Legal · Privacy
Privacy Policy.
How we collect, use, store, and share your personal information. Written to comply with the NZ Privacy Act 2020.
Last updated: June 2026.
Who this policy applies to
This policy is published by Craig Smith Business Services Ltd (FSP712931), trading as Smiths Insurance and KiwiSaver. It applies to information we collect from clients, prospective clients, website visitors, and anyone who otherwise interacts with us.
What information we collect
To advise you and arrange insurance or KiwiSaver products on your behalf, we typically collect:
- Identity information: name, date of birth, NZ residency status, IRD number, photo identification.
- Contact information: address, phone, email.
- Financial information: income, debts, assets, household budget, existing insurance and KiwiSaver details.
- Health and lifestyle information: medical history and risk factors required by insurers for underwriting.
- Beneficiary and dependant information you choose to provide.
- Communications: emails, call notes, and meeting records related to your file.
How we use it
- To give you regulated financial advice that meets the FMA Code of Conduct.
- To apply for insurance cover, KiwiSaver transfers, or fund changes on your behalf.
- To run claims and ongoing reviews of your file.
- To meet legal obligations under the Financial Markets Conduct Act 2013, Anti-Money Laundering legislation, and tax laws.
- To communicate with you about your file, market updates, and review cycles.
Who we share it with
We share your information only where it’s necessary to deliver our service to you, including with:
- The insurer or KiwiSaver scheme provider you’ve asked us to apply to.
- Medical providers (with your authority) to obtain records for underwriting or claims.
- Reinsurers and underwriting partners of the insurer.
- Compliance, file-review, and AML-screening service providers we engage.
- Technology providers that host our website, CRM, document storage, and communications on our behalf (see “Where your information is processed” below).
- Advertising platforms, in hashed form only, for ad measurement (see “Advertising, analytics, and cookies” below).
- Regulators and law enforcement when required by law.
We do not sell your information.
Where your information is processed
Some of the service providers we use store or process information outside New Zealand. Specifically:
- Website hosting (Vercel): our website runs on Vercel’s infrastructure, which operates from the United States and a global edge network.
- CRM and document storage (Supabase): form submissions, your client file, and uploaded ID documents are stored with Supabase on Amazon Web Services data centres located overseas.
- Workflow automation (Zapier): a United States–based service we may use to route lead notifications into our internal tools.
- Phone and SMS (Twilio): a United States–based communications provider.
- Email delivery (Resend): a United States–based transactional-email provider.
Where information is held by an overseas provider, we only use providers that are subject to contractual and security obligations that, in our assessment, provide protections comparable to the NZ Privacy Act 2020, as required by Information Privacy Principle 12. Access is restricted to people who need it to do their job.
How long we keep it
- IRD numbers and ID documents are collected solely to arrange your KiwiSaver switch (the new provider requires them to set up your account). Uploaded ID documents are stored in a private, access-controlled bucket and are deleted within 90 days of your switch being completed.
- Your client file and CRM records are retained in line with our retention schedule and the periods required by financial-services regulation (typically seven years from the end of the relationship), then securely destroyed.
Your rights: access, correction, and complaints
Under the Privacy Act 2020 you have the right to:
- Access: ask for a copy of the personal information we hold about you. We’ll respond within 20 working days.
- Correction: ask us to correct anything that’s wrong. If we don’t agree to make the correction, you can ask us to attach a statement of correction to your file.
- Withdraw any consent you’ve given for non-essential uses (including the advertising uses described above).
- Complain to us if you believe we’ve breached this policy.
If you’re not satisfied with our response, you can complain to the Office of the Privacy Commissioner (OPC) free of charge: www.privacy.org.nz, 0800 803 909, or PO Box 10094, Wellington 6143.
Advertising, analytics, and cookies
Our website uses essential cookies and aggregated analytics to understand how pages are used.
We also use the Meta Pixel and Meta’s Conversions API to measure our advertising on Facebook and Instagram. When you submit a form on this site, we may send Meta a hashed (one-way encoded) version of your email address, phone number, and name, together with your IP address and browser information. Meta uses this to match the submission to a Meta account for ad measurement and to help us reach people similar to our clients. We do not send Meta your IRD number, date of birth, address, ID documents, or any financial or health information.
You can read how Meta handles this data in Meta’s Privacy Policy. To opt out, you can: adjust your Meta ad preferences; use browser tracking protection or an ad/tracker blocker (which prevents the Pixel loading); or email us at the address below and ask us to exclude your details from advertising measurement — this does not affect the advice or service you receive.
Contact
Privacy questions: craig@smiths.net.nz or 03 374 6800.
Office of the Privacy Commissioner: www.privacy.org.nz or 0800 803 909.
