Privacy & Data Policy
Version 2.1 | Last updated: 30 June 2026
Operated by Snowball Effect Ventures Limited | New Zealand company number 6415354 | NZBN 9429046333681
Your privacy matters
Welcome to BrandKit. When you trust us with account details, customer records, emails, artwork, pricing, supplier information and other business data, you are trusting us with information that matters to your organisation.
This Privacy & Data Policy explains what personal information BrandKit collects, why we collect it, how we use and share it, how long we keep it, and the choices and rights available to you.
We have written this policy to be practical and understandable. It applies to BrandKit's websites, applications, client portals, software, APIs, integrations, support services and related online services.
Our privacy principles
We use the following principles to guide how BrandKit handles information:
- Your customer relationships and business records belong to you.
- We do not sell Customer Data or synced mailbox content.
- We do not use Customer Data to compete with our customers or to benefit another customer, affiliated business or commercial venture.
- We aim to collect and use only the information reasonably needed to provide, secure and improve BrandKit.
- We explain our data practices as clearly as we can.
- We use service providers only where they help us operate BrandKit and are subject to appropriate obligations.
- We continually improve our privacy and security practices as BrandKit develops.
1. Who we are
BrandKit is operated by Snowball Effect Ventures Limited, a company incorporated in New Zealand under company number 6415354 and NZBN 9429046333681.
In this policy, BrandKit, we, us and our mean Snowball Effect Ventures Limited.
For questions, privacy requests or concerns, contact us at support@brandkitcrm.com.
2. When this policy applies
This policy applies when you:
- visit a BrandKit website or public page;
- create or use a BrandKit Account or Workspace;
- use a proposal portal, ordering portal or other client-facing BrandKit page;
- connect a mailbox or another third-party service;
- communicate with our sales, support or product teams;
- participate in a trial, beta, referral or special-offer programme; or
- otherwise interact with BrandKit where we collect personal information.
This policy does not govern the independent privacy practices of a BrandKit customer, supplier or third-party service. Those organisations may have their own privacy policies.
3. BrandKit's role
When BrandKit decides how information is used
BrandKit generally acts as the organisation responsible for personal information used to operate our own business. This includes website visitors, account registration, billing contacts, sales enquiries, support requests, security records, product analytics and communications about BrandKit.
When BrandKit processes information for a customer
A BrandKit customer generally decides why and how information in its Workspace is used. This may include customer contacts, lead records, quotes, orders, artwork, emails, portal users, employee information and other records uploaded or connected by that customer.
For that information, BrandKit usually acts as a service provider or processor on the customer's behalf. The customer remains responsible for its own privacy notices, permissions, lawful basis and instructions.
If you are an individual whose information is held in a customer's Workspace, the customer will usually be the best first point of contact. We will support the customer with valid privacy requests where required.
4. Information we collect
Information you provide directly
Depending on how you use BrandKit, you may provide:
- your name, work email address, telephone number, role and organisation details;
- Account credentials and authentication information;
- billing contacts, subscription details, tax information and payment-related records;
- messages, support requests, feedback, survey responses and meeting notes;
- customer and prospect details, contact records, opportunities, jobs, tasks and notes;
- quotes, orders, products, pricing, margins, supplier information and inventory data;
- logos, artwork, design files, mockups, images and attachments;
- portal information, delivery addresses, approval records and order information;
- emails, calendar-related information or files made available through connected services;
- AI prompts, instructions, uploaded files and feedback on generated outputs; and
- information submitted through referral, partner, beta or special-offer programmes.
Information collected automatically
When you use BrandKit, our systems may automatically collect:
- IP address, browser type, device type, operating system and language;
- approximate location inferred from an IP address;
- login times, Account activity, session records and authentication events;
- pages and features used, button interactions and workflow activity;
- API calls, integration activity, timestamps and technical identifiers;
- performance data, crash reports, diagnostic logs and error information;
- email or notification delivery status and related technical metadata;
- security events, suspected abuse and audit information; and
- cookie and similar technology information.
We use this information to operate the Services, diagnose problems, understand product usage, improve performance, maintain auditability and protect BrandKit and its users.
