practicably can, as the Privacy Act requires.
8. How long we keep it
We keep a business's information while its account is open. When an account is closed, we delete its information within 90 days, and it drops out of our provider's backups within a further 30 days. Before closing, the business should take copies of anything it needs for its own records (for example, invoices it must keep for tax). We may keep a minimal record that an account existed, and support conversations, for as long as needed to handle any questions or disputes.
9. Your rights
You can ask for a copy of the personal information we hold about you, and ask us to correct it. Many details you can change yourself in Settings → Your account. For anything else, email privacy@seance.co.nz. We'll respond within 20 working days, as the Privacy Act requires.
If you're not happy with how we've handled your information, please tell us first so we can put it right. You can also complain to the Office of the Privacy Commissioner at privacy.org.nz.
10. Changes
We'll update this policy when Seance or our providers change. If a change matters, we'll let you know in Seance or by email. The date at the top shows when it last changed. See also our Terms of Service.
11. Contact
Scott Mills (trading as Seance), New Zealand — privacy@seance.co.nz