FarmFlow
Draft — awaiting legal review. This privacy policy is a good-faith plain-English draft based on what FarmFlow actually does today. It is published so users can understand our practices before we collect their information. We are seeking review by a New Zealand-qualified lawyer; please treat this as our binding intent but accept that some wording may change.

Privacy Policy

How FarmFlow handles your personal information, and the rights you have under the New Zealand Privacy Act 2020.

Contents

  1. Who we are
  2. What we collect
  3. Why we collect it
  4. Where it's stored
  5. How long we keep it
  6. Who has access
  7. Overseas disclosure
  8. How we protect it
  9. Your rights
  10. Cookies
  11. Changes to this policy
  12. Contact us

1. Who we are

FarmFlow is a dairy farm management web application built and operated by the FarmFlow team, based in New Zealand. We provide software-as-a-service to dairy farmers and their teams under the farmflow.co.nz domain.

When this policy says "we", "us", or "FarmFlow", it means the FarmFlow team. The agent for any privacy enquiries is listed in section 12.

2. What we collect

The personal information we collect depends on how you use the service.

2.1 Visitors to farmflow.co.nz

Our marketing site does not load any third-party analytics, tracking pixels, advertising networks, or social-media trackers. The Netlify edge that serves the site logs basic request data (IP address, request path, timestamp, user agent) for its own infrastructure operations — we do not use those logs and they are managed under Netlify's own privacy practices.

2.2 People who request a free trial or contact us

Our trial-signup form collects: your name, email address, phone number (optional), farm address (optional), and farm name (optional). Our contact form collects your name, email, and the message you send.

2.3 Registered users of the application

Once you sign up for an account at app.farmflow.co.nz, we collect and store everything you enter into the application as part of running your farm. This includes (but is not limited to):

2.4 Information collected automatically while you use the service

3. Why we collect it

We collect personal information for the following purposes, and no others:

InformationPurpose
Email addressTo create your account, verify it, send account and security notifications, and reset your password.
Name + farm nameTo personalise the application and to address you when we email you.
Phone number (optional)So we can contact you about your trial or onboarding if email fails.
Hashed passwordTo authenticate your login attempts. We never store passwords in plain text.
IP + location + user-agent on loginTo detect suspicious logins (e.g. from a country you have never used before) and warn you, and to apply rate limits that block credential-stuffing attacks.
Farm operational data you enterTo run the application — that is the product you signed up for.
Employee personal data you enterTo run payroll, rostering, timesheet and leave features for your farm. You are responsible for telling your employees that you are using FarmFlow to handle their data.
Audit log of significant actionsTo investigate incidents, to detect abuse, and to support compliance enquiries.

4. Where it's stored

Your information is stored across a small number of carefully chosen services:

ServiceWhereWhat's stored there
RailwaySingapore (asia-southeast1) The application and the primary PostgreSQL database where all account and farm data lives, including backups.
ResendUnited States Transactional emails we send you (verification, password reset, suspicious-login alerts). Resend processes the email content and recipient address.
NetlifyGlobal CDN The static marketing site at farmflow.co.nz (no personal data).
cron-job.orgGermany Triggers the daily backup job. Sees only an authentication header, not your data.

5. How long we keep it

6. Who has access

7. Overseas disclosure

Under Information Privacy Principle 12 of the New Zealand Privacy Act 2020 we have to tell you when your personal information leaves New Zealand. As section 4 sets out, your information is stored on infrastructure located in Singapore (Railway), the United States (Resend), Germany (cron-job.org), and globally distributed (Netlify CDN, no personal data).

We rely on each of these providers' contractual commitments to handle data to a standard comparable to the Privacy Act. By using FarmFlow you accept that your information will be processed in those jurisdictions.

8. How we protect it

We apply the safeguards required by Information Privacy Principle 5:

No system is perfect. If we ever experience a security incident that is likely to cause you serious harm, we will notify you and the Office of the Privacy Commissioner as required by the Privacy Act (within 72 hours of becoming aware of the incident).

9. Your rights

The Privacy Act 2020 gives you the following rights. We honour them all:

10. Cookies

We use the minimum cookies needed to operate the service:

CookiePurposeLifetime
session Stores your signed-in session. HttpOnly, Secure, SameSite=Lax. Up to 31 days (we are tightening this to 7 days).
remember_token Keeps you logged in across browser restarts if you ticked "remember me". Up to 31 days.
ff_prefer_full Remembers whether you prefer the full desktop app or the mobile view. Indefinite (you control via UI).

We do not use cookies for advertising, analytics, or cross-site tracking. The marketing site at farmflow.co.nz does not set any cookies of its own.

11. Changes to this policy

We will update this policy when we change what we collect, how we use it, or who we share it with. Material changes will be announced via email to registered users at least 14 days before they take effect.

12. Contact us

For privacy enquiries, data-access requests, or correction requests:

If we cannot resolve your concern, you can complain directly to the Office of the Privacy Commissioner: privacy.org.nz · 0800 803 909

Effective date: 8 June 2026

Last updated: 8 June 2026

Version: 0.1 draft