Information received from other sources
We may receive information from:
- your employer or another administrator of your Workspace;
- Google, Microsoft or another connected service that you authorise;
- payment processors and billing providers;
- referral partners or people who introduce you to BrandKit;
- public business sources, company websites and professional profiles where permitted; and
- service providers that help us prevent fraud, secure Accounts or operate our business.
5. Customer Data
Customer Data is information submitted to, stored in or generated within a customer's Workspace. As between BrandKit and the customer, the customer owns its Customer Data.
BrandKit processes Customer Data only as reasonably necessary to:
- provide and maintain the Services;
- follow the customer's instructions and selected settings;
- deliver support and troubleshoot problems;
- secure the Services and prevent misuse;
- operate integrations and customer-requested workflows;
- meet legal obligations; and
- improve BrandKit using aggregated or de-identified information.
We do not use one customer's private Customer Data to market another business, create advertising audiences, or sell lead lists.
These commitments apply regardless of BrandKit's ownership, management, investors, affiliates or other commercial interests.
Where BrandKit has a relationship with another business operating in the same or a related industry as a customer, that relationship does not permit the other business to access or use the customer's Customer Data.
Access to Customer Data is permitted only where reasonably necessary to:
- provide, maintain, secure or support the Services;
- follow the customer's instructions or respond to a customer-authorised support request;
- investigate suspected fraud, abuse, technical failure or a security incident;
- meet a legal or regulatory obligation; or
- use information that has been aggregated or de-identified so it no longer reasonably identifies a customer, individual or commercial relationship.
6. We do not use your data to compete with you
BrandKit understands that customers may store commercially sensitive information in the Services, including customer lists, prospect details, supplier relationships, pricing, margins, product information, quotes, artwork and private communications.
We do not use private Customer Data to identify sales opportunities, compare customer pricing, target a customer's clients or suppliers, or support the operations of another business.
BrandKit personnel - including founders, directors, employees, contractors and support providers - are prohibited from accessing or using Customer Data for their own commercial purposes, to compete with a customer, or to benefit another customer, affiliated business or commercial venture.
7. Connected mailboxes and third-party integrations
How connections work
BrandKit may allow you to connect services such as Google Workspace, Gmail, Microsoft 365, Outlook, payment providers, ecommerce platforms, supplier systems, file storage services and other business tools.
Connections are established only after an authorised user grants permission through the provider's authentication or consent process.
Mailbox information
When a mailbox connection is enabled, BrandKit may process information such as:
- message and conversation identifiers;
- sender, recipient and participant details;
- subject lines, timestamps and email headers;
- message bodies and attachments;
- labels, folders, draft status and related mailbox metadata; and
- information needed to link messages to contacts, leads, quotes, jobs or other records.
The exact information processed depends on the connected feature, permissions granted and the user's settings.
How mailbox information is used
Mailbox information may be used to:
- display or organise relevant communications within BrandKit;
- associate messages with customer or production records;
- prepare user-requested drafts or summaries;
- extract information for quotes, jobs or workflows;
- send or manage messages where the user has enabled that functionality; and
- support, secure and troubleshoot the connection.
BrandKit does not use private synced mailbox content for personalised advertising, data-broker services or unrelated cold-outreach lists.
Disconnecting an integration
Authorised users may disconnect supported integrations through BrandKit or the third-party provider. Disconnecting stops future access after the revocation takes effect. We delete or invalidate active authorisation tokens in accordance with our operational and security processes, subject to limited retention required for logs, backups, security or law.
8. Google API Services
BrandKit's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data accessed through BrandKit is used only to provide or improve user-facing features that are visible and relevant to the user.
We do not use Google Workspace data for personalised advertising, sell it, or transfer it to data brokers.
Access may involve human review only where the user has given specific consent, where necessary for security or abuse investigation, to comply with law, or where data has been aggregated and de-identified.
9. Microsoft services
When you connect a Microsoft account, BrandKit uses the Microsoft identity platform and Microsoft Graph or related services.
We request permissions that are reasonably necessary for the enabled feature. Depending on the connection, this may include permission to:
- identify the connected user;
- read or manage selected mailbox information;
- create drafts or send messages at the user's direction;
- access related files or records where specifically enabled; and
- maintain the connection using secure authorisation tokens.
