Privacy Policy
wlbr
This policy explains what we collect and why, and the controls you have over your data. You can download a copy of your data or delete your account at any time from your account settings. This document is provided in good faith and is not legal advice.
1. About this Privacy Policy
This Privacy Policy explains how Financial Technologies Limited, trading as wlbr ("wlbr", "we", "us"), collects, uses, stores, discloses and protects your personal information. We handle personal information in accordance with the Privacy Act 2020 and its Information Privacy Principles.
It applies to everyone who uses the wlbr platform, both Buyers who fund escrow payments and Sellers who receive them. By using wlbr you agree to the handling of your information as described here.
2. What information we collect
We only collect personal information we need to run the escrow service, process payments and keep it safe. This includes:
- Account details: your name, email address, and the password hash used to sign you in.
- Business and profile details: your display or business name and contact email, used to identify you on payments.
- Verification information: where required to meet our AML/CFT obligations, identity information (such as government photo ID and proof of address), which we hold securely and restrict to authorised review staff only.
- Payment information: the escrow payments you fund or receive, their amounts, references and status, and movements into and out of our client trust account. Funds move by bank-to-bank transfer initiated through a New Zealand open-banking provider. We store the bank account details a Seller nominates for payouts in encrypted form; we do not collect or store your internet-banking login or card details.
- Technical information: limited log data such as IP address and browser type captured at key events (for example, when you accept the Terms) to keep the platform secure.
We also receive information about you from third-party services we use to operate the platform:
- Identity and AML/CFT verification: we use Didit, a third-party identity and transaction monitoring provider, to verify identities and screen payments against AML/CFT obligations. Didit may collect biometric data (a liveness check and document scan) directly from you on our behalf, and it returns a structured verification result and risk assessment to us. Its privacy policy is available at didit.me/privacy.
- Business register lookups: we query the New Zealand Companies Office NZBN register and the Licensed Building Practitioners (LBP) register to confirm business and practitioner details you provide. These are public registers and the information returned is not stored beyond what is needed for the check.
- Open-banking account data: when you authorise a bank transfer through Akahu (our open-banking provider), Akahu shares your nominated account details and transaction reference with us to initiate and confirm the payment. Akahu collects and processes that data under its own privacy policy, available at akahu.nz/privacy.
- Accounting integration: if you connect your Xero organisation, we receive invoice and account data from Xero in order to link payments to invoices and reconcile your accounts. This data is processed only as you direct.
3. How we use your information
We use your personal information to:
- create and operate your account and the escrow service;
- create, fund, hold, release and refund escrow payments, and pay out to Sellers;
- verify identity and meet our Anti-Money Laundering and Countering Financing of Terrorism Act 2009 obligations;
- detect, prevent and investigate fraud, abuse and security incidents;
- provide support, send service notifications, and handle complaints and disputes; and
- comply with our legal obligations.
We do not sell your personal information. We do not use it for unrelated marketing without your consent.
4. When we share information
We share personal information only where necessary:
- with the other party to a payment, for example a Buyer and the Seller can see the display name and reference associated with the payment between them;
- with service providers who help us operate (such as our hosting, database, email and open-banking payment providers), under confidentiality obligations;
- with regulators, law enforcement or others where the law requires or permits it, including AML/CFT reporting; and
- if our business is sold or reorganised, with the relevant party, subject to this Policy.
5. Overseas processing
Some of our service providers process data outside New Zealand. By using wlbr you authorise these transfers. The overseas locations and the nature of each transfer are:
- Neon (United States): our database host. All personal information in your account, including payment records and verification outcomes, is stored on Neon infrastructure in the US. Neon is SOC 2 Type II certified and we rely on standard contractual clauses for transfers. Details at neon.tech/privacy.
- Didit (European Union / United States): identity verification and AML/CFT transaction monitoring. Your identity documents and biometric liveness data are processed by Didit's infrastructure, which spans the EU and US. Didit is GDPR-certified. Details at didit.me/privacy.
- Resend (United States): transactional email delivery. Service notifications (payment receipts, status updates, dispute notices) are relayed through Resend's US infrastructure. Details at resend.com/privacy.
- Vercel (United States): web hosting and serverless compute. Your HTTP requests to wlbr are handled by Vercel infrastructure in the US and edge locations globally. Details at vercel.com/legal/privacy-policy.
We take reasonable steps to ensure overseas providers maintain safeguards comparable to the New Zealand Privacy Act 2020. Where a provider operates under GDPR, SOC 2, ISO 27001, or equivalent certification, we treat this as meeting the comparability requirement. If you would like more detail about a specific transfer, contact us at support@wlbr.app.
6. Storing and protecting your information
We take reasonable steps to keep your information safe, including encryption in transit, encryption of nominated bank account numbers at rest, access controls that restrict sensitive verification documents to authorised review staff, and signed/secured sessions.
We keep personal information only for as long as we need it for the purposes above or as required by law. AML/CFT records, for example, must be kept for at least five years. When information is no longer needed, we delete or de-identify it.
7. Your rights: access, correction, export and deletion
Under the Privacy Act 2020 you have the right to ask for access to the personal information we hold about you, and to request that we correct it if it is wrong. wlbr also gives you self-service tools in your account:
- Download my data: export a machine-readable copy of your account, business profile, payments and notifications at any time.
- Delete my account: permanently remove your account and personal profile data. Some records tied to completed payments or AML/CFT obligations may be retained in a minimised form where the law requires, and cannot be deleted while you have funds in escrow or an open dispute.
You can also contact us at support@wlbr.app to exercise any of these rights. If you are not satisfied with how we handle your information, you may complain to the Office of the Privacy Commissioner (privacy.org.nz).
8. Changes and contact
We may update this Privacy Policy from time to time. The version and effective date are shown at the top. If we make material changes we will take reasonable steps to let you know.
Questions about privacy can be sent to support@wlbr.app.