Privacy Policy

Effective 22 September 2026 · New Zealand

1. Who we are

KAAL GROUP LIMITED trading as Five Star Growth (“FiveStar”), of 27 Te Pihopa Way, Aidanfield, Christchurch 8025, provides loyalty, digital Wallet, checkout, review and customer-engagement software to participating New Zealand merchants. Contact hello@fivestargrowth.nz for privacy questions, requests or complaints.

2. Information we collect

For merchants and authorised staff, we may collect names, business contact details, approved locations, plan information, account and device activity, support communications, subscription identifiers, billing amounts and status, and security records. Stripe collects and processes payment-card and billing details through its secure Checkout. FiveStar does not store full payment-card numbers.

For FiveStar Affiliate applicants and approved Affiliates, we may collect name, verified email, mobile number, optional region, requested referral-link ending, GST status and number, encrypted bank-account details, Stripe Connect identity and payout status, agreement offers and acceptance evidence, Hub security activity, attributed-business status, commission calculations, statements and payout records. We use this information to assess applications, prevent fraud, administer the referral programme, meet tax and accounting duties, secure Hub access and make authorised payments. Required application information is voluntary, but we cannot assess or operate an Affiliate account without it.

For loyalty customers, we may collect preferred name, mobile number, verified email, merchant-specific consent and suppression status, loyalty balances, visits, purchases, rewards and vouchers, Wallet status, review-prompt activity, checkout-session records and referral relationships. A preferred name may be a first name or a full name chosen by the customer. Online Gift Voucher records connect a claim to its link, reward, eligible branches and expiry. Link analytics use a browser identifier to count visits once per voucher link; using another browser or device may be counted again. Referral records connect the referring customer, referred customer, offer and qualifying purchase so the correct vouchers can be issued and results reported.

We use limited technical information, including browser storage or saved-session identifiers, device and network signals, timestamps and security logs, to recognise returning users, keep the service reliable and prevent misuse. Merchants must provide required collection notices and establish lawful collection and consent, including for imports and information obtained indirectly.

3. Merchant Data and permitted use

As between FiveStar and the Merchant, the Merchant retains all rights in its lawful business records, identifiable customer list, loyalty and transaction records, programme settings, content and branding (“Merchant Data”), to the extent those rights can legally exist. FiveStar claims no ownership of Merchant Data and manages it on the Merchant’s behalf. Personal information is not property either party may freely own or sell. Customers retain their rights under the Privacy Act 2020.

We process identifiable Merchant Data on lawful instructions to operate, secure and support the Merchant’s programme, or as legally required. This includes account verification, loyalty and Wallet features, Online Gift Vouchers, referrals, checkout, rewards, requested transactional communications and consented promotions. We do not sell Merchant Data, share it with other merchants, or use it for unrelated marketing or public AI training. Branch access is restricted to authorised users.

When a business knowingly submits through a named FiveStar Affiliate link, the Affiliate may see the business name, selected plan, onboarding progress, attributed account and branch names and statuses, and commission information connected with that referral. The Affiliate does not receive the owner’s email, phone number, street address, customer list or payment-card details through Hub. The Affiliate’s display name is shown to the referred business so the attribution is transparent. FiveStar may correct or remove attribution where required to prevent error, fraud or unauthorised disclosure.

An authorised business owner may use the password-protected Customers area to view a limited ranked selection of that Merchant’s customers and export its complete customer list. The standard view may show names and mobile numbers, and shows a promotional email address only while the customer has a current merchant-specific opt-in and is not suppressed. Referral rankings show only a name and the final four mobile digits until the owner explicitly opens that customer after a password-backed security unlock. That protected record may then include the full mobile number, verified account email, promotional-consent status and loyalty activity. FiveStar logs protected-detail access. If the owner chooses the Unlock setting on their own device, access may continue for the same signed-in session and location across a refresh; it ends on sign-out, password change, expiry or when the owner presses Lock.

