Hurrah

Last updated · 2026-05-13

Privacy Policy

Hurrah Reviews (“the Service”) is a product of OPT Digital Limited (NZBN 9429052206474), registered in Wellington, New Zealand. Throughout this policy, “Hurrah” and “we” refer to the Service operated by OPT Digital Limited. This policy explains what we collect, why, where it is stored, and the rights you have under New Zealand’s Privacy Act 2020, Australia’s Privacy Act 1988 (with the 2024 amendments), the California Consumer Privacy Act (as amended by CPRA), and equivalent state laws in Virginia, Colorado, Texas, and others as they come into force.

1. Who is responsible for your data

For data submitted by a workspace owner (the small business signing up to use Hurrah), Hurrah acts as a data processor. The workspace owner is the data controller — they decide which contacts to upload and what messages to send.

For account data (email, name, billing) that the workspace owner gives us directly, Hurrah is the controller.

2. What we collect

  • Account data: email, name, password hash, workspace name, billing address, payment-method metadata (card last 4 only — full card numbers go to Stripe).
  • Workspace data: contact lists uploaded by the workspace owner (name, email, phone, postal address, source system, country), templates, sequence configurations.
  • Sending telemetry: when an email was sent, opened, or clicked; bounce + complaint events; unsubscribe events. Sourced from Resend webhooks.
  • Review data: star ratings, written reviews, and private feedback that recipients submit on the smart-link landing page.
  • Operational logs: IP address + user-agent on auth events for fraud detection (retained 90 days).

3. Where it lives

Application data (workspaces, contacts, templates, review_requests, events) is stored in Supabase, a managed PostgreSQL platform hosted on AWS infrastructure in the United States. This is a cross-border transfer for NZ + AU + EU residents. Supabase is bound by a Data Processing Agreement and Standard Contractual Clauses; the relevant DPA is published at supabase.com/legal/dpa.

Email delivery flows through Resend (US). SMS delivery flows through Twilio (US). Payment data flows through Stripe (US). When the AI review-assist feature is enabled, draft text is sent to Anthropic (US). Each is a sub-processor; the current list is maintained in our DPA at /dpa.

Sharing.We do not sell, rent, or share your personal information (or your customers’ personal information) with third parties for their own marketing purposes. Mobile phone numbers and SMS opt-in information are specifically not shared with third parties or affiliates for marketing or promotional purposes — these are collected solely to deliver review-request SMS on behalf of the workspace owner who collected them, and are never transferred to a third party except for the operational sub-processors listed above (Twilio, for SMS delivery only). Data is only disclosed to those sub-processors (and in our DPA) for the purpose of operating the Service, or where required by law.

4. Why we collect it (lawful bases)

  • Performance of contract (NZ IPP 1 / AU APP 3 / GDPR Art 6(1)(b)): account data + workspace data needed to deliver the Service.
  • Legitimate interests: operational logs for security, aggregated usage telemetry to improve the product.
  • Consent: AI review-assist is opt-in per workspace owner; only enabled if they tick the box in Settings.
  • Legal obligation: financial records retained per AU/NZ tax law (7 years).

5. How long we keep it

  • Active workspace data: for the life of your subscription + 30 days post-cancellation, then permanent deletion.
  • Sending telemetry: 24 months rolling (compliance defence window).
  • Suppression list (unsubscribes, bounces, spam complaints): indefinitely — required to honour unsubscribe even after account closure.
  • Operational logs: 90 days.
  • Financial records: 7 years from invoice date.

6. Your rights

You can ask us to access, correct, port, or delete your personal information. If you’re a recipient of a review request (not a workspace owner), the workspace owner who sent it is the primary point of contact, but we will pass requests through to them and follow up.

  • NZ residents: rights under Privacy Act 2020 IPPs 6, 7, 13. Complaints to the Office of the Privacy Commissioner: privacy.org.nz.
  • AU residents: rights under APP 12, 13. Complaints to the OAIC: oaic.gov.au.
  • California residents: rights under CCPA/CPRA — know, delete, correct, opt-out of sale/sharing (we do not sell), limit use of sensitive personal information. Submit at ben@opt.co.nz.

7. Marketing-message specific notes

Hurrah is used to send review-request emails and SMS messages. By design every outbound email includes the sender’s identity, postal address, and a one-click unsubscribe link (Gmail/Yahoo bulk-sender compliant per RFC 8058). Every outbound SMS identifies the sending business and includes opt-out instructions (“Reply STOP to opt out”). Unsubscribe and STOP events propagate to the workspace owner’s suppression list within seconds and are honoured for all future sends per CAN-SPAM §316.5, AU Spam Act s.18, NZ UEMA s.11, and the US TCPA.

8. Security

Data is encrypted at rest and in transit (TLS 1.2+). Workspace separation is enforced by PostgreSQL Row-Level Security policies. Service-role credentials are stored in a managed secrets vault and never logged.

9. Changes

Material changes to this policy are notified by email to the workspace owner and posted at the top of this page with an updated “Last updated” date. Continued use after the effective date is acceptance.

10. Contact

Questions, requests, or complaints: ben@opt.co.nz.