Microsoft administrators may control consent and access under their organisation's Microsoft settings. Users or administrators may revoke BrandKit's access through BrandKit or Microsoft.
10. Payments and billing
BrandKit uses third-party payment providers, such as Stripe, to process subscription payments, invoices and where applicable referral payouts.
BrandKit does not store complete payment card numbers or card security codes. Payment providers process those details under their own privacy and security terms.
We may receive and store payment-related information such as:
- billing name and address;
- payment status and transaction identifiers;
- the payment method type and limited card details such as brand and last four digits;
- invoice, tax and subscription information; and
- fraud, dispute or refund information.
11. Artificial intelligence
AI inputs and outputs
BrandKit may provide AI-assisted features for drafting, summarising, classifying, extracting information, suggesting products or workflows, analysing artwork and supporting other tasks.
When you use an AI feature, we may process the prompts, instructions, files, Workspace context and feedback needed to provide that feature.
AI providers
Some AI features may use carefully selected third-party model or infrastructure providers. We provide those providers only with information reasonably required to deliver the requested feature and manage them as subprocessors or service providers where appropriate.
Model training
BrandKit does not sell Customer Data or private mailbox content for AI training. BrandKit does not use private Customer Data to train BrandKit's own general-purpose models unless the customer has expressly agreed to a specific programme that clearly explains that use.
The treatment of information by an underlying model provider depends on BrandKit's agreement and configuration with that provider. We aim to use business or API services that do not train general-purpose models on submitted customer content by default.
Human review
AI inputs and outputs are not routinely read by BrandKit personnel. Limited access may occur where needed to provide requested support, investigate security or abuse, meet legal requirements, or improve a feature using appropriately controlled or de-identified information.
12. How we use personal information
We use personal information to:
- create and administer Accounts and Workspaces;
- provide, personalise and maintain the Services;
- operate portals, workflows, integrations, notifications and AI features;
- process payments, subscriptions, credits and referral rewards;
- provide sales, onboarding, training and customer support;
- send service messages, security alerts and administrative communications;
- understand usage and improve product design, reliability and performance;
- detect fraud, spam, abuse, vulnerabilities and security incidents;
- enforce our agreements and protect legal rights;
- meet accounting, tax, regulatory and legal obligations; and
- send marketing communications where permitted and allow recipients to opt out.
13. Legal grounds for processing
The legal basis for processing depends on the information, the relationship and the country concerned.
Where applicable, BrandKit may process personal information because:
- it is necessary to perform a contract or take requested pre-contract steps;
- we or a customer have a legitimate business interest that is not overridden by privacy rights;
- you have provided consent;
- processing is required to comply with law; or
- processing is necessary to protect rights, security or vital interests.
Where BrandKit processes Customer Data on behalf of a customer, the customer is responsible for identifying its legal basis and issuing lawful instructions.
15. We do not sell your data
BrandKit does not sell, rent or trade Customer Data, private Workspace records or synced mailbox content to advertisers, data brokers or lead sellers.
We may use aggregated or de-identified information for analytics, benchmarking, security and product improvement where the information does not reasonably identify a person or customer.
16. International data transfers
BrandKit is based in New Zealand, but some providers and infrastructure may operate in Australia, the United States, Europe or other countries.
This means personal information may be processed outside the country where it was collected. Privacy laws in those countries may differ.
Where required, BrandKit uses contractual commitments, provider due diligence and other reasonable safeguards for international disclosures or transfers.
Customers with specific regulatory requirements may request further information about relevant subprocessors or enter into a Data Processing Addendum where appropriate.
17. Data security
BrandKit uses administrative, technical and organisational safeguards designed to protect information against unauthorised access, loss, misuse, alteration or disclosure.
These safeguards may include:
- role-based access controls and authentication measures;
- logical separation of customer Workspaces;
- encryption in transit and appropriate encryption or managed protection for stored data;
- restricted access to production systems and secrets;
- logging, monitoring and security review;
- backup, recovery and continuity processes;
- provider due diligence; and
- incident response procedures.
No online service can guarantee absolute security. Customers are also responsible for protecting credentials, managing Authorised Users and configuring permissions appropriately.
Further information is available in BrandKit's Security & Trust documentation.
18. Privacy and security incidents
BrandKit maintains processes to assess and respond to suspected privacy and security incidents.
