Effective: March 2026

Who We Are

topzite is a website hosting platform operated by Rory, a sole trader based in New Zealand. We help small businesses create and host static websites.

This privacy policy explains how we handle your personal information in line with the New Zealand Privacy Act 2020. We take your privacy seriously and we're committed to being transparent about what we do with your data.

What We Collect

Account information

When you sign up, we collect:

  • Email address — so we can identify your account and contact you
  • Password — stored securely as a hash (we never see or store your actual password)

Site content

When you build your website, you may provide:

  • Business name and contact details — for your website's public pages
  • Images and media — photos, logos, and other files you upload
  • Text content — descriptions, blog posts, menu items, and other written content

Remember: any information you put on your published website is visible to the public. We're talking about the content you choose to publish, not hidden account data.

Technical information

When you use the CMS or visit your site, some technical data is collected automatically:

  • IP address and browser type — for security and basic analytics
  • Usage data — pages visited, features used, error logs

What we don't collect

We don't collect anything beyond what's listed above. We don't track you across other websites, we don't build advertising profiles, and we don't buy data about you from anyone.

Why We Collect It

We only collect personal information for specific, practical reasons:

  • To provide the service — your account needs an email and password to work; your content is what makes your website
  • To communicate with you — service updates, security notices, and support
  • To keep things secure — detecting and preventing unauthorised access or abuse
  • To improve the platform — understanding how people use topzite so we can make it better

We do not sell, rent, or share your personal information for marketing purposes. Full stop.

Where Your Data Is Stored

Infrastructure

Your data is stored and processed using cloud infrastructure in the Asia-Pacific region:

  • AWS ap-southeast-2 (Sydney, Australia) — your account data (in DynamoDB), uploaded files (in S3), and authentication (via Cognito) are all hosted in AWS's Sydney data centre
  • Cloudflare CDN — your published website is cached and served from Cloudflare's global network of data centres, which means copies of your public site content may be stored temporarily in multiple countries

Cross-border data transfers

Because our infrastructure is hosted in Australia and Cloudflare operates globally, your data may be processed outside of New Zealand. We've chosen reputable providers with strong security practices and data protection commitments.

Under the NZ Privacy Act 2020, we ensure that any overseas recipients of your personal information are subject to comparable privacy protections.

Third-Party Services

We use a small number of trusted third-party services to run topzite. These providers only process your data as needed to deliver their services to us:

  • Amazon Web Services (AWS) — cloud infrastructure, database, file storage, and authentication. Based in the US, data hosted in Sydney, Australia
  • Cloudflare — CDN, DNS, and DDoS protection. Based in the US, operates globally
  • Stripe — payment processing (coming soon). When we add paid billing, Stripe will handle your payment details. We won't store your credit card information ourselves

We don't use any advertising networks, tracking pixels, or social media trackers.

Cookies & Local Storage

We keep cookie usage to a minimum. Here's exactly what's stored in your browser:

  • Authentication tokens — when you sign in to the CMS, your session tokens are stored in your browser's localStorage (via AWS Cognito). These keep you logged in and are cleared when you sign out
  • Cloudflare cookies — Cloudflare may set cookies for bot detection and security purposes (e.g., __cf_bm). These are functional cookies required for the service to work properly

We don't use any tracking or advertising cookies. There are no analytics cookies from Google, Facebook, or anyone else.

Your Rights

Under the New Zealand Privacy Act 2020, you have the right to:

  • Access your data — ask us what personal information we hold about you
  • Correct your data — ask us to fix anything that's wrong
  • Delete your data — ask us to remove your personal information and close your account

To make any of these requests, email us at [email protected]. We'll respond within 20 working days, as required by the Privacy Act.

If you're not happy with how we've handled a request, you can make a complaint to the Office of the Privacy Commissioner.

Data Retention

We keep your personal information for as long as you have an active account and sites on topzite.

When you delete a site, the content and files for that site are removed. When you close your account, all your personal data is deleted.

After account closure, we may retain some data for a short period (up to 30 days) to handle any outstanding issues, after which it is permanently deleted.

We may retain anonymised, aggregated data (like total number of sites hosted) that can't identify you personally.

Data Breaches

We take security seriously and work to prevent data breaches. However, if a breach does occur that affects your personal information, we will:

  • Notify you — we'll let you know what happened, what data was affected, and what we're doing about it
  • Notify the Privacy Commissioner — as required under the NZ Privacy Act 2020, we'll report notifiable breaches to the Office of the Privacy Commissioner
  • Take action — we'll work to contain the breach and prevent it from happening again

Changes to This Policy

We may update this privacy policy from time to time. If we make significant changes, we'll let you know by email or by placing a notice on the website.

The "Effective" date at the top of this page tells you when it was last updated.

Contact Us

If you have any questions about this privacy policy or how we handle your data, get in touch:

Questions about your data?

We're happy to help. Drop us an email and we'll get back to you.

Contact us