GateBud

Privacy Policy · Last updated 4 August 2026

If you scanned a QR code and checked in at a site

The information you entered (your name, company, and any answers or document acknowledgements) belongs to the site you signed into, not to GateBud. We store and process it on that site operator's behalf, as their record-keeping system. If you want to see, correct, or remove your details, ask the site operator first; they can action that directly in GateBud. If you can't reach them, see “Contractors and visitors” below for how we can help.

Who this policy covers

GateBud (“we”, “us”) is a QR check-in and visitor management product for site-based teams, operated by GateBud Limited ( NZBN 9429053810656), a New Zealand business. This policy explains how we handle personal information under the Privacy Act 2020, for two different groups of people:

  • Customers and their staff: the organisations (e.g. site operators, contractors) that sign up for GateBud and the admin/manager accounts they create. We collect this information directly and are responsible for it in the normal way.
  • Contractors and visitors: people who check in at a customer's site via a QR code or check-in link. We collect this information on behalf of the customer, who decides what questions are asked and who has access to the answers. Under the Privacy Act 2020 (s11), GateBud holds this information as an agent of the customer, not as the agency responsible for it.

Contractors and visitors: what we collect and why

When you check in at a site using GateBud, we collect: your name, your company/organisation (if you provide one), your answers to any site questions (e.g. induction questions), acknowledgement that you were shown a site document (and which version), and the time you checked in and out. This forms the site's legal visitor and induction record under the Health and Safety at Work Act 2015; it's collected so the site operator knows who is on site, can account for everyone in an emergency, and can show they met their induction obligations.

Only the site operator's own team can see this information (the people they've given access to GateBud). GateBud staff can access it only to provide support or fix a technical problem, or where the law requires it.

Your check-in details are not used for advertising, not sold, and not shared with anyone outside the site operator's own organisation, except where the law requires disclosure or a service provider processes it strictly on our behalf (see “Where your information is stored” below).

Note on notification emails: if a check-in triggers an email alert to a site manager (a feature the operator can turn on), that email leaves our systems once sent. Anonymising a check-in record afterwards removes the name from GateBud's database, but it cannot recall or edit an email already delivered.

Contractors and visitors: how long we keep your details

Each site operator sets their own retention period for check-in records: 6, 12, or 24 months, or “never automatically remove”. New organisations start with a 24-month window by default; the operator can change or disable it at any time. When a record reaches that age, an automated process anonymises it: your name is replaced with “Anonymised visitor”, your company is cleared, and any free-text answers you gave are replaced with a placeholder. Document acknowledgements, yes/no answers, and timestamps are kept, because they carry no identity but remain part of the site's compliance history. Anonymisation cannot be undone.

A site operator can also anonymise records manually at any time, including in response to a request from you. If you want your check-in details removed and can't reach the site operator directly, contact us at privacy@gatebud.com with the site name and approximate date, and we will pass the request on or action it where we're able to.

Customers and staff accounts: what we collect

If you sign up for GateBud or are added as a team member, we collect your name, email address, and login credentials (stored securely, never in plain text), plus organisation details such as your company name and logo, site names, the questions and documents you configure, and your role/permissions within your organisation. We use this to operate your account, let you manage sites and check-in records, and to contact you about your account or the service.

Where your information is stored

GateBud is built on Supabase (database and file storage) and hosted on Vercel. Data may be stored or processed on servers located overseas (outside New Zealand): our primary database is hosted in Sydney, Australia, and some providers (for example email, backups and error monitoring) are in the United States and the European Union. Where information is held overseas, we take reasonable steps to ensure it is subject to safeguards comparable to the Privacy Act 2020 (consistent with Information Privacy Principle 12), and our service providers are contractually required to protect it. Data is encrypted in transit, and encrypted at rest where supported by our infrastructure providers. A full list of the service providers we use, what they do for us, and where they run is on our Subprocessors page.

We use Sentry for error monitoring, so that when something in the app breaks, we can see and fix it. Error reports may incidentally include technical details of the request that failed; we do not use Sentry for tracking or advertising.

Cookies and analytics

GateBud uses cookies necessary to keep you signed in and to operate the site securely. We also use PostHog, an EU-hosted analytics service, to understand how GateBud is used so we can improve it. Analytics collects usage events (pages viewed, features used) together with device and network identifiers, and may store a small identifier in your browser. For signed-in staff, analytics is linked to your account. For visitors checking in, analytics events never include your name, company, or answers. We do not use advertising or cross-site tracking cookies, and we do not sell analytics data.

On the signed-in staff dashboard only, we also use Microsoft Clarity to record how the dashboard is used (mouse movement, clicks, and heatmaps), so we can spot confusing screens and fix them. Clarity is configured to mask all text and images by default, so what you type and any client or site details on screen are hidden from the recording. Clarity never runs on the public visitor check-in pages, and we do not record your screen or what you type there.

Your rights

Under the Privacy Act 2020 you have the right to ask for access to, and correction of, personal information we hold about you. If you're a customer or staff member, contact us directly at privacy@gatebud.com. If you're a contractor or visitor, your first port of call is the site operator you checked in with (see above); we'll help if you can't reach them.

If something goes wrong

If we become aware of a privacy or security breach that is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected individuals, as required under the Privacy Act 2020.

If you have a complaint about how we've handled personal information and we haven't resolved it to your satisfaction, you can complain to the Office of the Privacy Commissioner: privacy.org.nz or 0800 803 909.

Contact

Questions about this policy or your information: privacy@gatebud.com.

Trust Centre · Terms of Service · Subprocessors