Where BrandKit becomes aware of a breach involving personal information, we will investigate and take reasonable steps to contain and remediate it.
We will notify affected customers, individuals, regulators or other parties where required by applicable law or contractual commitments.
Customers should promptly report suspected incidents affecting BrandKit to support@brandkitcrm.com.
19. Data retention
We keep personal information only for as long as reasonably necessary for the purposes described in this policy, to provide the Services, meet legal obligations, resolve disputes and maintain security.
Retention periods depend on the type of information. For example:
- Account and subscription records may be retained while the Account is active and for a reasonable period afterward;
- billing and tax records may be retained for legally required accounting periods;
- support and commercial communications may be retained where needed for service history and legal records;
- security, audit and diagnostic logs may be retained for limited operational periods;
- Customer Data is generally retained according to the customer's Subscription, settings and agreement; and
- backup copies may remain until overwritten through normal backup cycles.
After a Subscription ends, Customer Data may be deleted following the retrieval period described in the Customer Terms of Service, unless a different arrangement or law applies.
We may retain aggregated or de-identified information that no longer reasonably identifies a person or customer.
20. Your choices and rights
Depending on applicable law, you may have the right to:
- ask whether BrandKit holds personal information about you;
- request access to that information;
- request correction of inaccurate information;
- ask for deletion or restriction in certain circumstances;
- object to particular processing;
- receive certain information in a portable format;
- withdraw consent where processing relies on consent; and
- complain to a privacy regulator.
These rights are not absolute and may be subject to legal exceptions, identity verification and the role BrandKit or a customer has in relation to the information.
Workspace information
For information held in a customer's Workspace, please contact that customer first. BrandKit will assist the customer where reasonably required.
Marketing
You may opt out of BrandKit marketing emails using the unsubscribe link or by contacting us. You may still receive essential service, billing, security and Account communications.
Access and correction requests
Send requests to support@brandkitcrm.com. Please provide enough information for us to identify you and understand the request. We may ask for reasonable proof of identity or authority.
22. Client portals and end users
BrandKit customers may create proposal portals, ordering portals or other pages for their own clients, staff and contacts.
The BrandKit customer controls the content, purpose, access and information collected through its portal. BrandKit processes that information on the customer's behalf.
Portal users should contact the relevant BrandKit customer with questions about why their information is collected or how it is used.
23. Children
BrandKit is a business service and is not directed to children. We do not knowingly invite children to create BrandKit Accounts.
A customer's lawful use of information about minors in its own business records remains that customer's responsibility.
24. New Zealand, Australian and international privacy rights
New Zealand
BrandKit is subject to the New Zealand Privacy Act 2020 where it applies. This includes principles governing collection, storage, access, correction, use, disclosure, retention and overseas disclosure of personal information.
Individuals may also have the right to complain to the Office of the Privacy Commissioner.
Australia
Where Australian privacy law applies, BrandKit aims to handle personal information consistently with applicable requirements, including relevant Australian Privacy Principles.
Individuals may have the right to complain to the Office of the Australian Information Commissioner.
European Economic Area and United Kingdom
Where the GDPR or UK GDPR applies, individuals may have additional rights, including rights concerning access, correction, deletion, restriction, objection, portability and complaints to a supervisory authority.
BrandKit will provide information about applicable transfer safeguards and processing arrangements where reasonably required.
25. Subprocessors
BrandKit uses subprocessors and service providers to operate the Services. The providers used may change as BrandKit develops.
BrandKit intends to maintain a separate Subprocessors page listing material providers, their purpose and relevant processing locations.
Where required by an agreed Data Processing Addendum, BrandKit will provide notices and objection rights for material subprocessor changes.
26. Changes to this policy
We may update this policy as BrandKit, our providers or privacy laws change.
If a change materially affects how we handle personal information, we will provide reasonable notice through the Services, by email or through another appropriate method.
The date at the top shows when this policy was last updated.
27. Contact us
Have questions about privacy or how BrandKit handles data? Contact us at support@brandkitcrm.com.
BrandKit is operated by Snowball Effect Ventures Limited, New Zealand company number 6415354, NZBN 9429046333681.
If you are not satisfied with our response, you may have the right to contact the relevant privacy regulator in your country.