Privacy Policy

Your privacy is of the upmost importance to us. We have built our business on the core principles of trust and privacy.
When you become a customer we collect personal information from you, including information about your:

  • Name
  • Contact information
  • Residential and mailing addresses
  • Computer or network information
  • Interactions with us
  • Billing or purchase information
  • Other personal information such as date of birth and place of birth

We collect your personal information in order to:

  • Provide services to you
  • Comply with New Zealand’s Anti-Money Laundering and Countering Financing of Terrorism Act 2009

Besides our staff, we may share this information with:

  • Credit card fraud risk scoring provided by Maxmind.
  • One or more identification verification providers in order to verify the information presented (currently our verification partners include Trulioo, Immigration NZ Visa View and AplyID).

We keep your information safe by providing a bank level of digital security, conducting regular security audits and only allowing certain (and vetted) staff to access it.

We keep your information for five years after your account closure at which point we securely destroy it.

You have the right to ask for a copy of any personal information we hold about you, and to ask for it to be corrected if you think it is wrong. If you’d like to ask for a copy of your information, or to have it corrected, please contact us at, or +64 4 831 1333, or PO Box 83090, Wellington 6440, New Zealand.

If you believe you are a victim of fraud or identity theft, please contact us immediately at +64 4 831 1333.

Automatically collected information
For analytical purposes, we use a third-party to collect information about your visit to the Private Box website. To do this we use web cookies.

The type of information we collect automatically

  • The Internet protocol (IP) address from which you access the Internet.
  • The date and time, the Internet address of the website from which you linked directly to our site.
  • The name of the file or the words that you searched, and the browser used to access our site.

We use this information to measure the number of visitors to our site and to identify problem areas. It helps us learn about our visitors. We also use this information to help us design our website to be more user-friendly. This information is never connected with personal information.

Information you volunteer
If you choose to provide us with your personal information by signing up to our service through our website, or by sending us an email, we will use that information to provides services to you.

Signing up to our website is voluntary. If you do not register or provide personal information, you can still use the Private Box site. But you will not be able to use our online postal services.

We at Private Box believe that any information we collect as a valued asset of which we take great care. We will never share or distribute your information to anyone unless one of the following conditions is met:

  • We receive a court order or warrant
  • We reasonably believe that a public sector agency needs the information to investigate or detect criminal activity
  • If we think someone’s safety is at risk

Customer login
The Login on is secured with our own private using SSL 4096-bit key encryption. All users benefit from having an encrypted connection with our server.

Disclosure of contents from mail items
We take the opening and inspection of your mail very seriously, mail will only be opened by Private Box for scanning or for customs export declaration. However, we do not have control over other mail operators who may inspect your items. We take every effort to ensure that your information is not disclosed.

E-mail Notifications
Private Box will occasionally send emails to our customers who have activated ‘Notifications’. We believe direct communication can be an efficient way to present our customers with information about updates and discounts through our services. All communication is controlled by us, no other organisations have access to our customer’s details. All information is given to us remains confidential. We use a third party to send marketing (including newsletters) however we make sure your contact information is kept private by them.

Confidentiality / Security
We use the latest Bank standard PCI security procedures; allowing us to guarantee all our credit card payments. All transactions come under insurance policies so in the unlikely event of your card being compromised; you will be refunded the full amount. We have implemented security policies, rules and technical measures to protect the personal data that we have under our control from:

  • Unauthorised access
  • Improper use or disclosure
  • Unauthorised modification
  • Unlawful destruction or accidental loss

All our employees and data processors who have access to and are associated with the processing of personal data are obliged to respect the confidentiality of our client’s personal data.

We ensure that your personal data will not be disclosed to State institutions and authorities except if required by law or other regulation.

Cloud partners
We use a number of cloud partners in order to deliver services to you. We only use suppliers we trust. Our cloud-based partners are:

  • Google apps – we use google drive, gmail and other google services.  To see how Google looks after our customer’s data please see
  • Zendesk – Zendesk provides web-based helpdesk and phone services. View the Zendesk privacy policy.
  • Amazon AWS – we use Amazon Web Services to store digital copies of documents. You can see the Amazon AWS privacy policy, and you can see some of the amazing steps they take for their security. Note – all data is encrypted (“at rest”) with their Simple Storage Service.

Phone calls
We record all phone calls. We use these for quality assurance and training purposes. All recordings are disposed of after six months.

Staff Declaration
To ensure your mail is in safe hands, we check all our staff are trust-worthy and properly trained. This includes doing background checks and advanced testing wherever required.

All staff are required to sign confidentiality agreements and will complete Privacy training to ensure adherence to the privacy principles of the NZ Privacy Act.

Payment disputes
While charge-backs are against our terms and conditions (it is recommended that any disputes over past transactions be handled directly with Private Box staff) in order to investigate these fully we may need to disclose your identity and documents used to verify your identity (as charge-backs are often the result of fraud). We will only disclose these details to our merchant bank – Bank of New Zealand. The Bank of New Zealand’s privacy policy can be seen here. They, in turn, may disclose these details to the card issuing bank (Eg. your bank) to resolve the dispute.

Interest-Based Online Advertising and Google Analytics

We use Google Analytics to monitor the use of and improve our service. And Facebook Ads and Google Adwords attract new customers to Private Box.

We use Google Analytics Advertising features which include:

  • Remarketing with Google Analytics
  • Google Display Network Impression Reporting
  • Google Analytics Demographics and Interest Reporting
  • Integrated services that require Google Analytics to collect data for advertising purposes, including the collection of data via advertising cookies and identifiers

We use Google AdWords for remarketing purposes, see Google’s Remarketing website, as well as the general the Privacy Policy of Google as it applies to AdWords usage for more information.

Please note that:

  • third-party vendors, including Google, will be showing our advertising on websites across the internet
  • third-party vendors, including Google, will be using cookies that have been placed on a user’s device during past visits to our website in order to serve relevant advertisements to the user

Opting out

Complaints / breaches of privacy

If you have a complaint or feel your privacy has been breached please contact us in the first instance. Contact details can be seen here. We will investigate and reply to all queries within 10 working days by our Privacy Officer.

If you are unsatisfied with our response you can contact the Office of the Privacy Commissioner via their website

Last updated: 30th March 2019


StevenPrivacy Policy