We may create genuinely de-identified or aggregated service statistics. Necessary billing, security, fraud-prevention and legal records may be kept for our lawful duties.

4. Consent and returning customers

Promotional consent is merchant-specific, unticked for new customers by default, and separate from account verification. Customers can participate in loyalty without promotional email. Returning customers’ saved promotional preference is shown with an explicit option to change it. Opening another signup, Online Gift Voucher or referral link alone does not change that preference.

Every marketing email must identify the sender and include a working unsubscribe method. We provide consent and suppression controls. Unsubscribe requests must be honoured promptly and within legal time limits; suppression must not be bypassed. After unsubscribe, plaintext promotional email data is removed where designed. A protected suppression hash may remain to prevent accidental re-enrolment or further marketing. Contact information needed separately for requested transactional messages remains subject to the retention rules below.

5. Vouchers, referrals and transactional messages

A valid saved session may recognise a returning customer without another email verification. When verification is needed, we use it to confirm the customer’s account. We may check submitted email or mobile details for existing merchant membership before sending a new-customer referral verification.

Requested verification, account access, personal referral-link and issued-voucher messages are transactional and do not sign a customer up for promotional email. After the friend meets the referral offer’s saved qualifying-purchase terms, the referring customer and their friend may each receive their own voucher confirmation. Referral messages may identify the relevant friend or referring customer by preferred name and the merchant, so recipients understand why the voucher was issued. They do not disclose payment-card details or unrelated purchase records. Customers can view their available vouchers and choose whether to save a pass to their device’s Wallet.

6. Service providers and overseas processing

We use providers for payments and Affiliate payouts, identity checks, hosting, databases, email delivery, digital Wallets, monitoring and security. These may include Stripe, Supabase, Vercel, Resend, Google and Apple. Providers receive only information needed for their services and must have confidentiality and suitable security duties.

Some information may be processed outside New Zealand under required safeguards. Provider terms, access controls and other measures are intended to provide comparable protection. Provider and processing-location details are available on request. We will notify material provider changes in advance where practicable and address reasonable privacy objections.

7. Security and privacy incidents

We maintain reasonable technical and organisational safeguards, including encrypted connections, separation of merchant access, restricted staff access, protected credentials, security logs, patching and appropriate backups. Merchants must protect their devices and credentials. No internet service can guarantee complete security or uninterrupted availability.

We will notify the Merchant without undue delay of a discovered privacy breach affecting its data, share available facts, contain and investigate the incident, and assist with remedies. We will promptly assist lawful access, correction and deletion requests. FiveStar and the Merchant each retain their own legal duties concerning notification to the Privacy Commissioner and affected people.

8. Export, closure and retention

During service or within 30 days of closure, the Merchant may request a free standard export of its records, including available balances, history and consent status. We will supply it within 10 working days, subject to verifying authority, customer privacy rights and legal restrictions. A disputed bill alone cannot justify withholding an export.

We retain identifiable information only for as long as needed for the service, legal obligations, disputes and security. Following closure and the export opportunity, we delete unnecessary active data and allow protected backups to expire under our retention schedule, available on request. Necessary legal, transaction, security and suppression records remain protected. Confidentiality survives closure. Planned permanent product closure includes the notice and export protections in the Merchant Terms & Conditions.

9. Access, correction and choices

You may ask whether we hold your personal information and request access to or correction of it. We may need to verify your identity and coordinate with the relevant merchant. We will assist lawful deletion requests, taking account of retention duties and information needed to protect your rights. You can withdraw promotional consent without losing your loyalty account.

Contact hello@fivestargrowth.nz with the merchant name and enough information to locate your record safely. This policy does not limit an individual’s rights or replace statutory processes for handling their requests.

10. Complaints and changes

Please contact us so we can investigate a privacy concern promptly. You may also contact the New Zealand Office of the Privacy Commissioner. We may update this policy as the service or law changes and will update its effective date or provide additional notice for material changes. An online policy update does not remove protections or lifetime entitlements already agreed in a signed merchant agreement.